diff --git a/backend/cmd/webui/handlers/auth.go b/backend/cmd/webui/handlers/auth.go index 641c26c..fe9eb1e 100644 --- a/backend/cmd/webui/handlers/auth.go +++ b/backend/cmd/webui/handlers/auth.go @@ -48,9 +48,14 @@ func (h *H) Login(c *gin.Context) { } func (h *H) Me(c *gin.Context) { + // B7: only no-rows → 401; other errors (PG down) go through dbErr → 503. u, qerr := h.st.GetUserByID(c, uid(c)) if qerr != nil { - err(c, http.StatusUnauthorized, "unauthorized", "no such user") + if errors.Is(qerr, pgx.ErrNoRows) { + err(c, http.StatusUnauthorized, "unauthorized", "no such user") + return + } + dbErr(c, qerr) return } c.JSON(http.StatusOK, gin.H{"id": u.ID, "username": u.Username, "role": u.Role}) diff --git a/backend/cmd/webui/handlers/libraries.go b/backend/cmd/webui/handlers/libraries.go index 7edb9a1..586be1a 100644 --- a/backend/cmd/webui/handlers/libraries.go +++ b/backend/cmd/webui/handlers/libraries.go @@ -146,10 +146,17 @@ func (h *H) Upload(c *gin.Context) { err(c, http.StatusInternalServerError, "internal", "create tmp") return } + // B6: only MaxBytesError returns 413; other io.Copy failures (disk full, + // connection drop) return 500. if _, e := io.Copy(out, src); e != nil { out.Close() os.Remove(tmp) - err(c, http.StatusRequestEntityTooLarge, "too_large", "upload failed") + var mbe *http.MaxBytesError + if errors.As(e, &mbe) { + err(c, http.StatusRequestEntityTooLarge, "too_large", "file exceeds upload limit") + return + } + err(c, http.StatusInternalServerError, "internal", "upload failed") return } out.Close()