* fix(theme): tolerate work contexts persisted without a theme (#9139)
A tag/project entity can be persisted with no `theme` at all. Validation
at hydration is non-fatal, so such a snapshot loads anyway and every
consumer then dereferences `undefined`, crashing the theme pipeline on
every launch. Reproduced end-to-end: resolveBackground() throws on
backgroundImageDark/Light and _setColorTheme() on isAutoContrast.
Two layers:
- resolveContextTheme() extracted from the currentTheme$ map, defaulting
a missing theme to WORK_CONTEXT_DEFAULT_THEME. Single choke point for
both crashing consumers. This also fixes the tag-colour branch, which
spread an undefined theme into a partial `{ primary }` object.
- an auto-fix branch backfilling a missing tag/project theme, so data
already corrupted on disk is healed rather than merely tolerated.
Unrepaired, the same corruption also dead-ended legacy migration with
"Migration failed" and no way in.
The auto-fix branch matches on path + `value === undefined` and
deliberately NOT on `error.expected`: typia reports this as the
generated name `Readonly<__type>.oNN`, whose ordinal shifts with the
type graph, so an expected-based guard would silently stop firing.
Verified: both fixes sabotage-tested (3 failures each with the fix
reverted), full suite green in both TZ variants, and confirmed firing
against real typia output and real hydration in the browser.
* fix(theme): address review findings on the #9139 theme fix
Follow-up to d6eee18bc0, from a multi-agent review.
- Heal system entities with their OWN theme. The backfill discarded the
entity id and gave every entity the generic default, so TODAY -- the
entity from the report -- came back purple with background tint on
instead of cornflower/hue-400/tint-off, and INBOX lost its green. The
repair is written to disk, so that restyle was permanent. Looked up via
a Map, not an object literal, so a hostile `__proto__` id cannot resolve
to Object.prototype.
- Repair `theme: null`, not just a missing theme. The `setOne` 'replace'
branch applies a remote entity verbatim, so null is reachable and typia
reports it at the same path; gating on `undefined` left it dead-ending
the repair pipeline. resolveContextTheme already used `??`, so the two
layers now agree.
- Guard the two remaining unguarded derefs. nav-list-tree renders once
per project in the side nav and DEFAULT_PROJECT_ICON is not an emoji,
so the theme branch is the DEFAULT path -- a theme-less project still
crashed at launch, the very case the heal anticipates.
- Make both layers agree on the default: resolveContextTheme is now
type-aware, so a theme-less project no longer renders tag-purple and
then flips to project-teal once a repair runs.
- Scope the JSDoc's "single choke point" claim to currentTheme$, and
correct RECREATE_FALLBACK's doc, which still said TAG/PROJECT had no
heal branch. Added `theme` to their requiredKeys so the meta-reducer
warn names it.
- Replaced two vacuous tests: one asserted an input typia cannot produce
(every WorkContextThemeCfg field is optional, so the fixture was valid),
the other's assertions passed on `null`.
Verified: all four new behaviours sabotage-tested, full suite green in
both TZ variants, and confirmed end-to-end that a theme-less TODAY tag
migrates and persists #6495ED/hue-400/tint-off rather than the default.
* fix(theme): share one default-theme source between read and heal
Follow-up to ba29dc62ac, from a second multi-agent review.
The previous commit fixed two review findings that turned out to
interact: it made the on-disk heal id-aware (so TODAY keeps its own
theme) and the read side only type-aware. Each was right alone; together
they reintroduced the very read/write divergence the type-awareness was
meant to remove, relocated from projects onto system entities. For a
theme-less TODAY -- the active context at startup, and the entity in the
report -- the read side rendered purple/hue-500/tinted while a later
repair persisted cornflower/hue-400/untinted. Not a flicker: hydration
validates without repairing, so a local-only user saw the wrong theme
indefinitely, then it flipped the first time a sync repair ran.
- extract getDefaultWorkContextTheme() into a leaf util both sides call,
so the two cannot drift again. Net negative production lines.
- drop IN_PROGRESS_TAG from the lookup: its theme differs from
DEFAULT_TAG's only in backgroundImageDark ('' vs null), which
isBackgroundImageSet treats identically, so the row was provably inert.
