diff options
| author | Christophe Besson <cbesson@gmail.com> | 2026-09-07 10:35:09 +0200 |
|---|---|---|
| committer | Christophe Besson <cbesson@gmail.com> | 2026-09-07 10:35:09 +0200 |
| commit | 2c0903c648e24b4e2adf20492398e8b67d033b49 (patch) | |
| tree | 0435f298010f0f946362f28baebbe88337ca8768 /packages/meshbay-hub/tests/test_no_prompt_in_the_spa.py | |
| parent | 0ed078c92cabab1dab0f70f321562032ea549ce6 (diff) | |
| parent | eeda274d751c537f4ecef3087994a16a9517478f (diff) | |
| download | meshbay-2c0903c648e24b4e2adf20492398e8b67d033b49.tar.gz | |
Merge branch 'refactor/groups-phase1'
Groups refactor, phases 1-3.
The root model replaces the old `upload` flag and group-wide `member_upload`
with per-root `writable`/`removable`/`ejected`, carried by a `RootSet` that
both front doors — the loopback API and signed MNP — reach through the same
`ops` functions. MNP goes to 1.1, additively: the roots table now rides on
`index_delta`, so a root added, removed, ejected or plugged reaches every
connected client instead of only whoever reloaded.
The group UI becomes a plugin architecture: an application is a registry
entry in `apps.js` plus its own files, with directories stored generically
by `ops.set_app_directories` under whatever the app is called. A reference
application, hidden behind `?dev=1`, is what makes that claim testable —
adding it is what found the two places still naming apps by hand.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011pvMdvLBG92jyhvD5pD6us
Diffstat (limited to 'packages/meshbay-hub/tests/test_no_prompt_in_the_spa.py')
| -rw-r--r-- | packages/meshbay-hub/tests/test_no_prompt_in_the_spa.py | 90 |
1 files changed, 90 insertions, 0 deletions
diff --git a/packages/meshbay-hub/tests/test_no_prompt_in_the_spa.py b/packages/meshbay-hub/tests/test_no_prompt_in_the_spa.py new file mode 100644 index 0000000..d126a05 --- /dev/null +++ b/packages/meshbay-hub/tests/test_no_prompt_in_the_spa.py @@ -0,0 +1,90 @@ +""" +`window.prompt` does not exist in the desktop client. + +The same `static/` tree is the web page and the application (CLAUDE.md's "one +UI source"), and Electron does not implement `prompt` — Chromium leaves it to +the embedder and Electron declines. It does not return null: it **throws**, +`Error: prompt() is not supported.` + +That made the Files toolbar's New folder button do nothing whatsoever. The call +sat above its own try, so the click produced no folder, no error, and nothing +on screen to react to — the failure looks exactly like a dead button, which is +what it was reported as. + +Measured rather than assumed, against this repo's own Electron 44: + + prompt('name?') -> Error: prompt() is not supported. + confirm('sure?') -> opens a real modal + alert('hi') -> opens a real modal + +So `confirm` and `alert` stay allowed and are used in a dozen places; only +`prompt` is banned. Anything that needs typed input needs a field. +""" + +import re +from pathlib import Path + +import pytest + +STATIC = Path(__file__).resolve().parents[1] / "src" / "meshbay_hub" / "static" + +pytestmark = pytest.mark.skipif(not STATIC.exists(), + reason="SPA sources unavailable") + +# `prompt(` as a call, not `window.prompt` inside a comment or a longer +# identifier like `mkdir_prompt` / `promptForName`. +CALL = re.compile(r"(?<![\w.$])(?:window\.)?prompt\s*\(") + + +def _code_only(source: str) -> str: + source = re.sub(r"/\*.*?\*/", "", source, flags=re.S) + return re.sub(r"^\s*//.*$", "", source, flags=re.M) + + +def test_nothing_calls_prompt(): + offenders = [] + for path in sorted(STATIC.glob("*.js")): + if path.name == "sw.js": + continue + for i, line in enumerate(_code_only( + path.read_text(encoding="utf-8")).splitlines(), 1): + if CALL.search(line): + offenders.append(f"{path.name}:{i}: {line.strip()}") + + assert not offenders, ( + "prompt() throws in the desktop client, and the click that reaches it " + "does nothing at all:\n " + "\n ".join(offenders)) + + +def test_the_pattern_would_catch_a_real_call(): + """ + A guard that matches nothing passes over an empty set, which looks exactly + like success. Both spellings, and the near-misses it must not flag. + """ + assert CALL.search("const n = prompt('x');") + assert CALL.search("const n = window.prompt('x');") + assert not CALL.search("t('group.mkdir_prompt')") + assert not CALL.search("promptForName();") + assert not CALL.search("this.prompt(1);") + + +def test_creating_a_folder_uses_a_field(): + """ + The control the ban is about. A typed name needs somewhere to type it, and + an inline field can show the node's refusal beside the input rather than + after a dialog has closed. + """ + source = (STATIC / "files-app.js").read_text(encoding="utf-8") + assert "tb-mkdir-input" in source + assert "newDirName" in source + assert "group.mkdir_prompt" in source, "the field has no label or placeholder" + + +def test_leaving_the_folder_drops_a_half_typed_name(): + """ + Otherwise the folder is created where the person is no longer looking — + they navigated away, the draft came along, and the name lands in a + directory they were not thinking about. + """ + source = (STATIC / "files-app.js").read_text(encoding="utf-8") + assert "useEffect(() => { setNewDirName(null); }, [currentPath]);" in source |