Skip to content

fix(api): harden presence + reported read paths and trust share formatting - #84

Open
Ayush7614 wants to merge 1 commit into
Twigpine:mainfrom
Ayush7614:fix/presence-reported-trust-robustness
Open

Ayush7614 wants to merge 1 commit into
Twigpine:mainfrom
Ayush7614:fix/presence-reported-trust-robustness

Conversation

@Ayush7614

Copy link
Copy Markdown
Contributor

What / why

Three real, verified gaps — the leftovers after PR #83 hardened the meta/holder/count paths. Each is the outlier against its siblings:

  1. Presence GET+POST HTML-500 on DB failure — app/src/app/api/presence/route.ts:10-12,24 had zero error handling. readPulse/recordBeacon (presence.ts:33,43-53) throw on a configured-DB outage (maybeDb() null is safe, outage throws; memo.ts:37-40 rethrows). Every sibling read route (feed/list/live/search/candles/holders/me/posts) wraps in try/catch → JSON 502 + no-store. The site-wide pulse (LivePulse.tsx:24 beacons every 30s) went silently stale on HTML 500s.
  2. Reported-queue GET missing try/catch + a two-stage client break — app/src/app/api/posts/reported/route.ts:10 threw instead of JSON-erroring, and AdminQueue.tsx:29-30 called await res.json() before checking res.ok with no try/catch (invoked as void load()). So a DB blip became an unhandled promise rejection instead of the graceful error row a JSON error takes. Sibling posts/route.ts:17-32 already wraps both reads.
  3. fmtShare painted NaN%/Infinity% — holders.ts:39-44: NaN <= 0 and NaN < 1 are both false, so NaN fell through to "NaN%"; Infinity → "Infinity%". Rendered in the trust-critical panel (HoldersPanel.tsx:35-37,66,75, TokenProof.tsx:71, trustNotes) where users judge rug risk. Every sibling guards (math.ts fmtCompact/fmtEth, market-format.ts marketUsd, chart-terminal.ts, and fix(api): harden launch read paths — meta error shape, bounded holder swaps, finite count formatting #83's marketCount).

Fix

  • Presence GET + both POST branches: try/catch → JSON 502 + no-store + server log. Rate-limit bucket and prune logic untouched.
  • Reported GET: try/catch → JSON 502 + no-store. AdminQueue load(): defensive JSON parse (non-JSON → moderation queue returned <status>), friendlyError surfacing, setPosts(null) on failure — no more unhandled rejections.
  • fmtShare: !Number.isFinite → "—", matching siblings.

Uniqueness check (no open/merged/closed duplicate)

Verification (all true, nothing faked)

  • Repro: node -e confirms old fmtShare(NaN) → "NaN%", Infinity → "Infinity%"; new → "—" (test added).
  • New/extend tests: holders.test.ts non-finite fmtShare cases, new presence.test.ts (bot allow-list, 64-hex visitor-hash uniqueness/stability).
  • npm test: 1047 pass / 0 fail / 10 skipped (baseline 1045 — +2 new, no regressions).
  • npm run typecheck: clean. eslint on all 7 touched files: clean.
  • Branch: fresh fix/presence-reported-trust-robustness cut from upstream/main@c567605, single commit, no old commits.

…tting

Presence GET/POST were the last JSON read routes without try/catch:
a DB outage turned the site-wide pulse/beacon into HTML 500s
instead of the JSON 502 contract every sibling keeps. Both verbs
now return JSON 502 + no-store with a server log, keeping the
per-IP beacon bucket untouched.

GET /api/posts/reported had the same hole, with a two-stage break:
AdminQueue called res.json() before checking res.ok with no
try/catch (via void load()), so an HTML 500 became an unhandled
rejection instead of the graceful error row. Route now returns
JSON 502; the queue parses defensively and surfaces friendlyError.

fmtShare was the last trust formatter missing the finite guard its
siblings have: NaN painted as 'NaN%' and Infinity as 'Infinity%'
in the holder/trust panel where users judge rug risk. Now '—'.

Tests: fmtShare non-finite, presence bot/hash helpers (new file).
Verified: npm test 1047 pass / 0 fail, typecheck + eslint clean.
@coderabbitai

coderabbitai Bot commented Oct 8, 2026

Copy link
Copy Markdown

Warning

Review limit reached

Only developers with an assigned seat can use this organization's usage-based review budget, and seats here are assigned manually. Ask an admin to assign a seat, or change the review continuation mode in Billing.

Next included review available in 45 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 2255197c-69af-4660-9514-a050d212266e
📥 Commits

Reviewing files that changed from the base of the PR and between c567605 and d8cd2ed.

📒 Files selected for processing (6)
  • app/src/app/api/posts/reported/route.ts
  • app/src/app/api/presence/route.ts
  • app/src/components/launchpad/AdminQueue.tsx
  • app/src/lib/launchpad/holders.test.ts
  • app/src/lib/launchpad/holders.ts
  • app/src/lib/launchpad/presence.test.ts
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant