update dependencies to express 5, socket.io 4, node-cache 5 and fix breaking changes - #23
Merged
Merged
Conversation
…reaking changes
Bump express ^4.16 -> ^5.2.1, socket.io ^2.1 -> ^4.8.3, node-cache ^4.2 -> ^5.1.2,
mysql ^2.16 -> ^2.18.1 and regenerate package-lock.json (0 vulnerabilities).
Adapt app.js and the vendored browser client to the major-version changes:
- Express 5 rejects the bare '*' route (path-to-regexp v8 requires named
wildcards), which crashed the server on startup. Use '/{*splat}'.
- Socket.IO 3+ dropped the callback argument of socket.join(). The post-join
logic (board lookup/insert, boardState emit) would never have run. Call
join() synchronously and run that logic directly.
- Replace public/js/socket.io.js (v2.1.1) with the v4.8.3 client bundle. A
v4 server rejects v2 clients with "Unsupported protocol version".
- Honor PORT env var (default remains 8080).
Verified end-to-end against MySQL 8.0: join/insert, boardState, startDraw
ack + transaction, updateDraw/endDraw/undo/pan relays, late-joiner state.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Brings all dependencies to their latest versions (Express 5, Socket.IO 4, node-cache 5, mysql 2.18) and fixes the three breaking changes that came with them. Without the fixes, the upgraded app crashes on startup, and even if it started, no browser could connect. Also refreshes
package-lock.json, which was still pinning the old versions, and bumpsactions/checkoutto v7.What was broken by the upgrade
app.get('*')is invalid in path-to-regexp v8PathError: Missing parameter nameand exited/{*splat}socket.join(room, cb)no longer takes a callbackjoin()is called synchronously, then the post-join logic runs directlypublic/js/socket.io.jswas the v2.1.1 client{"code":5,"message":"Unsupported protocol version"}socket.io/client-distapp.jsalso honorsPORTif set (default is still 8080). No change for production, where nginx/Passenger incs50/serverrun Node 24, which satisfies Express 5.Test plan
Verified end-to-end against a MySQL 8.0 container loaded with
db_initialize.mysql, with three simulated clients on the v4 protocol:joined on insert); later joins getboardState.startDrawacks idx 0 then 1 (transaction +MAX(idx)work);updateDraw,endDraw,undo,panare relayed to the room;undodeletes the row.npm audit: 0 vulnerabilities.Worth a quick manual check in a browser on two tabs of the same board before merge; the deploy workflow ships
mainstraight to Elastic Beanstalk.Not changed
node-cacheis still listed but unused inapp.js(only referenced in commented-out code). Left in place; could be dropped in a follow-up.