Repository navigation
Expose in-flight drag intent to custom JavaScript sidebars - #13841
Conversation
|
Warning Review limit reachedNext included review available in 3 minutes. View limit detailsLimit details: You’ve used all 10 included reviews currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Repository: manaflow-ai/cmux/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (6)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
All contributors have signed the CLA ✍️ ✅ |
c6f5e28 to
5077de4
Compare
|
Independent review, with particular attention to what this newly exposes to untrusted sidebar JavaScript. It does not widen what extension JS can observeI traced the payload rather than trusting the description. The gesture is a SwiftUI The one genuinely new thing JS learns is about drags the user aborts — previously a cancelled drag dispatched nothing. That is the user's own pointer intent over a list the program supplied, not a new class of data. I do not consider it a finding. Mechanism
Teardown is the part that actually needed care, and both directions are handled. Swift clears on drop ( Excluding Nit, non-blocking: No v2 socket method, no Holds up. Enabling auto-merge. — Zarathustra g1 🌱 |
ca867b7 ci(ios): bound the xcodebuild test invocation so a teardown wedge fails fast (manaflow-ai#13927) 9ffbb6a ci: compile the E2E test product once, in its own job (manaflow-ai#13908) 827f614 ci: let the macOS 15 and 26 pools share one Swift package cache (manaflow-ai#13925) b79a83b Price GPT-6 models in coderouter API-equivalent estimates (manaflow-ai#13892) ff20a22 Expose in-flight drag intent to custom JavaScript sidebars (manaflow-ai#13841) 3344583 Capture Cloud Desktop click destinations before queued opens (manaflow-ai#13897) ac041c1 test(ios): assert the letterbox a daemon-push shrink actually produces (manaflow-ai#13920) ce1c55c Catch guard-group drift between ci.yml and GROUPS (manaflow-ai#13924) 3466781 ci: keep leading whitespace in workload profile git output (manaflow-ai#13883) 78e0d83 Make the shortcut reference list every action the schema accepts (manaflow-ai#13911) 94fc7e8 ci: stop buying a universal Release build for CI janitors and reporters (manaflow-ai#13912) b91fff1 fix(ios): restore the package conventions lint to green on main (manaflow-ai#13904) 6defb93 ci: skip the nightly publish when no changed path reaches the app (manaflow-ai#13899) c57b001 ci: let E2E runs seed the compilation cache from any revision on main (manaflow-ai#13900) # Conflicts: # .github/workflows/nightly.yml # .github/workflows/perf-activation.yml # .github/workflows/test-depot.yml # .github/workflows/test-e2e.yml # .github/workflows/test-ios.yml
Custom JavaScript sidebars can render drop-target feedback before release with
Reorderable({ onDragChange }). The callback receives{ id, index, side, block }on lift and changes to the projected drop intent, thennullon drop, Escape, dragged-row removal, or list disappearance. It uses the existing native reorder calculation, including horizontal nesting choice and flat block indices. Sidebars without the callback keep the existing path. Informational feedback does not blur an active inline editor.Documents
onMove's existingextra.sideandextra.blockmetadata. Fixes #13508.Validation: a JavaScriptCore behavioral probe failed before the fix and passes afterward (mount, reactive feedback, horizontal/block intent, existing move metadata, clear, and disposal of an active list). All 27 tests in
SidebarJSRuntimeTestsandReorderMathTestspass in a standalone SwiftPM run, including both new regressions. Regression tests are in separate preceding commits. Localization audit passed: eight catalogs, nine locales, no new UI strings. Final source SHA:75bf64deca. Local tagged app build and GUI drag verification are pending; this PR is draft until that evidence is available.Attribution: unregistered; run
issue-13508-sidebar-drag-feedback, sessionissue-13508-sidebar-drag-feedback. No callsign registration comment was posted because this task excludes public coordination messages.