Skip to content

⛴️ chore: Bring Canary Up to Date With Dev - #16457

Open
lia-by-librechat[bot] wants to merge 10 commits into
canaryfrom
lia/refresh-canary-from-dev
Open

lia-by-librechat[bot] wants to merge 10 commits into
canaryfrom
lia/refresh-canary-from-dev

Conversation

@lia-by-librechat

@lia-by-librechat lia-by-librechat Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Summary

dev has advanced since the previous canary sync. This PR merges dev 71398aef6275419b4cf69b8fdf97dddd664a1d7a into canary 9ac96c5ca94500c1d6c33868f9f30cebfaef4adc without rebasing, squashing, or moving either base branch. The ancestry-preserving merge commit is ffa54e0259bd0a7e180f33e1619cc3fbc3408edd (the two branch tips are its parents). The current PR head is d8b9371ad96059635fb527ce1c0544e6b410ca2a.

How it works

  • Keeps canary's redesigned composer, palette, in-thread pending steer view, MCP App test fixtures, and same-origin deep-link protection.
  • Carries dev's successful-send draft cleanup, blocked-session-storage redirect fallback, YAML route limiter fixture, and contributor guidance. The superseded in-flight steer component is not restored; the active in-thread steer bubble already caps its width.
  • Combines dev’s speech rate-limit fixture with canary’s MCP App quota fixture under one YAML rateLimits map. The quota-phase browser test asserts both sets of limits before exercising the service. Scoped formatting corrects class-order drift.
  • Keeps dev’s long/short code-steer layout assertions on canary’s actual in-thread SteerPart across pending-to-applied transitions, instead of looking for the old composer overlay and assuming the optional message-collapse preference is enabled.
  • Both dev and the prior canary tip remain ancestors of the PR head. The old canary sync was PR 🛶 chore: Bring Canary Up to Date With Dev #16361.

Verification

  • Scoped ESLint, import sorting, Prettier, and whitespace checks passed for the CI fixes. The generated quota-phase Playwright config was parsed with unique YAML keys; the map retained STT/TTS budgets and MCP App resource/tool-call quotas, and MCP Apps remained enabled.
  • The data-provider, data-schemas, API, and shared-client package builds passed locally. Redirect, storage, and startup assertions passed (61 in three suites). Composer and pending-steer component tests did not pass reliably in the reused local dependency overlay because its published data-provider/MCP App packages lag this head; a local client TypeScript run timed out. GitHub clean-install Jest and TypeScript checks are the verification gate for these.
  • The immediately preceding head passed clean-install TypeScript, static checks, and Lighthouse. Two Redis E2E tests still targeted the deleted composer overlay; the newest head adapts those layout assertions. The MCP Apps browser lane separately timed out waiting for an allowed-link popup after the App button click, with its policy and App initialization already passing. This is not yet resolved. All current-head browser checks and review are pending. Full Lighthouse and browser E2E were not run locally. If either base advances, merge its new tip into this PR and recheck.

Landing

After reviewing the exact passing head, prefer a non-forced fast-forward of canary to the PR head so shared ancestry remains intact and no outer merge commit is added. If branch protection requires GitHub's merge UI, choose Create a merge commit, never squash or rebase. Do not update dev or main for this PR.

berry-13 and others added 8 commits September 28, 2026 12:28
* 🥤 fix: Keep Pending Code Steers Within the Composer

* 🧪 test: Keep Pending Code Steer Preview Controls Visible

* 🧪 test: Prove Pending Code Starts Inside the Composer

---------

Co-authored-by: Lia <lia@librechat.ai>
Co-authored-by: Lia <lia@librechat.ai>
Route modules build their rate limiters while they load, and both server
entries required them before startup checks copied rateLimits from
librechat.yaml into the environment. The conversationsImport, tts, stt
and route-scoped fileUploads budgets therefore ignored the yaml unless
the matching environment variable was also set. Require the routes only
after performStartupChecks in index.js and experimental.js.
…16439)

* 🔒 fix: Guard 2FA Deep-Link Redirects Against Blocked Session Storage

The post-login redirect store was the one session-storage consumer in the
client that reached for it bare-handed: a context where storage access
throws crashed the login screen's persist effect and the post-challenge
boot instead of dropping the destination. Route every access through
throwing-safe helpers so a blocked store costs the deep link, never the
sign-in, and pin the ordinary 2FA challenge's deep-link survival and
consumption with mock-harness scenarios plus blocked-storage unit tests.
The challenge screen's code inputs also gain accessible names.

* ♿ fix: Name the 2FA Verify Button by Its Visible Text

The challenge submit button carried aria-label 'Continue' over the visible
text 'Verify', so its accessible name did not contain the visible label
(WCAG 2.5.3). The visible text names the button on its own; the label is
dropped.

* 🧪 test: Keep the 2FA Mock Harness From Re-Declaring Destinations

The shell's authenticated queries 401 against the real backend under the
stand-in bearer, and the auth-recovery login bounce carries the current URL
as redirect_to, re-persisting the deep link mid-test. Answer those queries
empty and leave /api/config real.

* 🧪 test: Answer the Shell's Empty Shapes in the 2FA Deep-Link Harness

The composer and its selectors iterate their query results, so the stand-in
session's shell queries need per-endpoint empty payloads rather than a
blank object; the destination's marker rides the query string so no
conversation has to exist for the landing to hold; and the second sign-in
declares its own destination, which is the deterministic form of
consumption-across-sign-ins.

* 🧪 test: Assert the 2FA Shell Across Viewports

The account button hides in the mobile drawer and the drawer never
satisfies a pointer click's stability check, so the shell assertion polls
for whichever marker the viewport shows and the session ends through an
in-page logout request, which the route mocks can actually see.

* 🧪 test: Locate the Login Password Field by Label

* 🧪 test: Let the CI Storage Polyfill Replace the Blocked Store

The CI-mode build ships a storage polyfill that answers a broken
sessionStorage by installing its own in-memory shim with
defineProperty, which crashed against a non-configurable blocker and
took the app boot with it. The blocker stays configurable: the shim is
per-document, so the challenge's document swap still empties it and the
landing contract is the same either way.
@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Review handoff for exact head ffa54e0259bd0a7e180f33e1619cc3fbc3408edd: merges canary 9ac96c5ca945 with dev 71398aef6275 as the two commit parents. Conflict resolution retains canary's new composer and same-origin redirects while adding dev's blocked-storage handling, accepted-send draft cleanup and YAML rate-limit fixture. Dev's removed old steer component is not reintroduced because the active in-thread steer view already caps its width. Clean-install CI is underway. The local shared node_modules overlay is incomplete, so Jest/TypeScript/lint need CI or an intact local install before claiming pass. Do not squash or rebase; leave canary untouched while the PR is reviewed.

@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Review handoff for exact head e20558b73635603bfe73c9215bd9cef681556fdd: the dev-to-canary merge keeps canary's redesigned composer and safe redirects. This follow-up resolves two confirmed CI failures on the preceding head: class order in two affected client files, and duplicate root rateLimits in the E2E fixture that disabled the MCP Apps quota phase. The actual quota Playwright config now parses with a single rateLimits root containing both speech limits and MCP App limits; Apps policy is enabled. Scoped Prettier, import sorting and ESLint pass locally. CI is restarting on this SHA; do not use checks from ffa54e025 to approve this head. Leave canary untouched until review and exact-head CI are assessed.

@lia-by-librechat

Copy link
Copy Markdown
Contributor Author

Review handoff for exact head d8b9371ad96059635fb527ce1c0544e6b410ca2a: the prior head passed clean-install TypeScript, static checks and Lighthouse. Its Redis E2E shard failed two new code-steer layout tests that still assumed the composer overlay removed by canary. The latest commit measures the actual in-thread SteerPart across pending-to-applied handoff at desktop/mobile sizes, checking bubble bounds and horizontally scrollable code without assuming the optional Show More preference is enabled. Source-only local Playwright discovery, ESLint and Prettier passed; browser shards are restarting for this SHA. The preceding head also had an MCP App popup timeout after a click despite passing policy and rendering assertions. That separate check remains under review, not claimed fixed here. Neither dev nor canary has moved or been rebased; please review this exact head.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants