show sync button for admin
Build and Push Containers / build-and-push-app (push) Successful in 1m38s
Build and Push Containers / build-and-push-db (push) Successful in 11s

This commit is contained in:
2026-08-28 23:24:23 -04:00
parent 3a404eb161
commit 6bf7f456d4
17 changed files with 368 additions and 284 deletions
+142 -123
View File
@@ -2,14 +2,15 @@
The browser behavior is E2E-covered (tests/e2e/test_sync_button.py,
task 03); here we pin the source-level wiring — the anonymous-safe
ship-hidden button markup, the header.js admin reveal on the SAME
cached whoami (no extra fetch), the header.js sync state machine
(moved here from sources.js in phase 34 task 02: 2 s poll, 202 start
ship-hidden button markup, the Sources-page admin reveal on the SAME
cached whoami (no extra fetch), the sync state machine that now lives
in sources.js (owner rework 2026-08-28: the button is Sources-page
only, so the page owns the machine it drives — 2 s poll, 202 start
/ 409 adoption / 403 hide, terminal labels, the "bor:sync-status"
event with the status object as detail, the single-poll-loop guard, no
client-side hard timeout), the Sources page's event-driven
#sync-result line + #sync-error-banner, and the §7.4 never-stale CSS
(spin + reduced-motion opt-out,
client-side hard timeout), the page's #sync-result line +
#sync-error-banner, the lazily created error modal (phase 41), and the
§7.4 never-stale CSS (spin + reduced-motion opt-out,
disabled state, 44px floor, contrast pair) — so a silent regression is
caught without a browser.
"""
@@ -44,9 +45,9 @@ def _body(js: str, fn_name: str) -> str:
def test_sync_button_ships_hidden_and_labeled() -> None:
"""#sync-btn SHIPS with the hidden attribute (anonymous-safe —
header.js reveals it for the admin), is a real <button type=
"button">, and carries aria-label="Sync sources" so the accessible
name stays stable across the label states."""
sources.js reveals it for the admin at page boot), is a real
<button type="button">, and carries aria-label="Sync sources" so
the accessible name stays stable across the label states."""
tag = re.search(r"<button[^>]*id=\"sync-btn\"[^>]*>", _text(SOURCES_HTML))
assert tag, "sources.html must carry the #sync-btn button"
attrs = tag.group(0)
@@ -58,13 +59,17 @@ def test_sync_button_ships_hidden_and_labeled() -> None:
def test_sync_button_has_icon_and_label_span() -> None:
"""The button body is a refresh-cycle svg (aria-hidden — decorative,
the spin is the visible running state) + the #sync-label span with
the spin is the visible running state) + the .sync-label span with
the idle text, so the label can be swapped by sources.js."""
text = _text(SOURCES_HTML)
btn = text[text.find('id="sync-btn"') : text.find("</button>", text.find('id="sync-btn"'))]
assert re.search(r'<svg[^>]*class="sync-icon"[^>]*aria-hidden="true"', btn)
assert 'id="sync-label"' in btn
assert re.search(r'<span[^>]*id="sync-label"[^>]*>Sync sources</span>', btn)
# class for the module query + id for the E2E label assertions
label = re.search(
r'<span\b[^>]*id="sync-label"[^>]*>\s*Sync sources\s*</span>', btn
)
assert label, "the #sync-label span carrying the idle text is missing"
assert 'class="sync-label"' in label.group(0)
def test_sync_result_is_the_aria_live_announcer() -> None:
@@ -97,13 +102,13 @@ def test_sync_error_banner_is_a_hidden_alert() -> None:
def test_page_sub_copy_mentions_the_button() -> None:
"""The page-sub copy still points at the import CLI and now names
the header button as the one-click alternative (task 02 step 1)."""
