Skip to content

refactor: simplify canvas validation and controls - #10

Merged
beastyrabbit merged 1 commit into
mainfrom
t3code/sonar-followup-20260929
Sep 29, 2026
Merged

beastyrabbit merged 1 commit into
mainfrom
t3code/sonar-followup-20260929

Conversation

@beastyrabbit

Copy link
Copy Markdown
Owner

Note

🤖 GPT-6 responding on behalf of beastyrabbit

Room validation, byte-range parsing, settings, collaborator search and audio rendering had five critical cognitive-complexity findings. This change splits their decisions into smaller functions while preserving validation errors, permissions, media playback and layout. It also makes immutable component props and shape metadata explicit and removes repeated nested conditionals.

Username and upload-filename punctuation trimming now runs linearly while preserving normalized output. The upload regex was an existing accepted finding; fixing it is separate from the open-issue reduction. Version 0.6.4 prepares the normal image release, with no migration or configuration changes.

Validation: lint, formatting, frontend/backend/test types, 95 frontend tests, 48 backend tests against disposable PostgreSQL, both builds, compiled runtime configuration, Convex codegen, and eight browser flows pass. New coverage checks boundary ranges and room settings, OBS controls, consent, collaborator keyboard navigation, long normalization inputs and audio play/pause. Gitleaks passes the complete outgoing source and commit range. Independent review by Claude Opus 5.5 at high effort found no issues on f93c339.

Sonar baseline on current main a034108: 107 open code smells, including five critical complexity findings; zero bugs, vulnerabilities or hotspots. Existing dispositions are six accepted and eight false positives. The only scan exclusion remains generated convex/_generated/**. Candidate and post-merge scans must establish the reduction; a green new-code gate alone is not backlog clearance.

One finding is supported as a false positive but has not been reclassified: 97c172c3-c4ac-409b-bf61-aeb415b26c8e, typescript:S6853, on the PolicyChoice wrapping label in app/app/settings/page.tsx. Its descendant span renders the required label prop, and all three callers supply fixed nonempty text. settings-controls.test.tsx finds every radio by its accessible name. No accessibility workaround or mass classification was applied.

Settings verified at desktop and mobile sizes using synthetic fixtures:

Desktop settings

Mobile settings

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-29T18:08:34.449831Z f93c339 PR opened
🔒 Security Review ✅ Completed 2026-09-29T18:09:05.689746Z f93c339 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@beastyrabbit

Copy link
Copy Markdown
Owner Author

Note

🤖 GPT-6 responding on behalf of beastyrabbit

Candidate Sonar analysis reports one new finding, 39462458-dbc3-494b-8c85-d5f9731928ad, rule typescript:S6819, at components/stream-canvas/UserMultiSelect.tsx:268-279. I verified this as a false positive before classifying this specific issue.

The rule recommends replacing button role="option" with native <option>. This is a custom searchable combobox, whose popup at lines 199-205 is div role="listbox", not an HTML select. Each suggestion exposes role="option", a stable ID and aria-selected; the input uses aria-controls and aria-activedescendant. A native option outside a select/optgroup/datalist would not supply the native select interaction assumed by the recommendation. The existing markup was moved unchanged into UserSearchResults by this refactor.

Evidence: components/__tests__/user-multi-select.test.tsx verifies option discovery, click selection, arrow-key wrap/clamping and Escape. The passing browser collaborator flow verifies active-descendant movement and Enter selection. The W3C combobox pattern specifies the custom listbox popup, active-descendant focus and selected option states used here. This disposition is limited to this issue and control; it does not disable the rule or assert that every custom option is accessible. No code-fix reduction will be credited for this classification.

@sonarqube-skyway-gmbh

Copy link
Copy Markdown

@beastyrabbit
beastyrabbit merged commit e10d462 into main Sep 29, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant