Skip to content

fix(webui-v2): surface tool permission save errors - #5699

Merged
think-in-universe merged 7 commits into
mainfrom
issue-5698-tools-save-error
Jul 7, 2026
Merged

think-in-universe merged 7 commits into
mainfrom
issue-5698-tools-save-error

Conversation

@italic-jinxin

Copy link
Copy Markdown
Contributor

Summary

  • Renders the existing tool-permission mutation error in Settings → Tools instead of failing silently.
  • Reuses the shared error.saveFailed copy so failed per-tool saves show a visible alert.
  • Adds component coverage for the Tools tab error state.
  • Adds Reborn WebUI v2 Playwright coverage for a failed tool-permission POST reverting the select and showing the save error.
image

Linked Issue

Closes #5698

Validation

  • node --test crates/ironclaw_webui_v2/static/js/pages/settings/components/tools-tab.test.mjs
  • node --test crates/ironclaw_webui_v2/static/js/pages/settings/**/*.test.mjs
  • IRONCLAW_WEBUI_V2_DIST_DIR=/tmp/ironclaw-webui-v2-issue-5698 npm run build
  • python -m py_compile tests/e2e/scenarios/test_reborn_webui_v2_legacy_tool_permissions.py
  • Playwright node not run locally; local fixture startup blocked before the new assertion by mock LLM readiness.

Security Impact

No security-sensitive behavior changes. This only surfaces an already-failed authenticated settings mutation to the user.

Database Impact

No schema or migration changes.

Blast Radius

Limited to WebUI v2 Settings → Tools error rendering and its frontend/e2e regression coverage.

Rollback Plan

Revert this PR to return failed per-tool permission saves to the prior silent UI behavior.


Review track: A

@italic-jinxin italic-jinxin added size: M 50-199 changed lines risk: low Changes to docs, tests, or low-risk modules contributor: core 20+ merged PRs labels Jul 6, 2026
@ironloopai

ironloopai Bot commented Jul 6, 2026 •

Copy link
Copy Markdown
Contributor

⚠️ IronLoop Review Status

Head: aca0754df364d8854e39f60362c727df56f8bc27
Result: One or more reviewer results were superseded by a newer PR head.
Next: Run @ironloopai review on the latest PR head.
Updated: 2026-07-07T09:00:35.333Z

Current reviewers:

Reviewer State Verdict Findings Last update
ironloop/common-reviewer (reviewer) Superseded N/A N/A 2026-07-07T08:55:37.199Z
Reviewer summaries
Reviewer Detail
ironloop/common-reviewer (reviewer) Superseded by a newer PR head. New head: ef4ab49. Previous verdict: Approved.
Recent activity
Time Reviewer State Detail
2026-07-06T15:03:44.356Z ironloop/common-reviewer (reviewer) Queued Waiting for this reviewer lane to become available.
2026-07-06T15:03:44.400Z ironloop/common-reviewer (reviewer) Queued Added to the local review work handoff.
2026-07-06T15:03:48.094Z ironloop/common-reviewer (reviewer) Started Reviewer worker started attempt 1.
2026-07-06T15:03:52.627Z ironloop/common-reviewer (reviewer) Workspace ready Prepared isolated checkout (merge_ref) at 9dab1cd.
2026-07-06T15:05:35.480Z ironloop/common-reviewer (reviewer) Superseded Old-head reviewer is still running after newer head ef4ab49 replaced it. Codex is reviewing; process live; elapsed 1m 44s; timeout in 18m 16s; last heartbeat 2026-07-06T15:05:35.480Z. Activity (stderr): ...dsWith(";"); 31 continue; 32 } 33 const stripped = stripExport(line); 34 if (stripped != null) lines.push(stripped);….
2026-07-06T15:05:46.837Z ironloop/common-reviewer (reviewer) Result captured Approved; 0 blocking findings.
2026-07-06T15:05:46.837Z ironloop/common-reviewer (reviewer) Completed Review completed and terminal status was persisted.
2026-07-07T08:55:37.199Z ironloop/common-reviewer (reviewer) Superseded A newer PR head replaced this review (ef4ab49).
Available commands
  • @ironloopai agents
  • @ironloopai review
  • @ironloopai review --agent <agent-id-or-alias>
  • @ironloopai status
Run metadata

Admission: webhook accepted the request and IronLoop persisted review state before this projection.

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5699 July 6, 2026 14:01 Destroyed
@github-actions github-actions Bot added size: S 10-49 changed lines and removed size: M 50-199 changed lines labels Jul 6, 2026
@italic-jinxin

Copy link
Copy Markdown
Contributor Author

@claude review

@ironloopai ironloopai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ IronLoop Review: reviewer

Verdict: ✅ Approved
Findings: 0 blocking / 0 notes
Next: No reviewer action needed.
Head: 832c807fca8bef1bbddfa2c6f93b259c9232b5c3

Run details

Status: Current
Needs human: no
Needs validation: no

**Inline candidates:** 0

Summary

No blocking issues found. The change wires the tool-permission mutation error into the Tools settings tab and adds focused unit plus Playwright coverage for failed saves without broadening the behavior surface.

Findings

None.

Developer follow-up

After fixing this feedback:

  1. Push the fix to this PR branch.
  2. Re-run this reviewer with @ironloop review --agent reviewer if you only changed this reviewer's findings.
  3. Re-run all reviewers with @ironloop review when the fix may affect multiple areas.
  4. Use @ironloop status to check queued/running/completed/stale/stalled state while reviewers run.

@coderabbitai

coderabbitai Bot commented Jul 6, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 97cfd48b-3402-4d08-b903-232be0c3255d

📥 Commits

Reviewing files that changed from the base of the PR and between 186da7c and ef4ab49.

📒 Files selected for processing (2)
  • crates/ironclaw_webui_v2/static/js/pages/settings/components/tools-tab.test.mjs
  • crates/ironclaw_webui_v2/static/js/pages/settings/hooks/useTools.test.mjs
💤 Files with no reviewable changes (2)
  • crates/ironclaw_webui_v2/static/js/pages/settings/hooks/useTools.test.mjs
  • crates/ironclaw_webui_v2/static/js/pages/settings/components/tools-tab.test.mjs

📝 Walkthrough

Summary by CodeRabbit

  • Bug Fixes
    • Improved the Settings > Tools permission-saving flow so errors are shown inline and failed changes are clearly reported.
    • When a permission update fails, the selection now reverts to the last saved value instead of staying in an unsaved state.
    • Added coverage for error handling in both unit and end-to-end tests, including localized error messaging.

Walkthrough

Adds a permission-save error alert to the WebUI v2 Tools tab, sourced from useTools()'s exposed mutation error. setPermission now calls mutation.reset() before mutation.mutate(). Unit tests cover the hook reset/mutate sequence and alert rendering; an e2e test covers the 403 failure path with UI reversion.

Changes

Tool permission save failure surfacing

Layer / File(s) Summary
ToolsTab error alert rendering
crates/ironclaw_webui_v2/static/js/pages/settings/components/tools-tab.js, tools-tab.test.mjs
ToolsTab destructures permissionError from useTools() and renders a translated error.saveFailed alert below AutoApproveCard; tests assert alert presence, danger styling, and message text.
Permission mutation reset
crates/ironclaw_webui_v2/static/js/pages/settings/hooks/useTools.js, useTools.test.mjs
setPermission calls mutation.reset() before mutation.mutate({ name, state }); new hook test verifies reset-then-mutate call order and payload.
E2E save-failure scenario
tests/e2e/scenarios/test_reborn_webui_v2_legacy_tool_permissions.py
Mocked tool-permission endpoint gains a fail_permission_saves flag returning a 403 payload; new e2e test asserts the alert, reverted selection, and captured request.

Estimated code review effort: 2 (Simple) | ~12 minutes

Sequence Diagram(s)

sequenceDiagram
  participant User
  participant ToolsTab
  participant useTools
  participant API

  User->>ToolsTab: change tool permission
  ToolsTab->>useTools: setPermission(name, state)
  useTools->>useTools: mutation.reset()
  useTools->>API: POST /api/webchat/v2/settings/tools/{tool}
  API-->>useTools: 403 permission_denied
  useTools-->>ToolsTab: permissionError
  ToolsTab-->>User: render error.saveFailed alert
Loading

Related issues: #5698 — Surface tool permission save failures in WebUI v2 Settings Tools tab (addressed by rendering permissionError in ToolsTab and adding regression tests).

Suggested labels: webui-v2, frontend, tests

Suggested reviewers: none identified from provided context

No sandbox, trust-boundary, secrets, egress, or migration invariants are implicated here — this is client-side error UI plus test coverage, gated by existing lint/format/CI checks.

Poem:

A permission denied, once silent and sly,
Now flashes in red where the user's eye lies.
Reset then retry, the mutation's new way,
With tests standing guard so the errors won't stray. 🐇

🚥 Pre-merge checks | ✅ 4
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title uses Conventional Commits style and accurately summarizes the main change: surfacing tool permission save errors.
Description check ✅ Passed The description covers summary, linked issue, validation, security, database, blast radius, rollback, and review track; only noncritical template items are sparse.
Linked Issues check ✅ Passed The changes satisfy #5698 by rendering permission-save errors in ToolsTab and adding regression coverage for failed tool permission saves.
Out of Scope Changes check ✅ Passed The hook reset behavior, unit tests, and Playwright harness changes all support the error-surfacing fix and do not appear unrelated.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request adds error handling for permission save failures in the tools tab of the settings page, displaying a translated alert banner when an error occurs, and includes corresponding unit and end-to-end tests. The feedback suggests replacing hardcoded Tailwind red colors with theme-aware semantic variables and color-mix to ensure the alert banner remains readable in both light and dark modes.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

Comment thread crates/ironclaw_webui_v2/static/js/pages/settings/components/tools-tab.js Outdated
@claude

claude Bot commented Jul 6, 2026

Copy link
Copy Markdown

No issues found.

@github-actions

github-actions Bot commented Jul 6, 2026 •

Copy link
Copy Markdown
Contributor

Coverage ratchet

Ratchet mode: ENFORCING

RATCHET PASS: global
  observed: 85.45% (276149 / 323178 lines)
  floor:    85.3% (tolerance 0.5pp -> effective floor 84.8%)
  denominator: 323178 lines now vs 320188 at floor capture (+2990 lines, +0.93%) — not a material change

⚠️ 3 Reborn crate(s) have 0 int-tier coverage (target: 0) — ironclaw_prompt_envelope, ironclaw_scripts, ironclaw_skill_learning

Reborn integration-tier coverage

Line coverage (Reborn crates): 85.45% — 276149 / 323178 lines

Per-crate breakdown (65 crates, lowest-covered first)
Crate Line % Covered / Total
ironclaw_prompt_envelope 0% 0 / 88
ironclaw_scripts 0% 0 / 347
ironclaw_skill_learning 0% 0 / 61
ironclaw_wasm_sandbox_core 7.37% 7 / 95
ironclaw_runtime_policy 33.2% 80 / 241
ironclaw_event_projections 43.34% 673 / 1553
ironclaw_run_state 52.73% 222 / 421
ironclaw_authorization 53.54% 461 / 861
ironclaw_triggers 60.32% 1736 / 2878
ironclaw_observability 61.54% 16 / 26
ironclaw_mcp 63.15% 581 / 920
ironclaw_reborn_cli 64.58% 3988 / 6175
ironclaw_filesystem 65.93% 3234 / 4905
ironclaw_webui_v2 66.15% 2423 / 3663
ironclaw_reborn_migration 67.01% 1172 / 1749
ironclaw_memory 67.12% 747 / 1113
ironclaw_dispatcher 67.15% 92 / 137
ironclaw_trust 72.88% 661 / 907
ironclaw_reborn_event_store 73.27% 940 / 1283
ironclaw_capabilities 74.08% 1658 / 2238
ironclaw_wasm_limiter 74.6% 47 / 63
ironclaw_extractors 74.72% 538 / 720
ironclaw_first_party_extensions 77.62% 5410 / 6970
ironclaw_llm 77.88% 19479 / 25013
ironclaw_product_context 78.57% 11 / 14
ironclaw_wasm_product_adapters 80.58% 1510 / 1874
ironclaw_process_sandbox 80.65% 671 / 832
ironclaw_reborn_openai_compat 80.95% 956 / 1181
ironclaw_memory_native 81.86% 3226 / 3941
ironclaw_secrets 82.33% 2716 / 3299
ironclaw_wasm 82.54% 950 / 1151
ironclaw_events 83.44% 1759 / 2108
ironclaw_processes 84.06% 965 / 1148
ironclaw_host_api 84.8% 3131 / 3692
ironclaw_threads 85.16% 3278 / 3849
ironclaw_projects 85.92% 659 / 767
ironclaw_network 86.12% 670 / 778
ironclaw_auth 86.32% 2727 / 3159
ironclaw_product_workflow 86.33% 10709 / 12405
ironclaw_turns 86.36% 10481 / 12136
ironclaw_common 86.59% 1472 / 1700
ironclaw_slack_v2_adapter 86.79% 1806 / 2081
ironclaw_reborn_config 86.98% 1730 / 1989
ironclaw_product_adapters 87.29% 3207 / 3674
ironclaw_skills 87.34% 4334 / 4962
ironclaw_reborn_traces 87.35% 10325 / 11820
ironclaw_hooks 87.84% 9916 / 11289
ironclaw_product_adapter_registry 87.96% 526 / 598
ironclaw_extensions 88.26% 2631 / 2981
ironclaw_reborn_identity 88.43% 344 / 389
ironclaw_reborn_composition 89.11% 68976 / 77409
ironclaw_host_runtime 89.13% 17302 / 19413
ironclaw_conversations 90% 2924 / 3249
ironclaw_approvals 90.51% 1507 / 1665
ironclaw_reborn 91.19% 17477 / 19166
ironclaw_event_streams 91.48% 1009 / 1103
ironclaw_reborn_webui_ingress 91.68% 2094 / 2284
ironclaw_loop_support 92.22% 14231 / 15432
ironclaw_attachments 93.06% 630 / 677
ironclaw_telegram_v2_adapter 94.01% 2447 / 2603
ironclaw_resources 94.2% 3605 / 3827
ironclaw_agent_loop 94.54% 8753 / 9259
ironclaw_safety 94.81% 3669 / 3870
ironclaw_first_party_extension_ports 95% 3094 / 3257
ironclaw_outbound 95.59% 3556 / 3720

This table itself is informational and never gates the PR on its own — not the percentage, not the per-crate holes, not the 0-coverage callout. A separate coverage ratchet (dry-run until enforce=true; see tests/integration/coverage-floor.toml) can fail the build on specific configured floors.

Exemptions (4 entry/entries excluded from the accounting above)
Module / Crate Reason Issue
crate: ironclaw_embeddings v1-only: consumed only by root ironclaw (src/app.rs, src/tools/builtin/memory.rs, src/workspace/mod.rs, src/config/{mod,embeddings}.rs); no crates/* dependents. Covered by "Tests (Legacy)". #5657
crate: ironclaw_gateway v1-only: consumed only by root ironclaw (src/channels/web/platform/static_files.rs, src/channels/web/handlers/frontend.rs); no crates/* dependents. Covered by "Tests (Legacy)". #5657
crate: ironclaw_oauth v1-only: consumed only by root ironclaw (src/auth/oauth.rs); no crates/* dependents. Crate's own doc comment confirms v1-only. Covered by "Tests (Legacy)". #5657
crate: ironclaw_tui v1-only: consumed only by root ironclaw (src/main.rs, src/channels/tui.rs); no crates/* dependents. Crate's own doc comment confirms it bridges INTO v1, not Reborn. Covered by "Tests (Legacy)". #5657

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@crates/ironclaw_webui_v2/static/js/pages/settings/components/tools-tab.js`:
- Line 187: The shared save error from useTools() is persisting across retries,
so the tools-tab.js banner can show a stale failure for the wrong save attempt.
Update the save flow in useTools.js and/or the ToolsTab component to call
mutation.reset() before starting a new permission update, or otherwise track the
error per row in setPermission so only the failing tool is marked. Refer to
useTools, setPermission, and the error value returned from useMutation when
wiring the retry/reset behavior.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 393ab814-06f3-4b65-9f09-f141f542d461

📥 Commits

Reviewing files that changed from the base of the PR and between 8b229e4 and 832c807.

📒 Files selected for processing (3)
  • crates/ironclaw_webui_v2/static/js/pages/settings/components/tools-tab.js
  • crates/ironclaw_webui_v2/static/js/pages/settings/components/tools-tab.test.mjs
  • tests/e2e/scenarios/test_reborn_webui_v2_legacy_tool_permissions.py

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5699 July 6, 2026 14:26 Destroyed
@ironloopai

ironloopai Bot commented Jul 6, 2026 •

Copy link
Copy Markdown
Contributor

🗂️ Archived IronLoop Review: reviewer

This result is from an older PR head and is no longer the active review.

Field Value
Status Superseded
Verdict ✅ Approved
Findings 0 blocking / 0 notes
Reviewed head 92b4d7b70ded
Archived summary

No concrete blocking issues found in the PR diff. The change surfaces failed tool-permission saves, resets the previous mutation error before retry, and adds focused unit/e2e coverage for the regression path.

@github-actions github-actions Bot added size: M 50-199 changed lines and removed size: S 10-49 changed lines labels Jul 6, 2026

@ironloopai ironloopai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ IronLoop Review: reviewer

Verdict: ✅ Approved
Findings: 0 blocking / 0 notes
Next: No reviewer action needed.
Head: e860afaf57a76289214c1d9a659125ceccfd5928

Run details

Status: Current
Needs human: no
Needs validation: no

**Inline candidates:** 0

Summary

No blocking issues found. The change surfaces tool permission mutation failures in the settings UI, clears stale mutation errors before retrying, and adds focused unit plus e2e coverage for the failure path.

Findings

None.

Developer follow-up

After fixing this feedback:

  1. Push the fix to this PR branch.
  2. Re-run this reviewer with @ironloop review --agent reviewer if you only changed this reviewer's findings.
  3. Re-run all reviewers with @ironloop review when the fix may affect multiple areas.
  4. Use @ironloop status to check queued/running/completed/stale/stalled state while reviewers run.

@ironloopai ironloopai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ IronLoop Review: reviewer

Verdict: ✅ Approved
Findings: 0 blocking / 0 notes
Next: No reviewer action needed.
Head: e860afaf57a76289214c1d9a659125ceccfd5928

Run details

Status: Current
Needs human: no
Needs validation: no

**Inline candidates:** 0

Summary

No blocking issues found. The change surfaces tool permission mutation failures in the settings UI, clears stale mutation errors before retrying, and adds focused unit plus e2e coverage for the failure path.

Findings

None.

Developer follow-up

After fixing this feedback:

  1. Push the fix to this PR branch.
  2. Re-run this reviewer with @ironloop review --agent reviewer if you only changed this reviewer's findings.
  3. Re-run all reviewers with @ironloop review when the fix may affect multiple areas.
  4. Use @ironloop status to check queued/running/completed/stale/stalled state while reviewers run.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@crates/ironclaw_webui_v2/static/js/pages/settings/hooks/useTools.test.mjs`:
- Around line 6-14: The local sourceForTest helper in useTools.test.mjs is
duplicated and still uses the fragile single-line import skip logic, so it can
break on wrapped imports. Extract the hardened helper shared with
tools-tab.test.mjs, or otherwise update this copy to use the same skippingImport
approach, and keep the export rewriting in sync with the shared test utility.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 1f29323a-4167-4745-9f3d-4bfe155e4448

📥 Commits

Reviewing files that changed from the base of the PR and between 832c807 and e860afa.

📒 Files selected for processing (4)
  • crates/ironclaw_webui_v2/static/js/pages/settings/components/tools-tab.js
  • crates/ironclaw_webui_v2/static/js/pages/settings/components/tools-tab.test.mjs
  • crates/ironclaw_webui_v2/static/js/pages/settings/hooks/useTools.js
  • crates/ironclaw_webui_v2/static/js/pages/settings/hooks/useTools.test.mjs

Comment thread crates/ironclaw_webui_v2/static/js/pages/settings/hooks/useTools.test.mjs Outdated
@railway-app

railway-app Bot commented Jul 6, 2026 •

Copy link
Copy Markdown

🚅 Deployed to the ironclaw-pr-5699 environment in ironclaw-ci-preview

Service Status Web Updated (UTC)
ironclaw ✅ Success (View Logs) Web Jul 7, 2026 at 9:06 am

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5699 July 6, 2026 14:46 Destroyed

@ironloopai ironloopai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ IronLoop Review: reviewer

Verdict: ✅ Approved
Findings: 0 blocking / 0 notes
Next: No reviewer action needed.
Head: 92b4d7b70dede0a407952b1062e0a4bd611a6bdc

Run details

Status: Current
Needs human: no
Needs validation: no

**Inline candidates:** 0

Summary

No concrete blocking issues found in the PR diff. The change surfaces failed tool-permission saves, resets the previous mutation error before retry, and adds focused unit/e2e coverage for the regression path.

Findings

None.

Developer follow-up

After fixing this feedback:

  1. Push the fix to this PR branch.
  2. Re-run this reviewer with @ironloop review --agent reviewer if you only changed this reviewer's findings.
  3. Re-run all reviewers with @ironloop review when the fix may affect multiple areas.
  4. Use @ironloop status to check queued/running/completed/stale/stalled state while reviewers run.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@crates/ironclaw_webui_v2/static/js/test-utils/source-for-test.mjs`:
- Around line 1-19: The export-stripping logic in sourceForTest only rewrites
export function declarations, so other export forms can slip through and break
vm.runInNewContext as invalid script syntax. Update sourceForTest to strip all
export variants it may encounter in the loaded source, not just function
declarations, and keep the transformation centered in the line-processing loop
that builds lines before __testExports is appended.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 0f13fff1-410d-4951-ba05-96aac25cfff2

📥 Commits

Reviewing files that changed from the base of the PR and between e860afa and 92b4d7b.

📒 Files selected for processing (3)
  • crates/ironclaw_webui_v2/static/js/pages/settings/components/tools-tab.test.mjs
  • crates/ironclaw_webui_v2/static/js/pages/settings/hooks/useTools.test.mjs
  • crates/ironclaw_webui_v2/static/js/test-utils/source-for-test.mjs

Comment thread crates/ironclaw_webui_v2/static/js/test-utils/source-for-test.mjs Outdated
@italic-jinxin italic-jinxin self-assigned this Jul 6, 2026
@italic-jinxin italic-jinxin added the human-verified Manually tested and verified label Jul 6, 2026
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5699 July 6, 2026 15:03 Destroyed
@github-actions github-actions Bot added size: L 200-499 changed lines and removed size: M 50-199 changed lines labels Jul 6, 2026

@ironloopai ironloopai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ IronLoop Review: reviewer

Verdict: ✅ Approved
Findings: 0 blocking / 0 notes
Next: No reviewer action needed.
Head: 186da7c86fd6d005bac2699f77615fa2fb78cfe0

Run details

Status: Current
Needs human: no
Needs validation: no

**Inline candidates:** 0

Summary

No concrete, actionable regressions found in the PR. The change surfaces tool permission save failures in the settings UI and adds focused unit/E2E coverage for that behavior.

Findings

None.

Developer follow-up

After fixing this feedback:

  1. Push the fix to this PR branch.
  2. Re-run this reviewer with @ironloop review --agent reviewer if you only changed this reviewer's findings.
  3. Re-run all reviewers with @ironloop review when the fix may affect multiple areas.
  4. Use @ironloop status to check queued/running/completed/stale/stalled state while reviewers run.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@crates/ironclaw_webui_v2/static/js/test-utils/source-for-test.mjs`:
- Around line 3-14: The export stripping logic in stripExport only removes the
first line of a multi-line brace export, leaving continuation lines behind as
invalid statements. Update stripExport to track multi-line export blocks,
similar to the import-skipping behavior, so all lines in an export { ... } list
are omitted until the closing brace and semicolon are reached.
- Around line 3-18: The default-export rewriting in stripExport is inconsistent
for named default functions/classes because it preserves the original identifier
while exportBinding("default") still expects __defaultExport. Update stripExport
so named default function/class declarations are aliased to __defaultExport in
the same way as anonymous defaults, and add a regression test covering export
default function foo() {} and export default class Foo {} when requesting the
"default" binding.

In `@crates/ironclaw_webui_v2/static/js/test-utils/source-for-test.test.mjs`:
- Around line 11-47: The current test in sourceForTest only covers anonymous
default exports, so it misses the __defaultExport bug for named default
declarations. Update the sourceForTest fixture test to include a named default
export case in fixture.js, such as a default function or class, and request
"default" in the exportNames passed to sourceForTest; then assert the default
export is available through __testExports so the ReferenceError regression is
covered.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: ba4af55f-ca0e-4786-a7ff-1f29b9fad075

📥 Commits

Reviewing files that changed from the base of the PR and between 92b4d7b and 186da7c.

📒 Files selected for processing (2)
  • crates/ironclaw_webui_v2/static/js/test-utils/source-for-test.mjs
  • crates/ironclaw_webui_v2/static/js/test-utils/source-for-test.test.mjs

Comment thread crates/ironclaw_webui_v2/static/js/test-utils/source-for-test.mjs Outdated
Comment thread crates/ironclaw_webui_v2/static/js/test-utils/source-for-test.mjs Outdated
Comment thread crates/ironclaw_webui_v2/static/js/test-utils/source-for-test.test.mjs Outdated
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5699 July 7, 2026 08:50 Destroyed
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5699 July 7, 2026 08:55 Destroyed
@github-actions github-actions Bot added size: M 50-199 changed lines and removed size: L 200-499 changed lines labels Jul 7, 2026
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5699 July 7, 2026 09:00 Destroyed
@think-in-universe
think-in-universe added this pull request to the merge queue Jul 7, 2026
Merged via the queue into main with commit aaec312 Jul 7, 2026
60 checks passed
@think-in-universe
think-in-universe deleted the issue-5698-tools-save-error branch July 7, 2026 09:26

This branch was successfully deployed

No deployments
ironclaw-ci-preview / ironclaw-pr-5699 — aca0754d Deployed Jul 7, 2026 by railway-app[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs human-verified Manually tested and verified risk: low Changes to docs, tests, or low-risk modules size: M 50-199 changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Surface tool permission save failures in WebUI v2 Settings Tools tab

2 participants