7fbbe420bd
Check Cross-Plugin Imports / check (push) Has been cancelled
CRITICAL: - Fix SQL injection in prestart.sh (parameterized query) - Fix secret key validation (always validate, not just production) - Fix workspace model partial index bug (func.text -> text) - Fix HealthResponse schema (add checks field) - Fix Tenant import in permissions.py (NameError on every auth request) - Fix README tech stack (React instead of Alpine.js) - Delete broken test_cross_tenant_security_v2.py - Add fail-closed RLS migration 0084 (48 tenant tables) HIGH: - Add GeneralRateLimitMiddleware for all API routes - Add file type blocklist for DMS and attachment uploads - Fix guest auth: Pydantic schema, tenant_slug required, CSRF bypass - Fix CSRF bypass path matching (in -> endswith) - Add worker healthcheck in docker-compose.yml - Add ARQ max_tries=3 for job retries - Fix 28 bare pass in mail services (-> logger.debug) - Fix print() -> logger in main.py and ai_assistant - Fix duplicate email handling (catch IntegrityError -> 409) - Add session revocation (invalidate_all_user_sessions) - Add resource limits to all containers - Fix CORS default (localhost -> production domain) - Fix SameSite=Lax -> Strict - Fix Redis password visibility in healthcheck - Fix npm vulnerabilities (19 -> 9) - Fix Sidebar OOM (wildcard lucide import -> curated ICON_MAP) MEDIUM: - Localize ErrorBoundary to German - Wire Mail.tsx save/delete filter to API - Document system_notif plugin (no routes needed) - Fix datetime.utcnow() -> datetime.now(UTC) - Pin litellm version (>=1.0,<2.0) - Move CSRF token from sessionStorage to in-memory - Fix restore_backup error handling and transaction - Fix Dms.tsx useEffect cleanup - Add skip-to-content link for accessibility - Add selectinload imports to 3 services - Add .env.example missing variables - Fix AppShell/TopBar/Sidebar test mocks NEW TESTS: - test_guest_auth.py (6 tests) - test_user_service.py (8 tests) - test_backup_service.py (5 tests) NEW SCHEMAS: - saved_filter, saved_view, user_preference, workspace, entity_policy Tests: 22/22 PASSED
85 lines
2.5 KiB
TypeScript
85 lines
2.5 KiB
TypeScript
import React from 'react';
|
|
import { QueryClient, QueryClientProvider } from '@tanstack/react-query';
|
|
import { AppRouter } from '@/routes';
|
|
import { setUnauthorizedHandler } from '@/api/client';
|
|
import { useAuthStore } from '@/store/authStore';
|
|
import { useThemeStore } from '@/store/themeStore';
|
|
import { ErrorBoundary } from '@/components/common/ErrorBoundary';
|
|
import { useToast } from '@/components/ui/Toast';
|
|
import { useOnlineStatus } from '@/hooks/useOnlineStatus';
|
|
|
|
function QueryClientWrapper({ children }: { children: React.ReactNode }) {
|
|
const toast = useToast();
|
|
|
|
const [queryClient] = React.useState(() => new QueryClient({
|
|
defaultOptions: {
|
|
queries: {
|
|
retry: 1,
|
|
staleTime: 5 * 60 * 1000,
|
|
refetchOnWindowFocus: false,
|
|
},
|
|
mutations: {
|
|
retry: 0,
|
|
onError: (error: any) => {
|
|
// Don't show toast for 401 (handled by auth)
|
|
if (error?.status === 401) return;
|
|
const msg = error?.detail || error?.message || 'Ein Fehler ist aufgetreten';
|
|
toast.error(msg);
|
|
},
|
|
},
|
|
},
|
|
}));
|
|
|
|
return (
|
|
<QueryClientProvider client={queryClient}>
|
|
{children}
|
|
</QueryClientProvider>
|
|
);
|
|
}
|
|
|
|
function OfflineBanner() {
|
|
const isOnline = useOnlineStatus();
|
|
|
|
if (isOnline) return null;
|
|
|
|
return (
|
|
<div className="fixed top-0 left-0 right-0 z-[200] bg-warning-500 text-white text-center py-2 px-4 text-sm font-medium shadow-md">
|
|
Sie sind offline. Änderungen werden gespeichert wenn die Verbindung wiederhergestellt ist.
|
|
</div>
|
|
);
|
|
}
|
|
|
|
export default function App() {
|
|
const { logout } = useAuthStore();
|
|
const loadThemeFromStorage = useThemeStore((s) => s.loadFromStorage);
|
|
const toast = useToast();
|
|
|
|
React.useEffect(() => {
|
|
setUnauthorizedHandler(() => {
|
|
toast.warning('Ihre Sitzung ist abgelaufen. Sie werden zur Anmeldung weitergeleitet.');
|
|
logout();
|
|
setTimeout(() => { window.location.href = '/login'; }, 1500);
|
|
});
|
|
}, [logout, toast]);
|
|
|
|
// Load theme from localStorage on app start
|
|
React.useEffect(() => {
|
|
loadThemeFromStorage();
|
|
}, [loadThemeFromStorage]);
|
|
|
|
return (
|
|
<QueryClientWrapper>
|
|
<OfflineBanner />
|
|
<a
|
|
href="#main-content"
|
|
className="sr-only focus:not-sr-only focus:absolute focus:top-2 focus:left-2 focus:z-[300] focus:px-4 focus:py-2 focus:bg-primary-600 focus:text-white focus:rounded-md"
|
|
>
|
|
Zum Hauptinhalt springen
|
|
</a>
|
|
<ErrorBoundary>
|
|
<AppRouter />
|
|
</ErrorBoundary>
|
|
</QueryClientWrapper>
|
|
);
|
|
}
|