1
Fork 0
mirror of https://github.com/thegeneralist01/archivr synced 2026-07-21 18:55:36 +02:00

fix: address 6 code-review findings

NixOS module (4 fixes):
- Remove RestrictNamespaces=true: Chromium (launched by single-file for
  web captures) needs Linux user namespaces; blocking them broke captures
- Escape TOML string values: labels/paths with quotes or backslashes
  would produce invalid archivr-server.toml and prevent startup
- Bracket IPv6 listen addresses: ::1:8080 is rejected by Rust's
  SocketAddr parser; [::1]:8080 is the correct form (RFC 2732)
- Add optional storePath per archive: covers archives initialised with
  a custom store path outside the default sibling store/ directory

Rust (1 fix):
- extract_client_ip loopback branch: take last XFF value not first.
  When a proxy appends to X-Forwarded-For an attacker controls the
  first entry; the last entry is always set by the trusted local proxy

Frontend (1 fix):
- Gate fetchArchives on authState === 'authenticated'. The empty-dep
  useEffect fired on mount (before login), hit 401, and never retried
  after login because authState was not in the dependency array
This commit is contained in:
TheGeneralist 2026-06-29 21:30:45 +02:00
parent 71e176cbd1
commit 9544e707ed
Signed by: thegeneralist01
SSH key fingerprint: SHA256:pp9qddbCNmVNoSjevdvQvM5z0DHN7LTa8qBMbcMq/R4
3 changed files with 35 additions and 11 deletions

View file

@ -70,8 +70,10 @@ export default function App() {
}
}, [])
// Mount: load archives, pick first, then parallel load
// Load archives once authenticated (re-runs when authState changes so
// it triggers correctly after first login or a session refresh).
useEffect(() => {
if (authState !== 'authenticated') return
fetchArchives().then(list => {
setArchives(list)
if (list.length > 0) {
@ -79,7 +81,7 @@ export default function App() {
setArchiveId(first)
}
})
}, [])
}, [authState])
// Archive change: parallel load entries + runs + tags
useEffect(() => {