Skip to content

feat(dns): one zone list — the name opens its records, and DNSSEC lives in the row's ⋯ menu — GH #1918 - #2000

Merged
shukiv merged 1 commit into
mainfrom
gh1918-dns-zone-menu
Oct 4, 2026
Merged

shukiv merged 1 commit into
mainfrom
gh1918-dns-zone-menu

Conversation

@shukiv

@shukiv shukiv commented Oct 4, 2026

Copy link
Copy Markdown
Owner

GH #1918 (johnnyq): merge the DNS page's Zones and DNSSEC tabs. Clicking the domain name opens its records, and the DNSSEC actions and the zone delete move into a ⋯ menu.

What changes (admin and tenant DNS page)

  • One list. The DNSSEC tab is gone. Old ?tab=dnssec links and the existing /dnssec redirects land on the list.
  • The domain name links to the zone's records. This is a real <Link> with an href, so middle-click works. The Manage Records button is gone.
    • A row whose DNS is hosted elsewhere keeps a plain name and its Enable DNS button. That is the row's only action, so it stays visible instead of becoming a one-item menu.
  • The row's ⋯ menu follows the Mail Domains pattern (GH Suggestion: UI Mail Domain Drill Down #1387):
    • Enable DNSSEC on an unsigned, provisioned zone.
    • View DS & keys and Disable DNSSEC on a signed zone.
    • Delete zone, or Delete domain for a DNS-only domain. A signed zone's delete stays disabled with the "Disable DNSSEC before deleting this zone" hint.
  • View DS & keys opens a modal with the keys (type, tag, algorithm, state) and the DS records to copy to the registrar. The admin's signing note (NSEC3 / ECDSAP256SHA256 / pdnsutil) moved into it.

Behavior changes beyond layout

  • Disable DNSSEC now confirms first. The old tab's switch turned signing off in one click. Doing that while the registrar still publishes the DS makes validating resolvers reject the zone, so the confirm tells the user to remove the DS first.
  • An unprovisioned, unsigned row has no DNSSEC action. The old tab listed every domain and offered the switch regardless. But PUT /domains/:id/dnssec runs pdnsutil on the zone, so it failed there anyway. A signed row always offers Disable, so a stuck state can still be cleared.
  • New hook. DNSSEC is flipped through useSetDNSSEC, which takes the domain at call time and also refreshes ["list","dns/zones"] so the Signed tag follows. DNSSECTable and the per-id useUpdateDNSSEC are removed (no other users).

Docs

dns.md, admin/dns-zones.md, user/dnssec.md and platform/dnssec.md now describe the menu. The user and platform pages still pointed at a Domain Edit DNSSEC toggle that no longer exists.

Tests

  • DNSZoneInventory.test.tsx (12 tests):
    • the name links per audience;
    • no tab and no Manage Records button;
    • the menu contents per row state;
    • Disable confirms before it PUTs, and Enable doesn't confirm;
    • an unprovisioned row has no menu;
    • the keys modal;
    • the GH Feature: Ability to Delete DNS Zone #1611 facet states.
  • useDNSSEC.test.tsx: the PUT targets the domain given at call time and invalidates the zone list (prefix match), with unrelated keys untouched.
  • tests/e2e/dns-zone-menu.spec.ts (Chromium, built SPA, mocked API):
    • link href, no tab and no Manage Records;
    • ⋯ → Enable DNSSEC → PUT → the tag flips to Signed;
    • View DS & keys shows the key and DS;
    • Disable shows the DS warning and PUTs only after the confirm, then the tag flips to Unsigned;
    • no horizontal overflow at 390px.
  • Falsified:
    • The old inventory fails 9 unit tests and all 3 e2e tests.
    • Removing the confirm fails the confirm test.
    • Dropping the zone-list refresh fails the hook test and the e2e Enable → Signed flip.
  • Ran: full vitest (157 files, 931 passed), tsc -b, eslint (0 errors), and the Playwright spec.

https://claude.ai/code/session_0173PcNd4h6NceYPc4FuhvXj

…es in the row's ⋯ menu — GH #1918

johnnyq asked to merge the Zones and DNSSEC tabs. The DNS page (admin and
tenant) is now one list:

- The domain name links to the zone's records, so the Manage Records
  button is gone. A row whose DNS is hosted elsewhere keeps a plain name
  and its Enable DNS button.
- The row's ⋯ menu holds Enable / Disable DNSSEC, View DS & keys (signed
  zones), and Delete zone or Delete domain. A signed zone's delete stays
  disabled with the "disable DNSSEC first" hint.
- Disable DNSSEC now confirms first. The old tab's switch turned signing
  off in one click, and doing that while the registrar still publishes
  the DS makes validating resolvers reject the zone.
- View DS & keys opens a modal with the keys (type, tag, algorithm,
  state) and the DS records. The admin signing note moved there.

DNSSEC is flipped through a new useSetDNSSEC hook. It takes the domain at
call time, since the menu is built per row, and it refreshes the zone
list so the Signed tag follows. The DNSSECTable component and the old
per-id hook are removed.

Docs: dns.md, admin/dns-zones.md, user/dnssec.md and platform/dnssec.md
now describe the menu (the user and platform docs still pointed at a
Domain Edit toggle that no longer exists).

Claude-Session: https://claude.ai/code/session_0173PcNd4h6NceYPc4FuhvXj
@shukiv
shukiv merged commit 012038b into main Oct 4, 2026
11 checks passed
@shukiv
shukiv deleted the gh1918-dns-zone-menu branch October 4, 2026 18:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant