Skip to content

Fix credential, import, upload retry, and offline failures found in local testing - #101

Merged
poitee merged 7 commits into
mainfrom
codex/full-function-audit
Sep 28, 2026
Merged

poitee merged 7 commits into
mainfrom
codex/full-function-audit

Conversation

@poitee

@poitee poitee commented Sep 28, 2026 •

Copy link
Copy Markdown
Owner

Six defects surfaced while running the current pending PR stack locally. This fixes GitHub token clearing/status, Spoolman connector ownership, failed queued-upload retry, Save-time ZIP retry, imported Build selection/dialog dismissal, and misleading offline-save promises.

Stacked on #100, which includes #99. The dependency versions from #93, #94, #96 and #97 are included and were tested together. The S3 bump in #95 is obsolete on this base because S3 support was removed.

  • Clearing a GitHub PAT now persists removal, and reload displays saved status correctly.
  • Filament deductions use the enabled Spoolman connector named in each spool reference.
  • Failed queued sends retain their staged artifact for explicit retry; success or cancellation cleans it up.
  • A ZIP chosen during the first Save remains available when that upload fails.
  • Reference import refreshes Build state, selects the returned Build, and closes the share dialog. Failed list refresh preserves the imported selection and shows a warning.
  • Offline/install copy now describes the connection and save-confirmation requirement. Cache v4 replaces the old offline page. Same-tab reconnect can resume an in-memory mutation; browser closure does not persist it.

Validation: full VITEST_MAX_WORKERS=2 TMPDIR=/private/tmp TZ=UTC npm run quality passed, including 3,712 unit/integration tests, production build, bundle/runtime checks and seven browser scripts. The later dialog change passed 15 focused tests and a real GitHub sync/export/map/import/reload browser run. The offline copy passed eight focused checks, a web build/typecheck, and before/after browser close/reopen checks. Local HTTP verification covered 30 authentication, settings, simulated connector, backup/restore, API-key and MCP checks. Each fix has before/after regression evidence.

The default-concurrency suite twice exceeded the existing 60-second timeout for the 10,000-unit STL stress test. The unchanged test passed alone and in the complete two-worker suite. No assertions or timeouts were relaxed.

Tracks GRE-304, GRE-305, GRE-306, GRE-307, GRE-308 and GRE-309. GRE-286 was separately reproduced during the final Production walkthrough and is being fixed in a follow-up. CodeRabbit CLI was signed out, so no CodeRabbit review is claimed. No physical print, deployment or remote merge is claimed.


Note

Medium Risk
Touches credential persistence, filesystem cleanup with path guards, and Spoolman API routing where wrong behavior could leak tokens, delete wrong files, or post deductions to the wrong instance; changes are covered by new integration tests.

Overview
Fixes several issues found in local testing across settings, printer queue, Spoolman, sharing, sources, and PWA messaging.

GitHub PAT — PUT /settings/github-pat now requires a string token (400 otherwise), trims it, and persists empty string to clear the stored PAT. Responses still avoid leaking the secret; Settings UI shows configured status with a default mask.

Printer send queue / uploads — Failed queued uploads keep staged G-code under tenant exports so dispatch can retry; artifacts are removed after success, after cancel (with assertPrinterUploadArtifactPath so paths outside exports are not deleted), and still cleaned for direct upload jobs. Cancel during an active send remains 409.

Spoolman after verify — Filament deductions call the Spoolman connector encoded in each spool reference, skipping disabled, wrong-type, or missing integrations instead of always using the newest Spoolman connector.

Reference share import — After a successful import, the app reloads the Build list, selects the new profile, navigates to Plan, and closes the share dialog when import runs inside it; a failed list refresh keeps the new selection and shows a toast. Failed imports leave mapping and dialog state intact.

Zip source wizard — New sources can pick the ZIP on first Save; retries reuse the same source and archive without re-creating the source.

Offline / install copy — Service worker bumps to v4 with updated offline page and install banner text: connection is required for Checkoff and saved changes, not implied offline queuing.

Minor dependency bumps (@fastify/multipart, TanStack Query, three, typescript-eslint) and broad regression tests accompany the behavior changes.

Reviewed by Cursor Bugbot for commit e3d5bd6. Bugbot is set up for automated code reviews on this repo. Configure here.

@coderabbitai

coderabbitai Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Team

Run ID: 9fe5aa06-e615-43b7-95e3-be4731b86427

📥 Commits

Reviewing files that changed from the base of the PR and between 59fec59 and e3d5bd6.

⛔ Files ignored due to path filters (1)
  • web/package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (22)
  • web/apps/server/package.json
  • web/apps/server/src/routes/printer-send-queue.ts
  • web/apps/server/src/routes/settings-github-pat.test.ts
  • web/apps/server/src/routes/settings.ts
  • web/apps/server/src/services/printer-upload-job.ts
  • web/apps/server/src/services/printer-upload-retry.test.ts
  • web/apps/server/src/services/spoolman-deduct.test.ts
  • web/apps/server/src/services/spoolman-deduct.ts
  • web/apps/web/package.json
  • web/apps/web/public/offline.html
  • web/apps/web/public/sw.js
  • web/apps/web/src/components/pwa/PwaInstallBanner.tsx
  • web/apps/web/src/components/share/ReferenceShareImport.navigation.test.tsx
  • web/apps/web/src/components/share/ReferenceShareImport.test.tsx
  • web/apps/web/src/components/share/ReferenceShareImport.tsx
  • web/apps/web/src/components/share/ReferenceSharePanel.tsx
  • web/apps/web/src/components/share/ShareBuildExportDialog.tsx
  • web/apps/web/src/pages/BoardPage.test.tsx
  • web/apps/web/src/pages/SettingsPage.tsx
  • web/apps/web/src/pages/SourcesPage.source-save.test.tsx
  • web/apps/web/src/pages/SourcesPage.tsx
  • web/package.json
 _____________________________________
< I don't chase bugs; they surrender. >
 -------------------------------------
  \
   \   (\__/)
       (•ㅅ•)
       /   づ
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

@cursor

cursor Bot commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bugbot couldn't run - usage limit reached

Bugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit.

A user or team admin can review and increase usage limits in the Cursor dashboard.

(requestId: serverGenReqId_ce834aa5-9c7b-48fd-9ffb-1b3ac1caeab4)

@poitee

poitee commented Sep 28, 2026

Copy link
Copy Markdown
Owner Author

Independent pre-merge verification: PASS+NOTES for e3d5bd6c071ed769277aac5e93f4f8ad1458109d against cc907fcd3570b2510c08bf46d78b7294824de78c.

An independent Codex agent that did not author these changes reviewed the exact 23-file diff and ran 44 focused tests: 30 server and 14 web. The checks cover PAT validation/clearing, connector-specific Spoolman deductions, failed upload retention and cleanup, ZIP retry, imported Build selection/navigation and dialog dismissal. Exact source inspection verified corrected offline wording and cache v4. No merge blocker was found.

Limits: tests ran on integrated head 94e42d00, whose later GRE-286 changes leave these implementations and test files unchanged. Offline browser proof and the full 3,720-test quality run are earlier supporting evidence, not rerun by this reviewer. Printer transports and Spoolman endpoints were simulated or loopback. Cursor cloud verification was unavailable, and CodeRabbit was signed out/skipped; this is an independent Codex verdict, not human or CodeRabbit approval. No production deployment was verified.

@poitee
poitee changed the base branch from perf/print-partner-optimizations to main September 28, 2026 04:28
@poitee
poitee merged commit 707c2ef into main Sep 28, 2026
5 of 6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant