refactor(web): harden oauth state store and session writes after review

- Drop the FIFO from oauthStates: consumed states left entries behind, so
  an unrate-limited start/cancel cycle grew the slice without bound.
  Evict by oldest expiry instead — the map alone now bounds memory.
- CreateSession runs INSERT + expiry sweep in one transaction.
- slices.Contains replaces a hand-rolled contains; APIBase typo fixed.
- Stale comments and test paths updated; login hover uses --ember-ink.
This commit is contained in:
2026-08-08 08:47:09 +07:00
parent 13e8e73da7
commit 1a7e130f9f
12 changed files with 51 additions and 49 deletions
+1 -1
View File
@@ -162,7 +162,7 @@ func loadConfig() Config {
ClientSecret: os.Getenv("DISCORD_CLIENT_SECRET"),
GuildID: os.Getenv("DISCORD_GUILD_ID"),
RequiredRole: os.Getenv("DISCORD_REQUIRED_ROLE"),
APIBBase: envOr("DISCORD_API_BASE", "https://discord.com/api/v10"),
APIBase: envOr("DISCORD_API_BASE", "https://discord.com/api/v10"),
RedirectURI: os.Getenv("DISCORD_REDIRECT_URI"),
OwnerDiscordID: c.OwnerDiscordID,
}