URGENT/IMPORTANT stay -- board.component's createTags() makes them
user-reachable and their primaries do differ.
- drop 'theme' from RECREATE_FALLBACK requiredKeys: the recreate path
already spreads defaults, so it only bought warn text at the cost of a
four-clause doc paragraph.
Tests:
- replace the __proto__ test, which named __proto__ but used entity id
't1' and so never entered the guarded branch -- unfalsifiable, and it
survived sabotaging the Map into a plain object literal.
- buildCtx defaulted to id 'TODAY', quietly routing the generic-default
cases through a system entity.
- table-driven system-entity coverage that asserts each row is
DISTINGUISHABLE from the generic default, so an inert row fails rather
than lingering.
- pin the branch's position in the else-if chain via its fix label.
- nav-list fixture now omits `icon`, the fall-through its comment claims.
Also scoped two over-claiming comments to what they actually guarantee,
including a KNOWN RESIDUAL for lwwUpdateMetaReducer's recreate branch --
a third, id-blind writer left alone deliberately as sync-critical.
Verified: shared-helper fix sabotage-tested, full suite green both TZ
variants (13195/13181), and the real bundle confirmed end-to-end -- no
circular import, migration succeeds, TODAY heals to #6495ED/hue-400.
* fix(theme): restore the recreate warn, make the inert-row guard real
Follow-up to c62b2eb88f, from a targeted review of that commit.
- restore 'theme' to RECREATE_FALLBACK TAG/PROJECT requiredKeys. Removing
it was NOT behaviour-free as claimed: the warn is gated on
`partialKeys.length > 0`, so a payload carrying title+taskIds and no
theme now logged nothing at all -- the diagnostic vanished rather than
merely dropping a field name. That is exactly the #9139 corruption
shape, on lwwUpdateMetaReducer's recreate branch, the one writer still
bypassing getDefaultWorkContextTheme. With provenance unknown that is
the wrong signal to delete. Now pinned by a test, since the entry looks
removable and I removed it once already.
My verification was a level too shallow: I confirmed requiredKeys "only
feeds the warn" and stopped, without checking the warn is gated on the
list being non-empty.
- make the system-entity table test actually do what it claimed. It was a
hand-written duplicate of SYSTEM_ENTITY_THEMES, so it caught rows
REMOVED from the Map but never rows ADDED -- re-adding the inert
IN_PROGRESS_TAG row left the suite green. Now driven from the Map's own
entries, and comparing OBSERVABLE difference: the background-image
fields reach the UI only via isBackgroundImageSet, so '' and null are
the same thing. My first attempt at this compared raw fields and was
weaker still -- it let the inert row pass. Verified by sabotage: the
re-added row now fails.
- __proto__ test built via JSON.parse, the only construction that yields
a genuine own key and what a hostile payload actually arrives as. The
previous comment claimed the opposite of what its line did:
`obj['__proto__'] = x` invokes the inherited setter and creates no own
property.
- scope two more over-claiming comments: the shared fallback guarantees
agreement on the FALLBACK, not on the tag-color override layered above
it (read-side only, re-applied after any repair); and the label
assertion cannot detect what its comment described.
- getDefaultWorkContextTheme takes WorkContextType rather than a boolean.
Verified: every fix sabotage-tested, full suite green both TZ variants
(13200/13186), lint clean.
* test(theme): pin the currentTheme$ wiring and the system-theme roster
The #9139 fix could be reverted at its only production integration point
with the suite green: resolveContextTheme was tested exhaustively as a pure
function, but nothing asserted currentTheme$ actually calls it. Replacing
map(resolveContextTheme) with the pre-fix map((awc) => awc.theme) passed
32/32. Adds a MockStore test driving a themeless TODAY through the real
stream, which is what every crashing consumer reads.
Also pins the SYSTEM_ENTITY_THEMES roster. The existing cases are driven
from the Map itself so an added row is covered automatically, but that is
blind to removal - deleting rows deletes their tests, which vanish rather
than fail. URGENT and IMPORTANT were removable undetected across both
suites. Both halves are needed; neither catches what the other does.
