fix(update): use server-side status endpoint instead of GitHub API from browser - #116
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Both
UpdateRibbon.tsxand the check button inAjustes.tsxwere fetching the latest release directly fromgithub.laiyagushi.com/ghapiin the browser. This causes GitHub rate-limit errors (403) on shared IPs (60 req/h unauthenticated), silently degrading to 'no updates available' with no user feedback.The backend already had a proper server-side cached endpoint (
GET /api/update/status) with a 5-minute kv cache, but the frontend was not using it.Fix
UpdateRibbon.tsx: replaced directgithub.laiyagushi.com/ghapifetch withapiFetch('/api/update/status'). The endpoint returns{ current, latest, available }from the server-side cache. Removed the now-unusedcompareSemverhelper andpkgimport.Ajustes.tsxcheckUpdates: same fix - replaced thegithub.laiyagushi.com/ghapicall (including the fallback to/tags) with the server-side endpoint. Removed the deadcompareSemverfunction.Result
-50 lines of duplicated GitHub API logic, +10 lines using the existing cached endpoint. The frontend no longer hits
github.com/ghapiat all - all update checks go through the server, which rate-limits itself via the kv cache (5 min TTL).Verified
npm run build(vite): OKnpm test(vitest): 105/105 passedeslint: 0 errors on touched files