refactor(web): harden oauth state store and session writes after review

- Drop the FIFO from oauthStates: consumed states left entries behind, so
  an unrate-limited start/cancel cycle grew the slice without bound.
  Evict by oldest expiry instead — the map alone now bounds memory.
- CreateSession runs INSERT + expiry sweep in one transaction.
- slices.Contains replaces a hand-rolled contains; APIBase typo fixed.
- Stale comments and test paths updated; login hover uses --ember-ink.
This commit is contained in:
2026-08-08 08:47:09 +07:00
parent 13e8e73da7
commit 1a7e130f9f
12 changed files with 51 additions and 49 deletions
+3 -4
View File
@@ -27,8 +27,8 @@ func TestOAuthStateUnknownOrExpired(t *testing.T) {
}
}
// The map is capped: a flood of starts evicts the oldest states, and consumed
// states (which leave the FIFO behind) must not defeat the cap.
// The map is capped: a flood of starts evicts older states instead of growing,
// and consumed states must not change that.
func TestOAuthStateEviction(t *testing.T) {
s := newOAuthStates()
key := func(i, salt int) string {
@@ -42,8 +42,7 @@ func TestOAuthStateEviction(t *testing.T) {
t.Fatalf("states after a flood = %d, want %d", got, maxStates)
}
// Consume everything, then flood again: the map stays bounded and the
// eviction loop pops the stale FIFO entries instead of stalling.
// Consume everything, then flood again: the map stays bounded.
for state := range s.expiry {
s.take(state)
}