fix(mobilehog): fix photo uploads and task visibility - #108887
Conversation
Use expo-file-system File objects for multipart photo uploads so Expo fetch can read each form-data part. Generated-By: PostHog Desktop Task-Id: b9f2e11a-748d-45c9-8f24-2b6b33235ff4
|
😎 Merged successfully - details. |
|
React Doctor found no issues in the changed files. 🎉 Reviewed by React Doctor for commit |
🤖 CI report✅ Trunk lane — non-backend lane (
|
Scope recent and searched task lists to the signed-in user and separate cached results by user ID. Generated-By: PostHog Desktop Task-Id: b9f2e11a-748d-45c9-8f24-2b6b33235ff4
|
[Medium risk] Fixes photo uploads and filters task list by user. The PR does not appear safe to merge while the previously flagged photo-upload failure remains. Reviews (2) · Last reviewed commit: "fix(mobilehog): show only the user's tas..." |
HostHog preview —
|
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. 📝 WalkthroughWalkthroughThe mobile app now uses Expo’s File class as the multipart attachment value. The task query hooks include the session user ID in their cache keys and request tasks created by that user. The app adds Vitest configuration and a test for photo upload bytes, the POST request, and the returned artifact ID. Priority: ⬇️ Low Merge Risk: ⚪ Minimal · up to Task queries are creator-scoped, and Expo’s multipart path supports uploading the selected photo bytes. No production failure is established; the remaining change improves regression coverage, so the PR is mergeable with normal checks. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to Task filtering improves account-specific visibility without expanding server permissions. Photo uploads preserve existing authorization, but interrupted uploads may leave photo data without confirmed cleanup. This limits confidence in a minimal-risk assessment. Retained concerns
Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 1✅ Passed checks (1 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
Generated-By: PostHog Desktop Task-Id: 3313e91d-d757-49f3-9553-dc14b9d26cc9
There was a problem hiding this comment.
🧹 Nitpick comments (1)
products/desktop/apps/mobilehog/src/lib/attachments.test.ts (1)
5-9: 🎯 Functional Correctness | 🔵 Trivial | ⚡ Quick winMake
MockFileURI-sensitive.
MockFileignores its URI and always returnsphotoBytes. The byte assertion can therefore pass even whenuploadStagedPhotosdoes not use the selected photo'sphoto.uri. Map the fixture bytes to the expected URI and reject unexpected URIs.Suggested test fix
const photoBytes = new Uint8Array([137, 80, 78, 71]); + const bytesByUri = new Map([["file:///photo.png", photoBytes]]); class MockFile extends Blob { - constructor(_uri: string) { - super([photoBytes], { type: "image/png" }); + constructor(uri: string) { + const bytes = bytesByUri.get(uri); + if (!bytes) throw new Error(`Unexpected file URI: ${uri}`); + super([bytes], { type: "image/png" }); } }This is a URI/data coverage gap, not a filename or MIME requirement. The staged-upload contract does not require those multipart fields.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository: PostHog/posthog/.coderabbit.yaml
Review profile: QUIET
Plan: Enterprise
Run ID: 7c651c93-a920-49dd-9860-1bd3a02e90d3
⛔ Files ignored due to path filters (1)
products/desktop/pnpm-lock.yamlis excluded by!**/pnpm-lock.yaml
📒 Files selected for processing (4)
products/desktop/apps/mobilehog/package.jsonproducts/desktop/apps/mobilehog/src/lib/attachments.test.tsproducts/desktop/apps/mobilehog/src/lib/attachments.tsproducts/desktop/apps/mobilehog/vitest.config.ts
Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 11 remain after this review.
Problem
Mobile users see other people's tasks in personal lists, and photo attachments fail before a task starts.
Changes
How did you test this code?
The MobileHog upload test confirms that Expo fetch receives the selected photo bytes. The MobileHog type check and lint passed. A device test was not available in this environment.
Release status
Automatic notifications
Docs update
None.
🤖 Agent context
Autonomy: Human-driven (agent-assisted)
Agent: PostHog Desktop, GPT-5
Skills: posthog-desktop and writing-pr-descriptions. No matching open PR covers these failures.
Created with PostHog Desktop