fix: ADC Local Test Run 3 defects (transport faults, login protection outage, register alert, role PUT, client IP) - #492
Merged
Conversation
- HttpResultExecutor treats Polly ExecutionRejectedException (timeout, open circuit) as a transport fault, so a down or hung backend becomes a failed Result instead of a prerender 500 (ADC X-07, U-35). - LoginProtectionService fails open with a Warning log when the cache is unavailable instead of answering 500 on login and register; caller cancellation still propagates (ADR-029 revision 2026-10-03). - Register: the duplicate-email alert names the rejected address and is dismissed by the first edit of the field (ADC U-13). - UserAdminList Spanish strings accented. - SetStoredPermissionsAsync answers RoleNotFound for a role outside the role universe and stores nothing, matching GetRoleAsync (ADC O-54). - AddCommonServerTokenStorage stamps X-Forwarded-For with the browser IP on server-side APIClient calls, so Identity's per-IP registration limit keys on the browser rather than the UI host (WASM path unchanged). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012sDGvYdTD88ZjjD7if2SMW
This was referenced Oct 4, 2026
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes the MMCA.Common defects found by ADC Local Test Run 3 (221 manual cases run locally with up to six concurrent browser users) and confirmed in source by an independent reviewer.
TimeoutRejectedException/BrokenCircuitExceptionescapeHttpResultExecutorIsTransportFaultalso matchesExecutionRejectedException, so the page gets a failedResultand shows its error with RetryPOST /Auth/loginanswers 500 while Redis is downLoginProtectionServicefails open with a Warning log on every check, increment and reset; caller cancellation still propagates. Decision recorded in ADR-029 (Website PR, revision 2026-10-03)UserAdminListResources.es.resxaccentedPUT /Admin/Roles/{typo}/permissions200 while GET is 404SetStoredPermissionsAsyncanswersRoleNotFoundand stores nothingBrowserForwardedForHandleron the"APIClient"pipeline stampsX-Forwarded-Forwith the browser IP (same source asCookieSessionRefresher.BrowserOrigin); the WASM path is unchangedPublic API:
LoginProtectionServicegains a trailing optionalILogger<LoginProtectionService>?constructor parameter (recompile only).Verification (local):
dotnet build MMCA.Common.slnx -c Release0 warnings / 0 errors; test exes UI 1229, Infrastructure 1723, API 866, UI.Web 205, Architecture 317, all 0 failed.Note for reviewers: the client-IP handler reads
IHttpContextAccessorper request, like the refresher. Prerender calls get the page request; interactive circuit calls rely on the accessor exposing the circuit's connection. If it does not, those calls send no header (no regression). The post-deploy ADC check confirms which.🤖 Generated with Claude Code
https://claude.ai/code/session_012sDGvYdTD88ZjjD7if2SMW