fix(02-review): purge legacy resource snapshots on schema change (CR-01 follow-up)
CR-01 fixed web5.lnd-info/web5.networking-profits to persist:false, stopping FUTURE writes to sessionStorage, but a tab already open before the update ships reloads in-place onto the new bundle and keeps whatever the OLD bundle already wrote under the old decision — indefinitely, since nothing but clearAll() (logout) ever purges a resource: snapshot. Long-lived tabs (installed PWA, kiosk display) are normal here, so this left updating users exposed to exactly the T-02-01 exposure CR-01 was meant to close. - Add a schema-version marker (resource:__schema) checked once at store setup: absent or stale marker purges every resource:-prefixed sessionStorage key, then writes the current version. One-time per tab session (a matching marker no-ops), not per navigation/reload, so this doesn't defeat the instant-paint-from-snapshot benefit the cache exists for. CURRENT_SCHEMA_VERSION must be bumped whenever a key's persist decision changes, documented inline as the contract for future changes. - Extract clearAll()'s purge loop into purgeAllSnapshots(), reused by both clearAll() (logout, T-02-02) and the new migration, so there's one place that enumerates/removes resource: keys. - Close the residual refresh()/useCachedResource() default: opts.persist ?? true was the exact footgun that caused CR-01 (a call site silently opting into persistence by omission). persist is now a required parameter on refresh() and useCachedResource()'s options, matching the entry()/optimistic() hardening WR-04 already applied. - Tests: legacy snapshot (no/stale marker) is purged on init; a snapshot under the current marker survives a later init (proves one-time, not every-boot); persist:false never writes a snapshot; marker is written after purge; purge is strictly bounded to the resource: prefix (seeded non-resource: sessionStorage keys and a localStorage auth flag survive byte-for-byte); migration cannot race an in-flight fetch (runs synchronously at store setup, before entries/inflight can hold anything). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
db629f6f0e
commit
5bfe608893
@@ -32,9 +32,13 @@ export interface CachedResourceOptions<T> {
|
||||
fetcher: (signal: AbortSignal) => Promise<T>
|
||||
/** Data older than this triggers a background revalidate (default 30s). */
|
||||
ttlMs?: number
|
||||
/** Snapshot to sessionStorage so reloads paint instantly (default true).
|
||||
* Disable for large payloads. */
|
||||
persist?: boolean
|
||||
/** Snapshot to sessionStorage so reloads paint instantly. REQUIRED (no
|
||||
* default) — `persist ?? true` was the exact footgun CR-01 hit (a wallet
|
||||
* resource omitted this and silently persisted balances to
|
||||
* sessionStorage), so every call site must make the decision explicitly.
|
||||
* Sensitive data (money, identity, peer-identity/DID/pubkey payloads)
|
||||
* MUST be `false`; static/aggregate/non-identifying data may be `true`. */
|
||||
persist: boolean
|
||||
/** Revalidate (if stale) when the window regains focus (default true). */
|
||||
revalidateOnFocus?: boolean
|
||||
/** Fetch on first use (default true). Set false for lazy resources. */
|
||||
@@ -61,7 +65,7 @@ export interface CachedResource<T> {
|
||||
export function useCachedResource<T>(opts: CachedResourceOptions<T>): CachedResource<T> {
|
||||
const store = useResourcesStore()
|
||||
const ttlMs = opts.ttlMs ?? 30_000
|
||||
const persist = opts.persist ?? true
|
||||
const persist = opts.persist
|
||||
const entry = store.entry<T>(opts.key, persist)
|
||||
|
||||
const aborter = new AbortController()
|
||||
|
||||
Reference in New Issue
Block a user