Sabotage-verified: each new test fails under the mutation it targets.
* fix(theme): copy the theme fallback and pin the PROJECT recreate warn
resolveContextTheme handed out the module constant itself on the fallback
path (DEFAULT_TAG.theme, TODAY_TAG.theme, ...). Nothing freezes those, so a
consumer mutating what it was handed would write through into the shared
constant app-wide. The on-disk heal already spreads for exactly this reason;
only the read side was aliased. Spread there too and assert non-aliasing, so
the invariant is enforced rather than just documented. Free for the stream:
currentTheme$ dedups via isShallowEqual, which is key-by-key.
Also parameterizes the recreate warn test over PROJECT as well as TAG.
RECREATE_FALLBACK.PROJECT's 'theme' entry was dead - dropping it passed
133/133 - so a diagnostic the fix depends on could be removed with nothing
going red.
Sabotage-verified: removing the spread fails 6 tests; dropping either
requiredKeys entry now fails one.
* test(theme): drive the #9139 heal with REAL typia validation
Every existing case hand-builds its typia errors, so all of them would pass
even if real typia reported a themeless entity somewhere the fix's branch
never matches. #9045 shipped exactly that: a fully tested check that never
fired in production.
Runs the actual validator instead. Confirms real typia reports a missing
theme at $input.<root>.entities.<id>.theme with an undefined value (and null
identically), which is precisely what the branch keys on, and round-trips
the repair back through validation to prove the written value is accepted.
Also pins the #9156 gap as characterization: every member of
WorkContextThemeCfg is optional, so typia accepts theme={} and even a theme
missing primary. No error is produced, so neither the heal nor the read-side
?? can ever see them - an empty theme is stickier than a missing one. Those
expectations should flip when #9156 is fixed.
Sabotage-verified: changing the branch gate to keys.length === 5, i.e. a
branch that never fires on real data, fails 9 tests.
* test(theme): add an E2E proving the app boots with a themeless TODAY tag
The unit tests pin the fallback, the heal and the currentTheme$ wiring, but
none of them can show the app actually STARTS with this data on disk, which
is the only claim #9139 makes. Seeds a legacy store whose TODAY tag has no
theme, then asserts migration completes, the shell renders, no theme-related
uncaught error fires, and the tag is HEALED on disk rather than merely
tolerated at read time.
Mutates the existing fixture in-code instead of committing a near-duplicate
100KB JSON, so the one deleted key stays visible in the diff.
Sabotage-verified, and the result bounded the test's scope: disabling the
heal fails it (TODAY does not survive migration at all), while removing the
read-side fallback leaves it GREEN - with the heal in place the data is
repaired before the read side is reached. So this covers the heal only; the
read side stays covered by the currentTheme$ unit test. Documented in the
spec header so nobody assumes broader coverage than it has.
* test(theme): cover the read-side fallback with a hydration E2E
The migration E2E only exercises the on-disk heal: with the heal in place the
data is repaired before the read side is ever reached, so removing the
fallback left it green. But #9139 was reported on an ordinary launch, not a
migration - hydration validates without repairing, so resolveContextTheme is
the only thing between the user and the crash on that path.
Adds a second test that corrupts an ALREADY-migrated store and relaunches.
Sabotage matrix now covers both defenses independently: disabling the heal
fails test 1, removing the read-side fallback fails test 2, each solo.
Two things this cost that are worth knowing:
- state_cache uses an in-line keyPath, so put(row, 'current') raises DataError
and ABORTS the transaction rather than erroring - it surfaces as a 30s hang
and a misleading 'execution context was destroyed'. Every IndexedDB request
here has onblocked/onerror/onabort and a JS-side timeout so a failure names
itself instead of looking like every other failure.
- Asserting 'no page errors' right after the side nav appears FALSE-PASSES:
the shell renders before the theme pipeline throws. Caught because the
sabotaged run failed alongside its sibling but passed solo. Both tests now
wait for something real first and assert errors last, without a bare
waitForTimeout (forbidden by e2e/CLAUDE.md).
Note TODAY membership is virtual (dueDay), so a fixture's TODAY.taskIds alone
renders an empty list - test 1 settles on an IndexedDB read instead.