Search palette grows up and down from the centre; hidden (dot) entries never in results #178

Closed
opened 2026-09-26 14:11:55 +00:00 by kayg · 39 comments
Owner

Owner 2026-09-26 (screenshot: palette with query 'r' grows only downward from a fixed top).

  1. The palette is vertically centred on the viewport and grows symmetrically up AND down as results arrive (animate height from the centre, measured motion, reduced motion = instant). It keeps a margin from both screen edges (at least ~10vh desktop, safe-area aware on phones); past that height the result list scrolls under a floating search input, the footer hint bar stays pinned. The selected row scrolls into view with scrollIntoView({block:'nearest'}). No layout jump while typing (debounce resize, keep the input fixed at the centre-relative position during a single query's growth).
  2. BUG: hidden (dot) entries appear in results ('.calternal' folder, 'saved-searches' inside .calternal). Search must never return dot files/folders or anything under them unless the user turned on Show hidden files; fix it on the server search route (one action, one route, DESIGN §41) with a regression test and an adversarial probe case.
  3. Screenshots 1440 and 390, few and many results, light and dark, for Claude's review. The overlay glass tokens come from #157 (merge dev first; do not fork).
Owner 2026-09-26 (screenshot: palette with query 'r' grows only downward from a fixed top). 1. The palette is vertically centred on the viewport and grows symmetrically up AND down as results arrive (animate height from the centre, measured motion, reduced motion = instant). It keeps a margin from both screen edges (at least ~10vh desktop, safe-area aware on phones); past that height the result list scrolls under a floating search input, the footer hint bar stays pinned. The selected row scrolls into view with scrollIntoView({block:'nearest'}). No layout jump while typing (debounce resize, keep the input fixed at the centre-relative position during a single query's growth). 2. BUG: hidden (dot) entries appear in results ('.calternal' folder, 'saved-searches' inside .calternal). Search must never return dot files/folders or anything under them unless the user turned on Show hidden files; fix it on the server search route (one action, one route, DESIGN §41) with a regression test and an adversarial probe case. 3. Screenshots 1440 and 390, few and many results, light and dark, for Claude's review. The overlay glass tokens come from #157 (merge dev first; do not fork).
Author
Owner

Starting #178 on branch job/search-palette, based on dev at c7dc7e408920ecfdd503edb5e0fa972fd564cfc7.

Starting #178 on branch `job/search-palette`, based on dev at `c7dc7e408920ecfdd503edb5e0fa972fd564cfc7`.
Author
Owner

Owner additions 2026-09-26 (screenshots: our palette vs Raycast):
4. 'See all N results ⌘↩' is not aligned with the rows (wrong inset) and looks like a row. Remove it from the list. Follow Raycast: one bottom bar with a right-aligned action pill that shows the primary action for the selected row with its shortcut (e.g. 'Open ↩', 'Run ↩') plus 'See all ⌘↩' and 'Actions ⌘K' (the action menu for the selected row, using the shared menu). The separate 'Run ↩' button in the preview pane goes away (one place for actions). Keyboard hints move into that pill; no second hint row.
5. BUG: two selection highlights at once (keyboard selection on one row, hover highlight on another, both painted with the selected style). Exactly one selected row: pointer hover moves the selection (Raycast behaviour); no separate hover style that looks like selection.
6. BUG: section headers are clipped under the search input when the list scrolls ('NAVIGATE' cut in half). Headers either stick below the input or scroll fully out; nothing is cut.
7. Preview pane: when a note or task is selected, show a content preview (rendered Markdown, read-only) with the matched text highlighted (all matches, the first scrolled into view). Other kinds keep their current preview. Snippets come from the search route (DESIGN §41), not a second fetch path per kind.
8. Alignment: every row, header and the bottom bar share one left inset; icons in one column (layout-sweep assertion).

Owner additions 2026-09-26 (screenshots: our palette vs Raycast): 4. 'See all N results ⌘↩' is not aligned with the rows (wrong inset) and looks like a row. Remove it from the list. Follow Raycast: one bottom bar with a right-aligned action pill that shows the primary action for the selected row with its shortcut (e.g. 'Open ↩', 'Run ↩') plus 'See all ⌘↩' and 'Actions ⌘K' (the action menu for the selected row, using the shared menu). The separate 'Run ↩' button in the preview pane goes away (one place for actions). Keyboard hints move into that pill; no second hint row. 5. BUG: two selection highlights at once (keyboard selection on one row, hover highlight on another, both painted with the selected style). Exactly one selected row: pointer hover moves the selection (Raycast behaviour); no separate hover style that looks like selection. 6. BUG: section headers are clipped under the search input when the list scrolls ('NAVIGATE' cut in half). Headers either stick below the input or scroll fully out; nothing is cut. 7. Preview pane: when a note or task is selected, show a content preview (rendered Markdown, read-only) with the matched text highlighted (all matches, the first scrolled into view). Other kinds keep their current preview. Snippets come from the search route (DESIGN §41), not a second fetch path per kind. 8. Alignment: every row, header and the bottom bar share one left inset; icons in one column (layout-sweep assertion).
Author
Owner

Build finding: the targeted calternal-server test first failed to compile because crates/plugins/files/src/index.rs:620 returned Ok(()) from a Result<bool, _> function. The unchanged-row branch is meant to report no index update; I am making that one-line compile fix separately so the search regression and requested gates can run.

Build finding: the targeted `calternal-server` test first failed to compile because `crates/plugins/files/src/index.rs:620` returned `Ok(())` from a `Result<bool, _>` function. The unchanged-row branch is meant to report no index update; I am making that one-line compile fix separately so the search regression and requested gates can run.
Author
Owner

Follow-up evidence: the Ok(false) compile fix made stable repeated Files operations return false from record_once. record_impl treats false only as a file-change retry and then returns 409 after its retry limit. The focused calternal-plugin-files run reported 12 failures, including hidden_entries::public_file_drop_refuses_hidden_targets (expected 201, got 409). The unchanged-row branch must return Ok(true) to mean the stable operation completed without an upsert; I am correcting that before resuming #178.

Follow-up evidence: the `Ok(false)` compile fix made stable repeated Files operations return `false` from `record_once`. `record_impl` treats `false` only as a file-change retry and then returns 409 after its retry limit. The focused `calternal-plugin-files` run reported 12 failures, including `hidden_entries::public_file_drop_refuses_hidden_targets` (expected 201, got 409). The unchanged-row branch must return `Ok(true)` to mean the stable operation completed without an upsert; I am correcting that before resuming #178.
Author
Owner

Finding for #178 item 2: the new /api/v1/search route regression failed before the filter was added. The fixture returned .calternal/saved-searches/query.json and Notes/.private.md in the default result set; expected results contained only the Unicode fullwidth-dot path and the visible document. The handler now applies the shared dot-path rule before duplicate-route merging, and the Notes title provider now includes its path so the server can apply that rule.

Finding for #178 item 2: the new `/api/v1/search` route regression failed before the filter was added. The fixture returned `.calternal/saved-searches/query.json` and `Notes/.private.md` in the default result set; expected results contained only the Unicode fullwidth-dot path and the visible document. The handler now applies the shared dot-path rule before duplicate-route merging, and the Notes title provider now includes its path so the server can apply that rule.
Author
Owner

Finding for #178 item 6: the production E2E run seeded real search results and scrolled .results-panel to 70 px. The first section heading then started at y=231 while the panel viewport started at y=295, placing the heading 64 px above the visible list. The current section label is lost as its rows scroll. I am pinning section headings inside the result scroller so they remain readable when the list moves under the search input.

Finding for #178 item 6: the production E2E run seeded real search results and scrolled `.results-panel` to 70 px. The first section heading then started at y=231 while the panel viewport started at y=295, placing the heading 64 px above the visible list. The current section label is lost as its rows scroll. I am pinning section headings inside the result scroller so they remain readable when the list moves under the search input.
Author
Owner

Finding for #178 item 8: the new real-server layout-sweep assertion failed on both 1440px search states. It measured the result icon and section label at the same x position, but the bottom bar's inner edge was 2px left of that column. I moved the row, section heading and bar to a shared 18px column inset; the rebuilt production app now reports checked 4 screens and LAYOUT SWEEP PASSED.

Finding for #178 item 8: the new real-server layout-sweep assertion failed on both 1440px search states. It measured the result icon and section label at the same x position, but the bottom bar's inner edge was 2px left of that column. I moved the row, section heading and bar to a shared 18px column inset; the rebuilt production app now reports `checked 4 screens` and `LAYOUT SWEEP PASSED`.
Author
Owner

Finding for #178 item 4: the real production E2E exposed two browser exceptions in the new action flow. CopyLink is not defined occurred because the search field still renders its saved-search link control after the import changed. Dismissing the Actions menu also raised Cannot read properties of null (reading 'items') because its prop read through the menu state during teardown. I restored the shared import and made the closing menu's anchor/items props null-safe; I added an E2E assertion that fails on any page error during the action interactions.

Finding for #178 item 4: the real production E2E exposed two browser exceptions in the new action flow. `CopyLink is not defined` occurred because the search field still renders its saved-search link control after the import changed. Dismissing the Actions menu also raised `Cannot read properties of null (reading 'items')` because its prop read through the menu state during teardown. I restored the shared import and made the closing menu's anchor/items props null-safe; I added an E2E assertion that fails on any page error during the action interactions.
Author
Owner

Finding for #178 item 4 integration: after the action interactions passed, the production E2E pressed Ctrl+Enter and observed is-expanded on the palette, but the surface stayed at 720×648 before and after the toggle. The new pinned bar is present in compact mode; the expanded view does not use its larger bounds in this run. I am tracing the computed layout before adjusting the action bar sizing.

Finding for #178 item 4 integration: after the action interactions passed, the production E2E pressed Ctrl+Enter and observed `is-expanded` on the palette, but the surface stayed at 720×648 before and after the toggle. The new pinned bar is present in compact mode; the expanded view does not use its larger bounds in this run. I am tracing the computed layout before adjusting the action bar sizing.
Author
Owner

Evidence: bun apps/web/e2e/layout-sweep.mjs --only search failed on the 390px coarse-pointer search view. The Save and Copy link controls painted at 43×35px and their 44×44px hit regions overlapped at the shared edge. I am adjusting the search header action group to use the shared feed-toolbar hit geometry, then rerunning the same sweep.

Evidence: `bun apps/web/e2e/layout-sweep.mjs --only search` failed on the 390px coarse-pointer search view. The Save and Copy link controls painted at 43×35px and their 44×44px hit regions overlapped at the shared edge. I am adjusting the search header action group to use the shared feed-toolbar hit geometry, then rerunning the same sweep.
Author
Owner

Finding for #178 item 1 (production E2E, current branch): TMPDIR=/home/kayg/Developer/calternal-wt/search-palette/target/tmp bun e2e/search.mjs failed the new centered-growth assertion. With seeded real search results, the palette center moved from y=509 for atlas brief to y=564 for atlas, a 55 px downward shift. The surface stays at its fixed top while results add height. I am implementing measured top and height updates with a bounded viewport band; the regression check is in apps/web/e2e/search.mjs.

Finding for #178 item 1 (production E2E, current branch): `TMPDIR=/home/kayg/Developer/calternal-wt/search-palette/target/tmp bun e2e/search.mjs` failed the new centered-growth assertion. With seeded real search results, the palette center moved from y=509 for `atlas brief` to y=564 for `atlas`, a 55 px downward shift. The surface stays at its fixed top while results add height. I am implementing measured top and height updates with a bounded viewport band; the regression check is in `apps/web/e2e/search.mjs`.
Author
Owner

The real-browser regression now also covers a coarse-pointer 390 px context. The Save and Copy link actions pass their 44×44 hit-region probe after the palette entry animation settles. On desktop 1440×900, the existing compact layout still fails the center assertion: the few-result center is y=485 and the many-result center is y=564 (79 px drift). I am addressing compact top and height as one measured viewport-band update; the result pane remains the only scroll area.

The real-browser regression now also covers a coarse-pointer 390 px context. The Save and Copy link actions pass their 44×44 hit-region probe after the palette entry animation settles. On desktop 1440×900, the existing compact layout still fails the center assertion: the few-result center is y=485 and the many-result center is y=564 (79 px drift). I am addressing compact top and height as one measured viewport-band update; the result pane remains the only scroll area.
Author
Owner

The production-browser suite exposed a second interaction defect in the selected Note preview. After keyboard selection changes, the match stayed at y=47–63 while the preview pane was y=181–271 with scrollTop=214. The Editor component defers ProseMirror DOM creation until after mount, but SearchPreview scrolled on a Svelte tick before that DOM existed. I moved match scrolling to the Editor's onEditorReady callback and kept a stale-result key guard.

The production-browser suite exposed a second interaction defect in the selected Note preview. After keyboard selection changes, the match stayed at y=47–63 while the preview pane was y=181–271 with scrollTop=214. The Editor component defers ProseMirror DOM creation until after mount, but SearchPreview scrolled on a Svelte tick before that DOM existed. I moved match scrolling to the Editor's onEditorReady callback and kept a stale-result key guard.
Author
Owner

The browser suite now passes the new compact-growth, edge-margin, pinned-chrome, coarse-pointer action and Markdown-match scroll checks. It then found an expansion regression: after the 260 ms transition wait, the expanded class is present but the same search surface remains 720×648 px (compact bounds were 720×648); its expanded top moves to 36 px. I am checking whether the compact inline height or CSS transition cap is retained.

The browser suite now passes the new compact-growth, edge-margin, pinned-chrome, coarse-pointer action and Markdown-match scroll checks. It then found an expansion regression: after the 260 ms transition wait, the expanded class is present but the same search surface remains 720×648 px (compact bounds were 720×648); its expanded top moves to 36 px. I am checking whether the compact inline height or CSS transition cap is retained.
Author
Owner

Screenshot harness finding: the 390px capture context cloned desktop storage before any result was opened, so the empty-palette screenshot had no persisted Recent group. The page was waiting for a Recent heading and timed out after all desktop screenshots passed. I updated the touch setup to open a real search result in that context, then return to Today before capturing; the app data remains real and context-local.

> Screenshot harness finding: the 390px capture context cloned desktop storage before any result was opened, so the empty-palette screenshot had no persisted Recent group. The page was waiting for a Recent heading and timed out after all desktop screenshots passed. I updated the touch setup to open a real search result in that context, then return to Today before capturing; the app data remains real and context-local.
Author
Owner

Adversarial probe correction: search_hidden reached the hidden default/opt-in checks without reporting a result leak. Its three setup calls were incorrectly expected to return 201 or 409; /api/v1/files/mkdir documents and returns 204. I corrected the probe expectation in commit a1b62ea0, and python3 -m py_compile tests/adversarial/attack2.py passed.

> Adversarial probe correction: `search_hidden` reached the hidden default/opt-in checks without reporting a result leak. Its three setup calls were incorrectly expected to return 201 or 409; `/api/v1/files/mkdir` documents and returns 204. I corrected the probe expectation in commit `a1b62ea0`, and `python3 -m py_compile tests/adversarial/attack2.py` passed.
Author
Owner

Post-merge web gate findings and fixes:

  • The first bun run check found a stale app-side editor type declaration and an incomplete fake Storage in the search provider test. The web type mirror now includes the editor's documented read-only editable prop, and the fixture implements the full Storage interface. Rerun output: svelte-check found 0 errors and 0 warnings.
  • The first bun run test could not resolve @calternal/ui/floating while importing the workspace editor. The UI package already exports that subpath; this worktree had not linked the editor's workspace dependency. bun install --frozen-lockfile reported Checked 267 installs across 312 packages (no changes). The rerun passed: Test Files 57 passed (57), Tests 440 passed (440).

No dependency versions or lockfile entries changed.

Post-merge web gate findings and fixes: - The first `bun run check` found a stale app-side editor type declaration and an incomplete fake `Storage` in the search provider test. The web type mirror now includes the editor's documented read-only `editable` prop, and the fixture implements the full Storage interface. Rerun output: `svelte-check found 0 errors and 0 warnings`. - The first `bun run test` could not resolve `@calternal/ui/floating` while importing the workspace editor. The UI package already exports that subpath; this worktree had not linked the editor's workspace dependency. `bun install --frozen-lockfile` reported `Checked 267 installs across 312 packages (no changes)`. The rerun passed: `Test Files 57 passed (57)`, `Tests 440 passed (440)`. No dependency versions or lockfile entries changed.
Author
Owner

Production E2E findings, 2026-09-26:

  • The phone action hit-target probe failed once with 35.46×35.46 px measured buttons and right-edge misses. A rerun reached the same probe and passed with the existing 36 px painted control / 44 px target. The E2E used a fixed 250 ms sleep to infer that the palette scale transition had ended. I replaced it with a condition that waits for the rendered button bounds to match their CSS dimensions.
  • The phone preview sheet opened, but its E2E locator timed out waiting for the exact accessible name Open or Run. The rendered action is named Open <result title> or Run <result title>. I changed the locator to match the action prefix.

These findings identify E2E synchronization and locator mismatches. The repeated touch probe passed without a product CSS change.

Production E2E findings, 2026-09-26: - The phone action hit-target probe failed once with 35.46×35.46 px measured buttons and right-edge misses. A rerun reached the same probe and passed with the existing 36 px painted control / 44 px target. The E2E used a fixed 250 ms sleep to infer that the palette scale transition had ended. I replaced it with a condition that waits for the rendered button bounds to match their CSS dimensions. - The phone preview sheet opened, but its E2E locator timed out waiting for the exact accessible name `Open` or `Run`. The rendered action is named `Open <result title>` or `Run <result title>`. I changed the locator to match the action prefix. These findings identify E2E synchronization and locator mismatches. The repeated touch probe passed without a product CSS change.
Author
Owner

Production E2E follow-up, 2026-09-27:

  • The phone search-action probe now waits for the 36 px controls to reach their resting CSS bounds instead of sleeping 250 ms. Five fresh palette openings passed all 44×44 hit-region samples. The stale phone-preview locator now matches Open <title> and Run <title>; the action pill, menu, phone preview and search flow pass.
  • A full screenshot run regenerated the requested few/many palette captures for 1440 px and 390 px in Paper and Tokyo Night. They are in /home/kayg/Developer/calternal-wt/search-palette-review.
  • The run then timed out after 20 seconds waiting for .grid .tile img to become visible. This is consistent with the thumbnail readiness/404 evidence already reported on #213; that issue remains the known E2E gap for this run.
Production E2E follow-up, 2026-09-27: - The phone search-action probe now waits for the 36 px controls to reach their resting CSS bounds instead of sleeping 250 ms. Five fresh palette openings passed all 44×44 hit-region samples. The stale phone-preview locator now matches `Open <title>` and `Run <title>`; the action pill, menu, phone preview and search flow pass. - A full screenshot run regenerated the requested few/many palette captures for 1440 px and 390 px in Paper and Tokyo Night. They are in `/home/kayg/Developer/calternal-wt/search-palette-review`. - The run then timed out after 20 seconds waiting for `.grid .tile img` to become visible. This is consistent with the thumbnail readiness/404 evidence already reported on #213; that issue remains the known E2E gap for this run.
Author
Owner

Forgejo #178 final report

Branch: job/search-palette
Base: dev at 57894643c840de27a35d5bd4215db103ce601a8a; git merge dev reported Already up to date.
Head SHA: d70820f422e012d1c8fe2b0957f822845cbfacc5

Built

  • /api/v1/search filters dot files and descendants by default. The explicit hidden-files opt-in is show_hidden=true. The server applies the shared path predicate to the search providers, including Notes. Regression coverage and the adversarial probe cover default exclusion and opt-in.
  • The palette measures its compact height and top together, keeps its centre fixed as results grow, keeps the input and action footer pinned, and scrolls results below them. Section headings stay below the input. The selected result drives one footer action pill. Note and task previews show highlighted matches and reveal the first match after the editor DOM is ready.
  • The web E2E now follows the current shortcut registry (Control+K), waits for the phone controls’ resting geometry, checks five fresh openings for 44×44 hit targets, and matches the preview action’s accessible name including its result title.
  • The production screenshot run refreshed the eight requested few/many captures at 1440 px and 390 px in Paper and Tokyo Night. Files are in /home/kayg/Developer/calternal-wt/search-palette-review.

Files

  • API and server: Cargo.lock, contracts/openapi.json, packages/api-client/src/generated.ts, crates/calternal-server/Cargo.toml, crates/calternal-server/src/main.rs, crates/plugins/files/src/index.rs, crates/plugins/notes/src/lib.rs, tests/adversarial/attack2.py.
  • Search UI and checks: apps/web/e2e/layout-sweep.mjs, apps/web/e2e/search.mjs, apps/web/src/lib/components/search-dialog.svelte, apps/web/src/lib/search/PhotoGrid.svelte, apps/web/src/lib/search/SearchPreview.svelte, apps/web/src/lib/search/SearchResultRow.svelte, apps/web/src/lib/search/SearchResultRow.svelte.test.ts, apps/web/src/lib/search/providers.test.ts, apps/web/src/lib/search/server.ts, apps/web/src/lib/search/snippet.test.ts, apps/web/src/lib/search/snippet.ts, apps/web/src/lib/shortcuts/registry.ts.
  • Editor and shared UI: apps/web/src/lib/notes/editor-types/index.d.ts, packages/editor/src/Editor.svelte, packages/editor/src/Editor.svelte.test.ts, packages/editor/src/source.ts, packages/ui/src/components/OverlaySurface.svelte.

Gates

cargo fmt --check: exit 0; stdout and stderr were empty.

cargo clippy --all-targets -- -D warnings (exit 0), verbatim:

Finished `dev` profile [unoptimized + debuginfo] target(s) in 9m 24s

cargo test (exit 101), verbatim failure output:

test continuous_typing_is_saved_within_the_maximum_wait ... FAILED

thread 'continuous_typing_is_saved_within_the_maximum_wait' (1349124) panicked at crates/calternal-collab/tests/hostile_clients.rs:370:5:
no save during 5 s of typing

test result: FAILED. 9 passed; 1 failed; 0 ignored; 0 measured; 0 filtered out; finished in 8.57s
error: test failed, to rerun pass `-p calternal-collab --test hostile_clients`

Follow-up checks passed; the focused test result was:

test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 9 filtered out; finished in 4.11s

The full hostile_clients binary result was:

test result: ok. 10 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 6.25s

bun run check (exit 0), verbatim:

svelte-check found 0 errors and 0 warnings

bun run test (exit 0), verbatim summary:

 Test Files  57 passed (57)
      Tests  440 passed (440)

Vitest also printed Not implemented: Window's scrollTo() method 26 times.

The production search E2E passed the phone hit-target check (five openings), centered growth, pinned chrome, result streaming, Markdown preview, action pill/menu, phone preview, and query checks. It then stopped at the known photo thumbnail gap:

TimeoutError: waitFor: Timeout 20000ms exceeded.
  - waiting for locator('.grid .tile img').first() to be visible

Known gaps

  • Public-link photo thumbnails returned 404 in the post-merge adversarial round and are tracked in #213. The production E2E thumbnail timeout matches that finding. Other concurrency findings in that round were tagged SLOW; the server remained alive.
  • The full workspace cargo test gate did not pass in one run. Its timed collaboration test passed alone and in the full hostile_clients binary; shared-host load is a likely cause, but the workspace gate remains failed.

Decisions for owner confirmation

  • The current shortcut registry assigns Search to ⌘K / Ctrl+K, so the E2E uses Control+K. DESIGN §34 still says ⌘/ / Ctrl+/; this mismatch remains in the docs.
  • OverlaySurface accepts pillTop and pillHeight as a pair so the palette can apply its measured viewport placement in one update.
  • The phone long-press preview sheet keeps its own Open and Copy link actions. Desktop preview actions remain in the palette footer.
  • The search API uses the query parameter show_hidden=true for the explicit hidden-files opt-in.
  • Match scrolling waits for the Editor’s rendered marks with a MutationObserver; the design specifies the visible result but not this render synchronization mechanism.

The build outputs were removed with cargo clean and deletion of apps/web/build and apps/web/.svelte-kit. Issue left open.

## Forgejo #178 final report Branch: `job/search-palette` Base: `dev` at `57894643c840de27a35d5bd4215db103ce601a8a`; `git merge dev` reported `Already up to date.` Head SHA: `d70820f422e012d1c8fe2b0957f822845cbfacc5` ### Built - `/api/v1/search` filters dot files and descendants by default. The explicit hidden-files opt-in is `show_hidden=true`. The server applies the shared path predicate to the search providers, including Notes. Regression coverage and the adversarial probe cover default exclusion and opt-in. - The palette measures its compact height and top together, keeps its centre fixed as results grow, keeps the input and action footer pinned, and scrolls results below them. Section headings stay below the input. The selected result drives one footer action pill. Note and task previews show highlighted matches and reveal the first match after the editor DOM is ready. - The web E2E now follows the current shortcut registry (`Control+K`), waits for the phone controls’ resting geometry, checks five fresh openings for 44×44 hit targets, and matches the preview action’s accessible name including its result title. - The production screenshot run refreshed the eight requested few/many captures at 1440 px and 390 px in Paper and Tokyo Night. Files are in `/home/kayg/Developer/calternal-wt/search-palette-review`. ### Files - API and server: `Cargo.lock`, `contracts/openapi.json`, `packages/api-client/src/generated.ts`, `crates/calternal-server/Cargo.toml`, `crates/calternal-server/src/main.rs`, `crates/plugins/files/src/index.rs`, `crates/plugins/notes/src/lib.rs`, `tests/adversarial/attack2.py`. - Search UI and checks: `apps/web/e2e/layout-sweep.mjs`, `apps/web/e2e/search.mjs`, `apps/web/src/lib/components/search-dialog.svelte`, `apps/web/src/lib/search/PhotoGrid.svelte`, `apps/web/src/lib/search/SearchPreview.svelte`, `apps/web/src/lib/search/SearchResultRow.svelte`, `apps/web/src/lib/search/SearchResultRow.svelte.test.ts`, `apps/web/src/lib/search/providers.test.ts`, `apps/web/src/lib/search/server.ts`, `apps/web/src/lib/search/snippet.test.ts`, `apps/web/src/lib/search/snippet.ts`, `apps/web/src/lib/shortcuts/registry.ts`. - Editor and shared UI: `apps/web/src/lib/notes/editor-types/index.d.ts`, `packages/editor/src/Editor.svelte`, `packages/editor/src/Editor.svelte.test.ts`, `packages/editor/src/source.ts`, `packages/ui/src/components/OverlaySurface.svelte`. ### Gates `cargo fmt --check`: exit 0; stdout and stderr were empty. `cargo clippy --all-targets -- -D warnings` (exit 0), verbatim: ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 9m 24s ``` `cargo test` (exit 101), verbatim failure output: ```text test continuous_typing_is_saved_within_the_maximum_wait ... FAILED thread 'continuous_typing_is_saved_within_the_maximum_wait' (1349124) panicked at crates/calternal-collab/tests/hostile_clients.rs:370:5: no save during 5 s of typing test result: FAILED. 9 passed; 1 failed; 0 ignored; 0 measured; 0 filtered out; finished in 8.57s error: test failed, to rerun pass `-p calternal-collab --test hostile_clients` ``` Follow-up checks passed; the focused test result was: ```text test result: ok. 1 passed; 0 failed; 0 ignored; 0 measured; 9 filtered out; finished in 4.11s ``` The full `hostile_clients` binary result was: ```text test result: ok. 10 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 6.25s ``` `bun run check` (exit 0), verbatim: ```text svelte-check found 0 errors and 0 warnings ``` `bun run test` (exit 0), verbatim summary: ```text Test Files 57 passed (57) Tests 440 passed (440) ``` Vitest also printed `Not implemented: Window's scrollTo() method` 26 times. The production search E2E passed the phone hit-target check (five openings), centered growth, pinned chrome, result streaming, Markdown preview, action pill/menu, phone preview, and query checks. It then stopped at the known photo thumbnail gap: ```text TimeoutError: waitFor: Timeout 20000ms exceeded. - waiting for locator('.grid .tile img').first() to be visible ``` ### Known gaps - Public-link photo thumbnails returned 404 in the post-merge adversarial round and are tracked in #213. The production E2E thumbnail timeout matches that finding. Other concurrency findings in that round were tagged `SLOW`; the server remained alive. - The full workspace `cargo test` gate did not pass in one run. Its timed collaboration test passed alone and in the full `hostile_clients` binary; shared-host load is a likely cause, but the workspace gate remains failed. ### Decisions for owner confirmation - The current shortcut registry assigns Search to `⌘K` / `Ctrl+K`, so the E2E uses `Control+K`. DESIGN §34 still says `⌘/` / `Ctrl+/`; this mismatch remains in the docs. - `OverlaySurface` accepts `pillTop` and `pillHeight` as a pair so the palette can apply its measured viewport placement in one update. - The phone long-press preview sheet keeps its own Open and Copy link actions. Desktop preview actions remain in the palette footer. - The search API uses the query parameter `show_hidden=true` for the explicit hidden-files opt-in. - Match scrolling waits for the Editor’s rendered marks with a `MutationObserver`; the design specifies the visible result but not this render synchronization mechanism. The build outputs were removed with `cargo clean` and deletion of `apps/web/build` and `apps/web/.svelte-kit`. Issue left open.
Author
Owner

Addendum to the known-gaps section: the adversarial bookmark write ambiguity is tracked separately in open #210. That report recorded 16 concurrent bookmark POSTs, 6 HTTP 201 responses, 10 client timeouts, then 7 matching Note files on disk. A retry after a timeout can create a duplicate. This is separate from the public thumbnail readiness issue #213.

Addendum to the known-gaps section: the adversarial bookmark write ambiguity is tracked separately in open #210. That report recorded 16 concurrent bookmark POSTs, 6 HTTP 201 responses, 10 client timeouts, then 7 matching Note files on disk. A retry after a timeout can create a duplicate. This is separate from the public thumbnail readiness issue #213.
Author
Owner

Claude review (search-palette-many-1440-paper-white, few-390-tokyo-night). Desktop behaviour is right (highlighted matches, preview with highlights, action pill). Fix before merge:

  1. Sticky section headers (NOTES, LOG ENTRIES, DAYS, PHOTOS) paint an opaque white band across the glass. Use the same translucent overlay material (or a subtle gradient fade under the input) so the surface stays uniform in both themes.
  2. At 390 the action pill runs together: 'Open EnterSee all Ctrl+EnterActions Ctrl+K'. On coarse pointers show no keyboard hints at all: buttons 'Open' and 'Actions' (and 'See all' only if it fits) with proper spacing and 44px targets. On desktop keep one space between label and key, a gap between items, and platform keys from the #159 registry (⌘ on macOS).
    Re-take the 8 screenshots.
Claude review (search-palette-many-1440-paper-white, few-390-tokyo-night). Desktop behaviour is right (highlighted matches, preview with highlights, action pill). Fix before merge: 1. Sticky section headers (NOTES, LOG ENTRIES, DAYS, PHOTOS) paint an opaque white band across the glass. Use the same translucent overlay material (or a subtle gradient fade under the input) so the surface stays uniform in both themes. 2. At 390 the action pill runs together: 'Open EnterSee all Ctrl+EnterActions Ctrl+K'. On coarse pointers show no keyboard hints at all: buttons 'Open' and 'Actions' (and 'See all' only if it fits) with proper spacing and 44px targets. On desktop keep one space between label and key, a gap between items, and platform keys from the #159 registry (⌘ on macOS). Re-take the 8 screenshots.
Author
Owner

Continuing Forgejo #178 on branch job/search-palette. Starting HEAD: d70820f422e012d1c8fe2b0957f822845cbfacc5; current dev base to merge before final gates: f6418fc72d750d941f23554ad16381f6dd400fd6. I am checking the two pending Claude review points: sticky header material and the action pill's touch/desktop spacing and shortcut labels.

Continuing Forgejo #178 on branch `job/search-palette`. Starting HEAD: `d70820f422e012d1c8fe2b0957f822845cbfacc5`; current `dev` base to merge before final gates: `f6418fc72d750d941f23554ad16381f6dd400fd6`. I am checking the two pending Claude review points: sticky header material and the action pill's touch/desktop spacing and shortcut labels.
Author
Owner

Reproduced the two pending points in the existing production captures: search-palette-many-1440-paper-white.png shows opaque white section bands; search-palette-few-390-tokyo-night.png shows the phone action labels and shortcut hints run together. The heading rule uses background: var(--surface) inside a material="clear" palette, while action Kbd spans are hidden only below 360px, not for coarse pointers. I am adding focused E2E assertions before the fixes.

Reproduced the two pending points in the existing production captures: `search-palette-many-1440-paper-white.png` shows opaque white section bands; `search-palette-few-390-tokyo-night.png` shows the phone action labels and shortcut hints run together. The heading rule uses `background: var(--surface)` inside a `material="clear"` palette, while action Kbd spans are hidden only below 360px, not for coarse pointers. I am adding focused E2E assertions before the fixes.
Author
Owner

Continuing Forgejo #178 after the VM restart on branch job/search-palette. Starting HEAD: 0fe2ae628f2fa7fab48578cbce62c14ce320772f (checkpoint); current dev: f6418fc72d750d941f23554ad16381f6dd400fd6; branch merge base: 57894643c840de27a35d5bd4215db103ce601a8a. The checkpoint adds a browser assertion for sticky header material. I am reproducing the two latest screenshot-review findings: translucent sticky section headings and spaced, hint-free touch actions, then I will retake the eight requested screenshots.

Continuing Forgejo #178 after the VM restart on branch `job/search-palette`. Starting HEAD: `0fe2ae628f2fa7fab48578cbce62c14ce320772f` (checkpoint); current `dev`: `f6418fc72d750d941f23554ad16381f6dd400fd6`; branch merge base: `57894643c840de27a35d5bd4215db103ce601a8a`. The checkpoint adds a browser assertion for sticky header material. I am reproducing the two latest screenshot-review findings: translucent sticky section headings and spaced, hint-free touch actions, then I will retake the eight requested screenshots.
Author
Owner

Build finding during continuation: the production server build failed with E0463 for hmac_sha1_compact, datasketches, levenshtein_automata and lz4_flex. The Cargo feature graph includes these dependencies, but each corresponding target/debug/deps artifact was 0 bytes (timestamps 2026-09-27 01:13 after the VM interruption). I am clearing the damaged local Cargo cache and rebuilding; this is not a source-code failure.

Build finding during continuation: the production server build failed with `E0463` for `hmac_sha1_compact`, `datasketches`, `levenshtein_automata` and `lz4_flex`. The Cargo feature graph includes these dependencies, but each corresponding `target/debug/deps` artifact was 0 bytes (timestamps 2026-09-27 01:13 after the VM interruption). I am clearing the damaged local Cargo cache and rebuilding; this is not a source-code failure.
Author
Owner

Finding and fix for sticky headings: the checkpoint E2E failed in the production build with header: rgb(255, 255, 255) and palette: color(srgb 1 1 1 / 0.71). The heading used the opaque theme surface while the parent used the clear-glass tint. The heading now uses the shared inherited --glass-tint token. A rebuilt production run reports PASS streaming grouped results and proceeds through PASS keyboard navigation with preview and PASS selected-result action pill, menu and phone preview; it then reaches the known .grid .tile img 20-second timeout tracked in #213. The eight requested few/many captures were refreshed from the fixed build.

Finding and fix for sticky headings: the checkpoint E2E failed in the production build with `header: rgb(255, 255, 255)` and `palette: color(srgb 1 1 1 / 0.71)`. The heading used the opaque theme surface while the parent used the clear-glass tint. The heading now uses the shared inherited `--glass-tint` token. A rebuilt production run reports `PASS streaming grouped results` and proceeds through `PASS keyboard navigation with preview` and `PASS selected-result action pill, menu and phone preview`; it then reaches the known `.grid .tile img` 20-second timeout tracked in #213. The eight requested few/many captures were refreshed from the fixed build.
Author
Owner

Phone footer review finding: the production E2E measured three visible keyboard hints at 390 px. The action button boxes also touched at their edges. The palette now hides shortcut hints for coarse pointers, adds spacing within the existing action pill, and hides the secondary See all action when the footer is too narrow. Regression assertions pass: 390 px shows Open / See all / Actions, the labels have at least 6 px between controls and fit within the bar, the 44×44 pointer probe passes for header and footer controls across five openings, and at 240 px only Open / Actions remain. The screenshot-enabled run refreshed all eight palette captures. The broader E2E continues to hit the previously reported 20-second .grid .tile img timeout tracked in #213.

Phone footer review finding: the production E2E measured three visible keyboard hints at 390 px. The action button boxes also touched at their edges. The palette now hides shortcut hints for coarse pointers, adds spacing within the existing action pill, and hides the secondary See all action when the footer is too narrow. Regression assertions pass: 390 px shows Open / See all / Actions, the labels have at least 6 px between controls and fit within the bar, the 44×44 pointer probe passes for header and footer controls across five openings, and at 240 px only Open / Actions remain. The screenshot-enabled run refreshed all eight palette captures. The broader E2E continues to hit the previously reported 20-second `.grid .tile img` timeout tracked in #213.
Author
Owner

Merge note: git merge dev had one conflict in tests/adversarial/attack2.py. I kept this branch's search_hidden probe and dev's analytics probe as separate sections. python3 -m py_compile tests/adversarial/attack2.py and git diff --check both passed; the merge is committed as f0244929.

Merge note: `git merge dev` had one conflict in `tests/adversarial/attack2.py`. I kept this branch's `search_hidden` probe and dev's `analytics` probe as separate sections. `python3 -m py_compile tests/adversarial/attack2.py` and `git diff --check` both passed; the merge is committed as `f0244929`.
Author
Owner

Merged API probe finding: the first authorization-matrix pass stopped at GET /api/v1/analytics (analytics_report) because authz_matrix.py had no policy for the new route. The handler requires data_scope_user(&principal) and the Analytics Plugin declares the data scope, so the route has its data-scope check. I added /api/v1/analytics to the matrix's standard-user/admin data policy and will rerun the matrix with a fresh local server.

Merged API probe finding: the first authorization-matrix pass stopped at `GET /api/v1/analytics` (`analytics_report`) because `authz_matrix.py` had no policy for the new route. The handler requires `data_scope_user(&principal)` and the Analytics Plugin declares the `data` scope, so the route has its data-scope check. I added `/api/v1/analytics` to the matrix's standard-user/admin data policy and will rerun the matrix with a fresh local server.
Author
Owner

Adversarial round evidence: the bookmark capture storm reported 1 HTTP 201 and 15 client timeouts (-1), with 1/16 unique IDs returned; the server stayed alive. This is the response/write ambiguity already tracked in open #210 (Concurrent bookmark capture can write after client timeout). The concurrent-host run does not establish a low-load limit, and the one-time round is continuing.

Adversarial round evidence: the bookmark capture storm reported 1 HTTP 201 and 15 client timeouts (`-1`), with 1/16 unique IDs returned; the server stayed alive. This is the response/write ambiguity already tracked in open #210 (`Concurrent bookmark capture can write after client timeout`). The concurrent-host run does not establish a low-load limit, and the one-time round is continuing.
Author
Owner

The Analytics authorization policy probe now passes on a fresh local server. AUTHZ_MATRIX_ONLY=1 tests/adversarial/run.sh checked 223 OpenAPI operations across 4 identities (892 requests), with policy classes public: 18, public_link: 9, user: 175, admin: 21; it exited 0. The policy fix is committed as test(authz): classify analytics as user data.

The Analytics authorization policy probe now passes on a fresh local server. `AUTHZ_MATRIX_ONLY=1 tests/adversarial/run.sh` checked 223 OpenAPI operations across 4 identities (892 requests), with policy classes `public: 18`, `public_link: 9`, `user: 175`, `admin: 21`; it exited 0. The policy fix is committed as `test(authz): classify analytics as user data`.
Author
Owner

Finding after merging dev: the full cargo test run failed in tests::search_route_hides_dot_paths_unless_requested because the fixture sent unauthenticated requests and received HTTP 401 where it expected 200. The route requires a user principal with the data scope and an allowed User Home root. I updated both requests in the fixture to attach that context. Verification: cargo test -p calternal-server --bin calternal-server search_route_hides_dot_paths_unless_requested passed (1 passed). Commit: 879374d8.

Finding after merging `dev`: the full `cargo test` run failed in `tests::search_route_hides_dot_paths_unless_requested` because the fixture sent unauthenticated requests and received HTTP 401 where it expected 200. The route requires a user principal with the `data` scope and an allowed User Home root. I updated both requests in the fixture to attach that context. Verification: `cargo test -p calternal-server --bin calternal-server search_route_hides_dot_paths_unless_requested` passed (1 passed). Commit: `879374d8`.
Author
Owner

The shared dev ref advanced during the long final-gate run (from the previously merged f6418fc7 to 21ee397d, including sync, share, collaboration, and calendar changes). I merged the current dev again before completing the job. The merge is ae33137bac8a92426f280d857a64365cda3c7266; it applied cleanly, git status --short is empty, and git diff --check passed. Since this merge includes API changes, I am rerunning the one-time adversarial round and final gates against the resulting tree.

The shared `dev` ref advanced during the long final-gate run (from the previously merged `f6418fc7` to `21ee397d`, including sync, share, collaboration, and calendar changes). I merged the current `dev` again before completing the job. The merge is `ae33137bac8a92426f280d857a64365cda3c7266`; it applied cleanly, `git status --short` is empty, and `git diff --check` passed. Since this merge includes API changes, I am rerunning the one-time adversarial round and final gates against the resulting tree.
Author
Owner

Post-merge adversarial finding (not marked SLOW): tests/adversarial/attack.py uploaded 120 tiny JPEGs to a Calendar day using an 8-worker TUS burst. Eight create/byte-upload requests for burst-106 through burst-113 timed out (NO RESPONSE), and the follow-up /api/v1/calendar/items listing reported expected 120 burst photos, saw 113. The server stayed alive. The same run had multiple unrelated worktrees and adversarial jobs active, so host load may have contributed, but this is a count mismatch and needs its own follow-up. I will file it separately; no files-plugin behavior change is in scope for #178.

Post-merge adversarial finding (not marked SLOW): `tests/adversarial/attack.py` uploaded 120 tiny JPEGs to a Calendar day using an 8-worker TUS burst. Eight create/byte-upload requests for `burst-106` through `burst-113` timed out (`NO RESPONSE`), and the follow-up `/api/v1/calendar/items` listing reported `expected 120 burst photos, saw 113`. The server stayed alive. The same run had multiple unrelated worktrees and adversarial jobs active, so host load may have contributed, but this is a count mismatch and needs its own follow-up. I will file it separately; no files-plugin behavior change is in scope for #178.
Author
Owner

I filed the 120-photo burst/listing mismatch in #217 (Calendar photo burst can leave items out of the Calendar listing) with the reproduction and expected regression check. The search-palette branch will not change file/index behavior for this finding.

I filed the 120-photo burst/listing mismatch in #217 (`Calendar photo burst can leave items out of the Calendar listing`) with the reproduction and expected regression check. The search-palette branch will not change file/index behavior for this finding.
Author
Owner

A separate non-SLOW result from the same adversarial run was one timeout among 64 concurrent PUT /api/v1/calendar/preferences requests (16 workers); the other 63 returned 200 and the subsequent GET had a valid shape. I added that evidence to existing open #205 for controlled-load request-timeout follow-up. The primary 120-photo count mismatch is filed as #217.

A separate non-SLOW result from the same adversarial run was one timeout among 64 concurrent `PUT /api/v1/calendar/preferences` requests (16 workers); the other 63 returned 200 and the subsequent GET had a valid shape. I added that evidence to existing open #205 for controlled-load request-timeout follow-up. The primary 120-photo count mismatch is filed as #217.
Author
Owner

Search palette continuation complete

Branch: job/search-palette
Head: ae33137bac8a92426f280d857a64365cda3c7266
Worktree: clean. git diff --check passed. The latest dev merge is included.

Built

  • Kept the search palette centered as results stream and pinned the input/footer while the result list scrolls.
  • Filtered dot paths in the server search route by default. The explicit opt-in is show_hidden=true.
  • Added result snippets, keyboard/phone preview actions, and production E2E coverage.
  • Made sticky section headings use the shared translucent --glass-tint.
  • Spaced the phone action pill, hid shortcut hints on coarse pointers, and hid See all when the footer is narrower than 240 CSS px.
  • Updated the hidden-path route fixture to carry the route's required data principal after merging current dev.

Files changed against current dev

Cargo.lock; apps/web/e2e/layout-sweep.mjs; apps/web/e2e/search.mjs; apps/web/src/lib/components/search-dialog.svelte; apps/web/src/lib/notes/editor-types/index.d.ts; apps/web/src/lib/search/PhotoGrid.svelte; apps/web/src/lib/search/SearchPreview.svelte; apps/web/src/lib/search/SearchResultRow.svelte; apps/web/src/lib/search/SearchResultRow.svelte.test.ts; apps/web/src/lib/search/providers.test.ts; apps/web/src/lib/search/server.ts; apps/web/src/lib/search/snippet.test.ts; apps/web/src/lib/search/snippet.ts; apps/web/src/lib/shortcuts/registry.ts; contracts/openapi.json; crates/calternal-server/Cargo.toml; crates/calternal-server/src/main.rs; crates/plugins/files/src/index.rs; crates/plugins/notes/src/lib.rs; packages/api-client/src/generated.ts; packages/editor/src/Editor.svelte; packages/editor/src/Editor.svelte.test.ts; packages/editor/src/source.ts; packages/ui/src/components/OverlaySurface.svelte; tests/adversarial/attack2.py.

Gates

cargo fmt --check: exit 0, no output.

cargo clippy --all-targets -- -D warnings (verbatim final line):

Finished `dev` profile [unoptimized + debuginfo] target(s) in 35.15s

cargo test: final run exit 0. Parsed from its output:

summaries=69 passed=1237 failed=0 ignored=12

One earlier full run hit Sqlx(PoolTimedOut) in agent_turn_order while other worktrees were running full tests. The isolated test passed in 0.84s, and the final full rerun passed.

bun run check (verbatim):

svelte-check found 0 errors and 0 warnings

bun run test (verbatim summary):

 Test Files  71 passed (71)
      Tests  545 passed (545)
   Start at  09:18:30
   Duration  22.77s (transform 62%, import 16%, environment 12%, tests 8%, setup 2%)

Vitest also logged one CSS parse warning and repeated Not implemented: Window's scrollTo() method; the run exited 0.

Screenshots and E2E

The eight production screenshots were refreshed at /home/kayg/Developer/calternal-wt/search-palette-review:

  • search-palette-few-1440-paper-white.png
  • search-palette-many-1440-paper-white.png
  • search-palette-few-390-paper-white.png
  • search-palette-many-390-paper-white.png
  • search-palette-few-1440-tokyo-night.png
  • search-palette-many-1440-tokyo-night.png
  • search-palette-few-390-tokyo-night.png
  • search-palette-many-390-tokyo-night.png

The production E2E passed centered growth, pinned chrome, streamed results, keyboard preview/actions, and phone hit targets. It then stopped at the open thumbnail issue #213:

TimeoutError: waitFor: Timeout 20000ms exceeded.
  - waiting for locator('.grid .tile img').first() to be visible

Adversarial round

The post-merge round exited 1. The authorization matrix passed 916 requests across 229 operations and four identities; hidden-search and analytics probes passed; hostile-bytes findings were 0; restart probe findings were 0. Journal race returned 201 for all 40 creates with zero timeouts.

The non-SLOW results were filed: the 120-photo TUS burst timed out on eight requests and the Calendar listing returned 113/120 items (#217); one of 64 concurrent Calendar preference writes timed out (#205). Thumbnail readiness returned 404 after its wait and remains tracked in #213. Other reported timings were marked SLOW while several worktrees were active.

Known gaps

  • #213: public photo thumbnails were not ready after the probe's 30-second wait; the production photo-grid E2E hit the related 20-second wait.
  • #217: Calendar photo burst/listing count mismatch.
  • #205: one Calendar preference request timed out under concurrency; this run used a shared host.
  • #210 remains open for the earlier bookmark response/write ambiguity.

Decisions not specified in DESIGN.md

  • Hide See all below a 240 CSS px action-bar width; at 390 px, keep Open, See all, and Actions visible.
  • Use the shortcut registry's Ctrl+K/⌘K for Search in E2E; DESIGN §34 still documents Ctrl+//⌘/.
  • Keep Open and Copy link on the phone long-press preview sheet; desktop preview actions stay in the palette footer.
  • Use a MutationObserver to wait for Editor match marks before scrolling.
  • Pass measured pillTop and pillHeight together to OverlaySurface for one placement update.
## Search palette continuation complete Branch: `job/search-palette` Head: `ae33137bac8a92426f280d857a64365cda3c7266` Worktree: clean. `git diff --check` passed. The latest `dev` merge is included. ### Built - Kept the search palette centered as results stream and pinned the input/footer while the result list scrolls. - Filtered dot paths in the server search route by default. The explicit opt-in is `show_hidden=true`. - Added result snippets, keyboard/phone preview actions, and production E2E coverage. - Made sticky section headings use the shared translucent `--glass-tint`. - Spaced the phone action pill, hid shortcut hints on coarse pointers, and hid `See all` when the footer is narrower than 240 CSS px. - Updated the hidden-path route fixture to carry the route's required data principal after merging current `dev`. ### Files changed against current `dev` `Cargo.lock`; `apps/web/e2e/layout-sweep.mjs`; `apps/web/e2e/search.mjs`; `apps/web/src/lib/components/search-dialog.svelte`; `apps/web/src/lib/notes/editor-types/index.d.ts`; `apps/web/src/lib/search/PhotoGrid.svelte`; `apps/web/src/lib/search/SearchPreview.svelte`; `apps/web/src/lib/search/SearchResultRow.svelte`; `apps/web/src/lib/search/SearchResultRow.svelte.test.ts`; `apps/web/src/lib/search/providers.test.ts`; `apps/web/src/lib/search/server.ts`; `apps/web/src/lib/search/snippet.test.ts`; `apps/web/src/lib/search/snippet.ts`; `apps/web/src/lib/shortcuts/registry.ts`; `contracts/openapi.json`; `crates/calternal-server/Cargo.toml`; `crates/calternal-server/src/main.rs`; `crates/plugins/files/src/index.rs`; `crates/plugins/notes/src/lib.rs`; `packages/api-client/src/generated.ts`; `packages/editor/src/Editor.svelte`; `packages/editor/src/Editor.svelte.test.ts`; `packages/editor/src/source.ts`; `packages/ui/src/components/OverlaySurface.svelte`; `tests/adversarial/attack2.py`. ### Gates `cargo fmt --check`: exit 0, no output. `cargo clippy --all-targets -- -D warnings` (verbatim final line): ```text Finished `dev` profile [unoptimized + debuginfo] target(s) in 35.15s ``` `cargo test`: final run exit 0. Parsed from its output: ```text summaries=69 passed=1237 failed=0 ignored=12 ``` One earlier full run hit `Sqlx(PoolTimedOut)` in `agent_turn_order` while other worktrees were running full tests. The isolated test passed in 0.84s, and the final full rerun passed. `bun run check` (verbatim): ```text svelte-check found 0 errors and 0 warnings ``` `bun run test` (verbatim summary): ```text Test Files 71 passed (71) Tests 545 passed (545) Start at 09:18:30 Duration 22.77s (transform 62%, import 16%, environment 12%, tests 8%, setup 2%) ``` Vitest also logged one CSS parse warning and repeated `Not implemented: Window's scrollTo() method`; the run exited 0. ### Screenshots and E2E The eight production screenshots were refreshed at `/home/kayg/Developer/calternal-wt/search-palette-review`: - `search-palette-few-1440-paper-white.png` - `search-palette-many-1440-paper-white.png` - `search-palette-few-390-paper-white.png` - `search-palette-many-390-paper-white.png` - `search-palette-few-1440-tokyo-night.png` - `search-palette-many-1440-tokyo-night.png` - `search-palette-few-390-tokyo-night.png` - `search-palette-many-390-tokyo-night.png` The production E2E passed centered growth, pinned chrome, streamed results, keyboard preview/actions, and phone hit targets. It then stopped at the open thumbnail issue #213: ```text TimeoutError: waitFor: Timeout 20000ms exceeded. - waiting for locator('.grid .tile img').first() to be visible ``` ### Adversarial round The post-merge round exited 1. The authorization matrix passed 916 requests across 229 operations and four identities; hidden-search and analytics probes passed; hostile-bytes findings were 0; restart probe findings were 0. Journal race returned 201 for all 40 creates with zero timeouts. The non-SLOW results were filed: the 120-photo TUS burst timed out on eight requests and the Calendar listing returned 113/120 items (#217); one of 64 concurrent Calendar preference writes timed out (#205). Thumbnail readiness returned 404 after its wait and remains tracked in #213. Other reported timings were marked `SLOW` while several worktrees were active. ### Known gaps - #213: public photo thumbnails were not ready after the probe's 30-second wait; the production photo-grid E2E hit the related 20-second wait. - #217: Calendar photo burst/listing count mismatch. - #205: one Calendar preference request timed out under concurrency; this run used a shared host. - #210 remains open for the earlier bookmark response/write ambiguity. ### Decisions not specified in DESIGN.md - Hide `See all` below a 240 CSS px action-bar width; at 390 px, keep `Open`, `See all`, and `Actions` visible. - Use the shortcut registry's `Ctrl+K`/`⌘K` for Search in E2E; DESIGN §34 still documents `Ctrl+/`/`⌘/`. - Keep `Open` and `Copy link` on the phone long-press preview sheet; desktop preview actions stay in the palette footer. - Use a `MutationObserver` to wait for Editor match marks before scrolling. - Pass measured `pillTop` and `pillHeight` together to `OverlaySurface` for one placement update.
Author
Owner

Merged into dev at c82549b9 after Claude's round-2 review (centred growth, single selection, action pill without key hints on touch, previews with highlighted matches, no dot entries, translucent headers). Deploy status on #203.

Merged into dev at c82549b9 after Claude's round-2 review (centred growth, single selection, action pill without key hints on touch, previews with highlighted matches, no dot entries, translucent headers). Deploy status on #203.
kayg closed this issue 2026-09-27 07:46:37 +00:00
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#178
No description provided.