fix: HEIC vips fallback, DB pool exhaustion, auth session persistence

HEIC thumbnails:
- Switch fallback from ffmpeg to vips for HEIC files that pillow-heif
  rejects. ffmpeg decoded gain map tiles instead of the primary image,
  producing inverted/negative thumbnails. vips uses libheif's item
  references correctly and extracts the full-resolution primary image.

Database pool exhaustion:
- Add idle_in_transaction_session_timeout=60s so Postgres auto-kills
  leaked connections from disconnected thumbnail requests.
- Add pool_timeout=10 so new requests fail fast instead of hanging.
- Bump pool from 5+5 to 10+10 for thumbnail concurrency headroom.
- get_db rolls back on exception before closing.

Auth session persistence:
- Narrow 401 interceptor exclusion to only /auth/refresh and /auth/login
  (was excluding all /auth/* including /auth/me, preventing token refresh
  on boot).
- fetchMe only clears tokens on 401/403, not network errors.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
root
2026-04-13 15:25:55 +02:00
parent 2adaaf18a1
commit ecd8bbe61d
4 changed files with 39 additions and 18 deletions

View File

@@ -72,9 +72,14 @@ export function AuthProvider({ children }: { children: ReactNode }) {
try {
const res = await api.get('/auth/me')
setUser(res.data)
} catch {
clearTokens()
setUser(null)
} catch (err: any) {
// Only clear tokens on auth failure (401/403), not network errors.
if (err?.response?.status === 401 || err?.response?.status === 403) {
clearTokens()
setUser(null)
}
// Network errors: leave tokens in place, user stays on login screen
// but can retry without re-entering credentials.
}
}, [])
@@ -136,7 +141,8 @@ export function AuthProvider({ children }: { children: ReactNode }) {
if (
error.response?.status === 401 &&
!original._retry &&
!original.url?.includes('/auth/')
!original.url?.includes('/auth/refresh') &&
!original.url?.includes('/auth/login')
) {
original._retry = true
const rt = getStoredRefreshToken()