fix(catalog): read furnidata from one cache, purge the gamedata edge on write
Gitea Actions Runner Test / test-job (push) Successful in 1s
CI / check (push) Successful in 36s
CI / tests-integration (push) Successful in 1m52s
CI / tests-unit (push) Successful in 1m56s
CI / tests-ui (push) Successful in 2m48s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m27s

Furniture was not always loading completely because the same file was cached
twice and nobody could reach the client.

The catalog items loader kept its own 30s TTL copy of FurnitureData.json next
to the mtime-validated cache in `furni-data.ts`. An import cleared only the
second one, so the catalog table kept serving pre-import furnidata — empty
descriptions and revisions — until the TTL ran out. The loader now reads
through `readFurniData`, which revalidates on mtime+size and is reset by
every write, so there is exactly one cache and it cannot go stale on its own.
`invalidateFurniDataCache` and its single call site are gone with it.

The client was worse: nginx served all of /gamedata/ with `max-age=604800`,
and the `cms-gamedata` purge that would have fixed it hung off the catalog Git
export, which is disabled in production. A freshly imported item was invisible
in the client for up to seven days no matter how often you imported.

- `writeFurniData` now purges the gamedata edge tag itself. One place covers
  import, batch, resync, regen, nitro-editor, translate and dedupe. It is
  fire-and-forget and swallowed at every level: a stale edge copy is bounded
  by the edge TTL, so a failed purge must never fail an import.
- nginx splits /gamedata/ by how mutable the content is: config/ gets
  `max-age=300, must-revalidate`, bundled/ `max-age=3600, must-revalidate`,
  and the content-addressed trees (c_images, album*, clothes) keep the long
  TTL. `must-revalidate` is the point — the client now revalidates instead of
  replaying the old body. All three keep `Cache-Tag: cms-gamedata` so the
  purge still reaches them.
- A 30-minute safety-net purge in the jobs worker covers the case where
  Cloudflare was unreachable at write time.
This commit is contained in:
openhands committed 2026-10-01 15:16:48 +02:00
1 parent cede541813
commit a6cc3cafa9
5 files changed
+125 -44

No files matched your search

+18
View File
@@ -464,6 +464,24 @@ async function main() {
logger.info("Scheduled: nitro auto-clean (daily 02:00)", {
module: "jobs",
});
new Cron("*/30 * * * *", () => {
// Purge the gamedata edge tag periodically as a safety net in case a
// single import failed to emit a purge (e.g. Cloudflare disabled at the
// moment of write). Without it, a long TTL on /gamedata/ would keep the
// client stuck on old FurnitureData.json until the browser or CDN cache
// expired. No-op when Cloudflare is not configured.
import("../src/lib/edge-cache")
.then(({ EDGE_CACHE_TAGS, purgeEdgeCache }) =>
purgeEdgeCache([EDGE_CACHE_TAGS.gamedata], "jobs-safety-net"),
)
.catch((e) =>
captureWorkerError(e, "Gamedata edge purge (safety net) failed"),
);
});
logger.info("Scheduled: gamedata edge purge safety net (every 30 min)", {
module: "jobs",
});
await Promise.all([
backupEmulatorJar(),
cleanupOldLogs(),