Fix HIGH and MEDIUM frontend defects

Files pane
- F16: a drag-out released back inside the app no longer re-imports its own
  staged copy over the container original. An in-flight flag (cleared from the
  drag plugin's `onEvent` channel, with a watchdog) suppresses the drop and the
  "Drop files into …" hint, and an exact staged-path filter is the second line
  of defence — the `path|size|modified` cache could otherwise write a
  minutes-old snapshot over a file an agent had since rewritten.
- F17: a slow upload/rename no longer yanks the user back to the directory the
  operation started in. Every operation captures its target path and re-lists
  only if the user is still there; failures go to the toast host either way.
- The grid keeps keyboard focus. Roving tabindex (one tab stop, not one per
  row) plus focus restore after navigation, rename commit/cancel and Escape.
- Transient failures now surface in `ToastHost` (z-[60], persistent aria-live)
  instead of a `role="alert"` 300 rows down a scroller or behind a modal
  overlay. The inline error is kept only for the listing failure.
- `navigate` is sequenced by generation; "Save to host…" sets `busy`.
- Grid a11y: column headers, a text affordance for folder vs file, a live
  region that is mounted empty and announces completion, Label-in-Name fixed.
- FileViewerModal: the blob URL is released only once its replacement exists;
  the preview is a focusable, named, scrollable region.

Native drop routing
- New `lib/dropTarget.ts`: the hit test now refuses a drop while any
  `[aria-modal="true"]` dialog or `[data-blocks-drop]` overlay is up, and
  checks z-order where the environment can answer it. Shared by FilesTab and
  TerminalView; App's shutdown overlay opts in.

Disk
- A partially failed reclaim says so in words ("… — 2 of 5 failed"), not by hue
  alone.
- The scan/reclaim race is closed: every mutation retires an in-flight scan, so
  a scan can no longer repaint a pre-reclaim report plus a clickable plan of
  objects that are gone. Scan is disabled while working; the status is a live
  region; a failed destructive action keeps its dialog open and reports there.
- The "unknown" layer count gets a screen-reader fallback; `--text-disabled`
  no longer carries live information.

Terminal / OAuth
- After the toast is dismissed, a truncated heuristic guess can no longer fill
  the slot that an exact OSC 8 or relay URL occupied — the detector remembers
  every exact URL and drops any candidate that is a strict prefix of one.
- The prompt is reachable by keyboard: Ctrl+Shift+O jumps to the default
  action, Escape dismisses, focus returns to the terminal, and auto-dismiss
  holds off while focus is inside. It deliberately does not steal focus.
- UrlToast renders through `ui/Button` and `--shadow-overlay`.

Elsewhere
- AuthBridgeRow: a pushed `auth-bridge-changed` status always outranks an older
  awaited toggle result.
- The last two ad-hoc byte formatters route through `lib/formatBytes`.

Contract for the backend agent: `upload_file_to_container` refusing to
overwrite must satisfy `isFileExistsError` in `src/lib/uploadErrors.ts` (marker
`FILE_EXISTS`) and accept an `overwrite` argument; the frontend turns that into
an `ui/Modal` Replace/Skip prompt rather than a raw error string.

Tests: 536 -> 627 passing. `npm run build` and `npx tsc --noEmit` green.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GBq2rGum6GX7xXgsas1fDc
This commit is contained in:
2026-08-23 11:11:43 -07:00
co-authored by Claude Opus 5
parent 0003793abb
commit d6f065a2b6
33 changed files with 3120 additions and 315 deletions
+92 -2
View File
@@ -45,8 +45,27 @@
*
* So each emitted candidate is tagged with where it came from, and the consumer
* refuses to let a `heuristic` candidate displace an `osc8` one.
*
* ## …and the exact copy keeps winning after the prompt is gone
*
* The consumer's precedence rule only compares a new candidate against what is
* *currently* in the prompt slot. Empty the slot — the user dismisses the
* toast, or its 30 s auto-dismiss fires — and it has nothing to compare
* against, so the next truncated guess walks straight in. Meanwhile the OSC 8
* target is deduped for the life of the session and cannot come back to
* displace it. The user is then holding a URL that parses, points at
* claude.ai, and authorises nothing, which is the exact bug the OSC 8 branch
* was added to kill.
*
* That is fixed *here* rather than in the consumer, because this is the side
* that knows both halves: {@link UrlDetector} remembers every exact URL it has
* seen and refuses to emit a heuristic candidate that is a strict prefix of
* one — see `truncatesKnownExact`. The rule then holds however often the slot
* is emptied, and needs no cooperation from whoever owns it.
*/
import { extendsUrl } from "./urlRelay";
const ANSI_RE =
/\x1b(?:\[[0-9;?]*[A-Za-z]|\][^\x07\x1b]*(?:\x07|\x1b\\)?|[()#][A-Za-z0-9]|.)/g;
@@ -196,6 +215,21 @@ export class UrlDetector {
/** OSC 8 targets already offered, so a hyperlink repainted every frame does
* not re-prompt. Bounded by {@link MAX_REMEMBERED_LINKS}. */
private emittedLinks = new Set<string>();
/**
* Every *exact* URL this session has seen — OSC 8 parameters, plus whatever
* the consumer reports through {@link noteExactUrl} (the OSC 7777 relay).
*
* Kept separately from `emittedLinks` because the two answer different
* questions: that one is "have I already prompted for this?", this one is "do
* I know the full text of a link some guess might be a prefix of?". The
* second answer must survive the prompt being dismissed; the whole defect is
* that a truncated guess fills the slot the moment it is empty.
*
* Bounded the same way, and cleared wholesale rather than evicted one by one:
* a program printing a fresh hyperlink every frame is not a program whose
* older links are still on screen to be mis-scraped.
*/
private exactUrls = new Set<string>();
constructor(callback: UrlCallback, columns: ColumnsGetter) {
this.callback = callback;
@@ -285,7 +319,7 @@ export class UrlDetector {
// 6. URL is clearly complete (more content follows) — dedup + emit
this.pendingUrl = null;
if (url !== this.lastEmitted) {
if (url !== this.lastEmitted && !this.truncatesKnownExact(url)) {
this.lastEmitted = url;
this.callback(url, "heuristic");
}
@@ -304,10 +338,23 @@ export class UrlDetector {
* `lastEmitted` is moved along with them so an identical string arriving on
* the heuristic path a moment later is recognised as the same candidate
* rather than fired a second time.
*
* Every target is remembered as exact whether or not it is offered — a
* hyperlink repainted a second time is the same known link, and the dedup
* that stops it re-prompting must not also stop it counting as something a
* later guess can be a truncation of.
*
* The alternative fix considered here was to make this dedup *releasable*,
* so the consumer could hand the exact URL back and have it re-offered once
* the prompt slot emptied. Rejected: it re-offers on the very next repaint,
* so dismissing the toast would put it straight back on screen — and it
* still would not establish the invariant, because a truncated guess and the
* released exact URL would simply race for the empty slot.
*/
private scanLinks(): void {
for (const uri of osc8Targets(this.buffer)) {
if (uri.length < MIN_URL_LENGTH) continue;
this.rememberExact(uri);
if (this.emittedLinks.has(uri)) continue;
if (this.emittedLinks.size >= MAX_REMEMBERED_LINKS) {
this.emittedLinks.clear();
@@ -319,13 +366,56 @@ export class UrlDetector {
}
private emitPending(): void {
if (this.pendingUrl && this.pendingUrl !== this.lastEmitted) {
if (
this.pendingUrl &&
this.pendingUrl !== this.lastEmitted &&
!this.truncatesKnownExact(this.pendingUrl)
) {
this.lastEmitted = this.pendingUrl;
this.callback(this.pendingUrl, "heuristic");
}
this.pendingUrl = null;
}
/**
* Whether `url` is a strict prefix of an exact URL already seen — i.e. a
* truncated guess at a link whose full text is known.
*
* {@link extendsUrl} is the predicate, used in the direction that asks "does
* the link I already have *extend* this guess?". It is the same rule the
* prompt slot uses to let a candidate grow into its complete form, which is
* the point: the two must agree about what "the same link, only shorter"
* means, so there is one implementation of it.
*
* Deliberately *not* symmetric. A candidate that is longer than a known exact
* URL and starts with it is a different problem (text glued onto the end by a
* wrap that was not a wrap), and it is still shown in full and confirmed by
* the user before anything opens.
*/
private truncatesKnownExact(url: string): boolean {
for (const exact of this.exactUrls) {
if (extendsUrl(exact, url)) return true;
}
return false;
}
/**
* Record a URL that arrived somewhere exact, outside this detector.
*
* The OSC 7777 relay hands `TerminalView` a base64-encoded URL — exact by
* construction, and never seen here. Without this the suppression rule above
* would cover hyperlinks and miss the relay, and a dismissed relay prompt
* could still be replaced by a truncated scrape of the same link.
*/
noteExactUrl(url: string): void {
this.rememberExact(url);
}
private rememberExact(url: string): void {
if (this.exactUrls.size >= MAX_REMEMBERED_LINKS) this.exactUrls.clear();
this.exactUrls.add(url);
}
dispose(): void {
if (this.timer !== null) {
clearTimeout(this.timer);