Fix HIGH and MEDIUM frontend defects

Files pane
- F16: a drag-out released back inside the app no longer re-imports its own
  staged copy over the container original. An in-flight flag (cleared from the
  drag plugin's `onEvent` channel, with a watchdog) suppresses the drop and the
  "Drop files into …" hint, and an exact staged-path filter is the second line
  of defence — the `path|size|modified` cache could otherwise write a
  minutes-old snapshot over a file an agent had since rewritten.
- F17: a slow upload/rename no longer yanks the user back to the directory the
  operation started in. Every operation captures its target path and re-lists
  only if the user is still there; failures go to the toast host either way.
- The grid keeps keyboard focus. Roving tabindex (one tab stop, not one per
  row) plus focus restore after navigation, rename commit/cancel and Escape.
- Transient failures now surface in `ToastHost` (z-[60], persistent aria-live)
  instead of a `role="alert"` 300 rows down a scroller or behind a modal
  overlay. The inline error is kept only for the listing failure.
- `navigate` is sequenced by generation; "Save to host…" sets `busy`.
- Grid a11y: column headers, a text affordance for folder vs file, a live
  region that is mounted empty and announces completion, Label-in-Name fixed.
- FileViewerModal: the blob URL is released only once its replacement exists;
  the preview is a focusable, named, scrollable region.

Native drop routing
- New `lib/dropTarget.ts`: the hit test now refuses a drop while any
  `[aria-modal="true"]` dialog or `[data-blocks-drop]` overlay is up, and
  checks z-order where the environment can answer it. Shared by FilesTab and
  TerminalView; App's shutdown overlay opts in.

Disk
- A partially failed reclaim says so in words ("… — 2 of 5 failed"), not by hue
  alone.
- The scan/reclaim race is closed: every mutation retires an in-flight scan, so
  a scan can no longer repaint a pre-reclaim report plus a clickable plan of
  objects that are gone. Scan is disabled while working; the status is a live
  region; a failed destructive action keeps its dialog open and reports there.
- The "unknown" layer count gets a screen-reader fallback; `--text-disabled`
  no longer carries live information.

Terminal / OAuth
- After the toast is dismissed, a truncated heuristic guess can no longer fill
  the slot that an exact OSC 8 or relay URL occupied — the detector remembers
  every exact URL and drops any candidate that is a strict prefix of one.
- The prompt is reachable by keyboard: Ctrl+Shift+O jumps to the default
  action, Escape dismisses, focus returns to the terminal, and auto-dismiss
  holds off while focus is inside. It deliberately does not steal focus.
- UrlToast renders through `ui/Button` and `--shadow-overlay`.

Elsewhere
- AuthBridgeRow: a pushed `auth-bridge-changed` status always outranks an older
  awaited toggle result.
- The last two ad-hoc byte formatters route through `lib/formatBytes`.

Contract for the backend agent: `upload_file_to_container` refusing to
overwrite must satisfy `isFileExistsError` in `src/lib/uploadErrors.ts` (marker
`FILE_EXISTS`) and accept an `overwrite` argument; the frontend turns that into
an `ui/Modal` Replace/Skip prompt rather than a raw error string.

Tests: 536 -> 627 passing. `npm run build` and `npx tsc --noEmit` green.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GBq2rGum6GX7xXgsas1fDc
This commit is contained in:
2026-08-23 11:11:43 -07:00
co-authored by Claude Opus 5
parent 0003793abb
commit d6f065a2b6
33 changed files with 3120 additions and 315 deletions
+49
View File
@@ -225,6 +225,55 @@ describe("UrlDetector — OSC 8", () => {
expect(seen).toEqual([[url, "heuristic"]]);
});
it("never hands back a truncated guess at a link it has already seen exactly", () => {
// The defect: the prompt slot is emptied (dismissed, or auto-dismissed
// after 30 s), the OSC 8 target is deduped for the session and cannot come
// back, and the next repaint — sliced at a different offset, so a *new*
// string — reassembles into a prefix of the real link that fills the empty
// slot. It parses, it points at claude.ai, and it authorises nothing.
//
// Nothing here knows the slot was emptied, and that is the point: the rule
// holds however many times it is.
const seen: [string, UrlSource][] = [];
const d = new UrlDetector((u, s) => seen.push([u, s]), () => COLS);
feed(d, "Open this link to sign in:\r\n" + slicedHyperlink(SIGN_IN_URL) + "\r\ndone\r\n");
expect(seen).toEqual([[SIGN_IN_URL, "osc8"]]);
// …the user dismisses the toast; the TUI repaints the same link as plain
// text, cut short by the frame it was painted into.
feed(d, SIGN_IN_URL.slice(0, 150) + "\r\nWaiting for the browser…\r\n");
expect(seen).toHaveLength(1);
expect(seen.map(([u]) => u)).not.toContain(SIGN_IN_URL.slice(0, 150));
});
it("still offers a genuinely different link after an exact one", () => {
// The suppression is a prefix rule, not "one prompt per session".
const seen: string[] = [];
const d = new UrlDetector((u) => seen.push(u), () => COLS);
const other = "https://github.com/login/device?code=" + "x".repeat(90);
feed(d, slicedHyperlink(SIGN_IN_URL) + "\r\n");
feed(d, other + "\r\nnext\r\n");
expect(seen).toEqual([SIGN_IN_URL, other]);
});
it("suppresses a guess at a URL the consumer reported from the relay", () => {
// The OSC 7777 relay hands `TerminalView` a base64-encoded — therefore
// exact — URL that this detector never sees. `noteExactUrl` is how it gets
// told, so a dismissed relay prompt cannot be replaced by a scrape of the
// same link either.
const seen: string[] = [];
const d = new UrlDetector((u) => seen.push(u), () => COLS);
d.noteExactUrl(SIGN_IN_URL);
feed(d, SIGN_IN_URL.slice(0, 150) + "\r\nnext\r\n");
expect(seen).toEqual([]);
});
it("ignores a short hyperlink", () => {
// `ls --hyperlink` decorates every filename; none of that is a prompt.
const seen: string[] = [];