⛴️ chore: Bring Canary Up to Date With Dev - #16457
lia-by-librechat[bot] wants to merge 10 commits into
Conversation
* 🥤 fix: Keep Pending Code Steers Within the Composer * 🧪 test: Keep Pending Code Steer Preview Controls Visible * 🧪 test: Prove Pending Code Starts Inside the Composer --------- Co-authored-by: Lia <lia@librechat.ai>
Co-authored-by: Lia <lia@librechat.ai>
Co-authored-by: Lia <lia@librechat.ai>
Co-authored-by: Lia <lia@librechat.ai>
Route modules build their rate limiters while they load, and both server entries required them before startup checks copied rateLimits from librechat.yaml into the environment. The conversationsImport, tts, stt and route-scoped fileUploads budgets therefore ignored the yaml unless the matching environment variable was also set. Require the routes only after performStartupChecks in index.js and experimental.js.
…16439) * 🔒 fix: Guard 2FA Deep-Link Redirects Against Blocked Session Storage The post-login redirect store was the one session-storage consumer in the client that reached for it bare-handed: a context where storage access throws crashed the login screen's persist effect and the post-challenge boot instead of dropping the destination. Route every access through throwing-safe helpers so a blocked store costs the deep link, never the sign-in, and pin the ordinary 2FA challenge's deep-link survival and consumption with mock-harness scenarios plus blocked-storage unit tests. The challenge screen's code inputs also gain accessible names. * ♿ fix: Name the 2FA Verify Button by Its Visible Text The challenge submit button carried aria-label 'Continue' over the visible text 'Verify', so its accessible name did not contain the visible label (WCAG 2.5.3). The visible text names the button on its own; the label is dropped. * 🧪 test: Keep the 2FA Mock Harness From Re-Declaring Destinations The shell's authenticated queries 401 against the real backend under the stand-in bearer, and the auth-recovery login bounce carries the current URL as redirect_to, re-persisting the deep link mid-test. Answer those queries empty and leave /api/config real. * 🧪 test: Answer the Shell's Empty Shapes in the 2FA Deep-Link Harness The composer and its selectors iterate their query results, so the stand-in session's shell queries need per-endpoint empty payloads rather than a blank object; the destination's marker rides the query string so no conversation has to exist for the landing to hold; and the second sign-in declares its own destination, which is the deterministic form of consumption-across-sign-ins. * 🧪 test: Assert the 2FA Shell Across Viewports The account button hides in the mobile drawer and the drawer never satisfies a pointer click's stability check, so the shell assertion polls for whichever marker the viewport shows and the session ends through an in-page logout request, which the route mocks can actually see. * 🧪 test: Locate the Login Password Field by Label * 🧪 test: Let the CI Storage Polyfill Replace the Blocked Store The CI-mode build ships a storage polyfill that answers a broken sessionStorage by installing its own in-memory shim with defineProperty, which crashed against a non-configurable blocker and took the app boot with it. The blocker stays configurable: the shim is per-document, so the challenge's document swap still empties it and the landing contract is the same either way.
|
Review handoff for exact head |
|
Review handoff for exact head |
|
Review handoff for exact head |
Summary
devhas advanced since the previous canary sync. This PR merges dev71398aef6275419b4cf69b8fdf97dddd664a1d7ainto canary9ac96c5ca94500c1d6c33868f9f30cebfaef4adcwithout rebasing, squashing, or moving either base branch. The ancestry-preserving merge commit isffa54e0259bd0a7e180f33e1619cc3fbc3408edd(the two branch tips are its parents). The current PR head isd8b9371ad96059635fb527ce1c0544e6b410ca2a.How it works
rateLimitsmap. The quota-phase browser test asserts both sets of limits before exercising the service. Scoped formatting corrects class-order drift.SteerPartacross pending-to-applied transitions, instead of looking for the old composer overlay and assuming the optional message-collapse preference is enabled.devand the priorcanarytip remain ancestors of the PR head. The old canary sync was PR 🛶 chore: Bring Canary Up to Date With Dev #16361.Verification
Landing
After reviewing the exact passing head, prefer a non-forced fast-forward of
canaryto the PR head so shared ancestry remains intact and no outer merge commit is added. If branch protection requires GitHub's merge UI, choose Create a merge commit, never squash or rebase. Do not updatedevormainfor this PR.