Skip to content

feat(mobile): add Manage Profiles and profile picker at web parity - #6386

Merged
iscekic merged 19 commits into
mainfrom
kwf/req-20260918-153926-dcb3
Sep 24, 2026
Merged

iscekic merged 19 commits into
mainfrom
kwf/req-20260918-153926-dcb3

Conversation

@iscekic

@iscekic iscekic commented Sep 19, 2026 •

Copy link
Copy Markdown
Collaborator

Changelog for users

  • Browse, create, edit, and delete profiles from the Profile tab.
  • Pick a profile at session start, including the "No profile" choice.
  • Change the profile from Advanced Configuration while starting a session.
  • See the active profile as a chip on the new-session and session screens.
  • Save the current environment variables and setup commands as a new profile, or edit an existing one.
  • Edit a profile's variables, setup commands, slash commands, MCP servers, skills, and agents.
  • Keep secret values masked until revealed, and enter a new value to rotate one.
  • Manage personal and organization profiles and repository bindings; reorder with up/down buttons, never drag.
  • Tapping the active-profile chip in an organization session opens the profile in its own owner's scope.
  • Editing an MCP server keeps its stored type, so remote headers and masked secrets stay intact.
  • Deleting a skill's frontmatter description now clears the stored description.
  • Text typed while the setup-command list refreshes is no longer dropped.
  • Marking a profile as the default updates the right owner and the effective default.
  • The web sidebar and survey no longer show signed-out after a temporary server error.
  • Profile rows show the MCP server count in place of the setup-command count.
  • Save as Profile appears only after a setup command has text.
  • The variable delete control is disabled while a delete is in progress.
  • The repository-binding profile picker explains when the context has no profiles.
  • Adding a variable whose key normalizes to an existing key is refused with an inline error instead of overwriting the stored variable.
  • Editing an MCP server keeps command arguments that contain spaces intact.
  • Manual environment variables and setup commands entered under Advanced Configuration are sent with the new session, even without saving a profile first.
  • The MCP server form reports over-limit commands, URLs, and environment or header JSON before saving.
  • Switching organization no longer briefly shows the previous organization's profiles.
  • Segmented-control labels wrap instead of being truncated to one line.

Changelog for maintainers

  • Mobile's tRPC mount now exposes every profile-management procedure; each reuses the web router's own auth and organization-access checks, so the mount adds no server behavior.
  • Personal and organization ownership follows web: a personal create never carries the selected organization, and an org-owned profile's reads and writes carry organizationId.
  • Removed renderProfileRow; NewSessionProfileRow replaces it and requires onOpenProfilePicker, selectedProfileId, onSelectProfile, and profileOverrideNeedsAttention.
  • The new-session profile pick is session state shared by the Environment row and the advanced-config selector; it drives the submitted profileId, and a stale pick reports attention without submitting.
  • The web picker now renders loading and error states plus a "No profile" row, so a pending or failed profile list no longer looks empty.
  • The catalog checker now requires translated strings to preserve $TOKEN expansion tokens; the allowlist adds literal profile examples (command, MCP, slug, and slash-command placeholders, top_p, and the MCP count).
  • The web app's typecheck script now passes a TS build-info file flag; this is a build-cache change, not a dependency or policy exception.
  • Platform check refuted: the flagged added lines import expo-router and react-native-safe-area-context, both cross-platform, and the diff adds no Platform.OS/Platform.select/.ios/.android branch.
  • Live-device platform proof is unavailable on this host: the shared mobile checks (typecheck, unit, i18n, unused) passed, and the iOS live check is skipped, pending owner verification.
  • The duplicate-key and MCP-bound messages are in the English catalog and every locale catalog; the catalog-parity checker allowlists the four keys as pending translation.
  • Removed the unused Android-only destructive-confirm selector; RTL tracked-label handling and segmented-control label wrapping were adjusted, and the affected mounted suites stub platform and safe-area modules.
  • The E2E proof keeps the picker and sidebar runtime captures, the dev-stack profile editor/CRUD capture, and the browser smoke that rendered the profile page under fake auth; the refreshed run log excerpts replace the earlier inline picker/CRUD excerpt.
  • apps/mobile/src/components/agents/session-detail-content.tsx:488 — accepted: the chip now resolves the profile's owner scope, so an org session opens a personal default in personal scope; EffectiveAgentProfile carries ownerType for the choice.
  • apps/mobile/src/components/profiles/mcp-form-sheet.tsx:118 — accepted: the local/remote selector renders only for a new server, so editing cannot re-envelope the stored config as the other type.
  • apps/mobile/src/components/profiles/skill-form-sheet.tsx:69 — accepted: the skills update now sends description: null when the frontmatter omits it, so clearing persists server-side.
  • apps/mobile/src/components/profiles/profile-commands-screen.tsx:89 — accepted: the refetch sync skips while a save is pending and only swaps a clean list, bumping generation so remounted fields show server truth; in-flight drafts survive.
  • apps/mobile/src/lib/hooks/use-agent-profile-mutations.ts:97 — accepted: optimistic default writes touch only the mutated owner and recompute the effective default personal-first; clearDefault passes the profile id and list/detail caches are keyed by input.
  • apps/web/src/app/(app)/components/PrefetchedOrganizations.tsx:40 — accepted: ['user'] is seeded only for a resolved user, so a failed context no longer pins signed-out for the global staleTime.
  • apps/mobile/src/components/profiles/profile-list-model.ts:109 — accepted: the row subtitle uses mcpServerCount and emits MCP in web order (vars, MCP, skills).
  • apps/mobile/src/components/agents/advanced-config-panel.tsx:154 — accepted: hasManualConfig uses the trimmed commands that are actually persisted, so a blank draft row no longer offers Save as Profile.
  • apps/mobile/src/components/profiles/profile-variables-screen.tsx:105 — accepted: delete is guarded and the row's delete control is disabled while the mutation is pending.
  • apps/mobile/src/components/profiles/repo-bindings-profile-sheet.tsx:57 — accepted: the picker renders an empty state when the context has no profiles.
  • apps/mobile/src/components/profiles/profile-variables-rows.tsx:186 — accepted: a new key is normalized with cleanVariableKey and refused when it matches a stored key, so the server's (profile_id, key) upsert can no longer silently replace a variable; the variables screen and the manual-vars editor pass their existing keys.
  • apps/mobile/src/components/profiles/profile-mcp-model.ts:112 — accepted: formatCommand quotes and escapes an argument holding whitespace, a quote, or a backslash, and commandParts parses it back, so an unedited ['tool', '--label=foo bar'] round-trips; a round-trip test covers it.
  • apps/mobile/src/components/agents/advanced-config-panel.tsx:257 — accepted: the manual env-var and setup-command draft now lives in the new-session route, the panel only reports changes, and the create carries envVars/setupCommands (omitted when empty) in the prepare-session body and intent fingerprint.
  • apps/mobile/src/components/profiles/profile-mcp-model.ts:187 — accepted: validateMcpForm mirrors the server bounds — 50 command arguments of 500 characters, a 2048-character URL, and 50 env/header entries with 128-character keys and 4096-character values — and surfaces the field error before the mutation.
  • apps/mobile/src/lib/hooks/use-agent-profiles.ts:40 — accepted: a key-aware placeholder replaces keepPreviousData, returning previous rows only when the query key is unchanged, so an organization switch starts empty while a same-key refetch keeps the list; a context-switch test covers it.

E2E proof

[e1] Web profile picker at session start: loading, error+Retry, No profile row, selection — e2e-web/e1-picker-loading.png

[e1] Web sidebar/survey user seed: SSR render and temporary /api/user error — e2e-web/e1-sidebar-ssr.png

[e1] Web parity surfaces this diff touches: web profile picker states + profile editor/CRUD on the live dev stack — live-bindings4/e1-d3-repo-bindings-dialog.png

browser smoke: profile local setup smoke

E2E proof — log excerpts

[e1] Web parity: Manage Profiles — picker, editor, ownership (owner request B, P -> pass :: Web reference surfaces live on port 7400: picker popover shows the new 'No profile' row plus 'e1 web parity'/'1 vars' (e1-cloud-githubuser.log: 'PICK A PROFILE' / 'No profile'); loading branch shows 'Loading profiles…' and error branch 'Could not load profiles.' with 'Retry' under a stubbed agentProfiles.list 500 (e1-picker-loading.log, e1-picker-error.log); Manage Profiles dialog renders Overview/Variables 1/Setup 0/Slash Cmds 0/MCP 0/Skills 0/Agents 0 plus 'Pinned to repositories' and 'iscekic/cloud GITHUB' (e1-manage.log); selecting a profile updates the row to 'e1 web parity · 1 vars' and the popover to 'ACTIVE PROFILE' (e1-select.log); org selector and org pair seed present (e1-org.log

Session profile id end to end (review thread PRRT_kwDORD_mN86lphlV)

The session-detail chip showed the context's effective default, not the profile the session was prepared with. The resolved profile id is now persisted at create and read back by the chip.

Layer Change
DB packages/db/src/schema.ts:6376 nullable cli_sessions_v2.profile_id (ON DELETE SET NULL); migration packages/db/src/migrations/0258_cynical_vapor.sql
Contract packages/session-ingest-contracts/src/rpc-contract.ts:144 optional/nullable profileId on the create payload
Ingest services/session-ingest/src/session-ingest-rpc.ts:320 writes profile_id on the root insert
Resolve packages/cloud-agent-profile/src/profile-session-config.ts:111,361 reports the resolved active profile id; services/cloud-agent-next/src/router/handlers/session-prepare.ts:168 carries it; services/cloud-agent-next/src/session/session-registration.ts:776,1880,1976 pass it; services/cloud-agent-next/src/session-service.ts:3031 sends it
SDK packages/cloud-agent-sdk/src/session-manager.ts:292 FetchedSessionData.profileId
Adapters apps/mobile/src/components/agents/mobile-session-manager.ts:468, apps/extension/src/shared/extension-agent-session-manager.ts:618; read surface apps/web/src/routers/cli-sessions-v2-router.ts:1556,1682
Chip apps/mobile/src/components/agents/session-detail-content.tsx:516-533 resolves the recorded id, default only when the session recorded none

Pushed head: 508fa194058761aed05d58dc9e21cb356136df1f

Test commands and decisive output

POSTGRES_URL=postgresql://unused:unused@localhost:5432/unused pnpm drizzle check
Everything's fine 🐶🔥

pnpm --filter cloudflare-session-ingest test
Test Files  31 passed (31) | Tests  1135 passed | 3 skipped (1138)

pnpm --filter cloud-agent-next exec vitest run src/session-prepare.test.ts src/session-service.test.ts src/router/handlers/session-prepare.test.ts
Test Files  3 passed (3) | Tests  300 passed (300)

pnpm --filter kilo-app exec vitest run src/components/agents/session-detail-content.test.ts src/components/agents/mobile-session-manager.test.ts
Test Files  2 passed (2) | Tests  173 passed (173)

pnpm --filter @kilocode/cloud-agent-sdk typecheck        # tsgo --noEmit, clean
pnpm --filter kilo-app typecheck                          # tsgo --noEmit, clean
pnpm --filter web typecheck                               # tsgo --noEmit, clean
pnpm --filter kilo-extension typecheck                    # tsc --noEmit, clean

After merging origin/main (main holds 0258/0259), the migration is now packages/db/src/migrations/0260_complex_smasher.sql; re-verified on e2173db90a — drizzle check fine, db 34 passed, session-ingest 1153 passed / 3 skipped, cloud-agent-next prepare+create 302 passed, mobile session-detail + session-manager 176 passed, all touched-package typechecks clean.


CI repair at a6a285da63

Two checks failed at 1d431aea77. Both came from this branch's own change, not from a flake.

  • cloud-agent-next — the profile-id change added profileId as the sixth argument of createCliSessionViaSessionIngest. That shifted every later argument, and src/session/session-prepare.test.ts pins them. The file now carries the new argument: 12 positional assertions and 3 arity checks agree with the call.
  • test (kilo-app) and test (the kilo-app CI workflow) — repo-picker-sheet.tsx rendered a raw single-line TextInput. main's single-line-input-guard requires the shared box. The field now renders @/components/ui/input, the box language-picker-sheet.tsx uses for the same pill.