"""The page-sub copy names the button as the one-click way to clone
the repos and re-import (the import CLI docs live elsewhere)."""
sub = re.search(r'<p class="page-sub">(.*?)</p>', _text(SOURCES_HTML), re.DOTALL)
assert sub, "sources.html must keep the .page-sub copy"
assert "Re-run the import" in sub.group(1)
assert "Sync sources" in sub.group(1)
assert "header" in sub.group(1)
copy = re.sub(r"\s+", " ", sub.group(1)) # the markup wraps lines
assert "Press <strong>Sync sources</strong>" in copy
assert "clone the repos and re-import" in copy
def test_sources_page_stays_cdn_free() -> None:
@@ -115,61 +120,61 @@ def test_sources_page_stays_cdn_free() -> None:
assert 'href="https://' not in text
# ---------- header.js: the admin reveal ----------
# ---------- sources.js: the admin reveal (page boot) ----------
def test_header_reveals_sync_btn_on_the_admin_branch() -> None:
"""initSharedHeader reveals #sync-btn in the SAME admin branch as
#nav-sources (hidden = !admin) — one cached whoami, no extra
whoami call; anonymous users never leave the hidden default. The
ref is the module-level one — the state machine shares it."""
js = _text(HEADER_JS)
assert 'querySelector("#sync-btn")' in js, "module-level #sync-btn ref"
fn = js.find("function initSharedHeader")
assert fn != -1
body = js[fn : js.find("\n}", fn)]
assert "syncBtn.hidden = !admin" in body, "#sync-btn must join the admin reveal"
def test_sources_js_reveals_sync_btn_on_the_admin_branch() -> None:
"""The page boot reveals #sync-btn for the admin on the SAME cached
whoami initSharedHeader() used (no extra fetch — header.js keeps
the single /api/whoami call site); anonymous users never leave the
ship-hidden default."""
js = _text(SOURCES_JS)
boot = js[js.rfind("(async () => {"):]
assert "const admin = await initSharedHeader()" in boot
assert "syncBtn.hidden = !admin" in boot, "#sync-btn must join the admin reveal"
# The reveal must not introduce a second whoami call site.
assert js.count('fetch("/api/whoami")') == 1
header = _text(HEADER_JS)
assert header.count('fetch("/api/whoami")') == 1
assert 'fetch("/api/whoami")' not in js
# ---------- header.js: the sync state machine (moved here from
# ---------- sources.js in phase 34 task 02) ----------
# ---------- sources.js: the sync state machine (moved here from
# ---------- header.js in the owner rework 2026-08-28) ----------
def test_header_js_owns_the_sync_button_elements() -> None:
"""The button refs are module-level and null-safe: #sync-btn,
#sync-label, the .sync-icon inside the button — a page without the
markup is a complete no-op, exactly like the rest of the module."""
js = _text(HEADER_JS)
def test_sources_js_owns_the_sync_button_elements() -> None:
"""The button refs are module-level and null-safe: #sync-btn, the
.sync-label inside the button, the .sync-icon inside the button — a
page without the markup is a complete no-op."""
js = _text(SOURCES_JS)
assert 'querySelector("#sync-btn")' in js
assert 'querySelector("#sync-label")' in js
assert 'syncBtn.querySelector(".sync-label")' in js
assert 'syncBtn.querySelector(".sync-icon")' in js
def test_header_js_calls_the_sync_api() -> None:
def test_sources_js_calls_the_sync_api() -> None:
"""The click posts to POST /api/sync and the poll loop GETs
/api/sync/status — both through the same-origin API (A10)."""
js = _text(HEADER_JS)
js = _text(SOURCES_JS)
assert 'fetch("/api/sync", { method: "POST" })' in js
assert 'fetch("/api/sync/status")' in js
def test_header_js_polls_every_2000ms() -> None:
def test_sources_js_polls_every_2000ms() -> None:
"""The feedback loop is a 2000 ms poll of the status endpoint,
re-scheduled one tick at a time (setTimeout, not setInterval — an
in-flight fetch can never overlap the next tick)."""
js = _text(HEADER_JS)
js = _text(SOURCES_JS)
assert "SYNC_POLL_MS = 2000" in js
assert "setTimeout(tick, SYNC_POLL_MS)" in js
assert "setInterval" not in js
def test_header_js_adopts_409_and_starts_on_202() -> None:
def test_sources_js_adopts_409_and_starts_on_202() -> None:
"""202 (started) and 409 (a run started elsewhere — e.g. a second
tab) both enter the running state and start polling: the UI never
starts a second run, it adopts the in-flight one."""
js = _text(HEADER_JS)
js = _text(SOURCES_JS)
assert "r.status === 202 || r.status === 409" in js
idx = js.find("r.status === 202 || r.status === 409")
branch = js[idx : idx + 400]
@@ -177,11 +182,11 @@ def test_header_js_adopts_409_and_starts_on_202() -> None:
assert "startSyncPolling()" in branch
def test_header_js_hides_the_button_on_403() -> None:
def test_sources_js_hides_the_button_on_403() -> None:
"""A 403 anywhere (POST, the status poll, the load re-attach) is
treated as not-admin: the button hides — defense in depth behind
the whoami reveal (the primary gate)."""
js = _text(HEADER_JS)
js = _text(SOURCES_JS)
assert len(re.findall(r"r\.status === 403", js)) >= 3, (
"POST, the status poll, and the load re-attach must all handle 403"
)
@@ -190,13 +195,13 @@ def test_header_js_hides_the_button_on_403() -> None:
)
def test_header_js_running_state_is_never_stale() -> None:
def test_sources_js_running_state_is_never_stale() -> None:
"""Entering the running state disables the button, sets aria-busy,
spins the icon, and swaps the label to 'Syncing…' (the §7.4
feedback while the poll waits) — and a fresh run starts clean: the
previous failure's title / aria-label / .is-error come off NOW,
not when the run settles."""
js = _text(HEADER_JS)
js = _text(SOURCES_JS)
body = _body(js, "enterSyncRunningState")
assert "syncBtn.disabled = true" in body
assert 'syncBtn.setAttribute("aria-busy", "true")' in body
@@ -207,15 +212,14 @@ def test_header_js_running_state_is_never_stale() -> None:
assert '"Syncing…"' in body
def test_header_js_terminal_states() -> None:
def test_sources_js_terminal_states() -> None:
"""Terminal rendering: success → enabled + 'Synced HH:MM' (local
time of finished_at); failed → enabled + retry-ready 'Sync sources'
label + the sanitized error in the button's title + aria-label +
the .is-error class (non-Sources pages: that is where the failure
is visible). The counts formatting (fmtSyncResult) lives here and
is EXPORTED for the Sources page ('added' always announced, zero
terms omitted — a no-op re-sync reads '0 added · 1 unchanged')."""
js = _text(HEADER_JS)
the .is-error class. The counts formatting (fmtSyncResult) lives
here ('added' always announced, zero terms omitted — a no-op
re-sync reads '0 added · 1 unchanged')."""
js = _text(SOURCES_JS)
success = _body(js, "applySyncSuccess")
assert '"Synced"' in success and "fmtSyncTime(status.finished_at)" in success
@@ -236,24 +240,24 @@ def test_header_js_terminal_states() -> None:
assert "getHours()" in time and "getMinutes()" in time, "local HH:MM of finished_at"
def test_header_js_failed_error_is_sanitized() -> None:
def test_sources_js_failed_error_is_sanitized() -> None:
"""The button's title/aria-label error is sanitized for the
attributes: the server already masks credentials (sync.py
_sanitize_error); the module collapses whitespace to a single line
_sanitize_error); the page collapses whitespace to a single line
and caps the length, and a missing error still names a failure."""
js = _text(HEADER_JS)
js = _text(SOURCES_JS)
body = _body(js, "sanitizeSyncError")
assert "replace(/\\s+/g, \" \")" in body, "single line for the attributes"
assert "200" in body, "long errors (chatty git stderr) are capped"
assert '"The sync failed."' in body
def test_header_js_settles_the_button_on_terminal() -> None:
def test_sources_js_settles_the_button_on_terminal() -> None:
"""settleSyncButton re-enables the control, drops aria-busy, the
title, and the failed affordances, and un-spins the icon — the
button can never sit disabled after a run reaches a terminal state
(failed included: retry-ready)."""
js = _text(HEADER_JS)
js = _text(SOURCES_JS)
body = _body(js, "settleSyncButton")
assert "syncBtn.disabled = false" in body
assert 'syncBtn.removeAttribute("aria-busy")' in body
@@ -262,11 +266,11 @@ def test_header_js_settles_the_button_on_terminal() -> None:
assert "syncIcon.classList.remove(\"is-spinning\")" in body
def test_header_js_never_starts_a_second_poll_loop() -> None:
def test_sources_js_never_starts_a_second_poll_loop() -> None:
"""startSyncPolling is guarded by the module-level timer: a 409
adoption, a reload re-attach, or a stray call can never run two
poll loops at once (phase completion criterion)."""
js = _text(HEADER_JS)
js = _text(SOURCES_JS)
fn = js.find("function startSyncPolling")
head = js[fn : js.find("const tick", fn)]
assert re.search(r"if\s*\(\s*syncPollTimer\s*!==\s*null\s*\)\s*return", head), (
@@ -275,27 +279,27 @@ def test_header_js_never_starts_a_second_poll_loop() -> None:
assert "clearTimeout(syncPollTimer)" in _body(js, "stopSyncPolling")
def test_header_js_has_no_client_side_hard_timeout() -> None:
def test_sources_js_has_no_client_side_hard_timeout() -> None:
"""Phase locked decision: a sync can legitimately run for minutes
(and outlive the page), so there is NO client-side hard timeout —
the 2 s poll is the feedback loop and the server state is
authoritative (the 120 s LLM-turn guard must not leak into the
sync path)."""
js = _text(HEADER_JS)
js = _text(SOURCES_JS)
assert "TURN_TIMEOUT" not in js
sync_start = js.find("sync sources (phase 32")
sync_start = js.find("Sync sources button (Sources page only)")
assert sync_start != -1, "the sync section marker comment"
assert "120" not in js[sync_start:]
def test_header_js_reattaches_on_load_admin_only() -> None:
"""initSyncButton (run at module import, button pages only) awaits
the SAME cached whoami — ADMIN ONLY (non-admins never poll, the
status endpoint is admin-only): a running run re-enters the
def test_sources_js_reattaches_on_load_admin_only() -> None:
"""initSyncButton (run at page boot, after the click binding)
awaits the SAME cached whoami — ADMIN ONLY (non-admins never poll,
the status endpoint is admin-only): a running run re-enters the
running state (reload mid-sync), a terminal run renders its last
result, idle settles retry-ready; the click binding wires
startSync to the button."""
js = _text(HEADER_JS)
js = _text(SOURCES_JS)
fn = js.find("function initSyncButton")
assert fn != -1
body = js[fn : js.find("\n}\n", fn)]
@@ -304,18 +308,18 @@ def test_header_js_reattaches_on_load_admin_only() -> None:
assert 'status.state === "running"' in body
assert 'status.state === "success"' in body
assert 'status.state === "failed"' in body
assert "syncBtn.addEventListener(\"click\", startSync)" in js
tail = js[js.rfind("if (syncBtn)") :]
assert "initSyncButton()" in tail, "boot re-attach runs at module import"
assert (
'syncBtn.addEventListener("click", startSync);\n initSyncButton();'
in js
), "the click binding and the boot re-attach ship together, guarded on syncBtn"
def test_header_js_emits_bor_sync_status_on_state_changes() -> None:
def test_sources_js_emits_bor_sync_status_on_state_changes() -> None:
"""Every state change dispatches window 'bor:sync-status' with the
status object as detail — the channel the Sources page's
banner/result line subscribe to. The click path emits the
synthetic running frame IMMEDIATELY (no 2 s poll lag — the exact
old enterRunningState clear behavior, now event-driven)."""
js = _text(HEADER_JS)
status object as detail — the channel other page scripts (or
future ones) can subscribe to. The click path emits the synthetic
running frame IMMEDIATELY (no 2 s poll lag)."""
js = _text(SOURCES_JS)
assert (
'window.dispatchEvent(new CustomEvent("bor:sync-status", { detail: status }))'
in js
@@ -327,23 +331,23 @@ def test_header_js_emits_bor_sync_status_on_state_changes() -> None:
assert "emitSyncStatus(status)" in _body(js, "initSyncButton")
# ---------- header.js: the sync failure modal (phase 41, TODO.md L4) ----------
# ---------- sources.js: the sync failure modal (phase 41, TODO.md L4) ----------
def test_header_js_owns_a_lazily_created_sync_modal() -> None:
"""The modal is module-owned and created lazily ONCE (module-level
`let syncModal = null`): a .sync-modal-backdrop holding a .sync-modal
panel with role="alertdialog" + aria-modal + labelled/described ids
+ the close button, appended to document.body — no page-markup
changes, so every page carrying #sync-btn gets it. The module
docstring's sync bullet records the modal (phase 41)."""
js = _text(HEADER_JS)
def test_sources_js_owns_a_lazily_created_sync_modal() -> None:
"""The modal is page-owned and created lazily ONCE (module-level
`let syncModal = null`): a .sync-modal-backdrop holding a
.sync-modal panel with role="alertdialog" + aria-modal +
labelled/described ids + the close button, appended to
document.body — no page-markup changes needed (the section marker
records that the former header.js modal was recreated here)."""
js = _text(SOURCES_JS)
assert "let syncModal = null" in js, "module-level once-only modal ref"
assert 'role="alertdialog"' in js
assert 'aria-modal="true"' in js
assert 'aria-labelledby="sync-modal-title"' in js
assert 'aria-describedby="sync-modal-error"' in js
assert "module-owned error modal" in js, "the docstring sync bullet"
assert "sync failure modal" in js, "the modal section marker"
create = _body(js, "createSyncModal")
assert "sync-modal-backdrop" in create
assert 'document.body.appendChild(backdrop)' in create
@@ -358,7 +362,7 @@ def test_sync_modal_error_is_rendered_via_text_content() -> None:
innerHTML with user data in the open path), and it is set BEFORE
the already-open check, so a second failure while open updates the
text IN PLACE (no stacking, no focus jump)."""
js = _text(HEADER_JS)
js = _text(SOURCES_JS)
body = _body(js, "showSyncModal")
assert 'querySelector("#sync-modal-error").textContent' in body
assert "innerHTML" not in body, "the open path never touches innerHTML"
@@ -376,7 +380,7 @@ def test_sync_modal_focus_goes_in_and_out_to_sync_btn() -> None:
the close must still land on the control that started the run);
on close: focus returns to the remembered element (guarded by
document.contains — a detached target is a no-op)."""
js = _text(HEADER_JS)
js = _text(SOURCES_JS)
open_body = _body(js, "showSyncModal")
assert "const active = document.activeElement" in open_body
assert "active !== document.body" in open_body, (
@@ -396,7 +400,7 @@ def test_sync_modal_closes_via_button_esc_and_backdrop() -> None:
the modal is open), and a click on the backdrop element itself —
the event.target check keeps clicks bubbling from the panel from
closing it."""
js = _text(HEADER_JS)
js = _text(SOURCES_JS)
create = _body(js, "createSyncModal")
assert 'addEventListener("click", closeSyncModal)' in create
assert 'e.key === "Escape"' in create
@@ -405,13 +409,12 @@ def test_sync_modal_closes_via_button_esc_and_backdrop() -> None:
assert "e.target === backdrop" in create
def test_apply_sync_failure_opens_the_modal_after_the_event() -> None:
def test_sources_js_apply_sync_failure_opens_the_modal_after_the_event() -> None:
"""applySyncFailure opens the modal with the SANITIZED error, and
the call comes AFTER the existing button title/aria/.is-error
lines + emitSyncStatus (the bor:sync-status event the Sources
banner renders off — those lines stay byte-identical; the modal is
additive)."""
js = _text(HEADER_JS)
lines + emitSyncStatus (the bor:sync-status event — those lines
stay byte-identical; the modal is additive)."""
js = _text(SOURCES_JS)
body = _body(js, "applySyncFailure")
call = body.find("showSyncModal(")
emit = body.find("emitSyncStatus(status)")
@@ -425,59 +428,75 @@ def test_apply_sync_failure_opens_the_modal_after_the_event() -> None:
assert "emitSyncStatus(status)" in body
# ---------- sources.js: the event-driven result line + banner ----------
# ---------- sources.js: the page-specific result line + banner ----------
def test_sources_js_renders_off_the_sync_status_event() -> None:
"""The Sources page keeps ONLY its page-specific rendering:
def test_sources_js_renders_result_line_and_banner_directly() -> None:
"""sources.js owns the page-specific rendering on the Sources page:
#sync-result (aria-live) + #sync-error-banner (role=alert), driven
by the module's 'bor:sync-status' event (detail = the status
object): running → clear + hide; success → the counts (the
imported fmtSyncResult) + a live catalog refresh; failed → the
banner with the error; idle → hide + clear."""
directly by the state appliers: success → the counts (fmtSyncResult)
+ a live catalog refresh; failed → the banner with the sanitized
error; every state change still emits 'bor:sync-status' (the status
object as detail) for other subscribers."""
js = _text(SOURCES_JS)
assert 'window.addEventListener("bor:sync-status"' in js
assert 'status.state === "running"' in js
assert 'status.state === "success"' in js
assert 'status.state === "failed"' in js
assert "fmtSyncResult(status.detail)" in js
assert "loadDocs()" in js, "the catalog re-fetches live on a successful sync"
assert "showSyncError(status.error)" in js
assert "syncResult.textContent" in js
success = _body(js, "applySyncSuccess")
assert "syncResult.textContent = fmtSyncResult(status.detail)" in success, (
"the counts live in status.detail — a bare status renders all zeros"
)
assert "loadDocs()" in success, "the catalog re-fetches live on a successful sync"
failure = _body(js, "applySyncFailure")
assert "showSyncError(error)" in failure
assert "emitSyncStatus" in _body(js, "applySyncIdle")
assert (
'window.dispatchEvent(new CustomEvent("bor:sync-status", { detail: status }))'
in _body(js, "emitSyncStatus")
)
def test_sources_js_no_longer_owns_the_sync_machine() -> None:
"""The state machine is GONE from sources.js (header.js owns it):
no button refs, no POST, no status poll, no button-state helpers,
no click binding, no load re-attach."""
js = _text(SOURCES_JS)
def test_header_js_no_longer_owns_the_sync_machine() -> None:
"""The state machine is GONE from header.js (sources.js owns it —
the button is Sources-page only, so the page drives it): no button
refs, no POST, no status poll, no button-state helpers, no modal.
sources.js keeps every one of them."""
header = _text(HEADER_JS)
for gone in (
"SYNC_POLL_MS",
"syncPollTimer",
"startSyncPolling",
"stopSyncPolling",
"enterRunningState",
"enterSyncRunningState",
"settleSyncButton",
"applySyncSuccess",
"applySyncFailure",
"applySyncIdle",
"initSyncButton",
"startSync",
"syncModal",
"syncBtn",
'fetch("/api/sync", { method: "POST" })',
'fetch("/api/sync/status")',
'querySelector("#sync-btn")',
'querySelector("#sync-label")',
'querySelector(".sync-icon")',
):
assert gone not in js, f"{gone!r} must be gone from sources.js (header.js owns it)"
assert gone not in header, f"{gone!r} must be gone from header.js (sources.js owns it)"
js = _text(SOURCES_JS)
for kept in (
"SYNC_POLL_MS = 2000",
"syncPollTimer",
"startSyncPolling",
"enterSyncRunningState",
"initSyncButton",
'fetch("/api/sync", { method: "POST" })',
'fetch("/api/sync/status")',
'querySelector("#sync-btn")',
):
assert kept in js, f"{kept!r} must be in sources.js (the owner)"
# ---------- styles.css: the §7.4 states ----------
def test_sync_button_css_ghost_pill_and_disabled_state() -> None:
""".sync-btn is the same ghost pill as .new-chat-btn (contrast pair
ink-soft on surface ≈6.9:1 ≥ 4.5:1), with a ≥44px touch floor and a
""".sync-btn is a pill in the shared button family (contrast pair
ink-soft on surface ≥ 4.5:1), with a ≥44px touch floor and a
:disabled state (never stale — the busy look is visible)."""
css = _text(STYLES_CSS)
block = re.search(r"\.sync-btn\s*\{([^}]*)\}", css)