fix: more audit findings — perf, types, and a11y polish

- backend/photos: collapse the per-tag subquery loop in the tag filter
  into a single GROUP BY ... HAVING COUNT(DISTINCT) = N subquery so the
  cost is independent of how many tags the user is filtering on.
- useFilterUrlSync: type the parseUrl return value as
  Partial<FilterState> & { currentSection?: string } so the section field
  doesn't need an (out as any) cast.
- Timeline sticky header: bump opacity, padding, and border so it reads
  more clearly against the underlying grid.
- FilterPill clear: convert the nested <button> (invalid HTML — buttons
  cannot nest) to a span with role=button + keyboard handler, with a
  larger hit area.
- RightSidebar: add aria-label to the close-X buttons so screen readers
  announce them.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-04-08 20:22:23 +02:00
parent 749e836617
commit a55839d9a2
5 changed files with 33 additions and 14 deletions

View File

@@ -146,17 +146,21 @@ async def list_photos(
)
# Tag filter — comma-separated tag ids, AND semantics. A photo must
# have a row in photo_tags for EVERY listed tag. Implemented as one
# subquery per tag id since SQLite doesn't have an efficient
# "set-contains-all" operator.
# have a row in photo_tags for EVERY listed tag. Implemented as a
# single GROUP BY ... HAVING COUNT(DISTINCT) = N subquery so the cost
# is independent of the number of tags being filtered.
if tag_ids:
tag_id_list = [t.strip() for t in tag_ids.split(',') if t.strip()]
for tid in tag_id_list:
filters.append(
Photo.id.in_(
select(photo_tags.c.photo_id).where(photo_tags.c.tag_id == tid)
if tag_id_list:
matching_photos = (
select(photo_tags.c.photo_id)
.where(photo_tags.c.tag_id.in_(tag_id_list))
.group_by(photo_tags.c.photo_id)
.having(
func.count(func.distinct(photo_tags.c.tag_id)) == len(tag_id_list)
)
)
filters.append(Photo.id.in_(matching_photos))
# Apply all filters
if filters: