Skip to content

fix(swe): restore catalog-bound feedback launcher - #120

Merged
sarthakagrawal927 merged 4 commits into
mainfrom
agent/swe-feedback-restore-20261004
Oct 4, 2026
Merged

sarthakagrawal927 merged 4 commits into
mainfrom
agent/swe-feedback-restore-20261004

Conversation

@sarthakagrawal927

Copy link
Copy Markdown
Member

Cause and fix

The existing React-owned feedback launcher returned null unless a build-time key was present, while the host intentionally kept shared footer composition disabled to preserve focused-study and public-share behavior. The shared capture-config endpoint already resolves a project's public key from its catalog ID, so the existing widget now requests /v1/capture-config/swe-interview-prep, validates the producer's public-key shape, and mounts only after a valid response. The request fails closed and aborts on timeout or unmount. Widget styling and the app's route guards remain unchanged.

Added focused tests for successful binding, invalid key shapes, HTTP/network failures, and request abort on unmount. Fixtures use a synthetic key only.

Checks

  • pnpm typecheck — passed
  • pnpm exec biome check src/components/saasmaker-feedback.tsx src/components/saasmaker-feedback.test.tsx — passed
  • pnpm test -- src/components/saasmaker-feedback.test.tsx — blocked at startup: Rolldown's Darwin native binding cannot load under the system code-sign policy
  • pnpm dev -- --host 127.0.0.1 — blocked by the same native binding, so this worktree has no rendered after-capture yet
  • Design workflow preflight — passed; completion review is pending rendered evidence

Review boundary

No production config, secrets, shared package source, dependencies, or unrelated worktrees changed. No merge or deployment is included.

@sarthakagrawal927
sarthakagrawal927 merged commit b5ff3cd into main Oct 4, 2026
2 checks passed
@sarthakagrawal927

Copy link
Copy Markdown
Member Author

Guarded production release

Merged #120 as b5ff3cd4307102d79488d5142ce79afa0fb6f42b. Qualified PR head 22a6d9b5dae7c3187645b971d67413438b6659af and merge have identical trees. Exact-main CI 37177276619 and Docs37177276598 passed; all six Fleet deployment guards passed against a clean independent main checkout. The dirty primary checkout was not changed.

Existing manual deployment run37177465375 succeeded. apply_migrations=false and its migration step was skipped. Provider production Pages deployment ef5dd274-7673-44fe-b874-b4a7877e8baa reports source b5ff3cd; the workflow recorded completion at 2026-10-04T04:36:53.1615612Z. Previous production source was339375d.

Live desktop /dashboard renders the existing Feedback launcher. Opening it shows the feedback dialog and required Title, Description and Email controls; no message or address was entered and no submission was made. The newsletter and explicit consent still render. Settled /practice retains focused suppression. The nonexistent share probe redirected to dashboard, so it is excluded as rendered proof of a valid shared page; the unchanged source guard remains inspected.

The release diff against previous production339375d changes feedback binding, its tests, docs, and the bounded Node-tooling advisory policy/tests. No tracker source, identity policy, collector, dependency version, schema, resource or production configuration changed. No collector rollout or visitor day seal was fabricated for this consumer-only repair.

Responsive qualification found an existing src/index.css rule hiding [data-saasmaker-widget] below1024px. Desktop restoration is verified; tablet/mobile feedback is currently hidden and a scoped visibility correction is in progress. Do not claim all-device completion from the desktop check.

The braces3.0.3 tooling advisory remains known; the audited exact path exception expires2026-10-18UTC and rejects changed versions, paths, extra findings or unrelated advisories. It is not a claim the upstream vulnerability is fixed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant