Files
familienarchiv/frontend/src/lib/document
Marcel 58254b492b
Some checks failed
CI / Unit & Component Tests (pull_request) Failing after 2m52s
CI / OCR Service Tests (pull_request) Successful in 21s
CI / Backend Unit Tests (pull_request) Successful in 3m48s
CI / fail2ban Regex (pull_request) Successful in 44s
CI / Semgrep Security Scan (pull_request) Successful in 20s
CI / Compose Bucket Idempotency (pull_request) Successful in 1m4s
fix(security): add csrfFetch wrapper and apply to all client-side mutating requests
Introduces `csrfFetch` (= `makeCsrfFetch(fetch)`) in cookies.ts as a
drop-in fetch replacement that auto-injects X-XSRF-TOKEN on POST/PUT/PATCH/DELETE.

Previously 8 call sites sent mutating requests without the CSRF header —
annotation resize, comment POST/PATCH/DELETE, Geschichte CRUD, Stammbaum
relationship creation, bulk-edit PATCH, and file upload — all would fail
with CSRF_TOKEN_MISSING if the backend's cookie-based protection triggered.

All 14 client-side mutating fetches now use csrfFetch; withCsrf/makeCsrfFetch
remain in the API for injectable-fetch use cases (e.g. useTranscriptionBlocks).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-30 10:50:56 +02:00
..

document (frontend)

UI for the archive's core concept: viewing, uploading, editing, searching, bulk-selecting, and transcribing documents.

What this domain owns

Components: DocumentRow, DocumentThumbnail, DocumentTopBar, DocumentViewer, DocumentMetadataDrawer, DocumentEditLayout, DocumentStatusChip, UploadZone, BulkSelectionBar, BulkDropZone. Utilities: search.ts (search-param helpers), filename.ts (filename formatting), documentStatusLabel.ts (i18n label mapping), validateFile.ts (upload validation), groupDocuments.ts (list grouping). Sub-folders: annotation/, transcription/, viewer/.

What this domain does NOT own

  • Person typeahead — person/PersonTypeahead.svelte (cross-domain import, allowed by ESLint rule)
  • Tag input — tag/TagInput.svelte (cross-domain import, allowed)
  • Shared discussion — shared/discussion/ (comment/mention editor)

Key components

Component Route used in Notes
DocumentRow.svelte / (search results), admin queues Compact document card with thumbnail
DocumentViewer.svelte /documents/[id] PDF/image inline viewer
DocumentEditLayout.svelte /documents/[id]/edit Full edit form with sticky save bar
UploadZone.svelte /documents/new, bulk upload Drag-and-drop file drop area
BulkSelectionBar.svelte /documents bulk mode Multi-select action bar

Cross-domain imports

  • person/PersonTypeahead.svelte — sender / receiver selection
  • tag/TagInput.svelte — tag chip input
  • ocr/OcrProgress.svelte — job status indicator in the document header
  • shared/primitives/BackButton.svelte, shared/discussion/ — shared UI

Backend counterpart

backend/src/main/java/org/raddatz/familienarchiv/document/README.md