From 582e2ae1dc67f87b495fe264c10ef9255ad7b131 Mon Sep 17 00:00:00 2001 From: Eli Mallon Date: Fri, 24 Jul 2026 17:02:37 -0700 Subject: [PATCH] fix: only set notificationToken after successful backend registration MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Greptile flagged that enableWebNotifications committed the subscription token to the store before the POST /api/notification call, and never checked the response status. A network hiccup or server error after PushManager.subscribe() left the toggle showing "on" while the server had no subscription row — the user believed they were subscribed when they weren't. Now the token is only set after a confirmed successful POST (res.ok check), mirroring the disableWebNotifications fix from the earlier review pass. On failure the catch block returns "denied" so the toggle stays honest and the user can retry. Co-Authored-By: Claude Opus 4.8 --- js/app/store/slices/platformSlice.ts | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/js/app/store/slices/platformSlice.ts b/js/app/store/slices/platformSlice.ts index 426457b1..80dc662d 100644 --- a/js/app/store/slices/platformSlice.ts +++ b/js/app/store/slices/platformSlice.ts @@ -108,9 +108,11 @@ export const createPlatformSlice: StateCreator< applicationServerKey: urlBase64ToUint8Array(publicKey) as BufferSource, }); const subJSON = JSON.stringify(subscription); - set({ notificationToken: subJSON }); - // Register the subscription with the backend. + // Register the subscription with the backend. Only commit the token to + // the store after a confirmed successful POST — otherwise the toggle + // shows "on" while the server has no subscription row, and the user + // believes they're subscribed when they aren't. const { oauthSession } = get(); const body: { token: string; type: string; repoDID?: string } = { token: subJSON, @@ -124,6 +126,10 @@ export const createPlatformSlice: StateCreator< headers: { "content-type": "application/json" }, body: JSON.stringify(body), }); + if (!res.ok) { + throw new Error(`server registration failed: ${res.status}`); + } + set({ notificationToken: subJSON }); console.log("web notification registration status:", res.status); return permission; } catch (e) { -- 2.51.2