fix: code cleanup — path traversal, test leaks, dead code, consistency

- Add path traversal protection to GET /api/cases/:name and fix-plan
- Use safePathSchema for LinkCaseSchema.path
- Fix QR auth test timer leak (afterAll → afterEach) and env var try/finally
- Remove dead terminal size check after Zod validation in resize route
- Remove no-op sampleCount guard in adaptive timing
- Replace hardcoded values with constants in notification-manager and subagent-windows
- Add Zod validation to POST /api/auth/revoke
- Use _apiPut instead of raw fetch in subagent-windows
- Add SwipeHandler.cleanup() for consistency with other mobile handlers
- Move NiceConfig/ProcessStats from types/plan.ts to types/common.ts

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
arkon
2026-03-01 17:26:31 +01:00
co-authored by Claude Opus 4.6
parent f94ab08cbe
commit d094d9ec50
11 changed files with 94 additions and 71 deletions
+20 -2
View File
@@ -403,6 +403,10 @@ const SwipeHandler = {
maxSwipeTime: 300, // Maximum ms for a swipe gesture
maxVerticalDrift: 100, // Max vertical movement allowed
_touchStartHandler: null,
_touchEndHandler: null,
_element: null,
/** Initialize swipe handling */
init() {
// Only on touch devices
@@ -411,8 +415,22 @@ const SwipeHandler = {
const terminal = document.querySelector('.main');
if (!terminal) return;
terminal.addEventListener('touchstart', (e) => this.onTouchStart(e), { passive: true });
terminal.addEventListener('touchend', (e) => this.onTouchEnd(e), { passive: true });
this._element = terminal;
this._touchStartHandler = (e) => this.onTouchStart(e);
this._touchEndHandler = (e) => this.onTouchEnd(e);
terminal.addEventListener('touchstart', this._touchStartHandler, { passive: true });
terminal.addEventListener('touchend', this._touchEndHandler, { passive: true });
},
/** Remove swipe listeners */
cleanup() {
if (this._element && this._touchStartHandler) {
this._element.removeEventListener('touchstart', this._touchStartHandler);
this._element.removeEventListener('touchend', this._touchEndHandler);
}
this._touchStartHandler = null;
this._touchEndHandler = null;
this._element = null;
},
onTouchStart(e) {