修复(钱包store): 应用余额快照时空值安全

- captureWalletBalanceSnapshot 在 owner 不匹配时返回 null,applyWalletBalanceSnapshot 之前会直接解引用
- applyWalletBalanceSnapshot 入参放宽为 ProfileWalletBalanceSnapshot | null,null 直接返回 false
- 单测去掉非空断言,锁住「他人 owner 的快照捕获为 null 且必须被拒绝」
This commit is contained in:
2026-10-06 10:23:16 +08:00
parent 796cf9843c
commit a38407344d
2 changed files with 7 additions and 2 deletions
@@ -296,7 +296,7 @@ describe('createProfileWalletStore', () => {
const snapshot = store.getState().captureWalletBalanceSnapshot('user-b');
expect(
store.getState().applyWalletBalanceSnapshot(snapshot!, balance(37)),
store.getState().applyWalletBalanceSnapshot(snapshot, balance(37)),
).toBe(false);
expect(store.getState().mudPointBalance).toBeNull();
});
@@ -35,7 +35,7 @@ export type ProfileWalletStore = {
ownerUserId: string,
) => ProfileWalletBalanceSnapshot | null;
applyWalletBalanceSnapshot: (
snapshot: ProfileWalletBalanceSnapshot,
snapshot: ProfileWalletBalanceSnapshot | null,
balance: ProfileMudPointBalance,
) => boolean;
onWalletBalanceMayHaveChanged: () => Promise<void>;
@@ -117,6 +117,11 @@ export function createProfileWalletStore(
};
},
applyWalletBalanceSnapshot: (snapshot, balance) => {
// captureWalletBalanceSnapshot 在 owner 不匹配时返回 null;null 本身即「快照已失效」,
// 直接拒绝,避免把 capture 的可空返回喂回 apply 时解引用崩溃。
if (!snapshot) {
return false;
}
if (
get().ownerUserId !== snapshot.ownerUserId ||
ownerVersion !== snapshot.ownerVersion ||