Conversation
…mpty db rows should note creation fail
…mpty db rows should note creation fail
…d, then uploading a file, followed by creating the DB entry.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
ZeyadAbbas
reviewed
Sep 25, 2026
Contributor
There was a problem hiding this comment.
Since id originates in a "use client" component and the create procedure accepts it directly, the database's nanoid(20) default is bypassed whenever an ID is provided. That means a client can submit an arbitrary ID instead of the NanoID generated by the UI. This ID should be generated server-side rather than accepted from the client.
ZeyadAbbas
requested changes
Sep 25, 2026
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Attempt at resolving #204
Note: I saw some issues that could lead to an entry without a PDF being able to be a note, but I wasn't able to actually get that result, so maybe I was testing incorrectly or reading the code wrong (createFileFormSchema in note.ts).
Testing
Once logged in, go to create a note and make it fail somehow. I put the line below
throw new Error('TESTING: force upload failure');
in useUploadToUploadURLS.ts, right after const blob [...] and before const uploadResponse [...] because I couldn't figure out another way to fail it.
Once saving that file, try uploading a note. It will fail. Run
npx drizzle-kit studio
in your terminal to look at all the DB entries. Sort/filter by upload or update timing (descending), and you should NOT see an entry for your failed upload!
AI Disclosure
I used information from the Copilot search result that comes up in Edge to vaguely understand how nanoid works, how to generate an id for a new note before creating a DB row, and to understand some of the TypeScript lines in storage.ts. The VSCode AI autocomplete was partially used when rewriting the ownedFileProcedure in storage.ts (mostly copying the existing method with minor changes).
Checklist