Repository navigation
Conversation
Reviewer's GuideThe PR prevents restore-state verification stampedes by sharing a per-database retry deadline across all sync callers, honoring Retry-After with safe busy-response fallbacks, and keeping databases fenced until fresh verification succeeds. Permanent permission failures remain terminal, while hints and local edits are preserved during cooldowns; focused tracker and hook regressions cover concurrent lifecycle paths and recovery behavior. Sequence diagram for shared database restore verification cooldownsequenceDiagram
participant Caller as Sync callers
participant Tracker as DatabaseRestoreTracker
participant Server as Restore state service
participant Hook as Restore sync hook
Caller->>Tracker: check(databaseId)
Tracker->>Server: readState(databaseId)
Server-->>Tracker: transient error with Retry-After
Tracker->>Tracker: store deferred retryAtMs
Tracker-->>Caller: DatabaseRestoreVerificationDeferredError
Caller->>Hook: schedule retry
Hook->>Tracker: check(databaseId)
Tracker-->>Hook: reject until retryAtMs
Note over Caller,Tracker: open, sync, focus, and reconnect callers share one deadline
Tracker->>Server: readState(databaseId)
Server-->>Tracker: verified restore state
Tracker-->>Caller: fresh verification succeeds
Flow diagram for restore verification error handlingflowchart TD
A[Restore verification fails] --> B{Permanent denial?}
B -->|Yes| C[Keep database fenced]
C --> D[Stop retrying]
B -->|No| E{Retryable busy or transient error?}
E -->|No| F[Propagate verification error]
E -->|Yes| G[Use Retry-After or fallback delay]
G --> H[Store per-database retry deadline]
H --> I[Reject callers during cooldown]
I --> J[Retry fresh verification]
J --> K{Verification succeeds?}
K -->|Yes| L[Release fence]
K -->|No| G
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
After restore-state verification returned a transient error, later open, sync, focus, and reconnect checks could bypass the retry timer and immediately request verification again. The tracker now shares one retry deadline per database, honors Retry-After, and uses a 30-second fallback for busy responses. Callers remain fenced until fresh verification succeeds; permission denials remain terminal and queued edits are preserved.
Validation: 71 focused tracker/hook tests pass, including 32 concurrent and staggered callers, restore hints during a busy request, retained local edits, and permanent denial handling. Four regression cases failed before the fix. Full TypeScript checking, production ESLint, and
git diff --checkpass.Related server work: https://github.com/AppFlowy-IO/AppFlowy-Cloud-Premium/pull/1336. This Web fix is independent and can be reviewed separately.
Summary by Sourcery
Prevent database restore checks from bypassing transient verification cooldowns while preserving terminal denial handling and unsent local changes.
Bug Fixes:
Enhancements:
Tests: