Settings sheet title disagrees with visible App Password setup after scrolling #1068

Closed
opened 2026-10-04 19:18:15 +00:00 by kayg · 7 comments
Owner

The combined Mail round captured a Settings sheet title that disagrees with its visible body at phone width.

Use the real production build from job/mailround-1038 (6ff665b85), navigate to /settings/apps-devices/app-passwords, choose Sync with Your Devices and create a real test credential. Bring the Copy incoming Mail server control into view in the scrollable panel. At 390 px, light and dark, the screenshot shows a Calendar Feeds title and a New feed button above the App Password ready body and Mail connection controls. The URI and visible credential body concern App Passwords.

The production screenshot set is attached to #1038. Relevant files: device-setup-390-light.png and device-setup-390-dark.png. Password values and profile QR codes are masked. macOS platform metadata is enabled. These are real local API data, not a standalone mockup.

Expected: the sheet title and its header actions identify the same Settings view as the body. Recheck the Copy link target as well. The Mail setup itself grants Calendar, Notes and Mail and has working shared copy controls; the observed disagreement is in the shared Settings sheet/scroll routing. The Mail integration kept that shared behavior intact. The orchestrator will merge final 7b after this round, so recheck this finding on that combined revision.

Do not close #1038 for this report. Its separate sustained SELECT finding is #1067; staging readiness remains no.

The combined Mail round captured a Settings sheet title that disagrees with its visible body at phone width. Use the real production build from job/mailround-1038 (`6ff665b85`), navigate to `/settings/apps-devices/app-passwords`, choose Sync with Your Devices and create a real test credential. Bring the Copy incoming Mail server control into view in the scrollable panel. At 390 px, light and dark, the screenshot shows a Calendar Feeds title and a New feed button above the App Password ready body and Mail connection controls. The URI and visible credential body concern App Passwords. The production screenshot set is attached to #1038. Relevant files: `device-setup-390-light.png` and `device-setup-390-dark.png`. Password values and profile QR codes are masked. macOS platform metadata is enabled. These are real local API data, not a standalone mockup. Expected: the sheet title and its header actions identify the same Settings view as the body. Recheck the Copy link target as well. The Mail setup itself grants Calendar, Notes and Mail and has working shared copy controls; the observed disagreement is in the shared Settings sheet/scroll routing. The Mail integration kept that shared behavior intact. The orchestrator will merge final 7b after this round, so recheck this finding on that combined revision. Do not close #1038 for this report. Its separate sustained SELECT finding is #1067; staging readiness remains no.
Author
Owner

Masked production evidence attached to #1038:

device-setup-390-dark.png

device-setup-390-light.png

Masked production evidence attached to #1038: [device-setup-390-dark.png](https://git.kayg.org/attachments/02a3873e-2535-4ce4-b1a2-5cb948bbea1f) [device-setup-390-light.png](https://git.kayg.org/attachments/0c2b00dc-aaaf-4a37-84c4-d191a1587bb5)
Author
Owner

Starting #1068 on job/mailround-1038; base is 9fb9a4bfb2488152c83d50c55441ff5f43b572b2 (origin/dev and merge-base), current head is 8091d5788ad86aaee1da831801031110462c6f6d. I am tracing the shared Settings sheet route, title and Copy link state before making the focused fix.

Starting #1068 on `job/mailround-1038`; base is `9fb9a4bfb2488152c83d50c55441ff5f43b572b2` (`origin/dev` and merge-base), current head is `8091d5788ad86aaee1da831801031110462c6f6d`. I am tracing the shared Settings sheet route, title and Copy link state before making the focused fix.
Author
Owner

Finding: AppsSection.svelte renders Calendar Feeds before App Passwords. AppPasswordsGroup.svelte sets hideTitleOnSheet, which marks its SettingsCard heading data-sheet-title-ignore and removes it from the sheet-title tracker. After scrolling to App Passwords, OverlaySurface can therefore keep Calendar Feeds as the active title and data-sheet-href. The card already has the stable /settings/apps-devices/app-passwords group link. I am wiring a stable “App Passwords” sheet title to that card and adding a focused regression assertion.

Finding: `AppsSection.svelte` renders Calendar Feeds before App Passwords. `AppPasswordsGroup.svelte` sets `hideTitleOnSheet`, which marks its `SettingsCard` heading `data-sheet-title-ignore` and removes it from the sheet-title tracker. After scrolling to App Passwords, OverlaySurface can therefore keep Calendar Feeds as the active title and `data-sheet-href`. The card already has the stable `/settings/apps-devices/app-passwords` group link. I am wiring a stable “App Passwords” sheet title to that card and adding a focused regression assertion.
Author
Owner

Gate finding: the component file contains two existing list exceptions. The performance guard includes the full Svelte component hash in each list exception identity, so the phone-title change made those 24 records stale even though neither loop body nor its recorded limit changed. Five function-scoped cache exceptions still match. I am updating only the 24 list hashes and preserving every owner, reason, test, expiry and limit.

Gate finding: the component file contains two existing list exceptions. The performance guard includes the full Svelte component hash in each list exception identity, so the phone-title change made those 24 records stale even though neither loop body nor its recorded limit changed. Five function-scoped cache exceptions still match. I am updating only the 24 list hashes and preserving every owner, reason, test, expiry and limit.
Author
Owner

Repro after exposing the App Passwords card heading: at 390 px, the incoming Mail server button is visible while the App Passwords heading is still 322 px below the sheet header. The scroll tracker therefore reports Calendar Feeds and /settings/apps-devices/feeds while the URL is /settings/apps-devices/app-passwords. The phone sheet must use the active Settings group deep link for its compact title and Copy link, independent of which group heading last crossed the header.

Repro after exposing the App Passwords card heading: at 390 px, the incoming Mail server button is visible while the App Passwords heading is still 322 px below the sheet header. The scroll tracker therefore reports `Calendar Feeds` and `/settings/apps-devices/feeds` while the URL is `/settings/apps-devices/app-passwords`. The phone sheet must use the active Settings group deep link for its compact title and Copy link, independent of which group heading last crossed the header.
Author
Owner

Finished

Fixed the phone Settings sheet for /settings/apps-devices/app-passwords. The active group route now owns the compact title and Copy link, so scrolling past Calendar Feeds does not change the sheet to that view. Copy link copies /settings/apps-devices/app-passwords.

Added a focused OverlaySurface regression test for a pinned Settings title and link while the body heading differs. Refreshed existing performance exception hashes for the changed source syntax; exception owners, reasons, tests, bounds and expiry dates are unchanged.

Screenshots

Captured from the production build with macOS platform metadata. The one-time app password and QR code are masked.

Width Light Dark
390 px Light Dark
820 px Light Dark
1440 px Light Dark

Verification

bun run check:

perf-lint: PASS; 0 violations; 19340 scoped exceptions
Warn: Do not use empty rulesets (css)
Warn: Do not use empty rulesets (css)
Warn: Unused CSS selector ".note-page-lede"
Warn: Unused CSS selector ".note-state"
svelte-check found 0 errors and 4 warnings in 3 files

Focused Vitest:

 Test Files  2 passed (2)
      Tests  36 passed (36)
   Start at  00:50:05
   Duration  13.59s (transform 74%, tests 9%, environment 9%, import 6%, setup 3%)

Production build:

✓ built in 18.11s
✓ built in 13ms
✓ built in 42.11s
  Wrote site to "build"
Compressed 534 static variants; saved 9823420 bytes.

UX gaps closed

  • The 390 px sticky title and Copy link now remain on App Passwords after scrolling into the Sync with Your Devices setup.
  • The real Copy link action copied the active group URL in the browser capture.
  • Light and dark screenshots cover phone, tablet and desktop widths; the secret and QR code are masked.

UX gaps left

None known on this path. The merge round still owns full e2e and adversarial suites.

Decisions

For a phone URL that names a Settings group, the stable group route owns the sticky title and header Copy link throughout body scrolling. The route uses the existing groupLabel and settingsHref helpers, in line with DESIGN §§33 and 50.

Files

  • packages/ui/src/components/OverlaySurface.svelte
  • apps/web/src/routes/settings/[...path]/+page.svelte
  • apps/web/src/lib/components/OverlaySurface.svelte.test.ts
  • contracts/perf/exceptions.json

Head: 5c691f703a9c91486fe9ce20cd05ecf0768908e3

READY FOR MERGE: yes

## Finished Fixed the phone Settings sheet for `/settings/apps-devices/app-passwords`. The active group route now owns the compact title and Copy link, so scrolling past Calendar Feeds does not change the sheet to that view. Copy link copies `/settings/apps-devices/app-passwords`. Added a focused OverlaySurface regression test for a pinned Settings title and link while the body heading differs. Refreshed existing performance exception hashes for the changed source syntax; exception owners, reasons, tests, bounds and expiry dates are unchanged. ## Screenshots Captured from the production build with macOS platform metadata. The one-time app password and QR code are masked. | Width | Light | Dark | | --- | --- | --- | | 390 px | [Light](https://git.kayg.org/attachments/8390f303-7624-4ead-b3e5-491e395e5d87) | [Dark](https://git.kayg.org/attachments/9ca6ccbe-edde-45b8-a33e-c862790998a6) | | 820 px | [Light](https://git.kayg.org/attachments/5c9834d5-c55a-4b1e-a541-3c899bb9662c) | [Dark](https://git.kayg.org/attachments/68a5b5fe-2351-4224-b9d2-8fc4a600f74a) | | 1440 px | [Light](https://git.kayg.org/attachments/f3c529fb-6d3b-4ad2-8b18-d610469672b5) | [Dark](https://git.kayg.org/attachments/b4b9a65b-9f4b-4da5-9225-9984c2d1ccc0) | ## Verification `bun run check`: ```text perf-lint: PASS; 0 violations; 19340 scoped exceptions Warn: Do not use empty rulesets (css) Warn: Do not use empty rulesets (css) Warn: Unused CSS selector ".note-page-lede" Warn: Unused CSS selector ".note-state" svelte-check found 0 errors and 4 warnings in 3 files ``` Focused Vitest: ```text Test Files 2 passed (2) Tests 36 passed (36) Start at 00:50:05 Duration 13.59s (transform 74%, tests 9%, environment 9%, import 6%, setup 3%) ``` Production build: ```text ✓ built in 18.11s ✓ built in 13ms ✓ built in 42.11s Wrote site to "build" Compressed 534 static variants; saved 9823420 bytes. ``` ## UX gaps closed - The 390 px sticky title and Copy link now remain on App Passwords after scrolling into the Sync with Your Devices setup. - The real Copy link action copied the active group URL in the browser capture. - Light and dark screenshots cover phone, tablet and desktop widths; the secret and QR code are masked. ## UX gaps left None known on this path. The merge round still owns full e2e and adversarial suites. ## Decisions For a phone URL that names a Settings group, the stable group route owns the sticky title and header Copy link throughout body scrolling. The route uses the existing `groupLabel` and `settingsHref` helpers, in line with DESIGN §§33 and 50. ## Files - `packages/ui/src/components/OverlaySurface.svelte` - `apps/web/src/routes/settings/[...path]/+page.svelte` - `apps/web/src/lib/components/OverlaySurface.svelte.test.ts` - `contracts/perf/exceptions.json` Head: `5c691f703a9c91486fe9ce20cd05ecf0768908e3` READY FOR MERGE: yes
Author
Owner

Deployed to production 2026-10-05 ~04:40 CEST in round 9 (269b1b51b). Includes the mail proxy (CalternalDAV, real Apple Mail acceptance PASS on the Mac VM), provider sync fixes, the stress-round fixes, #1067, #1068, #1078 and the Files upload identity repair. Staging healthy first; production healthy in 18 s; Auth 14 and Mail 17 migrations applied; change events 0/30 s; no expired leases.

Deployed to production 2026-10-05 ~04:40 CEST in round 9 (269b1b51b). Includes the mail proxy (CalternalDAV, real Apple Mail acceptance PASS on the Mac VM), provider sync fixes, the stress-round fixes, #1067, #1068, #1078 and the Files upload identity repair. Staging healthy first; production healthy in 18 s; Auth 14 and Mail 17 migrations applied; change events 0/30 s; no expired leases.
kayg closed this issue 2026-10-05 03:08:51 +00:00
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#1068
No description provided.