Sending already switched to the target terminal's tab, which looks like it
should be enough: `TerminalView` focuses xterm whenever a terminal becomes
active. But that effect keys off `active`, so it only fires on a *change* —
and the dock's ordinary case is sending to the terminal already on screen.
`setActiveTabKey` writes the key that is already set, nothing changes, no
effect re-runs, and focus stays on the Send button. The note is sitting in the
prompt and the user still has to click the terminal before pressing Enter.
So the send now asks for focus explicitly, through a one-shot request in the
store that `TerminalView` consumes and clears — the shape `pendingHomeTab`
already uses. Clearing is not tidiness: hold the id and the second send to the
same terminal writes a value that is already there, which is precisely the
no-op this exists to fix.
Focus is requested only on success. A failed send toasts and leaves the user
where they are, because there is nothing in the prompt to press Enter on.
The three `TerminalView` tests give focus away after mounting before making
any assertion, so what they observe is the request landing and never the focus
that `active` already grants on mount — which would pass with the feature
absent.
752 tests pass, 62 files.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011YPqHpjV4EL6RNEwrRKqQm
The gate that decides whether a native file drop is accepted has been wrong
twice in opposite directions, both times because it tried to be precise about
*which points* a dialog covers:
- Round 1 asked `el.contains(elementFromPoint(x, y))` and was handed the inner
xterm host while the overlays are siblings, so the always-rendered
Following/Paused button made the terminal's top-right corner permanently
refuse drops.
- Round 2 replaced that with "is a blocking overlay painted here?" and deleted
the document-wide gate. `elementFromPoint` returns the *topmost* element, and
ToastHost is z-[60] against the Modal backdrop's z-50 in the same stacking
context — so a refused drop pushed a toast, the toast covered the dialog, and
the next drop released on it was reported clear and landed in the directory
the dialog was covering. The gate armed its own hole.
Split the two questions instead of merging them:
- Geometry answers *whose* drop it is (rect hit test, unchanged), so exactly
one listener speaks for a drop and a hidden pane's zero-size rect still keeps
TerminalView and FilesTab from both firing.
- `dropIsBlocked` answers whether the app should take a drop at all —
document-wide, no z-index in it. While a modal or blocking overlay is on
screen anywhere, every drop is refused.
There is no `elementFromPoint` call left, so no future overlay can become a
drop hole by being painted high enough and no chrome can become a dead zone by
being painted at all. The cost is over-refusal while a dialog is open, in a
state the user entered deliberately, announced, writing nothing.
Also:
- `[aria-hidden="true"]` no longer disqualifies a blocker. It is not a
visibility statement (it sits on visible decorative content), so a blocker
nested in such a wrapper would have silently stopped blocking.
- Modal drops `data-blocks-drop` when its pane hides, and moves focus out of
itself rather than leaving it inside a `display:none` panel.
- The refusal notice stays `kind: "info"` (an expected refusal is not an
error, and an error card never auto-dismisses) and carries a `dedupeKey`, so
repeated refusals replace rather than stack.
Tests: mutation-checked against the previous implementation — four in
dropTarget.test.ts, two in each of TerminalView/FilesTab, two in Modal.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GBq2rGum6GX7xXgsas1fDc
Two things the UI couldn't do: rearrange the tab strip, and watch the
browser while working somewhere else.
**Drag to reorder.** `moveTab`/`moveActiveTab` on the store, HTML5 drag on
the strip with a marker showing where the drop lands, `Ctrl+Shift+←/→` for
the same thing without a mouse. Reordering deliberately does not select
what it moves, so a drag aimed at a background tab doesn't yank the main
area away from a terminal mid-run. A tab being renamed is not draggable —
a draggable ancestor swallows the mouse-drag that selects text in its
input.
**Pop the browser view out.** `browser_view/popout.rs` opens the view's
existing token-bearing loopback URL as a second OS window, with a
"Keep on top" toggle so it can float above the app. Window-only: the
viewer, the proxy and the container are untouched, so popping out and
back interrupts nothing.
Three things it rests on:
- No capability lists that window, so it has no IPC surface — right for a
page served out of a container, and it must stay that way.
- The app CSP is irrelevant to it: `frame-src` constrains what the app's
document may *embed*, and this is a top-level document. The port range
and the token gate are what actually protect it, unchanged.
- The window is owned by the session, so the supervisor's teardown closes
it. A window onto a viewer that no longer exists is worse than none.
The pane drops its iframe while popped out — two viewers can both *drive*
the browser, and two cursors on one page is not a feature.
`lib.rs`'s `on_window_event` is now guarded on `label() == "main"`. It
fires for every window and its body stops every container and exits, so
without the guard closing a pop-out would quit the app.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>