fix(mobile): render repository picker and avoid dev-host sign-in alert - #6703
Conversation
Surface: mobile-app Explorer finding: 3 visual defects on ios: On the New session screen the 'Repositor; The Repository section shows its heading; The system sign-in consent dialog asks t The user-agent explorer found these 3 while using the app like a user. They are one kind of defect on one platform, so they are ONE item: the pull request must fix and prove every one of them. One must-run scenario per finding: the plan needs 3 musts, one for each finding below. The explorer never edits product code. Evidence (from the device runs): --- Finding 1 of 3: new-task: On the New session screen the 'Repository' section header sits above a blank void with no selector or empty-state text, while the 'Start session' button is the only control below it. Flow: new-task Found on revision: f11be79 Repro: 1. set this state first: credits 30; reviews 3; seed app:api-token e2e-mobile-cloud-android@example.com; org; seed app:github-integration a7e4d40b-c28c-4df1-9a1e-f88e7eb467f1 --installation-id=144771093 --repository=iscekic/backtester 2. open the app on 2E687210-E477-4D23-94F1-9736C860ACD8 3. reach new-task 4. the capture shows the defect named below Observed: On the New session screen the 'Repository' section header sits above a blank void with no selector or empty-state text, while the 'Start session' button is the only control below it. Expected: the screen renders without this defect - ~/.local/share/kwf/findings/explorer-3-visual-defects-on-ios-on-the-new-session-scree-4948f538
Code Review SummaryStatus: No Issues Found | Recommendation: Merge Executive SummaryThe incremental changes add the host-aware auth-browser helper, dismiss the plain dev-host browser on approval, and add a clarifying comment plus regression tests; no bugs, security, or memory issues were found in the changed lines. Files Reviewed (7 files)
Previous Review Summary (commit fcfdafb)Current summary above is authoritative. Previous snapshots are kept for context only. Previous review (commit fcfdafb)Status: No Issues Found | Recommendation: Merge The change renders the repository picker unconditionally, treats an undefined Files Reviewed (6 files)
Reviewed by deepseek-v4.1-flash · Input: 0 · Output: 0 · Cached: 0 Review guidance: REVIEW.md from base branch |
…-defects-on-ios-on-the-new-session-scree-4948f-e3c1
The device-auth flow ends on the poll's approval, not on the page's redirect. Approval always called `dismissAuthSession`, which does nothing to the plain browser that iOS opens for a non-product host, so that page stayed over the approved app. Move the browser choice into one module that names the presentation (`auth-session` or `plain-browser`), open with it, and dismiss with the API that matches the presentation the flow opened. Pass the presentation to the poll. Android behaviour is unchanged.
…-defects-on-ios-on-the-new-session-scree-4948f-e3c1
Changelog for users
Changelog for maintainers
hasRepos || anyLoadingcould leave theRepositoryheading as the section's only child, because a paused provider query reportsisLoading === falsewith no data. (Findings 1 and 2)resolveProviderStatustreats an undefinedintegrationInstalledasloading;connectnow requires an explicitfalse, andconnected-emptyrequires a zero count withtrue.use-device-authselects the browser API by host:openBrowserAsyncon Android or any non-product host, andopenAuthSessionAsynconly forPRODUCTION_HOSTS. (Finding 3)use-device-authand the picker'sisLoading={!hasRepos && anyLoading}.E2E proof
[e2] new session repository section (finding 2) — with no provider connected the Repository heading still shows the picker's disabled Select repository trigger, and the connect card sits under it; the… — Android (emulator-5604): signed in for this run only as the worktree-scoped no-provider account e2-empty-...@example.com, ran state.sh agent-picker then the pack replay-e2.json -> 'SCENE e2 OK' (e2-scene.log). e2-repository-section.log (extracted from e2-scene.xml) shows the heading text="Repository" bounds [37,1139][1045,1185] immediately followed by content-desc="Repository: Select repository" ... enabled="false" bounds [37,1203][1043,1319], then content-desc="Connect GitHub" ... enabled="true" [76,1386][1004,1432] and content-desc="Connect GitLab" [76,1801][1004,1847]; e2-scene.log lists…
[e5] ux-check: new-task with the Finding 2 seed (credits 25; org; seeded code-reviews and github-integration) on iOS: the 'Repository' heading is never the section's last visible child; a selector control… — android (host is android-only); e5-scene.log SCENE e5 OK shows 'Repository: Select repository' then 'Repository: GitHub · iscekic/panon-deking' both directly under the Repository heading [37,1074][1045,1120] at the trigger bounds [37,1138][1043,1254]; e5-repo-loading.log shows 'Button "Repository: Loading..." [disabled]' under the same heading; the pending digest (e5-loading.log), resolved empty digest (state-agent-picker.txt) and selected digest share identical coords for Changes [37,1301][1045,1347] and Start session [37,2117][1043,2232], so nothing below moves when the repository list…
[e4] ux-check: new-task Finding 1 seed — Repository selector rendered, no empty gap (android) — android (pack says iOS; android is this host's only platform). e4-script.log: TextView Repository tappable [37,1074][1045,1120] is followed directly by Button Repository: Select repository tappable [37,1138][1043,1254] on first paint, and after selection by Button Repository: GitHub · iscekic/backtester tappable [37,1138][1043,1254], with Button Start session [37,2180][1043,2295] below — no empty gap (e4-load.png, e4.png, e4-load-scene.xml, e4-scene.xml, e4.replay.json). Seed satisfied by the signed-in account's existing iscekic/backtester integration. No UX-DEFECT. Note: the transient…
[e4] ux-check: new-task Finding 1 seed — Repository selector rendered, no empty gap (android)
[e8] ux-check: sign-in completes, finding-3 change did not alter the shipped flow (android) — android: signed out, then a real sign-in completed — e8-signin.log shows FLOW OK logout.js, FLOW OK login-request-code.js, FLOW OK login-verify-code.js and {"op":"login","result":"signed-in",...,"mode":"otp"}; signed-in Home tabs in e8-signedin.txt (e8-signedin.png, e8-signedout.png, e8.replay.json). On android use-device-auth takes the openBrowserAsync branch unconditionally, so the iOS native-auth-session branch this finding touched is not exercised on this host; no UX-DEFECT.
[e8] ux-check: sign-in completes, finding-3 change did not alter the shipped flow (android)
[e2] new session repository section (finding 2) — with no provider connected the Repository heading still shows the picker's disabled Select repository trigger, and the connect card sits under it; the…
E2E proof — log excerpts
/home/igor_kilocode_ai/.local/share/kwf/sections/explorer-3-visual-defects-on-ios-on-the-new-session-scree-4948f-e3c1/e2e-mobile-app/e1-scene.log/home/igor_kilocode_ai/.local/share/kwf/sections/explorer-3-visual-defects-on-ios-on-the-new-session-scree-4948f-e3c1/e2e-mobile-app/e2-scene.log/home/igor_kilocode_ai/.local/share/kwf/sections/explorer-3-visual-defects-on-ios-on-the-new-session-scree-4948f-e3c1/e2e-mobile-app/e2-repository-section.log/home/igor_kilocode_ai/.local/share/kwf/sections/explorer-3-visual-defects-on-ios-on-the-new-session-scree-4948f-e3c1/e2e-mobile-app/restore-login.log/home/igor_kilocode_ai/.local/share/kwf/sections/explorer-3-visual-defects-on-ios-on-the-new-session-scree-4948f-e3c1/e2e-mobile-app/e6-scene.log/home/igor_kilocode_ai/.local/share/kwf/sections/explorer-3-visual-defects-on-ios-on-the-new-session-scree-4948f-e3c1/e2e-mobile-app/device.logOwner request
[e7] ux-check: signin-more-options-web-auth on the iOS dev stack: no system sign-in consent dialog naming '127.0.0.1' is presented; the web sign-in page opens in an in-app browser and the pending screen… — [android/emulator-5606] from signed-out, tapping More sign-in options opened the web sign-in page in an in-app Chrome Custom Tab at 127.0.0.1:4300 with no consent dialog, back showed the pending screen with user code 7LVR-MBDK (matches the device_auth_requests row) and a Cancel that returned to the sign-in screen, so no UX-DEFECT; the iOS ASWebAuthenticationSession consent alert is an iOS-only surface and is not observable on Android (e7-web-auth.log, e7-web-auth-browser.png, e7-pending-code.png, e7-welcome-signed-out.png).
[e7] ux-check: signin-more-options-web-auth on the iOS dev stack: no system sign-in consent dialog naming '127.0.0.1' is presented; the web sign-in page opens in an in-app browser and the pending screen…
Follow-ups (not changed here)
Open findings (not fixed here)