P1 complete: web front, test suite, CI — acceptance ALL GREEN

Fan-out integration + fixes found by the test/acceptance pass:
- FIX ring-buffer: chunks >= capacity skipped bytes now count into the
  monotonic offset (invariant: stream byte k lives at k % capacity) —
  window order was corrupted on unaligned big chunks
- FIX auth: non-numeric cookie expiry no longer bypasses expiration
- FIX protocol: safe-integer validation on ack.bytes / hello.protocol
- FIX @fastify/websocket v11: websocket route must be registered in an
  encapsulated context after plugin load (handler got REST signature)
- FIX flow-control deadlock found by e2e acceptance: client only ACKs
  on data receipt, so pausing with an unACKed residue in (LOW,
  ACK_EVERY] stalled both sides at 0.9 MB. ACK_EVERY now 64 KiB (<=
  LOW invariant, tested) + trailing debounced ACK in the web client
- Web: Vue 3 + Vite + Pinia + Tailwind 4 + vue-i18n (EN/FR) + xterm 6
  (fit + webgl fallback), multiplexed ws-client with reconnect/backoff
  and resync epochs
- Tests: 100 vitest (protocol fuzz, ring edges, auth, pty-manager flow
  control with mocked pty, REST e2e) ; CI Node 22/24 + pack-smoke
- scripts/acceptance-p1.mjs: real daemon + real WS client — boot,
  login, attach, stdin, 10 MB flood w/ ACK (13.7 MB/1.9s, RSS bounded),
  brutal disconnect + replay resync, kill broadcast, SIGTERM drain
This commit is contained in:
2026-06-11 22:29:58 +02:00
parent 4768b606e4
commit e9404cb567
42 changed files with 4624 additions and 32 deletions

View File

@@ -69,7 +69,9 @@ export class AuthService {
const expected = this.sign(payload);
if (sig.length !== expected.length || !timingSafeEqual(Buffer.from(sig), Buffer.from(expected))) return null;
const [tokenId, expiresStr] = payload.split('.');
if (!tokenId || !expiresStr || Number(expiresStr) < Date.now()) return null;
if (!tokenId || !expiresStr) return null;
const expires = Number(expiresStr);
if (!Number.isFinite(expires) || expires < Date.now()) return null;
const row = this.db
.prepare('SELECT id, label FROM auth_tokens WHERE id = ? AND revoked_at IS NULL')
.get(tokenId) as { id: string; label: string } | undefined;