Skip to content

Keep History's errors when the tab refreshes, and bump rustls - #102

Merged
AndersRobstad merged 3 commits into
mainfrom
fix-main-ci
Sep 29, 2026
Merged

AndersRobstad merged 3 commits into
mainfrom
fix-main-ci

Conversation

@AndersRobstad

@AndersRobstad AndersRobstad commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator

Main's CI has been red since #99/#100: check and e2e and dependency audit both fail at db1c52d. This fixes both, so #101 (and the release after it) can go out on a green pipeline.

History errors vanished when the tab opened

#99 made History catch up whenever the tab is opened. refresh() set this.error = null after any list that succeeded, which also wiped a failed body load or a failed clear before the tab that reports them could show it. The two e2e tests covering that fail on main:

  • a body-load failure is reported without taking history down
  • a failed per-request clear restores the response

History now remembers the message of the last failed list, and a list that succeeds clears that message and nothing else. a transient history-body error clears after reopening succeeds still passes.

RUSTSEC-2026-0285

cargo audit fails on rustls 0.23.43 (TLS 1.3 handshake messages accepted across encryption level boundaries; fixed in ≥ 0.23.45). cargo update -p rustls moves only that crate to 0.23.45. rustls is the TLS stack of the MCP image, so this is worth shipping in the same release.

fast-uri

With cargo audit passing, the next step of the same job, pnpm audit --prod --audit-level high, fails on fast-uri 3.1.6 (via ajv): GHSA-qw65-cvwx-89v3 and GHSA-58mr-gqgx-xq4g. pnpm update fast-uri --depth Infinity moves it to 3.1.8, which is inside ajv's ^3.0.1; nothing else in the lockfile changes. The audit then reports one low finding and passes.

A flaky settings-drawer test

After the audit went green, opening another collection’s settings flushes the one being left failed on this PR, first try and retry. It is flaky on main too: 4 of 40 local runs failed with main's code. Clicking another collection's cog is also a click outside the open drawer, so it both dismissed the drawer and started opening the next one. When the dismissal landed last, no drawer stayed open. The drawer now ignores outside interactions on a cog (data-opens-settings), since the cog switches collections itself and flushes the one being left. 60/60 local runs pass.

Verification

Locally: pnpm check is clean and the full Playwright suite passes (339/339) with every change here, and json-schema.spec.ts again after the fast-uri bump.

Opening History runs a refresh, and a refresh whose list succeeded set
`error = null` — wiping a failed body load or clear before the tab that
reports it could show it. Two e2e tests have failed on main since #99 for
this reason. A successful list now clears only an error a failed list set.

rustls 0.23.43 -> 0.23.45 for RUSTSEC-2026-0285 (TLS 1.3 handshake
messages accepted across encryption level boundaries), which fails the
dependency audit on main.
pnpm audit --prod --audit-level high fails on fast-uri 3.1.6, pulled in by
ajv. 3.1.8 is within ajv's ^3.0.1 range; nothing else in the lockfile moves.
A click on another collection's cog is outside the open drawer, so it both
closed the drawer and started opening the next one; when the close landed
last, no drawer stayed open. It made 'opening another collection's settings
flushes the one being left' fail about one run in ten, on main too. The
drawer now ignores outside interactions on a cog, which switches
collections itself.
@AndersRobstad
AndersRobstad merged commit cc2451c into main Sep 29, 2026
4 checks passed
@AndersRobstad
AndersRobstad deleted the fix-main-ci branch September 29, 2026 12:26
@github-actions github-actions Bot mentioned this pull request Sep 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant