Skip to content

Follow-ups to #257: suggestion-hides-unapproved edge, hiddenChannels privacy test, cache-copy and TTL test gaps #276

Description

@dborup

Follow-ups from pve-agent3's round-2 review of #257 (#251, merged as c6b356de). Details and evidence are in the review comment on #257.

  1. Semantics (minor): an anonymous suggestion can hide a channel the admin never acted on. A channel with stored history whose name the ingestor no longer decrypts through config is listed on master before fix(channels): hide revoked shared channels from the channel list (#251) #257. Examples are a name removed from hashChannels/channelKeys by a hot reload, or a name past the 4096-name cap of builtin-channels.json. After fix(channels): hide revoked shared channels from the channel list (#251) #257, an anonymous suggestion for that name (pending) hides it. Decide on one of these and lock it with a test:
    • hide only names whose proposal has ever been approved (needs history);
    • or document the trade-off.
  2. Test gap: the cache-safety copy in hideRevoked on the default path. TestRevokedFilterDoesNotMutateCacheAndKeepsEncrypted only covers ?includeEncrypted=true, where the slice is already copied. Add the default request, where hideRevoked receives GetChannels' cached slice. The mutant that drops the copy must fail.
  3. Test gap (privacy-relevant): the EXISTS (… transmissions …) clause. Without it, hiddenChannels on the public /api/channels would list proposals that have no traffic, including pending suggestions, which are otherwise admin-only. Add a test that a pending suggestion without traffic never appears in hiddenChannels. Mutant G1 must fail.
  4. Test gap: invalidateApiCache('/channels') in refreshChannelList. The harness api() has no TTL cache, so mutant F3 survives. The same gap exists for onApproved. Add a harness with a TTL cache, or an E2E that revokes and checks the list without waiting 15 s.
  5. Docs: hiddenChannels is global, not per region, and another open tab keeps its old hidden set until it reloads. That also applies after a re-approval. Add one sentence about it.

Activity

  1. added a commit that references this issue on Oct 6, 2026
  2. dborup commented on Oct 6, 2026

    @dborup
    OwnerAuthor

    Fixed by #283 (merged as ffd80527).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requesttype:choreMaintenance, refactoring, cleanup

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions