From 80ca7dd0765a6c08fa5ea54c2e14972bba6fa564 Mon Sep 17 00:00:00 2001 From: Christophe Besson Date: Mon, 7 Sep 2026 00:18:54 +0200 Subject: fix(client): New folder did nothing — prompt() throws in the desktop client MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The same `static/` tree is the web page and the application, and Electron does not implement `window.prompt`: Chromium leaves it to the embedder and Electron declines. It does not return null — it **throws**. The call sat above its own try, so clicking produced no folder, no error and nothing on screen to react to. A dead button, which is exactly how it was reported. Measured against this repo's own Electron 44 rather than assumed, because the first two diagnoses this session were reasoned and wrong: prompt('name?') -> Error: prompt() is not supported. confirm('sure?') -> opens a real modal alert('hi') -> opens a real modal So `confirm` and `alert` stay — a dozen call sites depend on them — and only `prompt` is banned. `test_no_prompt_in_the_spa.py` holds the whole tree to it, with the near-misses it must not flag (`mkdir_prompt`, `promptForName`). The name now comes from a field in the toolbar, which works in both clients and can show the node's refusal beside the input instead of after a dialog has closed. Navigating away drops a half-typed name: it would otherwise create the folder somewhere the person is no longer looking. The rest of the chain was verified end to end and was sound: `dir_create` {dir,name} → the node's handler → `dir_create_ack`, and `list_dirs` walks the filesystem rather than the index, so a folder with nothing in it appears on the very fetch that follows. The field itself was then driven inside a real Electron window — typing, Enter, the click, and the icon rendering. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_011pvMdvLBG92jyhvD5pD6us --- .../meshbay-hub/tests/test_no_prompt_in_the_spa.py | 90 ++++++++++++++++++++++ .../tests/test_upload_controls_hidden.py | 17 ++-- 2 files changed, 102 insertions(+), 5 deletions(-) create mode 100644 packages/meshbay-hub/tests/test_no_prompt_in_the_spa.py (limited to 'packages/meshbay-hub/tests') diff --git a/packages/meshbay-hub/tests/test_no_prompt_in_the_spa.py b/packages/meshbay-hub/tests/test_no_prompt_in_the_spa.py new file mode 100644 index 0000000..d126a05 --- /dev/null +++ b/packages/meshbay-hub/tests/test_no_prompt_in_the_spa.py @@ -0,0 +1,90 @@ +""" +`window.prompt` does not exist in the desktop client. + +The same `static/` tree is the web page and the application (CLAUDE.md's "one +UI source"), and Electron does not implement `prompt` — Chromium leaves it to +the embedder and Electron declines. It does not return null: it **throws**, +`Error: prompt() is not supported.` + +That made the Files toolbar's New folder button do nothing whatsoever. The call +sat above its own try, so the click produced no folder, no error, and nothing +on screen to react to — the failure looks exactly like a dead button, which is +what it was reported as. + +Measured rather than assumed, against this repo's own Electron 44: + + prompt('name?') -> Error: prompt() is not supported. + confirm('sure?') -> opens a real modal + alert('hi') -> opens a real modal + +So `confirm` and `alert` stay allowed and are used in a dozen places; only +`prompt` is banned. Anything that needs typed input needs a field. +""" + +import re +from pathlib import Path + +import pytest + +STATIC = Path(__file__).resolve().parents[1] / "src" / "meshbay_hub" / "static" + +pytestmark = pytest.mark.skipif(not STATIC.exists(), + reason="SPA sources unavailable") + +# `prompt(` as a call, not `window.prompt` inside a comment or a longer +# identifier like `mkdir_prompt` / `promptForName`. +CALL = re.compile(r"(? str: + source = re.sub(r"/\*.*?\*/", "", source, flags=re.S) + return re.sub(r"^\s*//.*$", "", source, flags=re.M) + + +def test_nothing_calls_prompt(): + offenders = [] + for path in sorted(STATIC.glob("*.js")): + if path.name == "sw.js": + continue + for i, line in enumerate(_code_only( + path.read_text(encoding="utf-8")).splitlines(), 1): + if CALL.search(line): + offenders.append(f"{path.name}:{i}: {line.strip()}") + + assert not offenders, ( + "prompt() throws in the desktop client, and the click that reaches it " + "does nothing at all:\n " + "\n ".join(offenders)) + + +def test_the_pattern_would_catch_a_real_call(): + """ + A guard that matches nothing passes over an empty set, which looks exactly + like success. Both spellings, and the near-misses it must not flag. + """ + assert CALL.search("const n = prompt('x');") + assert CALL.search("const n = window.prompt('x');") + assert not CALL.search("t('group.mkdir_prompt')") + assert not CALL.search("promptForName();") + assert not CALL.search("this.prompt(1);") + + +def test_creating_a_folder_uses_a_field(): + """ + The control the ban is about. A typed name needs somewhere to type it, and + an inline field can show the node's refusal beside the input rather than + after a dialog has closed. + """ + source = (STATIC / "files-app.js").read_text(encoding="utf-8") + assert "tb-mkdir-input" in source + assert "newDirName" in source + assert "group.mkdir_prompt" in source, "the field has no label or placeholder" + + +def test_leaving_the_folder_drops_a_half_typed_name(): + """ + Otherwise the folder is created where the person is no longer looking — + they navigated away, the draft came along, and the name lands in a + directory they were not thinking about. + """ + source = (STATIC / "files-app.js").read_text(encoding="utf-8") + assert "useEffect(() => { setNewDirName(null); }, [currentPath]);" in source diff --git a/packages/meshbay-hub/tests/test_upload_controls_hidden.py b/packages/meshbay-hub/tests/test_upload_controls_hidden.py index a61de1f..bdba373 100644 --- a/packages/meshbay-hub/tests/test_upload_controls_hidden.py +++ b/packages/meshbay-hub/tests/test_upload_controls_hidden.py @@ -94,13 +94,20 @@ def test_an_icon_only_button_still_says_what_it_is(): The name moved into a tooltip to save toolbar width. A `title` is invisible to a screen reader on a button with no text, so the label has to be there as well — otherwise the control is simply unnamed for anyone not reading - with their eyes. + with their eyes. The same goes for the field it opens, which has a + placeholder and no visible label. """ page = _component(FILES_APP.read_text(encoding="utf-8"), "FilesPanel") - block = page[page.index("canCreateDir && html`"):] - block = block[:block.index("")] - assert "title=" in block and "aria-label=" in block - assert "group.mkdir" in block + opener = page[page.index("canCreateDir && newDirName === null"):] + opener = opener[:opener.index("")] + assert "title=" in opener and "aria-label=" in opener + assert "group.mkdir" in opener + + field = page[page.index("canCreateDir && newDirName !== null"):] + field = field[:field.index("")] + assert "aria-label=" in field, ( + "the name field is labelled by a placeholder alone, which a screen " + "reader does not announce as a name") def test_the_chat_composer_hides_its_paperclip(): -- cgit v1.2.3