Fix bugs across app + server, optimize UI/UX, add Gitea CI
Some checks failed
CI / Test (Server, optional) (push) Failing after 2m10s
Windows Build / Build Windows (x64) (push) Failing after 29s
CI / Test (Flutter, Linux) (push) Has been cancelled
CI / Analyze (Flutter) (push) Has been cancelled

Bug fixes (Flutter):
- Wrap multi-statement DB writes (insert/update/delete note, deleteDocument,
  deletePageData, OCR FTS merge, migrations) in transactions to prevent data
  loss on interruption and a read-modify-write FTS race.
- Fix PdfDocument leaks on exception (try/finally dispose) and preserve image
  aspect ratio when stamping images onto PDF pages.
- Guard file-picker against empty selection (was .single -> crash).
- Fix eraser ConcurrentModificationError and unmodifiable-list crash on PDF
  pages; capture page synchronously on save to stop wrong-page data loss.
- Fix Riverpod DB-not-ready races, broken pull-to-refresh, settings load race,
  and search N+1; transform stored annotations on PDF page rotation.
- Normalize pen pressure for devices without a pressure range.
- PPT: single source of truth for slide strokes so ink displays and exports.

UI/UX:
- Material 3 typography, theme-aware colors (dark-mode fixes), hover cursors
  and right-click/visible actions on desktop, keyboard shortcuts (undo/redo/
  save/find), toolbar overflow handling, friendlier empty states, semantic OCR
  status badges, relative timestamps, 1-based page indicators, large-deck PPT
  navigation, and a scratchpad-scope label in split view.

Server (optional backend):
- Persist JWT secret (was per-process random), block path traversal in storage,
  fix CORS '*'+credentials, add OCR job ownership checks, last-writer-wins sync
  guard, constant-time login, and split out heavy OCR deps so the API/tests run
  without them.

CI: Gitea workflows for format+analyze+test (Linux, system sqlite) and a
Windows release build; pristine `flutter analyze`, all Flutter and server tests
green.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-06-21 03:18:00 +08:00
commit 72428dc075
210 changed files with 18171 additions and 0 deletions

View File

@@ -0,0 +1,56 @@
"""File-system document storage for BadNote."""
import os
import shutil
from .config import settings
def _safe_filename(filename: str) -> str:
"""Reduce a client-supplied filename to a safe basename.
Prevents path traversal (e.g. ``../../etc/passwd``) by stripping any
directory components and parent references before the name is joined onto
the storage path.
"""
name = os.path.basename(filename or "")
name = name.replace("\\", "").replace("/", "").strip()
if not name or name in (".", ".."):
name = "document"
return name
def _resolve_within(base: str, *parts: str) -> str:
"""Join ``parts`` onto ``base`` and ensure the result stays inside ``base``."""
base_abs = os.path.abspath(base)
target = os.path.abspath(os.path.join(base_abs, *parts))
if os.path.commonpath([base_abs, target]) != base_abs:
raise ValueError("Resolved path escapes the storage directory")
return target
def save_document(file_bytes: bytes, doc_id: str, filename: str) -> str:
"""Save uploaded file bytes to storage. Returns the stored file path."""
safe_doc_id = _safe_filename(doc_id)
safe_name = _safe_filename(filename)
doc_dir = _resolve_within(settings.storage_path, safe_doc_id)
os.makedirs(doc_dir, exist_ok=True)
file_path = _resolve_within(doc_dir, safe_name)
with open(file_path, "wb") as f:
f.write(file_bytes)
return file_path
def get_document_path(doc_id: str, filename: str) -> str:
"""Return the full path to a stored document file."""
safe_doc_id = _safe_filename(doc_id)
safe_name = _safe_filename(filename)
return _resolve_within(settings.storage_path, safe_doc_id, safe_name)
def delete_document(doc_id: str) -> None:
"""Remove a document's directory and all its contents."""
safe_doc_id = _safe_filename(doc_id)
doc_dir = _resolve_within(settings.storage_path, safe_doc_id)
if os.path.isdir(doc_dir):
shutil.rmtree(doc_dir)