Skip to content

fix(bestax-mcp): give Theme, ConfigProvider, Portal and ClientOnly prop tables - #969

Merged
allxsmith merged 21 commits into
mainfrom
fix/933-helper-component-props
Oct 9, 2026
Merged

allxsmith merged 21 commits into
mainfrom
fix/933-helper-component-props

Conversation

@allxsmith

@allxsmith allxsmith commented Oct 7, 2026 •

Copy link
Copy Markdown
Owner

The MCP index shipped every page under helpers/ as prose, so get_props answered Theme, ConfigProvider, Portal and ClientOnly as if they were hooks: no table, and a pointer at get_helper_props, which describes none of them. Search could not reach their props either. The real hooks fared no better. useFocusTrap and useBulmaClasses were pointed at get_helper_props too, and search named it as the next step for a hook.

A component documented on a helpers page is now built like every other component, from its props interface, and keeps its page for include: ["reference"]. The props extractor learns the two shapes that hid these components. Portal and ClientOnly are declared as functions rather than constants, and ConfigProvider reaches the barrel through an export * from a module of another name. Neither change moves the generated API pages. ConfigProviderProps and ThemeProps now document their members in TSDoc rather than in @property tags, so their tables have notes, and each of Theme's variable props names the variable it sets. In bulma-ui that is a doc-comment change and nothing else.

A hook's record now carries its ## API signature block. get_component and get_props answer a hook with that block, then point at its whole page (giving the page's size, since useBulmaClasses' runs to tens of thousands of characters) and at get_examples. Search names get_component as the next step for a hook. useBulmaClasses still names get_helper_props too, since its page is where the helper props it reads are documented.

The index now resolves every link it ships to the URL bestax.io serves, so text cut from a page no longer points at a relative file or an anchor the answer does not carry. A component documented in prose says where its page is under its table. A prose page whose capitalised title names no component stops the build with the page and the rule, rather than shipping a component as prose.

pnpm all passes locally.

Fixes #933

Summary by CodeRabbit

  • New Features
    • Component and helper lookups now provide clearer API details and direct links to full documentation, including usage examples where available.
    • Documentation now includes expanded guidance for focus management, class utilities, and components such as ClientOnly, ConfigProvider, Portal, and Theme.
    • ConfigProvider now supports an optional icon library setting.
  • Documentation
    • Updated cross-references to use direct documentation links and clarified prop descriptions and rendering behavior.

…op tables

The index shipped every helpers page as prose, so get_props answered these four components
as if they were hooks, with no table, and sent the caller to get_helper_props, which
describes none of them. Search could not reach their props either.

Their records are now built like every other component's, from their props interfaces, and
keep the page for include: ["reference"]. The extractor learns the two shapes that hid
them, a component declared as a function (Portal, ClientOnly) and one the barrel
re-exports with export * from a module of another name (ConfigProvider).
ConfigProviderProps now documents its members in TSDoc, so its table has notes.

A hook's get_component and get_props now answer with its API signature block and point at
its reference page and its examples, and search names get_component as the next step for
one. useBulmaClasses still names get_helper_props too, since its page is where the helper
props it reads are documented.
@coderabbitai

coderabbitai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 46 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Repository: allxsmith/bestax/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: b8082c81-36f4-4fee-bd60-2c136a422e3e
📥 Commits

Reviewing files that changed from the base of the PR and between 6158d0b and f60ee05.

📒 Files selected for processing (33)
  • bestax-mcp/data/catalog.json
  • bestax-mcp/data/components/Avatars.json
  • bestax-mcp/data/components/Cell.json
  • bestax-mcp/data/components/ClientOnly.json
  • bestax-mcp/data/components/Columns.json
  • bestax-mcp/data/components/ConfigProvider.json
  • bestax-mcp/data/components/Dialog.json
  • bestax-mcp/data/components/Grid.json
  • bestax-mcp/data/components/Link.json
  • bestax-mcp/data/components/Notification.json
  • bestax-mcp/data/components/Portal.json
  • bestax-mcp/data/components/Theme.json
  • bestax-mcp/data/components/Valid value constants.json
  • bestax-mcp/data/components/classNames.json
  • bestax-mcp/data/components/useBulmaClasses.json
  • bestax-mcp/data/components/useFocusTrap.json
  • bestax-mcp/data/components/usePrefixedClassNames.json
  • bestax-mcp/src/__tests__/format.test.ts
  • bestax-mcp/src/__tests__/server.test.ts
  • bestax-mcp/src/data.ts
  • bestax-mcp/src/format.ts
  • bestax-mcp/src/search.ts
  • bestax-mcp/src/server.ts
  • bulma-ui/src/helpers/Config.tsx
  • bulma-ui/src/helpers/Theme.tsx
  • docs/docs/api/helpers/usebulmaclasses.md
  • docs/docs/guides/telemetry.md
  • plugin/README.md
  • scripts/gen-mcp-index.mjs
  • scripts/gen-mcp-index.test.mjs
  • scripts/lib/api-sources.mjs
  • scripts/lib/props-extract.mjs
  • scripts/props-extract.test.mjs

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: allxsmith/bestax/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 22c1dc09-c67f-4f38-8043-9446ce2cd3df
📥 Commits

Reviewing files that changed from the base of the PR and between fd134fa and 6158d0b.

📒 Files selected for processing (18)
  • bestax-mcp/data/catalog.json
  • bestax-mcp/data/components/Cell.json
  • bestax-mcp/data/components/ClientOnly.json
  • bestax-mcp/data/components/Columns.json
  • bestax-mcp/data/components/ConfigProvider.json
  • bestax-mcp/data/components/Grid.json
  • bestax-mcp/data/components/Link.json
  • bestax-mcp/data/components/Valid value constants.json
  • bestax-mcp/data/components/useBulmaClasses.json
  • bestax-mcp/data/components/usePrefixedClassNames.json
  • bestax-mcp/src/__tests__/server.test.ts
  • bestax-mcp/src/format.ts
  • bestax-mcp/src/search.ts
  • bestax-mcp/src/server.ts
  • docs/docs/api/helpers/usebulmaclasses.md
  • scripts/gen-mcp-index.mjs
  • scripts/gen-mcp-index.test.mjs
  • scripts/lib/props-extract.mjs
🚧 Files skipped from review as they are similar to previous changes (4)
  • bestax-mcp/data/components/Link.json
  • bestax-mcp/data/components/Valid value constants.json
  • bestax-mcp/data/components/usePrefixedClassNames.json
  • docs/docs/api/helpers/usebulmaclasses.md

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


Walkthrough

The MCP index now extracts prop tables from component-like documentation pages and stores API signatures separately from full references. Search and retrieval responses provide prop tables or pointers to documentation. Indexed documentation links now resolve to hosted documentation URLs.

Changes

Component indexing and MCP access

Layer / File(s) Summary
Prop extraction from component declarations
scripts/lib/props-extract.mjs, scripts/props-extract.test.mjs, bulma-ui/src/helpers/Config.tsx, bulma-ui/src/helpers/Theme.tsx, scripts/lib/api-sources.mjs
The extractor resolves star exports and reads function declarations, including their TSDoc and prop defaults. Tests cover overloads, same-named declarations, and star exports. ConfigProvider and Theme source comments describe their props.
Component and helper index records
scripts/gen-mcp-index.mjs, scripts/gen-mcp-index.test.mjs, bestax-mcp/data/catalog.json, bestax-mcp/data/components/*
The generator extracts props from component-like prose pages, rewrites documentation links, and stores API sections separately from full-page documentation. The catalog and component records include updated classifications and prop metadata.
Search, prop, and reference responses
bestax-mcp/src/data.ts, bestax-mcp/src/format.ts, bestax-mcp/src/search.ts, bestax-mcp/src/server.ts, bestax-mcp/src/__tests__/server.test.ts, docs/docs/api/helpers/usebulmaclasses.md
Search hits route to get_component. MCP responses provide prop tables or API signatures and pointers to full references. Tests cover component props, helper and hook references, and search results.

Priority: ➖ Normal

Estimated code review effort: 4 (Complex) | ~45 minutes

Change: Bug fix · Severity of issue fixed: Medium

Sequence Diagram(s)

sequenceDiagram
  participant Caller
  participant search_bestax
  participant get_component
  participant get_props
  Caller->>search_bestax: Search component or prop
  search_bestax-->>Caller: Return result with get_component route
  Caller->>get_component: Request component details
  get_component-->>Caller: Return API details or reference pointer
  Caller->>get_props: Request component props
  get_props-->>Caller: Return prop table or helper API details
Loading

Merge Risk: ⚪ Minimal · up to 6158d

The prop-table and reference changes have no identified merge-blocking issue. Normal checks remain appropriate before merging.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage Warning Docstring coverage is 66.67% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 21 functions across 12 files. (11 skipped… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check Passed The title clearly identifies the primary change: adding prop tables for Theme, ConfigProvider, Portal, and ClientOnly. It is concise and directly related to the changeset.
Description check Passed The description gives a detailed summary of the MCP, extractor, documentation, hook, search, and test changes. It identifies the affected areas, references issue #933, and reports that pnpm all passes…
Linked Issues check Passed Issue #933 requirements are met. The generated catalog classifies Theme, ConfigProvider, Portal, and ClientOnly as components and includes prop counts and prop records. The extractor supports function…
Out of Scope Changes check Passed The changes remain connected to issue #933. Generator and extractor changes create searchable component records from helper pages. Formatter, server, and search changes provide correct component and h…
Full details: Docstring Coverage

Explanation

Docstring coverage is 66.67% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 21 functions across 12 files. (11 skipped: 11 unsupported.)

✨ Finishing Touches 💡 2
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Preview Deployment

Preview URL: https://27bebc97.bestax.pages.dev

@allxsmith

Copy link
Copy Markdown
Owner Author

deep-review: fresh

The previous run was cancelled at the runner limit before it posted anything, so this asks for the same full review again. The core is scripts/lib/props-extract.mjs (function declarations and star exports), the helper-record branch of scripts/gen-mcp-index.mjs, and bestax-mcp/src/format.ts, server.ts and search.ts; start there, then the tests. The files under bestax-mcp/data/ are generated by pnpm gen:mcp and CI's gen:mcp:check holds them to the source.

Comment thread bestax-mcp/src/format.ts
Comment thread scripts/gen-mcp-index.mjs Outdated
Comment thread scripts/gen-mcp-index.mjs Outdated
@allxsmith

Copy link
Copy Markdown
Owner Author

deep-review: fresh

The last run on fddfd65 was cancelled at the runner limit after it posted three threads (one on bestax-mcp/src/format.ts, two on scripts/gen-mcp-index.mjs) but before its summary. Read them, don't post them again, and count each as a row in this review's table. Then carry on with what they don't cover: scripts/lib/props-extract.mjs, bestax-mcp/src/server.ts and search.ts, then the tests. The files under bestax-mcp/data/ are generated by pnpm gen:mcp and CI's gen:mcp:check holds them to the source.

…page, name the title rule

Theme's table came back with a blank Notes cell on most of its rows, because its props were
described in @Property tags the extractor does not read. Those blank rows also outranked the
documented ones in search, since a row with no description is scored on its name alone. Each
member of ThemeProps now carries its own TSDoc, naming the variable it sets, in place of the
@Property block.

A component documented on a prose page lost the line pointing at that page when it stopped
being answered as a helper, so get_component and get_props now say where the page is and how
long it is.

A prose page with a capitalised title that names no export stops the index build, as it did
before, and now says that the title is the thing to change. The rule is noted where
GENERATED_EXEMPT is defined.
Comment thread scripts/lib/props-extract.mjs
@allxsmith

Copy link
Copy Markdown
Owner Author

deep-review: fresh

Two runs on fddfd65 were cancelled at the runner limit before posting a summary. Between them they posted four threads, on bestax-mcp/src/format.ts, two on scripts/gen-mcp-index.mjs and one on scripts/lib/props-extract.mjs. Read them, don't post them again, and count each as a row in this review's table. What's left is bestax-mcp/src/server.ts and search.ts, then the tests. The files under bestax-mcp/data/ are generated by pnpm gen:mcp and CI's gen:mcp:check holds them to the source.

…ts first signature

The extractor took the first function declaration of a name, and for an overloaded function
that is a signature, which cannot carry parameter initializers. The props type still
resolved, so the table would have come back with every default missing and no error. Only an
implementation counts now. No component in the library is overloaded today, so every
generator's output is unchanged.
Comment thread scripts/gen-mcp-index.mjs
@allxsmith

Copy link
Copy Markdown
Owner Author

deep-review: fresh

Three runs on fddfd65 were cancelled at the runner limit before posting a summary. Between them they posted five threads: one on bestax-mcp/src/format.ts, three on scripts/gen-mcp-index.mjs and one on scripts/lib/props-extract.mjs. Read them, don't post them again, and count each as a row in this review's table. What's left is bestax-mcp/src/server.ts and search.ts, then the tests. The files under bestax-mcp/data/ are generated by pnpm gen:mcp and CI's gen:mcp:check holds them to the source.

A hook's API block, a prose page and an Accessibility section are served on their own, but
they kept the page's relative links. Away from the page, `./valid-values.md` names a file in
the reader's own workspace and `#scheme-backgrounds-and-bulmahelperstyles` a section the
answer does not carry. The generator now points each link at the URL the docs site serves for
it, leaving fenced code alone. useBulmaClasses' API block also said "see table below" of a
table it does not carry, so the page links that section by name instead.
@allxsmith

Copy link
Copy Markdown
Owner Author

deep-review: fresh

Several runs on fddfd65 were cancelled at the runner limit before posting a summary. Between them they posted five threads: one on bestax-mcp/src/format.ts, three on scripts/gen-mcp-index.mjs and one on scripts/lib/props-extract.mjs. Read them, don't post them again, and count each as a row in this review's table. They cover the generator, the extractor and the formatter, so what's left is bestax-mcp/src/server.ts and search.ts and the tests.

Comment thread bestax-mcp/src/search.ts
@allxsmith

Copy link
Copy Markdown
Owner Author

deep-review: fresh

The review on 02551c9 covered this PR, and its threads are settled. Since then the branch has two fixes for those threads (e620347, e45b4b8), merges of main, and one new change: the bestax.io links inside index answers now carry utm_source=bestax-mcp, added at render time by attributedLinks in bestax-mcp/src/format.ts (fence- and code-span-aware, never on examples or skill text), with the disclosure updated in docs/docs/guides/telemetry.md and plugin/README.md. The latest merge resolved a conflict with #975 in scripts/gen-mcp-index.mjs and its test by keeping both sides. Give the tagging change, its call sites and tests, the disclosure text and that merge resolution the full read. This reviews f94fda2 and posts every finding, advisory included, as its own thread.

Comment thread bestax-mcp/src/__tests__/server.test.ts Outdated
Comment thread bestax-mcp/src/format.ts Outdated
Comment thread bestax-mcp/src/format.ts Outdated
Comment thread bestax-mcp/src/__tests__/server.test.ts Fixed
Comment thread bestax-mcp/src/format.ts Fixed
Comment thread bestax-mcp/src/format.ts Fixed
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Preview Deployment

Preview URL: https://7ca1f3b7.bestax.pages.dev

Comment thread bestax-mcp/src/format.ts Outdated
Comment thread bestax-mcp/src/__tests__/server.test.ts
Comment thread bestax-mcp/src/__tests__/server.test.ts Outdated
Comment thread plugin/README.md Outdated

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Deep review — 1 blocking · 3 advisory

# Severity Area Finding Location
1 🟡 Minor Security Three new includes('https://bestax.io') fast paths took CodeQL from green to 3 high alerts — the same rule 1a7dec61 already reworked a test for bestax-mcp/src/format.ts:162
2 🔵 Advisory Coverage The render-time tag has no exhaustive guard: the generator sweeps every string in the index, the renderer pins seven sampled calls bestax-mcp/src/__tests__/server.test.ts:448
3 🔵 Advisory Robustness "no tag in a skill answer" is asserted on the whole response, which carries the tagged version note when there is drift bestax-mcp/src/__tests__/server.test.ts:481
4 🔵 Advisory Correctness plugin README's "reference docs … stay untagged" reads onto include: ["reference"], which this PR made tagged plugin/README.md:100

Overall: The tagging change is well built and I could not break it. attributedLinks is a real inline-markdown reader, not a regex over raw text — shadowOf masks code spans and backslash escapes at equal length so shadow offsets map back exactly, closesLinkText walks the bracket nesting and rejects images, and SITE_TARGET is genuinely host-anchored (bestax.io.example.com and bestax.io@evil.com both fail the [/?#] class and the closing lookahead). Against the committed index it tags 77 of 77 site links in served prose and corrupts none: stripping the tag from all 20 changed fields reproduces each raw field byte-for-byte, and all 75 /docs/… targets resolve to a real page and a real anchor. The riskiest part is not the parser but the eleven hand-placed call sites it is applied through — finding 2 — because a missed one is invisible: the answer still reads right and the link still works, only the attribution is gone. Focus the human read there and on finding 1, which is the only thing standing between this PR and a green board.

Residual risk:

  • A site link the server prints but does not tag. Refuted for the current tree by sweep, not by reading: every field path that carries a site link (accessibility, summary, parts[].summary, doc, api, catalog.components[].purpose) has an attributedLinks call on its emission path, and all 77 targets come back tagged through get_component, get_props, list_components, search_bestax, get_helper_props and the bestax://components resource. Untagged by design and tested: examples (get_examples), skill bodies, prompts and skill resources.
  • A link shape attributedLinks does not read. Bare URLs, autolinks, raw <a href> and reference-style [ref]: definitions are all left alone, and so is anything inside a fence. Refuted as live: zero of any of those four shapes exists in any served field today (docsUrl/storybook are bare, and those go through attributed in the footer). Open: a future page adding one ships untagged and nothing fails — the same gap as finding 2, which is why I posted that one rather than three.
  • Generator and renderer disagreeing about what is code. absoluteLinks (gen-mcp-index.mjs:407) splits on fences only; attributedLinks is additionally code-span-aware. A markdown link inside a code span would therefore be rewritten by the generator and skipped by the renderer. Refuted as live: zero code spans anywhere under docs/docs/api contain ](. The asymmetry is in the safe direction for the one case that matters — a literal backticked [x](https://bestax.io/…) passes the generator untouched (absolute targets return as-is) and the renderer's span awareness then keeps it so.
  • Cost of tagging on the hot path. referenceOf runs a full pass over the prose page on every get_component/get_props for a hook or a prose component, purely to quote a size. Measured rather than assumed: 0.46 ms for useBulmaClasses' 76,290 characters, 0.17 ms for Theme's 42,393 — three orders of magnitude under the event-loop stalls server.ts:80 was written about. Not a concern.
  • The merge resolution. #975's side (SCHEMA_VERSION 2, orderDeclarers, cssVarIndex as arrays) and this PR's side (absoluteLinks, withAbsoluteLinks, proseComponentInfo, COMPONENT_NAME) are both live in gen-mcp-index.mjs, their tests both kept in gen-mcp-index.test.mjs and server.test.ts, and pnpm gen:mcp:check re-runs the committed index byte-identical. cssVarIndex is built outside withAbsoluteLinks, so the new arrays are untouched by the rewrite.
  • Gates. 367/367 bestax-mcp jest, 26/26 gen-mcp-index.test.mjs, 81/81 gen-skills-repo.test.mjs, check:conformance 23/23, typecheck 7/7, coverage 97.76 / 92.42 / 98.72 / 99.03 against the 95 / 78 gate with the new functions fully covered. pnpm test:scripts could not be judged here (eslint-plugin/dist absent gives the documented "build first" failures), but CI's Build and Test ran it green on this SHA — its one failing step is Audit (high severity), which fails identically on main at 3ffa76b6, so that red is inherited, not this PR's. CodeQL's is finding 1.

🏄 This one paddles out with a proper hand-shaped board — a real little markdown reader that knows a code span from prose, 77 for 77 links tagged and not a byte bent out of shape. Only thing between it and a clean ride is CodeQL squinting at three includes() calls like they're a riptide; swap 'em for an anchored pattern and this set's good to go.

…a substring

CodeQL read the substring tests that skip text with no site link in it as URL
sanitization. Both now use one pattern, the origin with nothing word-like after
it, which admits everything SITE_TARGET does after the host. New cases pin a
target that ends at the host, closed by each thing that may follow it there.
The server test picks its examples with the same pattern.
The tag is applied field by field, and seven sampled calls were all that held
it. The sweep asks every tool that renders a record for every record, each
part and every catalog category, with every section get_component offers, and
fails on any bestax.io link target outside code that lacks the tag. Each
example holding a site URL is checked as served as written. Dropping any call
site whose field carries a site link today fails it.
… tag

get_skill ends its answer with the version note when the installed library has
drifted from the index, and that note's link is tagged, so asserting no tag
anywhere in the answer failed in a normal state. The test now reads the bundled
SKILL.md, requires an untagged site link in it, and checks that get_skill, the
prompt and the resource each open with that body exactly as written.
get_component serves a prose page under include: ["reference"], tagged, so
"reference docs ... stay untagged" read backwards there. The plugin README now
says only that skill bodies are served as written, and the telemetry guide ties
its reference docs to the skills they belong to.
@allxsmith

Copy link
Copy Markdown
Owner Author

deep-review: verify

Every open thread has a reply: fixed, with the commit, or refuted with a reason. This settles them on f60ee05.

@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Preview Deployment

Preview URL: https://c17ce77e.bestax.pages.dev

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Deep review (verify) — 4 resolved · 0 open

# Severity Area Finding Location
1 🟡 Minor Security includes('https://bestax.io') fast paths red CodeQL — verified fixed (SITE_ORIGIN anchored pattern; CodeQL green on HEAD) bestax-mcp/src/format.ts:162
2 🔵 Advisory Coverage Render-time tag had no exhaustive guard — verified fixed (schema-driven sweep over every record, part and catalog entry) bestax-mcp/src/__tests__/server.test.ts:460
3 🔵 Advisory Robustness "no tag in a skill answer" asserted on the envelope — verified fixed (asserts the body slice against the bundled markdown) bestax-mcp/src/__tests__/server.test.ts:481
4 🔵 Advisory Correctness "reference docs … stay untagged" collided with include: ["reference"] — verified fixed (clause deleted) plugin/README.md:100

Overall: This pass settled threads and reviewed no commits. All four previously-open threads — one blocking, three advisory — are addressed in the current code and are now resolved. The one I checked hardest was the CodeQL fix: SITE_ORIGIN's (?![\w.-]) lookahead rejects nothing that SITE_TARGET accepts after the host (/, ?, #, whitespace, ), >), so it stays a strictly broader pre-check, and because shadowOf only substitutes \0 for backtick/backslash runs, a literal present in the shadow is present at the same offset in the raw block — the raw-vs-shadow split cannot silently drop a match. CodeQL on f60ee05d reports No new alerts in code changed by this pull request, and 374/374 bestax-mcp tests pass locally.

Residual risk: out of scope for a verify pass — this run raised no new findings. The one limitation already on the record in thread 2 stands: the exhaustive sweep is data-driven, so a dropped attributedLinks call on p.description, p.deprecationNote, t.summary or searchAll's prop description goes unnoticed until a site link appears in one of those fields. A reader who wants the current code reviewed afresh should ask with a deep-review: fresh steer.

🏄 Author paddled back out and cleaned up every last one — anchored the regex, made the sweep read its own schema, and trimmed the one sentence that read two ways. Board's waxed, CodeQL's glassy, nothing left floating out there.

@github-actions github-actions Bot added the review-converged Deep review converged: no blocking findings, all review threads resolved, checks green label Oct 9, 2026
@allxsmith
allxsmith merged commit 55c4384 into main Oct 9, 2026
100 checks passed
@allxsmith
allxsmith deleted the fix/933-helper-component-props branch October 9, 2026 00:38
@bestax-release-bot

Copy link
Copy Markdown

🎉 This PR is included in version 5.27.2 🎉

The release is available on:

Your semantic-release bot 📦🚀

@bestax-release-bot

Copy link
Copy Markdown

🎉 This PR is included in version 1.14.2 🎉

The release is available on:

Your semantic-release bot 📦🚀

@bestax-release-bot

Copy link
Copy Markdown

🎉 This PR is included in version 2.25.2 🎉

The release is available on:

Your semantic-release bot 📦🚀

@bestax-release-bot

Copy link
Copy Markdown

🎉 This PR is included in version 4.2.15 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

deep-review needs-human-review Loop converged (or contested): awaiting owner review + manual merge released review-converged Deep review converged: no blocking findings, all review threads resolved, checks green

Projects

None yet

Development

Successfully merging this pull request may close these issues.

bestax-mcp gives Theme, ConfigProvider, Portal and ClientOnly no prop table

2 participants