super-productivity/e2e/tests/migration
Johannes Millan 88b5055504
fix(theme): tolerate work contexts persisted without a theme (#9139) (#9145)
* fix(theme): tolerate work contexts persisted without a theme (#9139)

A tag/project entity can be persisted with no `theme` at all. Validation
at hydration is non-fatal, so such a snapshot loads anyway and every
consumer then dereferences `undefined`, crashing the theme pipeline on
every launch. Reproduced end-to-end: resolveBackground() throws on
backgroundImageDark/Light and _setColorTheme() on isAutoContrast.

Two layers:

- resolveContextTheme() extracted from the currentTheme$ map, defaulting
  a missing theme to WORK_CONTEXT_DEFAULT_THEME. Single choke point for
  both crashing consumers. This also fixes the tag-colour branch, which
  spread an undefined theme into a partial `{ primary }` object.

- an auto-fix branch backfilling a missing tag/project theme, so data
  already corrupted on disk is healed rather than merely tolerated.
  Unrepaired, the same corruption also dead-ended legacy migration with
  "Migration failed" and no way in.

The auto-fix branch matches on path + `value === undefined` and
deliberately NOT on `error.expected`: typia reports this as the
generated name `Readonly<__type>.oNN`, whose ordinal shifts with the
type graph, so an expected-based guard would silently stop firing.

Verified: both fixes sabotage-tested (3 failures each with the fix
reverted), full suite green in both TZ variants, and confirmed firing
against real typia output and real hydration in the browser.

* fix(theme): address review findings on the #9139 theme fix

Follow-up to d6eee18bc0, from a multi-agent review.

- Heal system entities with their OWN theme. The backfill discarded the
  entity id and gave every entity the generic default, so TODAY -- the
  entity from the report -- came back purple with background tint on
  instead of cornflower/hue-400/tint-off, and INBOX lost its green. The
  repair is written to disk, so that restyle was permanent. Looked up via
  a Map, not an object literal, so a hostile `__proto__` id cannot resolve
  to Object.prototype.

- Repair `theme: null`, not just a missing theme. The `setOne` 'replace'
  branch applies a remote entity verbatim, so null is reachable and typia
  reports it at the same path; gating on `undefined` left it dead-ending
  the repair pipeline. resolveContextTheme already used `??`, so the two
  layers now agree.

- Guard the two remaining unguarded derefs. nav-list-tree renders once
  per project in the side nav and DEFAULT_PROJECT_ICON is not an emoji,
  so the theme branch is the DEFAULT path -- a theme-less project still
  crashed at launch, the very case the heal anticipates.

- Make both layers agree on the default: resolveContextTheme is now
  type-aware, so a theme-less project no longer renders tag-purple and
  then flips to project-teal once a repair runs.

- Scope the JSDoc's "single choke point" claim to currentTheme$, and
  correct RECREATE_FALLBACK's doc, which still said TAG/PROJECT had no
  heal branch. Added `theme` to their requiredKeys so the meta-reducer
  warn names it.

- Replaced two vacuous tests: one asserted an input typia cannot produce
  (every WorkContextThemeCfg field is optional, so the fixture was valid),
  the other's assertions passed on `null`.

Verified: all four new behaviours sabotage-tested, full suite green in
both TZ variants, and confirmed end-to-end that a theme-less TODAY tag
migrates and persists #6495ED/hue-400/tint-off rather than the default.

* fix(theme): share one default-theme source between read and heal

Follow-up to ba29dc62ac, from a second multi-agent review.

The previous commit fixed two review findings that turned out to
interact: it made the on-disk heal id-aware (so TODAY keeps its own
theme) and the read side only type-aware. Each was right alone; together
they reintroduced the very read/write divergence the type-awareness was
meant to remove, relocated from projects onto system entities. For a
theme-less TODAY -- the active context at startup, and the entity in the
report -- the read side rendered purple/hue-500/tinted while a later
repair persisted cornflower/hue-400/untinted. Not a flicker: hydration
validates without repairing, so a local-only user saw the wrong theme
indefinitely, then it flipped the first time a sync repair ran.

- extract getDefaultWorkContextTheme() into a leaf util both sides call,
  so the two cannot drift again. Net negative production lines.
- drop IN_PROGRESS_TAG from the lookup: its theme differs from
  DEFAULT_TAG's only in backgroundImageDark ('' vs null), which
  isBackgroundImageSet treats identically, so the row was provably inert.
  URGENT/IMPORTANT stay -- board.component's createTags() makes them
  user-reachable and their primaries do differ.
- drop 'theme' from RECREATE_FALLBACK requiredKeys: the recreate path
  already spreads defaults, so it only bought warn text at the cost of a
  four-clause doc paragraph.

Tests:
- replace the __proto__ test, which named __proto__ but used entity id
  't1' and so never entered the guarded branch -- unfalsifiable, and it
  survived sabotaging the Map into a plain object literal.
- buildCtx defaulted to id 'TODAY', quietly routing the generic-default
  cases through a system entity.
- table-driven system-entity coverage that asserts each row is
  DISTINGUISHABLE from the generic default, so an inert row fails rather
  than lingering.
- pin the branch's position in the else-if chain via its fix label.
- nav-list fixture now omits `icon`, the fall-through its comment claims.

Also scoped two over-claiming comments to what they actually guarantee,
including a KNOWN RESIDUAL for lwwUpdateMetaReducer's recreate branch --
a third, id-blind writer left alone deliberately as sync-critical.

Verified: shared-helper fix sabotage-tested, full suite green both TZ
variants (13195/13181), and the real bundle confirmed end-to-end -- no
circular import, migration succeeds, TODAY heals to #6495ED/hue-400.

* fix(theme): restore the recreate warn, make the inert-row guard real

Follow-up to c62b2eb88f, from a targeted review of that commit.

- restore 'theme' to RECREATE_FALLBACK TAG/PROJECT requiredKeys. Removing
  it was NOT behaviour-free as claimed: the warn is gated on
  `partialKeys.length > 0`, so a payload carrying title+taskIds and no
  theme now logged nothing at all -- the diagnostic vanished rather than
  merely dropping a field name. That is exactly the #9139 corruption
  shape, on lwwUpdateMetaReducer's recreate branch, the one writer still
  bypassing getDefaultWorkContextTheme. With provenance unknown that is
  the wrong signal to delete. Now pinned by a test, since the entry looks
  removable and I removed it once already.

  My verification was a level too shallow: I confirmed requiredKeys "only
  feeds the warn" and stopped, without checking the warn is gated on the
  list being non-empty.

- make the system-entity table test actually do what it claimed. It was a
  hand-written duplicate of SYSTEM_ENTITY_THEMES, so it caught rows
  REMOVED from the Map but never rows ADDED -- re-adding the inert
  IN_PROGRESS_TAG row left the suite green. Now driven from the Map's own
  entries, and comparing OBSERVABLE difference: the background-image
  fields reach the UI only via isBackgroundImageSet, so '' and null are
  the same thing. My first attempt at this compared raw fields and was
  weaker still -- it let the inert row pass. Verified by sabotage: the
  re-added row now fails.

- __proto__ test built via JSON.parse, the only construction that yields
  a genuine own key and what a hostile payload actually arrives as. The
  previous comment claimed the opposite of what its line did:
  `obj['__proto__'] = x` invokes the inherited setter and creates no own
  property.

- scope two more over-claiming comments: the shared fallback guarantees
  agreement on the FALLBACK, not on the tag-color override layered above
  it (read-side only, re-applied after any repair); and the label
  assertion cannot detect what its comment described.

- getDefaultWorkContextTheme takes WorkContextType rather than a boolean.

Verified: every fix sabotage-tested, full suite green both TZ variants
(13200/13186), lint clean.

* test(theme): pin the currentTheme$ wiring and the system-theme roster

The #9139 fix could be reverted at its only production integration point
with the suite green: resolveContextTheme was tested exhaustively as a pure
function, but nothing asserted currentTheme$ actually calls it. Replacing
map(resolveContextTheme) with the pre-fix map((awc) => awc.theme) passed
32/32. Adds a MockStore test driving a themeless TODAY through the real
stream, which is what every crashing consumer reads.

Also pins the SYSTEM_ENTITY_THEMES roster. The existing cases are driven
from the Map itself so an added row is covered automatically, but that is
blind to removal - deleting rows deletes their tests, which vanish rather
than fail. URGENT and IMPORTANT were removable undetected across both
suites. Both halves are needed; neither catches what the other does.

Sabotage-verified: each new test fails under the mutation it targets.

* fix(theme): copy the theme fallback and pin the PROJECT recreate warn

resolveContextTheme handed out the module constant itself on the fallback
path (DEFAULT_TAG.theme, TODAY_TAG.theme, ...). Nothing freezes those, so a
consumer mutating what it was handed would write through into the shared
constant app-wide. The on-disk heal already spreads for exactly this reason;
only the read side was aliased. Spread there too and assert non-aliasing, so
the invariant is enforced rather than just documented. Free for the stream:
currentTheme$ dedups via isShallowEqual, which is key-by-key.

Also parameterizes the recreate warn test over PROJECT as well as TAG.
RECREATE_FALLBACK.PROJECT's 'theme' entry was dead - dropping it passed
133/133 - so a diagnostic the fix depends on could be removed with nothing
going red.

Sabotage-verified: removing the spread fails 6 tests; dropping either
requiredKeys entry now fails one.

* test(theme): drive the #9139 heal with REAL typia validation

Every existing case hand-builds its typia errors, so all of them would pass
even if real typia reported a themeless entity somewhere the fix's branch
never matches. #9045 shipped exactly that: a fully tested check that never
fired in production.

Runs the actual validator instead. Confirms real typia reports a missing
theme at $input.<root>.entities.<id>.theme with an undefined value (and null
identically), which is precisely what the branch keys on, and round-trips
the repair back through validation to prove the written value is accepted.

Also pins the #9156 gap as characterization: every member of
WorkContextThemeCfg is optional, so typia accepts theme={} and even a theme
missing primary. No error is produced, so neither the heal nor the read-side
?? can ever see them - an empty theme is stickier than a missing one. Those
expectations should flip when #9156 is fixed.

Sabotage-verified: changing the branch gate to keys.length === 5, i.e. a
branch that never fires on real data, fails 9 tests.

* test(theme): add an E2E proving the app boots with a themeless TODAY tag

The unit tests pin the fallback, the heal and the currentTheme$ wiring, but
none of them can show the app actually STARTS with this data on disk, which
is the only claim #9139 makes. Seeds a legacy store whose TODAY tag has no
theme, then asserts migration completes, the shell renders, no theme-related
uncaught error fires, and the tag is HEALED on disk rather than merely
tolerated at read time.

Mutates the existing fixture in-code instead of committing a near-duplicate
100KB JSON, so the one deleted key stays visible in the diff.

Sabotage-verified, and the result bounded the test's scope: disabling the
heal fails it (TODAY does not survive migration at all), while removing the
read-side fallback leaves it GREEN - with the heal in place the data is
repaired before the read side is reached. So this covers the heal only; the
read side stays covered by the currentTheme$ unit test. Documented in the
spec header so nobody assumes broader coverage than it has.

* test(theme): cover the read-side fallback with a hydration E2E

The migration E2E only exercises the on-disk heal: with the heal in place the
data is repaired before the read side is ever reached, so removing the
fallback left it green. But #9139 was reported on an ordinary launch, not a
migration - hydration validates without repairing, so resolveContextTheme is
the only thing between the user and the crash on that path.

Adds a second test that corrupts an ALREADY-migrated store and relaunches.
Sabotage matrix now covers both defenses independently: disabling the heal
fails test 1, removing the read-side fallback fails test 2, each solo.

Two things this cost that are worth knowing:
- state_cache uses an in-line keyPath, so put(row, 'current') raises DataError
  and ABORTS the transaction rather than erroring - it surfaces as a 30s hang
  and a misleading 'execution context was destroyed'. Every IndexedDB request
  here has onblocked/onerror/onabort and a JS-side timeout so a failure names
  itself instead of looking like every other failure.
- Asserting 'no page errors' right after the side nav appears FALSE-PASSES:
  the shell renders before the theme pipeline throws. Caught because the
  sabotaged run failed alongside its sibling but passed solo. Both tests now
  wait for something real first and assert errors last, without a bare
  waitForTimeout (forbidden by e2e/CLAUDE.md).

Note TODAY membership is virtual (dueDay), so a fixture's TODAY.taskIds alone
renders an empty list - test 1 settles on an IndexedDB read instead.
2026-07-18 21:37:56 +02:00
..
hydration-fallback-recovery.spec.ts fix(sync): recover from migration-path hydration failures via op-log replay (#9153) 2026-07-18 18:22:08 +02:00
legacy-data-migration.spec.ts test(migration): navigate to project tasks route to de-flake legacy migration e2e 2026-06-15 15:48:34 +02:00
legacy-themeless-tag-9139.spec.ts fix(theme): tolerate work contexts persisted without a theme (#9139) (#9145) 2026-07-18 21:37:56 +02:00
pre-migration-dialog.spec.ts feat(tasks): allow dragging tasks into subtask lists (#7962) 2026-06-02 19:43:41 +02:00