v1.1: harden recovery and control boundaries
WP-D and WP-E complete the planned v1.1 implementation packages. WP-D — recovery honesty: - backups verify the completed copy with PRAGMA integrity_check - corruption missed by quick_check is detected by the full check - existing good backups remain protected - oversized exports are still delivered but declare whether this version can import them, while the 20 MB import limit remains unchanged - backup was exercised through the real browser UI on both the normal campaign database and a campaign-shaped database over 100 MB WP-E — control-boundary contrast: - interactive control boundaries meet the WCAG 1.4.11 3:1 target - the contrast audit is now a failing gate rather than an advisory - rendered browser measurements pass for the composer, controls, tabs and nav - text contrast and focus visibility remain intact - owner reviewed and approved the before/after screenshots Reports: - planning/reports/v1.1/V1.1-WP-D-REPORT.md - planning/reports/v1.1/V1.1-WP-E-REPORT.md All planned v1.1 work packages A-E are now complete. Release validation has not yet begun.
This commit is contained in:
@@ -129,6 +129,34 @@ MAX_BODY_BYTES = 2 * 1024 * 1024
|
||||
MAX_IMPORT_BODY_BYTES = 20 * 1024 * 1024
|
||||
|
||||
|
||||
def import_limit_label(limit: int | None = None) -> str:
|
||||
"""The import ceiling as a reader would say it, e.g. "20 MB".
|
||||
|
||||
Derived from the constant rather than written beside it, so the refusal, the
|
||||
export warning and the documentation cannot drift apart from each other or
|
||||
from what the middleware actually enforces (v1.1 WP-D).
|
||||
"""
|
||||
size = MAX_IMPORT_BODY_BYTES if limit is None else limit
|
||||
megabytes = size / (1024 * 1024)
|
||||
return f"{megabytes:.0f} MB" if abs(megabytes - round(megabytes)) < 0.05 else f"{megabytes:.1f} MB"
|
||||
|
||||
|
||||
def oversized_export_warning(export_bytes: int, limit: int | None = None) -> str:
|
||||
"""What to tell a reader whose export is larger than import will accept.
|
||||
|
||||
v1.1 WP-D. The file is written and is not damaged: what it exceeds is this
|
||||
version's import ceiling, so it cannot be brought back in *here*. Saying that
|
||||
plainly is the whole point — the alternative is a reader who finds out when
|
||||
they try to restore it.
|
||||
"""
|
||||
size = MAX_IMPORT_BODY_BYTES if limit is None else limit
|
||||
return (
|
||||
f"This export is larger than this version's {import_limit_label(size)} import "
|
||||
f"limit ({export_bytes:,} bytes). The file was exported successfully, but this "
|
||||
f"version cannot import it."
|
||||
)
|
||||
|
||||
|
||||
class BodySizeLimitMiddleware:
|
||||
"""Rejects oversized request bodies by their declared `Content-Length`.
|
||||
|
||||
|
||||
Reference in New Issue
Block a user