fix: cap request bodies, link login error, add book-form retry, guard double add

Limit request bodies to 1 MiB (413 JSON), wire aria-describedby on the
login form, add Retry and cancellation to the book form load, disable
Add entry while a note POST is in flight, and poll pg_isready in README.

Claude-Session: https://claude.ai/code/session_01M9MLit5Ko3X4s7rzC5Kv7X
This commit is contained in:
2026-10-02 14:36:14 -05:00
parent 35ad0b13e2
commit 2512c67893
9 changed files with 72 additions and 13 deletions
+19 -1
View File
@@ -1,4 +1,4 @@
import { screen, within } from '@testing-library/react'
import { fireEvent, screen, within } from '@testing-library/react'
import { describe, expect, it } from 'vitest'
import type { Note } from '../api'
import { dune, renderApp, signedIn } from '../test/helpers'
@@ -77,4 +77,22 @@ describe('NotesJournal', () => {
await user.click(screen.getByRole('button', { name: 'Add entry' }))
expect(await screen.findByRole('alert')).toHaveTextContent('body must be at most 10000 characters')
})
it('posts a double-clicked entry only once', async () => {
const calls = signedIn({
'GET /api/books/7': () => [200, dune],
'GET /api/books/7/notes': () => [200, []],
'POST /api/books/7/notes': ({ body }) => [201, { ...older, id: 12, body: (body as { body: string }).body }],
})
const user = renderApp('/books/7')
await screen.findByText('No entries yet.')
await user.type(screen.getByLabelText('New journal entry'), 'Once only')
const add = screen.getByRole('button', { name: 'Add entry' })
// Two clicks before the pending POST settles; user.dblClick would wait for it and mask the bug.
fireEvent.click(add)
fireEvent.click(add)
await screen.findByText('Once only')
expect(calls.filter((c) => c.method === 'POST')).toHaveLength(1)
})
})