refactor(web): harden oauth state store and session writes after review
- Drop the FIFO from oauthStates: consumed states left entries behind, so an unrate-limited start/cancel cycle grew the slice without bound. Evict by oldest expiry instead — the map alone now bounds memory. - CreateSession runs INSERT + expiry sweep in one transaction. - slices.Contains replaces a hand-rolled contains; APIBase typo fixed. - Stale comments and test paths updated; login hover uses --ember-ink.
This commit is contained in:
+1
-1
@@ -134,7 +134,7 @@ func discordConfig(stubURL string) web.DiscordConfig {
|
||||
ClientID: "client-1",
|
||||
ClientSecret: "client-secret-1",
|
||||
GuildID: "guild-1",
|
||||
APIBBase: stubURL,
|
||||
APIBase: stubURL,
|
||||
RedirectURI: "https://bm.example.com/auth/discord/callback",
|
||||
OwnerDiscordID: testOwnerID,
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user