Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
067a34f56d |
@@ -23,6 +23,16 @@ latest run passes.
|
|||||||
|
|
||||||
# Completed Steps
|
# Completed Steps
|
||||||
|
|
||||||
|
- 2026-09-28: frontend reporting client (issue #53): a `Reporter` class posts
|
||||||
|
collected samples to `/api/v1/reports` every `reportInterval` (default 60s) as
|
||||||
|
a per-host delta, with the report-building step a pure exported function of
|
||||||
|
host state; a per-host mark advances only on a delivered POST; at most one
|
||||||
|
report POST is pending at a time and it is abandoned after half the interval,
|
||||||
|
so a slow POST never overlaps the next report and a mark never moves
|
||||||
|
backwards; the samples of an abandoned POST are sent again at the next
|
||||||
|
interval, so a backend that stored them but answered late receives them twice;
|
||||||
|
the per-browser client id works in insecure (plain-HTTP) contexts;
|
||||||
|
`vite.config.js` proxies `/api` to the local backend for `yarn dev`
|
||||||
- 2026-09-28: report ingest correctness (issue #23): a storage failure now
|
- 2026-09-28: report ingest correctness (issue #23): a storage failure now
|
||||||
returns 500 instead of a false `ok`; oversize bodies return 413 (distinguished
|
returns 500 instead of a false `ok`; oversize bodies return 413 (distinguished
|
||||||
from malformed JSON, which stays 400); a `MaxBodyBytes` middleware caps every
|
from malformed JSON, which stays 400); a `MaxBodyBytes` middleware caps every
|
||||||
@@ -42,13 +52,6 @@ latest run passes.
|
|||||||
`OnStop` is idempotent; and `writeTimeout` now exceeds the chi per-request
|
`OnStop` is idempotent; and `writeTimeout` now exceeds the chi per-request
|
||||||
budget so that budget is actually reachable. Dead `startupTime`, `exitCode`,
|
budget so that budget is actually reachable. Dead `startupTime`, `exitCode`,
|
||||||
and `cancelFunc` fields were removed
|
and `cancelFunc` fields were removed
|
||||||
- 2026-09-21: frontend reporting client — a `Reporter` class posts collected
|
|
||||||
samples to `/api/v1/reports` every `reportInterval` (default 60s) as a
|
|
||||||
per-host delta, with the report-building step a pure exported function of host
|
|
||||||
state; only one report POST is in flight at a time and it is abandoned after
|
|
||||||
half the interval, so a slow backend cannot cause re-sent samples or a mark
|
|
||||||
moving backwards; the per-browser client id works in insecure (plain-HTTP)
|
|
||||||
contexts; `vite.config.js` proxies `/api` to the local backend for `yarn dev`
|
|
||||||
- 2026-09-21: backend HTTP hardening (issue #19): added `ReadHeaderTimeout` and
|
- 2026-09-21: backend HTTP hardening (issue #19): added `ReadHeaderTimeout` and
|
||||||
`IdleTimeout` to the server, a `SecurityHeaders` middleware (HSTS, tight CSP,
|
`IdleTimeout` to the server, a `SecurityHeaders` middleware (HSTS, tight CSP,
|
||||||
frame/sniff/referrer/permissions headers) registered before CORS, and
|
frame/sniff/referrer/permissions headers) registered before CORS, and
|
||||||
|
|||||||
Reference in New Issue
Block a user