Skip to content

fix(storage): prevent workspace data loss (#244) - #248

Merged
ThisIs-Developer merged 14 commits into
mainfrom
fix/issue-244-data-loss
Aug 24, 2026
Merged

ThisIs-Developer merged 14 commits into
mainfrom
fix/issue-244-data-loss

Conversation

@ThisIs-Developer

@ThisIs-Developer ThisIs-Developer commented Aug 23, 2026 •

Copy link
Copy Markdown
Owner

Fixes #244. cc @changbb.

Root cause

The confirmed losses came from treating stale or failed snapshots as authoritative: full-workspace writers inferred deletions, startup read failures could become an empty workspace, and normal/Secret metadata and content lacked revisioned atomicity. The post-fix audit also found desktop writes that could finish before their index transaction, collision-prone paths, silently skipped corrupt Secret records, and initialization waits that could make saved data inaccessible.

Changes

  • use revision/CAS writes, three-way organization merges, and conflict copies for concurrent edits
  • add normal and encrypted dirty journals with IndexedDB fallback and abrupt-close recovery
  • make browser restore/reset/Secret updates transactional and validate backup hashes and encrypted envelopes before replacement
  • add redundant Secret manifests, corruption detection, desktop write/index/move/delete/restore journals, verified writes, and SHA-256 document path suffixes
  • replace the embedded recovery selector with a dedicated compact, responsive Trash window in Explorer and Settings
  • move ordinary normal and encrypted file deletions directly to recoverable Trash; Restore is also immediate
  • reserve confirmation dialogs for permanent Trash deletion, name the selected file(s) in the warning, and keep Empty Trash explicitly confirmed
  • add a shared-style Trash toolbar with search, selected count, visible-file Select All, Delete, and Restore actions
  • support checkbox/row selection, Ctrl+mouse toggling, Shift+mouse range selection, filtered selection, multi-file restore, and multi-file permanent deletion
  • keep asynchronous action controls disabled until refresh finishes and retain failed items safely when a multi-item operation only partly succeeds
  • limit the footer to Empty Trash and Cancel
  • show a persistent regular-weight red hat-and-glasses Private mode is on status without a background or border while Private Mode prevents persistence; storage errors still take priority and Settings keeps its original blue active design
  • keep Private Mode page-session-only so refresh, tab close/reopen, and browser restart return to normal mode; clear legacy stored flags and exclude the mode from backups
  • flush current editor/split state and pending persistence before deletion so immediate Delete cannot race a revision update or trash stale content
  • reuse the existing Storage Recovery note and GitHub import selection-toolbar components directly in Trash
  • simplify each Trash row to its selection control, unboxed file icon, regular-weight filename, and clock with remaining time
  • retain deleted normal and encrypted items for 30 days and auto-purge only recognized, structurally valid expired records
  • keep corrupt, missing-date, and future-format records unchanged and block unsafe restore
  • make desktop permanent deletion crash-recoverable with a purge marker, and never let maintenance failure block startup
  • keep web and packaged desktop persistence/UI sources in parity and document Trash/backup boundaries

Verification

  • relevant Chromium regression suites: 42/42 passed (Trash, responsive storage, Explorer, and tab/split behavior)
  • broader Trash/storage/responsive Chromium suite: 17/17 passed
  • final focused Trash and shared-overlay matrix: 12/12 passed across Chromium, Firefox, and WebKit
  • lifecycle and focused interaction coverage verify search, visible Select All/deselect, arbitrary checkbox selection, Ctrl+mouse toggling, Shift+mouse ranges, multi-restore, single and multi-file deletion warnings, confirmation cancellation, multi-delete, Empty Trash, and IndexedDB results
  • direct-delete coverage verifies no confirmation appears and inspects IndexedDB Trash to confirm the latest document content was preserved
  • computed-style parity checks prove the Trash retention note matches Storage Recovery and the Trash summary/search/actions match the GitHub import selection toolbar
  • row-structure checks verify a direct unboxed file icon, 40px shared row sizing, regular text weight, removed metadata elements, and clock/remaining-time output
  • failure injection covers expiry cleanup, corrupt/unknown records, initialization failure, IndexedDB lifecycle, desktop interrupted purge, explicit desktop purge, confirmation cancellation, restore, selected permanent delete, and Empty Trash
  • responsive checks passed at compact desktop, phone portrait, and phone landscape sizes with no horizontal overflow
  • in-app browser visual QA confirmed shared typography/icons/spacing/colors, requested action order, Ctrl-click selection, compact item layout, and footer placement
  • focused Private Mode lifecycle coverage: 5/5 passed, verifying write suppression, refresh reset, tab close/reopen reset, legacy-flag cleanup, and the status visual state
  • related orphaned-content and missing-content recovery checks: 2/2 passed after switching their reload setup to the real session-only mode
  • in-app browser QA confirmed the regular-weight red status text/icon, transparent borderless status, restored blue Settings toggle/focus design, and active-to-off refresh transition, then restored the preview profile to normal mode
  • static build/source parity, JavaScript syntax, desktop resource preparation, and diff checks passed

Verdict

SAFE WITH LIMITATIONS. No reproducible current application workflow was found that silently loses committed data after these fixes. Browser/site-data deletion, total device or storage loss, a hard crash before any asynchronous journal commit, intentionally ephemeral Private Mode edits, loss of a Secret Workspace key, and the intentional 30-day Trash expiry remain outside what the application can fully prevent.

@vercel

vercel Bot commented Aug 23, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
markdown-viwer Ready Ready Preview Aug 24, 2026 12:08pm

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Aug 23, 2026 •

Copy link
Copy Markdown

Deploying markdownviewer with  Cloudflare Pages  Cloudflare Pages

Latest commit: e9f7078
Status: ✅  Deploy successful!
Preview URL: https://886b02cc.markdownviewer.pages.dev
Branch Preview URL: https://fix-issue-244-data-loss.markdownviewer.pages.dev

View logs

@ThisIs-Developer
ThisIs-Developer merged commit da0eb71 into main Aug 24, 2026
5 checks passed
@ThisIs-Developer
ThisIs-Developer deleted the fix/issue-244-data-loss branch August 24, 2026 13:38
@ThisIs-Developer ThisIs-Developer added bug Something is broken or not working as expected. priority: high Important issue with significant user or product impact. labels Oct 2, 2026 — with ChatGPT Codex Connector

This branch was successfully deployed

1 active deployment
Preview — e9f70781 Deployed Aug 24, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something is broken or not working as expected. priority: high Important issue with significant user or product impact.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

数据丢失了,在线的数据没了

1 participant