Proof at a6a285da63:

Check Result
src/session/session-prepare.test.ts 288 passed (288)
cloud-agent-next package suite 252 files, 7649 passed, 3 skipped
single-line-input-guard.test.ts 20 passed (20)
mobile tsgo --noEmit exit 0
oxlint, the mobile change 0 warnings, 0 errors
oxfmt --list-different no file differs

@iscekic
iscekic marked this pull request as draft September 19, 2026 18:41
Comment thread apps/mobile/src/components/agents/session-detail-content.tsx Outdated
Comment thread apps/mobile/src/components/profiles/mcp-form-sheet.tsx Outdated
Comment thread apps/mobile/src/components/profiles/skill-form-sheet.tsx
Comment thread apps/mobile/src/components/profiles/profile-commands-screen.tsx Outdated
Comment thread apps/mobile/src/lib/hooks/use-agent-profile-mutations.ts Outdated
Comment thread apps/mobile/src/components/profiles/profile-list-model.ts Outdated
Comment thread tools/i18n/check-catalogs.mjs
Comment thread apps/mobile/src/components/agents/advanced-config-panel.tsx Outdated
Comment thread apps/mobile/src/components/profiles/profile-variables-screen.tsx
Comment thread apps/mobile/src/components/profiles/repo-bindings-profile-sheet.tsx
@kilo-code-bot

kilo-code-bot Bot commented Sep 19, 2026 •

Copy link
Copy Markdown
Contributor

Code Review Summary

Status: No Issues Found | Recommendation: Merge

Executive Summary

The incremental diff at c4f73b2fc adds I18nManager: { isRTL: false } to the react-native mocks of the two mounted profile tests, matching the established pattern used by the other mounted suites; the mocked prop is sufficient for the @/components/ui/text reads in those trees, and no new defects were found.

Files Reviewed (2 files)
  • apps/mobile/src/components/profiles/profile-repo-pins-section.mounted.test.tsx
  • apps/mobile/src/components/profiles/repo-bindings-screen.mounted.test.tsx
Previous Review Summaries (10 snapshots, latest commit a6a285d)

Current summary above is authoritative. Previous snapshots are kept for context only.

Previous review (commit a6a285d)

Status: No Issues Found | Recommendation: Merge

Executive Summary

The incremental diff at a6a285da63 routes the repo-picker search field through the shared Input and realigns the profileId positional assertions; both changes are correct and consistent with existing patterns.

Files Reviewed (2 files)
  • apps/mobile/src/components/profiles/repo-picker-sheet.tsx
  • services/cloud-agent-next/src/session/session-prepare.test.ts

Previous review (commit 1d431ae)

Status: No Issues Found | Recommendation: Merge

The incremental change builds IDX_cli_sessions_v2_profile_id concurrently, resolving the prior lock warning; schema, migration, and snapshot are consistent and follow the repository's documented concurrent-index pattern.

Files Reviewed (4 files)
  • packages/db/src/schema.ts
  • packages/db/src/migrations/0260_free_amazoness.sql
  • packages/db/src/migrations/meta/_journal.json (generated)
  • packages/db/src/migrations/meta/0260_snapshot.json (generated)

Previous review (commit c448248)

Status: 1 Issue Found | Recommendation: Address before merge

Executive Summary

The two commits since the previous review resolve both prior findings - the restored session-chip error layer and the missing profile_id index - but the new index is created non-concurrently on the large cli_sessions_v2 table, which locks writes for the build.

Overview

Severity Count
CRITICAL 0
WARNING 1
SUGGESTION 0
Issue Details (click to expand)

WARNING

File Line Issue
packages/db/src/schema.ts 6428 New IDX_cli_sessions_v2_profile_id is declared without .concurrently(), so the generated migration builds it with a write-blocking lock on the large cli_sessions_v2 table
Files Reviewed (5 files, 2 generated)
  • apps/mobile/src/components/agents/session-detail-content.tsx - prior unused-binding finding resolved (hasProfileError: isSessionProfileError restored); new current-row guard is correct
  • packages/db/src/schema.ts - prior missing-index finding resolved; 1 new concurrent-build issue
  • packages/db/src/migrations/0260_misty_gabe_jones.sql - plain CREATE INDEX (see schema finding)
  • packages/db/src/migrations/meta/_journal.json (generated)
  • packages/db/src/migrations/meta/0260_snapshot.json (generated)

Fix these issues in Kilo Cloud

Previous review (commit 508fa19)

Status: 2 Issues Found | Recommendation: Address before merge

Executive Summary

The recorded-profile plumbing is wired correctly end to end, but the mobile session-detail refactor leaves a dead binding that fails pnpm lint, and the new cli_sessions_v2.profile_id foreign key ships without a supporting index.

Overview

Severity Count
CRITICAL 0
WARNING 1
SUGGESTION 1
Issue Details (click to expand)

WARNING

File Line Issue
apps/mobile/src/components/agents/session-detail-content.tsx 514 isSessionProfileError is now unused after hasProfileError was dropped; oxlint no-unused-vars fails pnpm lint

SUGGESTION

File Line Issue
packages/db/src/schema.ts 6376 New profile_id FK (ON DELETE set null) has no supporting index; profile deletion scans the large cli_sessions_v2 table
Files Reviewed (22 files, 2 generated)
  • apps/extension/src/shared/extension-agent-session-manager.ts
  • apps/mobile/src/components/agents/mobile-session-manager.ts
  • apps/mobile/src/components/agents/session-detail-content.test.ts
  • apps/mobile/src/components/agents/session-detail-content.tsx - 1 issue
  • apps/web/src/routers/cli-sessions-v2-router.ts
  • apps/web/src/routers/cli-sessions-v2-worktree.test.ts
  • apps/web/src/tests/cloud-agent-profile/profile-session-config.test.ts
  • packages/cloud-agent-profile/src/profile-session-config.ts
  • packages/cloud-agent-sdk/src/session-manager.ts
  • packages/db/src/migrations/0258_cynical_vapor.sql
  • packages/db/src/migrations/meta/_journal.json (generated)
  • packages/db/src/migrations/meta/0258_snapshot.json (generated)
  • packages/db/src/schema.ts - 1 issue
  • packages/session-ingest-contracts/src/rpc-contract.ts
  • services/cloud-agent-next/src/router/handlers/session-prepare.ts
  • services/cloud-agent-next/src/session-prepare.test.ts
  • services/cloud-agent-next/src/session-service.test.ts
  • services/cloud-agent-next/src/session-service.ts
  • services/cloud-agent-next/src/session/session-registration.ts
  • services/cloud-agent-next/src/session/session-requests.ts
  • services/session-ingest/src/session-ingest-rpc.test.ts
  • services/session-ingest/src/session-ingest-rpc.ts

Fix these issues in Kilo Cloud

Previous review (commit f6b8270)

Status: No Issues Found | Recommendation: Merge

Executive Summary

The incremental commit f6b8270f5 (three profile-picker/profile-save fixes) was reviewed against its changed lines; the label, draft-clearing, and bound changes are correct and no new defects were found.

Files Reviewed (11 files)
  • apps/mobile/src/app/(app)/agent-chat/profile-picker.tsx
  • apps/mobile/src/components/agents/advanced-config-editors.tsx
  • apps/mobile/src/components/agents/advanced-config-panel.tsx
  • apps/mobile/src/components/agents/advanced-config-panel.mounted.test.tsx
  • apps/mobile/src/components/agents/profile-picker-sheet.tsx
  • apps/mobile/src/components/agents/profile-picker-sheet.mounted.test.tsx
  • apps/mobile/src/components/agents/profile-selector-model.ts
  • apps/mobile/src/components/agents/profile-selector-model.test.ts
  • apps/mobile/src/components/agents/profile-selector-row.tsx
  • apps/mobile/src/components/profiles/profile-variables-rows.tsx
  • apps/mobile/src/lib/agent-profile-forms.ts

Previous review (commit 794d8cf)

Status: No Issues Found | Recommendation: Merge

Executive Summary

The incremental changes since 8b3b33fa2 resolve all six prior findings and add focused tests; no new issues were found in the changed code.

Files Reviewed (18 files)
  • apps/mobile/src/components/agents/advanced-config-editors.tsx - setup-command list/row bounds added, no issues
  • apps/mobile/src/components/agents/advanced-config-panel.mounted.test.tsx - cap test, no issues
  • apps/mobile/src/components/profiles/kilo-command-form-sheet.tsx - name/description/template maxLength, no issues
  • apps/mobile/src/components/profiles/kilo-command-form-sheet.mounted.test.tsx - bound test, no issues
  • apps/mobile/src/components/profiles/profile-agents-model.ts - variant retention fix, no issues
  • apps/mobile/src/components/profiles/profile-agents-model.test.ts - variant tests, no issues
  • apps/mobile/src/components/profiles/profile-commands-model.ts - re-exports bounds, no issues
  • apps/mobile/src/components/profiles/profile-commands-model.test.ts - cap test, no issues
  • apps/mobile/src/components/profiles/profile-commands-screen.tsx - maxLength + add cap, no issues
  • apps/mobile/src/components/profiles/profile-kilo-commands-model.ts - server bound constants, no issues
  • apps/mobile/src/i18n/catalog-parity.test.ts - pending-translation set emptied; all four keys verified present in all 87 catalogs
  • apps/mobile/src/lib/agent-profile-forms.ts - MAX_SETUP_COMMANDS/MAX_SETUP_COMMAND_LENGTH, add cap, no issues
  • apps/mobile/src/lib/agent-profile-forms.test.ts - cap test, no issues
  • apps/mobile/src/lib/hooks/use-agent-profiles.ts - exported key-aware placeholder, no issues
  • apps/mobile/src/lib/hooks/use-repo-bindings.ts - key-aware placeholder replaces keepPreviousData, no issues
  • apps/mobile/src/lib/hooks/use-repo-bindings.mounted.test.tsx - context-switch test, no issues
  • apps/web/src/components/cloud-agent/ProfilePickerPopover.tsx - error state now requires empty cache, no issues
  • apps/web/src/components/cloud-agent/ProfilePickerPopover.test.ts - cached-error test, no issues

Previously reported findings re-verified resolved at 794d8cfd0: agent effort-variant retention, repo-bindings cross-scope placeholder, picker error-with-cached-data, kilo-command and setup-command server bounds, and the stale pending-translation allowlist. No memory-leak patterns were found in the changed code.

Previous review (commit 8b3b33f)

Status: 6 Issues Found | Recommendation: Address before merge

Executive Summary

The rebase (previous reviewed SHA by force-push/rewrite) carried over every earlier accepted fix, and this pass on the current single-commit diff (b9007d12b..8b3b33fa2, 221 files) raised six new issues: a stale-data/cross-scope placeholder in the repo-bindings hook, a dropped agent effort variant, an error branch that hides cached web profiles, and three client/server bound-parity gaps.

Overview

Severity Count
CRITICAL 0
WARNING 3
SUGGESTION 3
Issue Details (click to expand)

WARNING

File Line Issue
apps/mobile/src/components/profiles/profile-agents-model.ts 273 Changing an agent's model discards an effort variant the new model supports (existing.model === model guard).
apps/mobile/src/lib/hooks/use-repo-bindings.ts 30 Raw keepPreviousData leaks the previous organization's bindings across an org switch while mutations use the new scope.
apps/web/src/components/cloud-agent/ProfilePickerPopover.tsx 402 isError is !!error, so a failed background refetch hides the picker even though cached profiles are present.

SUGGESTION

File Line Issue
apps/mobile/src/components/profiles/profile-kilo-commands-model.ts 138 Validation omits the server's name (50) / template (100k) / description (2k) length bounds.
apps/mobile/src/components/agents/advanced-config-editors.tsx 209 Setup-commands editor is unbounded while prepareSession/setCommands cap 20 commands of 500 chars.
apps/mobile/src/i18n/catalog-parity.test.ts 34 The four allowlisted keys already exist (translated) in every catalog, so the pending-translation set is stale.
Files Reviewed (221 files)

All 221 files in the current PR diff (b9007d12b..8b3b33fa2). Substantive source reviewed in full: the mobile profile screens, models, sheets, rows and pickers under apps/mobile/src/components/profiles/; the agents feature (advanced-config-panel, advanced-config-editors, save-profile-sheet, profile-picker-sheet, profile-selector-*, active-profile-indicator, new-session-*, session-detail-content, use-effective-agent-profile, use-new-session-creator); the hooks and libs (use-agent-profile-mutations, use-agent-profile-section-mutations, use-agent-profiles, use-repo-bindings, agent-profile-forms, profile-count-labels, profile-agent-navigation, picker-bridge, route-registry, prepare-agent-session); the (3_profile) routes; the web surfaces (PrefetchedOrganizations, SeedUserQuery, (app)/layout, ProfilePickerPopover, TriggerForm); packages/trpc/src/agent-profiles-mobile.ts; and tools/i18n/check-catalogs.mjs. The remaining files are locale catalogs and test/helper files spot-checked for key parity and placeholder integrity.

Previously reported findings re-verified resolved at HEAD: owner-scope chip, MCP edit type lock, skill description clearing, commands refetch generation, owner-scoped optimistic defaults, ['user'] seeding, profile-list MCP count, manual-commands gate, variables delete guard, repo-bindings empty state, duplicate-key normalization, MCP command quoting, manual env/command propagation into the create body, MCP form bounds, and the key-aware profile-list placeholder. The one rejected item (numeric expansion tokens in check-catalogs.mjs) remains unchanged by owner decision.

No memory-leak patterns (uncleared timers, listeners, subscriptions, or retained bridge state) were found in the added code.

Fix these issues in Kilo Cloud

Previous review (commit cd3af0d)

Status: No Issues Found | Recommendation: Merge

Executive Summary

Incremental review at HEAD cd3af0d73: the rebase onto current main introduced no new PR code — the only content deltas since the last-reviewed tree (b0460cef9) are adoptions of already-merged main changes (tool-summary retry mount wiring, a test secure-store mock, a passkey case-guard rewrap, and openSession/approveFailed locale keys from merged PRs), and every previously accepted fix was verified present at the current tree; no memory-leak patterns were found in the added lines.

Files Reviewed (217 files)
  • All 217 files in the current PR diff (f5e3cf7 → cd3af0d) were verified byte-identical to the last-reviewed tree for every profile-management file (screens, sheets, models, hooks, tRPC mount, tests, web components), except four groups whose head-to-head deltas come solely from rebase adoption of merged main content: (app)/_layout.tsx, session-detail-queue.test.ts, case-guard.test.ts, and the locale catalogs. Previously raised findings are all resolved: ten accepted fixes verified at current HEAD (session-detail-content owner-scope chip, mcp-form-sheet edit-locked type, skill description clearing, commands refetch sync with generation bump, owner-scoped optimistic defaults, PrefetchedOrganizations user seeding, profile-list-model MCP count, advanced-config manual-commands gate, variables delete guard, repo-bindings empty state) and one rejected by the owner (i18n numeric expansion tokens, no change requested).

Previous review

Status: No Issues Found | Recommendation: Merge

Executive Summary

Incremental review of the profile-management fix set at HEAD b0460cef9 (96fe3c6 is not an ancestor, so each fix hunk was verified against the current tree); no new defects were found.

Files Reviewed (27 files)
  • apps/mobile/src/app/(app)/_layout.tsx
  • apps/mobile/src/components/agents/advanced-config-panel.mounted.test.tsx
  • apps/mobile/src/components/agents/advanced-config-panel.tsx
  • apps/mobile/src/components/agents/session-detail-content.test.ts
  • apps/mobile/src/components/agents/session-detail-content.tsx
  • apps/mobile/src/components/agents/session-detail-queue.test.ts
  • apps/mobile/src/components/agents/use-effective-agent-profile.ts
  • apps/mobile/src/components/profiles/mcp-form-sheet.tsx
  • apps/mobile/src/components/profiles/profile-commands-screen.mounted.test.tsx
  • apps/mobile/src/components/profiles/profile-commands-screen.tsx
  • apps/mobile/src/components/profiles/profile-list-model.test.ts
  • apps/mobile/src/components/profiles/profile-list-model.ts
  • apps/mobile/src/components/profiles/profile-mcp-screen.mounted.test.tsx
  • apps/mobile/src/components/profiles/profile-skills-screen.mounted.test.tsx
  • apps/mobile/src/components/profiles/profile-skills-screen.tsx
  • apps/mobile/src/components/profiles/profile-variables-rows.tsx
  • apps/mobile/src/components/profiles/profile-variables-screen.mounted.test.tsx
  • apps/mobile/src/components/profiles/profile-variables-screen.tsx
  • apps/mobile/src/components/profiles/profiles-list-screen.mounted.test.tsx
  • apps/mobile/src/components/profiles/repo-bindings-profile-sheet.mounted.test.tsx
  • apps/mobile/src/components/profiles/repo-bindings-profile-sheet.tsx
  • apps/mobile/src/lib/case-guard.test.ts
  • apps/mobile/src/lib/hooks/use-agent-profile-mutations.ts
  • apps/mobile/src/lib/hooks/use-agent-profiles.mounted.test.tsx
  • apps/web/package.json
  • apps/web/src/app/(app)/components/PrefetchedOrganizations.test.ts
  • apps/web/src/app/(app)/components/PrefetchedOrganizations.tsx

Previous review (commit 96fe3c6)

Status: 11 Issues Found | Recommendation: Address before merge

Overview

Severity Count
CRITICAL 0
WARNING 6
SUGGESTION 5
Issue Details (click to expand)

WARNING

File Line Issue
apps/mobile/src/components/agents/session-detail-content.tsx 488 Active-profile chip opens a personal profile with the session organization scope, so the editor screen errors
apps/mobile/src/components/profiles/mcp-form-sheet.tsx 118 Editable type toggle on an existing MCP server can reinterpret masked env/headers and lose secrets
apps/mobile/src/components/profiles/skill-form-sheet.tsx 69 Clearing a skill frontmatter description on update is omitted, so the stored value is not cleared
apps/mobile/src/components/profiles/profile-commands-screen.tsx 89 Refetch sync does not bump generation, so in-flight command edits are lost and state diverges from the fields
apps/mobile/src/lib/hooks/use-agent-profile-mutations.ts 97 Optimistic default write ignores owner scoping and personal-first effective-default resolution
apps/web/src/app/(app)/components/PrefetchedOrganizations.tsx 40 Seeding null after a failed SSR context pins ['user'] to signed-out for the 60s staleTime

SUGGESTION

File Line Issue
apps/mobile/src/components/profiles/profile-list-model.ts 109 Row subtitle shows commands where web shows MCP servers; mcpServerCount is dropped
tools/i18n/check-catalogs.mjs 221 Expansion-token check misses numeric $1/$2 tokens
apps/mobile/src/components/agents/advanced-config-panel.tsx 154 hasManualConfig counts blank draft rows that are never saved
apps/mobile/src/components/profiles/profile-variables-screen.tsx 105 Variable delete has no in-flight guard, allowing a duplicate delete
apps/mobile/src/components/profiles/repo-bindings-profile-sheet.tsx 57 Profile picker has no empty state
Files Reviewed (231 files)
  • apps/mobile/src/components/agents/session-detail-content.tsx - 1 warning
  • apps/mobile/src/components/profiles/mcp-form-sheet.tsx - 1 warning
  • apps/mobile/src/components/profiles/skill-form-sheet.tsx - 1 warning
  • apps/mobile/src/components/profiles/profile-commands-screen.tsx - 1 warning
  • apps/mobile/src/lib/hooks/use-agent-profile-mutations.ts - 1 warning
  • apps/web/src/app/(app)/components/PrefetchedOrganizations.tsx - 1 warning
  • apps/mobile/src/components/profiles/profile-list-model.ts - 1 suggestion
  • tools/i18n/check-catalogs.mjs - 1 suggestion
  • apps/mobile/src/components/agents/advanced-config-panel.tsx - 1 suggestion
  • apps/mobile/src/components/profiles/profile-variables-screen.tsx - 1 suggestion
  • apps/mobile/src/components/profiles/repo-bindings-profile-sheet.tsx - 1 suggestion
  • All other files in the 231-file PR diff were reviewed; the mobile tRPC mount (packages/trpc/src/agent-profiles-mobile.ts) re-exposes the web router procedures with their existing server-side auth and ensureOrganizationAccess checks, and no memory-leak (uncleaned listeners/subscriptions/timers) patterns were found.

Fix these issues in Kilo Cloud


Reviewed by deepseek-v4.1-flash · Input: 0 · Output: 0 · Cached: 0

Review guidance: REVIEW.md from base branch main

@iscekic

iscekic commented Sep 20, 2026

Copy link
Copy Markdown
Collaborator Author

bot: Rejected, no code change (kwf kwf-fix-platform-713b).

Why: (already implemented, verified live: no change needed: Refuted: all 20 flagged added lines are cross-platform expo-router / react-native-safe-area-context imports, and the mobile diff adds no Platform.OS/.ios/.android branch, so there is no platform fork to remove. Finding refuted with evidence. The 20 flagged added lines are imports o

@iscekic
iscekic marked this pull request as ready for review September 20, 2026 00:49
@iscekic
iscekic requested a review from eshurakov September 20, 2026 01:53
@iscekic iscekic added the human-ready The PR is ready for human review. label Sep 20, 2026
@iscekic
iscekic requested a review from pandemicsyn September 20, 2026 01:53
@iscekic iscekic self-assigned this Sep 20, 2026
@iscekic
iscekic force-pushed the kwf/req-20260918-153926-dcb3 branch from b0460ce to cd3af0d Compare September 20, 2026 18:16
@iscekic iscekic removed the human-ready The PR is ready for human review. label Sep 21, 2026
@iscekic
iscekic marked this pull request as draft September 21, 2026 00:55
@iscekic
iscekic marked this pull request as ready for review September 21, 2026 01:17
@iscekic iscekic added the human-ready The PR is ready for human review. label Sep 21, 2026

@eshurakov eshurakov left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved after a shallow triage pass. Note: also carries a signed-out web seed fix (SeedUserQuery.tsx).

@iscekic iscekic removed the human-ready The PR is ready for human review. label Sep 22, 2026
@iscekic
iscekic marked this pull request as draft September 22, 2026 02:54
Comment thread apps/mobile/src/components/profiles/profile-variables-rows.tsx
Comment thread apps/mobile/src/components/profiles/profile-mcp-model.ts Outdated
Comment thread apps/mobile/src/components/agents/advanced-config-panel.tsx Outdated
Comment thread apps/mobile/src/components/profiles/profile-mcp-model.ts
Comment thread apps/mobile/src/lib/hooks/use-agent-profiles.ts Outdated
@iscekic
iscekic force-pushed the kwf/req-20260918-153926-dcb3 branch from de44358 to 8b3b33f Compare September 23, 2026 04:33
@iscekic
iscekic marked this pull request as ready for review September 23, 2026 04:51
Comment thread apps/mobile/src/components/profiles/profile-agents-model.ts Outdated
Comment thread apps/mobile/src/lib/hooks/use-repo-bindings.ts Outdated
Comment thread apps/web/src/components/cloud-agent/ProfilePickerPopover.tsx
Comment thread apps/mobile/src/components/profiles/profile-kilo-commands-model.ts
Comment thread apps/mobile/src/components/agents/advanced-config-editors.tsx
Comment thread apps/mobile/src/i18n/catalog-parity.test.ts Outdated
@iscekic
iscekic marked this pull request as draft September 23, 2026 05:37
@iscekic
iscekic force-pushed the kwf/req-20260918-153926-dcb3 branch from f88d12a to 794d8cf Compare September 23, 2026 08:34
@iscekic
iscekic requested a review from pandemicsyn September 23, 2026 09:10
Comment thread apps/mobile/src/components/agents/advanced-config-panel.tsx
Comment thread apps/mobile/src/components/agents/profile-picker-sheet.tsx
Comment thread apps/mobile/src/components/agents/session-detail-content.tsx
Comment thread apps/mobile/src/components/profiles/profile-variables-rows.tsx
- advanced-config-panel.tsx: clear the manual env-var and setup-command
  drafts after a profile save succeeds. The saved profile now carries those
  values, and the create request appends the profile's setup commands to the
  inline ones, so a kept draft ran every saved command twice.
- profile-picker-sheet.tsx, profile-selector-model.ts, profile-selector-row.tsx:
  clearing the pick hands the session to the effective default, so the
  no-override row names that default (`profiles.defaultSectionTitle`) whenever
  the context resolves one, and says `No profile` only when nothing applies.
- profile-variables-rows.tsx, agent-profile-forms.ts: the manual env-var editor
  applies the prepare-session bound (256 characters) to the value field, so an
  over-long value cannot be entered under Advanced Configuration.
…sion profile

Records the profile a session was prepared with. Nullable and
ON DELETE SET NULL so pre-existing rows and profile deletion stay
readable.
…eate

mergeProfileConfiguration now reports the profile that claimed the
active layer (explicit pick, else effective default, else repo binding).
applyProfileResolution carries it on the request and the session-ingest
create call writes it to cli_sessions_v2.
…rofile

The chip read the context's effective default, which can differ from the
profile the session was prepared with. It now resolves the recorded
profileId and only falls back to the effective default when the session
recorded none; an id that no longer resolves leaves the chip unselected.
…26-dcb3

# Conflicts:
#	packages/db/src/migrations/meta/0258_snapshot.json
#	packages/db/src/migrations/meta/_journal.json
Comment thread apps/mobile/src/components/agents/session-detail-content.tsx
Comment thread packages/db/src/schema.ts
… stale row

The chip reads the current session's row (kiloSessionId match) before
using its profileId, and restores the profile-query error layer the
earlier edit dropped.
Supports the ON DELETE SET NULL scan when a profile is deleted. The
profile_id migration is regenerated as 0260 (now 0260_misty_gabe_jones)
so it carries the column, the FK, and the index.
Comment thread packages/db/src/schema.ts Outdated
cli_sessions_v2 is large, so the generated plain CREATE INDEX would block
writes for the whole build. The index now uses .concurrently() and the
regenerated migration (0260_free_amazoness) carries the COMMIT;/BEGIN;
boundaries the transactional migrator needs.
…file id

Add the new `profileId` argument to the 12 positional assertions in
`session-prepare.test.ts`.
Widen the three arity checks from 9 arguments to 10.
Render the repo picker's search field with the shared `Input` box.
`main`'s `single-line-input-guard` requires that box.
The repo picker renders the shared `Input` box now.
That box reads the RTL state through `rtl-text.ts`.
Both mounted mocks describe `react-native` with four keys, so add `I18nManager`.
@iscekic
iscekic merged commit 3b9eb60 into main Sep 24, 2026
61 checks passed
@iscekic
iscekic deleted the kwf/req-20260918-153926-dcb3 branch September 24, 2026 19:42
iscekic pushed a commit to Kilo-Org/kilocode that referenced this pull request Sep 26, 2026
…4554)

## Automated docs sync — 2026-09-25

This PR keeps kilo.ai/docs in sync with features merged to [Kilo-Org/cloud](https://github.com/Kilo-Org/cloud) and [Kilo-Org/kilocode](https://github.com/Kilo-Org/kilocode). Every change below links to the merged PR it documents.

- Window: `2026-09-24T07:08:33.639Z` → `2026-09-25T07:05:29.302Z`
- Verification (docs build + tests): **passing**

### Surface: `cloud-mobile`

- Assignees / requested reviewers: @iscekic and @eshurakov
- Derivation: Derived from the repository layout. A product surface is a package under packages/ that ships a distinct client, plugin, backend, or hosted service: cli = packages/opencode/ + packages/tui/ + packages/server/ + packages/sdk/ + packages/plugin/; vscode = packages/kilo-vscode/ + packages/kilo-web-ui/ + packages/kilo-ui/; jetbrains = packages/kilo-jetbrains/; gateway = packages/kilo-gateway/; web = packages/kilo-console/ + packages/kilo-indexing/ + packages/kilo-memory/ + packages/kilo-sandbox/. Docs route from the IA tree packages/kilo-docs/pages/ plus docs/jetbrains-vscode-settings-parity.md: each surface lists the pages sections that document it, and the per-platform pages under packages/kilo-docs/pages/code-with-ai/platforms/ map to the matching extension surface (the vscode/ directory to vscode, jetbrains.md to jetbrains). A doc path belongs to the surface with the longest matching prefix; a path that matches none of those prefixes falls to `other` (the explicit other prefixes are listed under other.docs). The cloud surfaces are derived the same way from the Kilo-Org/cloud layout: cloud-mobile = apps/mobile/, cloud-web = apps/web/, cloud-extension = apps/extension/, and cloud-agent = the cloud-agent packages under packages/ (packages/cloud-agent-sdk/ + packages/cloud-agent-profile/). A cloud source names its repository while a bare string still means this repository. The pages under packages/kilo-docs/pages/collaborate/ document the cloud web app (app.kilo.ai: teams dashboard, billing, SSO, adoption dashboard), so they route to cloud-web. No page under packages/kilo-docs/pages/ documents the browser side-panel extension yet, so cloud-extension lists no docs prefix.
- Map: `.github/docs-sync/surfaces.json`
- Surface map: `cli`, `vscode`, `jetbrains`, `gateway`, `web`, `cloud-mobile`, `cloud-web`, `cloud-extension`, `cloud-agent`, `other`
- Source prefixes: `apps/mobile/` (Kilo-Org/cloud)
- Doc prefixes: `packages/kilo-docs/pages/code-with-ai/platforms/mobile.md`
- Paths that fall to `other`: `packages/kilo-docs/pages/community/`, `packages/kilo-docs/pages/kiloclaw/`, `packages/kilo-docs/pages/contributing/`, `packages/kilo-docs/LEARNINGS.md`, `docs/`
- Reviewers are ranked from `Kilo-Org/cloud`; the workflow needs a token with `contents: read` on that repository (repository secret `CROSS_REPO_ACCESS_TOKEN`, exposed to the upsert step as `CLOUD_REPO_TOKEN`).
- How the two were computed: Reviewers for `cloud-mobile` are ranked from `Kilo-Org/cloud` git history over `apps/mobile/` (a commit 180 days old counts half as much, half-life 180 days). Bots (author type "Bot" or a login matching /\[bot\]$/i) and people without admin, write, or maintain permission are excluded.

### Changes

<!-- docs-sync:changes:start -->
| Docs change | Source |
| --- | --- |
| updated pages/code-with-ai/platforms/mobile.md | [Kilo-Org/cloud#6386](Kilo-Org/cloud#6386) |
| updated pages/ai-providers/openai-chatgpt-plus-pro.md | [Kilo-Org/cloud#6702](Kilo-Org/cloud#6702) |
| updated pages/code-with-ai/platforms/cloud-agent.md | [Kilo-Org/cloud#6683](Kilo-Org/cloud#6683) |
| updated pages/getting-started/byok.md | [Kilo-Org/cloud#6692](Kilo-Org/cloud#6692) |
<!-- docs-sync:changes:end -->

### Pending — will retry

<!-- docs-sync:pending:start -->
_None._
<!-- docs-sync:pending:end -->

### Considered, no docs change needed

<!-- docs-sync:skipped:start -->
| PR | Reason |
| --- | --- |
| [Kilo-Org/cloud#6658](Kilo-Org/cloud#6658) | Internal sandbox lifecycle fix with no user-visible workflow or setting. |
| [Kilo-Org/cloud#6673](Kilo-Org/cloud#6673) | Internal container CA trust plumbing, no user-facing behavior. |
| [Kilo-Org/cloud#6672](Kilo-Org/cloud#6672) | Internal sandbox launch/recovery fix with no documented workflow change. |
| [Kilo-Org/cloud#6660](Kilo-Org/cloud#6660) | Internal cloud-agent queue delivery fix; no new command, setting, or workflow for users. |
| [Kilo-Org/cloud#6226](Kilo-Org/cloud#6226) | Internal gateway alias-routing change, not user-visible. |
| [#14490](#14490) | Tool-call animation and streaming UI polish; users do not need to learn a new workflow. |
| [#14530](#14530) | Bug fix restoring intended worktree-pool behavior, no doc change needed. |
| [#14529](#14529) | Bug fix restoring tab/panel state across project switches. |
| [#14531](#14531) | Reconnect recovery bug fix, restores already-documented behavior. |
| [#14532](#14532) | Bug fix keeping session tab title in sync on rename. |
| [Kilo-Org/cloud#6088](Kilo-Org/cloud#6088) | Removes internal/admin model-experiment surfaces, not public product docs. |
| [Kilo-Org/cloud#6682](Kilo-Org/cloud#6682) | Internal control-socket reconnect race fix, no user-facing change. |
| [#14534](#14534) | Transcript re-render performance bug fix. |
| [#14535](#14535) | Bug fix preserving the loaded browser page across context switches. |
| [Kilo-Org/cloud#6684](Kilo-Org/cloud#6684) | Reverted by Kilo-Org/cloud#6685. |
| [Kilo-Org/cloud#6678](Kilo-Org/cloud#6678) | Dead-code constant removal, no user-visible effect. |
| [Kilo-Org/cloud#6687](Kilo-Org/cloud#6687) | Removes internal model-experiment maintenance and retains tables, no user-facing change. |
| [#14515](#14515) | JetBrains plugin unload crash fix, no documented behavior change. |
| [#14520](#14520) | JetBrains transcript/list rendering performance work. |
| [Kilo-Org/cloud#6614](Kilo-Org/cloud#6614) | Mobile PR Review header and session title bug fix, no doc change needed. |
| [Kilo-Org/cloud#6625](Kilo-Org/cloud#6625) | Internal mobile secure-store error-handling refactor. |
| [Kilo-Org/cloud#6624](Kilo-Org/cloud#6624) | Mobile auth bug fix that stops a retry loop; restores expected sign-in behavior with no new setting or workflow. |
| [#14310](#14310) | Contributor/CI fix making the kilo-v2 checkout installable; not user-visible product behavior. |
| [Kilo-Org/cloud#6611](Kilo-Org/cloud#6611) | Mobile notification-tap fix that selects the session's organization; restores correct behavior rather than adding a learnable feature. |
| [Kilo-Org/cloud#6644](Kilo-Org/cloud#6644) | Mobile sign-in layout/alignment polish; no change to what a user must do. |
| [Kilo-Org/cloud#6601](Kilo-Org/cloud#6601) | Mobile layout fix keeping empty states clear of the tab bar; purely visual. |
| [#14543](#14543) | CI/release infrastructure adding Windows binary code signing; no public docs impact. |
| [Kilo-Org/cloud#6616](Kilo-Org/cloud#6616) | Mobile visual defect fixes and a session-title fallback; no new user workflow or setting. |
| [Kilo-Org/cloud#6630](Kilo-Org/cloud#6630) | Reports an edge-case partial worktree restore; failure-path plumbing with no new user-facing workflow, target setting, or config. |
| [Kilo-Org/cloud#6699](Kilo-Org/cloud#6699) | Cloud Agent e2e stabilization plus internal idle-sandbox capacity handling; not user-visible. |
| [#14545](#14545) | Automated JetBrains release/changelog PR; underlying user-facing changes are triaged from their own PRs. |
| [Kilo-Org/cloud#6708](Kilo-Org/cloud#6708) | Internal AI-gateway request-logging policy change in the admin panel; no existing public docs surface and no change to how users run Kilo Code. |
| [#14533](#14533) | Documentation already shipped with the merged PR. The experimental.task_model_selection flag is gone from the current source, and pages/code-with-ai/agents/model-selection.md, pages/code-with-ai/agents/context-mentions.md, and pages/getting-started/settings/index.md already describe per-task selection as default-on with no stale experiment references. |
| [#14510](#14510) | Documentation already shipped with the merged PR. Marketplace companion-skill support is present in the current source (packages/opencode/src/kilocode/marketplace/companions.ts and installer), and pages/customize/marketplace.md already documents installing, publishing, and removing MCP servers with companion skills. |
<!-- docs-sync:skipped:end -->

---

(bot) Generated by the docs-sync workflow. Humans review and merge; while this PR stays open, the next daily run appends new changes here. Branch: `docs/auto-sync-2026-09-25`.
<!-- docs-sync: processed-through 2026-09-25T07:05:29.302Z -->
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

human-ready The PR is ready for human review.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants