Milestone 23a: 3-pane asset review workspace (keyboard-first) - #43
Conversation
🤖 Devin AI EngineerI'll be helping with this pull request! Here's what you should know: ✅ I will automatically:
Note: I can only respond to comments from users who have write access to this repository. ⚙️ Control Options:
|
…lectable from library directly
M23a end-to-end test — 8/8 passedTested against the local compose stack ( No escalations — every assertion matched the plan's pass criteria. The keyboard-first claims hold up:
Evidence — screenshotsDetailed per-test breakdownTest 1 — CTA → workspace. Navigated to Test 2 — 3-pane rendering. All three panes visible simultaneously. STIG selector shows Test 3 — row click swaps middle pane + URL. Clicked V-100002. URL gained Test 4 — Test 5 — Test 6 — Test 7 — Test 8 — F5 deep-link rehydration. Pressed F5 at Out of scope (intentional): M23b multi-tab chrome, M23c Attachments tab, mobile-layout Devin session: https://app.devin.ai/sessions/022810763c4643c0848ba894c1512b92 |






Summary
Replaces the previous "one rule = one page" review flow with a single 3-pane workspace at
/collections/{cid}/assets/{aid}/workspace. On a 300-rule STIG the user no longer round-trips through/rules/{ruleId}for every check.Layout (mirrors the upstream stig-manager screenshot)
GET /stigs/rules/{ruleId}(only the rows you click are fetched, so opening a 434-rule STIG doesn't pull 434 detail bodies up front).GET /collections/{cid}/review-history; Other Assets + Status Text tabs scaffolded — Other Assets is the M23b follow-up) above an inline Evaluation form (result, detail, comment, status) with prev/next chevrons and last-touched attribution footer.STIG picker lives in the page header. Switching STIGs clears
?ruleso the workspace lands on the new STIG's first rule.Keyboard-first (only fires when no input/textarea is focused — text fields swallow the keys naturally):
j/ArrowDown,k/ArrowUp— next / prev rule (auto-scrolls into view)f/p/n/u— set Result to fail / pass / notapplicable / notcheckedCtrl+Enter— saveCtrl+Shift+Enter— save + advance to the next unreviewed rule in the filtered list/— focus the rule-list search boxURL state —
?stig=<benchmarkId>&rule=<ruleId>. Selecting a row pushesrule; switching STIGs replaces it. Reload / share link both work.Entry point — the asset detail page gets a primary "Open Review Workspace" CTA next to Edit / Delete. The per-rule
/rules/{ruleId}editor stays mounted (no breaking changes for direct links).Out of scope for M23a (deliberately deferred so this PR stays focused):
Server changes — none. Every endpoint the workspace needs already shipped between M8 and M21c.
Review & Testing Checklist for Human
/collections/{cid}/assets/{aid}/workspacefor an asset with at least one assigned STIG; verify the 3 panes render and the rule list is virtualisation-friendly (try a 400+ rule STIG)j/k→ selection moves; pressing/focuses the search box; pressingf/p/n/uupdates the result without savingCtrl+Enter→ review row is saved (poll/collections/{cid}/reviews/{aid}); pressingCtrl+Shift+Enteradvances to the next unreviewed rule?stig=updates and rule list reloadsNotes
The Playwright test covers the "workspace mounts + STIG picker +
/keyboard focus" smoke path against the live compose stack. Saving + Ctrl+Enter is exercised by the existing per-rule editor test and by theusePutReviewinvalidation hook; we intentionally don't re-exercise the same mutation surface in the workspace e2e to keep the suite fast.Link to Devin session: https://app.devin.ai/sessions/022810763c4643c0848ba894c1512b92
Requested by: @Exonical