Compare commits

..

2 Commits

Author SHA1 Message Date
byGalax b0f9f1dada fix(keysync): silence expected RLS rejections during best-effort backfill
Release desktop app / build (, windows-latest) (push) Has been cancelled
Release desktop app / build (--target universal-apple-darwin --bundles app,updater, macos-14) (push) Has been cancelled
2026-04-19 22:03:49 +02:00
byGalax 961ac2dde5 fix: idempotent conv-key upsert + guard tauri-only notification calls
Release desktop app / build (, windows-latest) (push) Has been cancelled
Release desktop app / build (--target universal-apple-darwin --bundles app,updater, macos-14) (push) Has been cancelled
2026-04-19 22:00:21 +02:00
4 changed files with 47 additions and 20 deletions
+1 -1
View File
@@ -1,7 +1,7 @@
{ {
"$schema": "https://schema.tauri.app/config/2", "$schema": "https://schema.tauri.app/config/2",
"productName": "ChatApp", "productName": "ChatApp",
"version": "0.4.1", "version": "0.4.3",
"identifier": "com.meinname.chatapp", "identifier": "com.meinname.chatapp",
"build": { "build": {
"beforeDevCommand": "pnpm vite:dev", "beforeDevCommand": "pnpm vite:dev",
+14 -3
View File
@@ -164,9 +164,19 @@ async function syncOneConversationGaps(ctx: SyncCtx, convId: string): Promise<vo
try { try {
await shareConvKeyToDevice(supabase, convId, dev.id, pgHexToBytes(dev.public_key), ownCtx); await shareConvKeyToDevice(supabase, convId, dev.id, pgHexToBytes(dev.public_key), ownCtx);
} catch (err: unknown) { } catch (err: unknown) {
// Most common: this device hasn't been wrapped for us yet either, so // Backfill is best-effort. Common silent failures:
// tryGetConvKey couldn't unwrap. Another peer with the key will fill // - This device hasn't been wrapped for us yet either, so
// the gap when they hit syncAllExistingGaps. // tryGetConvKey couldn't unwrap (another peer will fill the gap).
// - RLS rejects because the recipient's owner is a pending (not-yet
// accepted) DM member, or has been removed from the conv.
// Any of these are recoverable — log only at debug level.
const msg = err instanceof Error ? err.message : String(err);
const isExpected =
msg.includes('does not have it yet') ||
msg.includes('row-level security') ||
msg.includes('403') ||
msg.includes('Forbidden');
if (!isExpected) {
console.warn('keySync: shareConvKeyToDevice gap-fill failed', { console.warn('keySync: shareConvKeyToDevice gap-fill failed', {
convId, convId,
recipient: dev.id, recipient: dev.id,
@@ -174,6 +184,7 @@ async function syncOneConversationGaps(ctx: SyncCtx, convId: string): Promise<vo
}); });
} }
} }
}
} }
async function wrapForOneDevice( async function wrapForOneDevice(
+8 -1
View File
@@ -4,6 +4,8 @@ import {
sendNotification, sendNotification,
} from '@tauri-apps/plugin-notification'; } from '@tauri-apps/plugin-notification';
import { isTauriRuntime } from './globalShortcut';
// Tracks whether permission has already been requested this session so we // Tracks whether permission has already been requested this session so we
// don't spam the OS prompt. Actual permission state lives in the OS. // don't spam the OS prompt. Actual permission state lives in the OS.
let permissionChecked = false; let permissionChecked = false;
@@ -12,6 +14,11 @@ let permissionGranted = false;
export async function ensureNotificationPermission(): Promise<boolean> { export async function ensureNotificationPermission(): Promise<boolean> {
if (permissionChecked) return permissionGranted; if (permissionChecked) return permissionGranted;
permissionChecked = true; permissionChecked = true;
if (!isTauriRuntime()) {
// Web preview / Chrome — Tauri notification plugin not available.
permissionGranted = false;
return false;
}
try { try {
let granted = await isPermissionGranted(); let granted = await isPermissionGranted();
if (!granted) { if (!granted) {
@@ -20,7 +27,6 @@ export async function ensureNotificationPermission(): Promise<boolean> {
} }
permissionGranted = granted; permissionGranted = granted;
} catch (err: unknown) { } catch (err: unknown) {
// Not running under Tauri (e.g. web preview) — fall back silently.
permissionGranted = false; permissionGranted = false;
console.warn('notification permission check failed', err); console.warn('notification permission check failed', err);
} }
@@ -40,6 +46,7 @@ interface NotifyOpts {
export async function notify({ title, body, force = false }: NotifyOpts): Promise<void> { export async function notify({ title, body, force = false }: NotifyOpts): Promise<void> {
if (!force && isAppFocused()) return; if (!force && isAppFocused()) return;
if (!isTauriRuntime()) return;
const granted = await ensureNotificationPermission(); const granted = await ensureNotificationPermission();
if (!granted) return; if (!granted) return;
try { try {
+13 -4
View File
@@ -161,7 +161,10 @@ export async function bootstrapConvKey(
}); });
} }
const { error } = await rawFrom(client, 'conversation_keys').insert(rows); const { error } = await rawFrom(client, 'conversation_keys').upsert(rows, {
onConflict: 'conversation_id,recipient_device_id,key_version',
ignoreDuplicates: true,
});
if (error) throw error; if (error) throw error;
const handle = { conversationId, keyVersion, key: convKey }; const handle = { conversationId, keyVersion, key: convKey };
@@ -262,15 +265,21 @@ export async function shareConvKeyToDevice(
recipientPublicKey, recipientPublicKey,
own.privateKey, own.privateKey,
); );
const { error } = await rawFrom(client, 'conversation_keys').insert({ const { error } = await rawFrom(client, 'conversation_keys').upsert(
{
conversation_id: conversationId, conversation_id: conversationId,
recipient_device_id: recipientDeviceId, recipient_device_id: recipientDeviceId,
key_version: version, key_version: version,
sender_device_id: own.deviceId, sender_device_id: own.deviceId,
encrypted_key: bytesToPgHex(wrapped.ciphertext), encrypted_key: bytesToPgHex(wrapped.ciphertext),
nonce: bytesToPgHex(wrapped.nonce), nonce: bytesToPgHex(wrapped.nonce),
}); },
if (error && !String(error.message ?? '').includes('duplicate')) throw error; {
onConflict: 'conversation_id,recipient_device_id,key_version',
ignoreDuplicates: true,
},
);
if (error) throw error;
} }
// Re-exports for convenience. // Re-exports for convenience.