fix(swe): restore catalog-bound feedback launcher - #120
Conversation
Guarded production releaseMerged #120 as Existing manual deployment run37177465375 succeeded. Live desktop /dashboard renders the existing Feedback launcher. Opening it shows the feedback dialog and required Title, Description and Email controls; no message or address was entered and no submission was made. The newsletter and explicit consent still render. Settled /practice retains focused suppression. The nonexistent share probe redirected to dashboard, so it is excluded as rendered proof of a valid shared page; the unchanged source guard remains inspected. The release diff against previous production339375d changes feedback binding, its tests, docs, and the bounded Node-tooling advisory policy/tests. No tracker source, identity policy, collector, dependency version, schema, resource or production configuration changed. No collector rollout or visitor day seal was fabricated for this consumer-only repair. Responsive qualification found an existing src/index.css rule hiding [data-saasmaker-widget] below1024px. Desktop restoration is verified; tablet/mobile feedback is currently hidden and a scoped visibility correction is in progress. Do not claim all-device completion from the desktop check. The braces3.0.3 tooling advisory remains known; the audited exact path exception expires2026-10-18UTC and rejects changed versions, paths, extra findings or unrelated advisories. It is not a claim the upstream vulnerability is fixed. |
Cause and fix
The existing React-owned feedback launcher returned
nullunless a build-time key was present, while the host intentionally kept shared footer composition disabled to preserve focused-study and public-share behavior. The shared capture-config endpoint already resolves a project's public key from its catalog ID, so the existing widget now requests/v1/capture-config/swe-interview-prep, validates the producer's public-key shape, and mounts only after a valid response. The request fails closed and aborts on timeout or unmount. Widget styling and the app's route guards remain unchanged.Added focused tests for successful binding, invalid key shapes, HTTP/network failures, and request abort on unmount. Fixtures use a synthetic key only.
Checks
pnpm typecheck— passedpnpm exec biome check src/components/saasmaker-feedback.tsx src/components/saasmaker-feedback.test.tsx— passedpnpm test -- src/components/saasmaker-feedback.test.tsx— blocked at startup: Rolldown's Darwin native binding cannot load under the system code-sign policypnpm dev -- --host 127.0.0.1— blocked by the same native binding, so this worktree has no rendered after-capture yetReview boundary
No production config, secrets, shared package source, dependencies, or unrelated worktrees changed. No merge or deployment is included.