Skip to content

fix(settings): add missing home page pin keys to updateSettingsSchema - #2915

Merged
diegosouzapw merged 2 commits into
diegosouzapw:release/v3.8.7from
apoapostolov:fix/pin-settings-schema-validation
May 29, 2026
Merged

diegosouzapw merged 2 commits into
diegosouzapw:release/v3.8.7from
apoapostolov:fix/pin-settings-schema-validation

Conversation

@apoapostolov

@apoapostolov apoapostolov commented May 29, 2026 •

Copy link
Copy Markdown
Contributor

Problem

The "Pin Information to Home Page" toggles in the Appearance settings tab (Provider Quota Limits, Quick Start, Provider Topology) were non-functional. Changing any of these toggles had no effect on the visibility of the corresponding sections on the Home page.

Root Cause

The three settings keys — pinProviderQuotaToHome, showQuickStartOnHome, and showProviderTopologyOnHome — were missing from the updateSettingsSchema Zod schema in settingsSchemas.ts. When the Appearance tab sent a PATCH request to /api/settings, Zod's default .strip() mode silently removed these unrecognized keys from the parsed body. The updateSettings() function therefore never received them, and they were never persisted to the database. Since the Home page reads these settings from the database on mount, the changes were invisible.

Solution

Added the three missing keys to the updateSettingsSchema Zod schema, enabling them to pass through validation and be persisted correctly.

These keys already existed in the general settings schema (schemas.ts) — the gap was isolated to the PATCH-specific validation schema.

Changes

  • Added pinProviderQuotaToHome: z.boolean().optional() to updateSettingsSchema
  • Added showQuickStartOnHome: z.boolean().optional() to updateSettingsSchema
  • Added showProviderTopologyOnHome: z.boolean().optional() to updateSettingsSchema

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request adds three new optional configuration settings (pinProviderQuotaToHome, showQuickStartOnHome, and showProviderTopologyOnHome) to the updateSettingsSchema in src/shared/validation/settingsSchemas.ts. The review feedback notes that critical security-impacting keys (localOnlyManageScopeBypassEnabled and localOnlyManageScopeBypassPrefixes) are missing from the schema, which silently prevents them from being updated. Additionally, the reviewer requests that unit tests be added to validate these new settings keys, as required by the repository style guide.

Comment on lines +39 to +41
pinProviderQuotaToHome: z.boolean().optional(),
showQuickStartOnHome: z.boolean().optional(),
showProviderTopologyOnHome: z.boolean().optional(),

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

high

In addition to the home page pin keys, the security-impacting settings keys localOnlyManageScopeBypassEnabled and localOnlyManageScopeBypassPrefixes (referenced in src/app/api/settings/route.ts and src/types/settings.ts) are also completely missing from updateSettingsSchema.

Because they are missing, any PATCH request to /api/settings attempting to update these keys will have them silently stripped by Zod. Consequently, the security-impacting password re-auth gate in the route handler is never triggered for them, and they can never be persisted to the database.

Please add these keys to the schema to restore their functionality.

Suggested change
pinProviderQuotaToHome: z.boolean().optional(),
showQuickStartOnHome: z.boolean().optional(),
showProviderTopologyOnHome: z.boolean().optional(),
pinProviderQuotaToHome: z.boolean().optional(),
showQuickStartOnHome: z.boolean().optional(),
showProviderTopologyOnHome: z.boolean().optional(),
localOnlyManageScopeBypassEnabled: z.boolean().optional(),
localOnlyManageScopeBypassPrefixes: z.array(z.string().max(200)).optional(),

hideEndpointNgrokTunnel: z.boolean().optional(),
autoRefreshProviderQuota: z.boolean().optional(),
autoRefreshProviderQuotaInterval: z.number().int().min(10).max(3600).optional(),
pinProviderQuotaToHome: z.boolean().optional(),

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

According to the Repository Style Guide (Rule 9), tests must always be included when changing production code under src/. Please add corresponding unit tests (e.g., in tests/) to verify that the new settings keys are correctly validated and parsed by updateSettingsSchema.

References
  1. Always include tests when changing production code (src/, open-sse/, electron/, bin/). (link)

@apoapostolov

Copy link
Copy Markdown
Contributor Author

Addressed both review points:

  1. High priority — Added \localOnlyManageScopeBypassEnabled\ and \localOnlyManageScopeBypassPrefixes\ to \updateSettingsSchema\ so they pass through Zod validation and can be persisted correctly (same fix as the pin keys).

  2. Medium priority — Added unit test file \ ests/unit/home-page-pin-settings-schema.test.ts\ with 6 tests covering:

    • Pin settings accepted and parsed correctly
    • Default to undefined when omitted
    • Rejection of non-boolean values
    • \localOnlyManageScopeBypass\ settings accepted and parsed correctly
    • Rejection of invalid types for both security keys

@kilo-code-bot

kilo-code-bot Bot commented May 29, 2026 •

Copy link
Copy Markdown

Code Review Summary

Status: No Issues Found | Recommendation: Merge

The PR correctly adds 5 new optional settings to updateSettingsSchema:

  • pinProviderQuotaToHome, showQuickStartOnHome, showProviderTopologyOnHome (boolean options for home page UI)
  • localOnlyManageScopeBypassEnabled (boolean toggle for security scope bypass)
  • localOnlyManageScopeBypassPrefixes (array of path prefixes, max 200 chars each)

All schema validations are appropriate and consistent with existing patterns. The unit tests comprehensively cover:

  • Schema acceptance with valid values
  • Default behavior (undefined when omitted)
  • Type rejection for invalid inputs

The existing review comments have been addressed by the author. All changes are minimal, focused, and follow the established codebase patterns.

Files Reviewed (2 files)
  • src/shared/validation/settingsSchemas.ts - Schema additions
  • tests/unit/home-page-pin-settings-schema.test.ts - New test file

Reviewed by laguna-m.1-20260312:free · 539,979 tokens

@diegosouzapw diegosouzapw left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved after local verification, quality checks and merging into release/v3.8.7.

@diegosouzapw
diegosouzapw changed the base branch from main to release/v3.8.7 May 29, 2026 20:42
@diegosouzapw
diegosouzapw merged commit 338636a into diegosouzapw:release/v3.8.7 May 29, 2026
3 checks passed
tkgo11 pushed a commit to tkgo11/OmniRoute that referenced this pull request Sep 23, 2026
…gs-schema-validation

fix(settings): add missing home page pin keys to updateSettingsSchema
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants