SHORTCUTS: platform audit + Apple / Windows & Linux presets (auto-picked at first sign-in) + Settings → Shortcuts #542

Open
opened 2026-09-30 17:31:00 +00:00 by kayg · 27 comments
Owner

Owner request (2026-09-30)

"i want a shortcut audit done so that it feels natural to apple users and as well as linux/windows users depending on the preset they select. Settings → Shortcuts - the preset should be auto selected based on the device they first login from."
State today:

  • apps/web/src/lib/shortcuts/registry.ts is the one registry (about 333 lines).
  • format.ts renders cmd as ⌘ on Mac and Ctrl elsewhere, based on the current device (isMacPlatform).
  • KeyboardShortcutsCard.svelte lists the shortcuts (opened from the layout).
  • There is no Settings → Shortcuts section yet, even though the registry comments name one.

Part 1: audit (write docs/shortcuts-audit.md, ASD-STE100)

  • For every registry entry and every hand-matched key handler that is not in the registry (grep all onkeydown/keydown handlers; each one found outside the registry is a defect to fix):
    • What does the Apple convention say? Sources: Apple HIG keyboard shortcuts, the macOS Finder/Mail/Calendar/Notes/Photos/Reminders menus.
    • What does the Windows/Linux convention say? Sources: Windows File Explorer/Outlook/Microsoft 365, GNOME HIG and KDE standard shortcuts.
    • Does calternal match? Where it does not, what is the fix?
    • Cite a source URL per convention (use web search).
  • Cover:
    • modifier mapping (Cmd↔Ctrl, Option↔Alt; is Ctrl+Alt a safe equivalent of ⌘⌥ on Windows (AltGr) and Linux?);
    • delete (⌘⌫ vs Delete);
    • rename (Return on Mac vs F2);
    • open (⌘↓ vs Enter);
    • parent folder (⌘↑ vs Alt+↑);
    • Quick Look (Space);
    • select all, find, new item (⌘N), close (⌘W: is it reserved?), preferences (⌘, vs Ctrl+,);
    • redo (⌘⇧Z vs Ctrl+Y and Ctrl+Shift+Z);
    • tab switching (⌘1…9 vs Ctrl+1…9: both reserved by browsers, so what do we do?);
    • the sidebar, search, date navigation, the Mail keys (Gmail/Apple Mail), text formatting, Money.
  • Also list browser-reserved keys per platform (extend the sourced reserved list in registry.test.ts), and which keys only work in an installed app window.

Part 2: presets

  • Two presets: Apple (macOS) and Windows & Linux. Each registry entry gets per-preset keys where the conventions differ (for example, rename is Return on Apple and F2 on Windows & Linux), not only a modifier swap. format.ts renders hints from the chosen preset, not from the current device.
  • Auto-selection: at the User's first sign-in, the server stores the preset from the device used (the client sends its platform; macOS/iOS/iPadOS → Apple, everything else → Windows & Linux). Later sign-ins on other devices do not change it. The preset is a per-User preference, synced like other settings, with parity over API/CLI/MCP (#484).
  • The User can change it at any time in Settings → Shortcuts.

Part 3: Settings → Shortcuts

  • It is a sub-section in the User half of Settings (DESIGN §50; coordinate with settings-50: if that job has landed, slot into its structure, else add the section where §50 puts it).
  • A preset chooser at the top, with user-friendly names and no jargon.
  • Below it, a searchable list grouped by SHORTCUT_GROUPS, rendered from the registry. It reuses KeyboardShortcutsCard rather than a second list.
  • Each group and entry is deep-linkable (the registry id is the anchor) with Copy link.
  • Rebinding is not in scope (registry "Variant B, later").
    Test:
  • unit tests: preset key resolution, and that no entry lacks a key on either preset;
  • registry.test.ts: no preset binds a reserved key for that platform;
  • e2e: a User on a Linux user agent signs in first and sees Ctrl hints and F2 rename; they switch to Apple in Settings → Shortcuts and the hints change without a reload; a second sign-in from a Mac UA keeps the stored preset.
  • Attach screenshots of Settings → Shortcuts in both presets and both themes.
## Owner request (2026-09-30) "i want a shortcut audit done so that it feels natural to apple users and as well as linux/windows users depending on the preset they select. Settings → Shortcuts - the preset should be auto selected based on the device they first login from." **State today:** - `apps/web/src/lib/shortcuts/registry.ts` is the one registry (about 333 lines). - `format.ts` renders `cmd` as ⌘ on Mac and Ctrl elsewhere, based on the current device (`isMacPlatform`). - `KeyboardShortcutsCard.svelte` lists the shortcuts (opened from the layout). - There is no Settings → Shortcuts section yet, even though the registry comments name one. ### Part 1: audit (write `docs/shortcuts-audit.md`, ASD-STE100) - For every registry entry and every hand-matched key handler that is not in the registry (grep all `onkeydown`/`keydown` handlers; each one found outside the registry is a defect to fix): - What does the Apple convention say? Sources: Apple HIG keyboard shortcuts, the macOS Finder/Mail/Calendar/Notes/Photos/Reminders menus. - What does the Windows/Linux convention say? Sources: Windows File Explorer/Outlook/Microsoft 365, GNOME HIG and KDE standard shortcuts. - Does calternal match? Where it does not, what is the fix? - Cite a source URL per convention (use web search). - Cover: - modifier mapping (Cmd↔Ctrl, Option↔Alt; is Ctrl+Alt a safe equivalent of ⌘⌥ on Windows (AltGr) and Linux?); - delete (⌘⌫ vs Delete); - rename (Return on Mac vs F2); - open (⌘↓ vs Enter); - parent folder (⌘↑ vs Alt+↑); - Quick Look (Space); - select all, find, new item (⌘N), close (⌘W: is it reserved?), preferences (⌘, vs Ctrl+,); - redo (⌘⇧Z vs Ctrl+Y and Ctrl+Shift+Z); - tab switching (⌘1…9 vs Ctrl+1…9: both reserved by browsers, so what do we do?); - the sidebar, search, date navigation, the Mail keys (Gmail/Apple Mail), text formatting, Money. - Also list browser-reserved keys per platform (extend the sourced reserved list in `registry.test.ts`), and which keys only work in an installed app window. ### Part 2: presets - Two presets: **Apple (macOS)** and **Windows & Linux**. Each registry entry gets per-preset keys where the conventions differ (for example, rename is Return on Apple and F2 on Windows & Linux), not only a modifier swap. `format.ts` renders hints from the chosen preset, not from the current device. - **Auto-selection:** at the User's first sign-in, the server stores the preset from the device used (the client sends its platform; macOS/iOS/iPadOS → Apple, everything else → Windows & Linux). Later sign-ins on other devices do not change it. The preset is a per-User preference, synced like other settings, with parity over API/CLI/MCP (#484). - The User can change it at any time in Settings → Shortcuts. ### Part 3: Settings → Shortcuts - It is a sub-section in the User half of Settings (DESIGN §50; coordinate with settings-50: if that job has landed, slot into its structure, else add the section where §50 puts it). - A preset chooser at the top, with user-friendly names and no jargon. - Below it, a searchable list grouped by `SHORTCUT_GROUPS`, rendered from the registry. It reuses `KeyboardShortcutsCard` rather than a second list. - Each group and entry is deep-linkable (the registry id is the anchor) with Copy link. - Rebinding is not in scope (registry "Variant B, later"). **Test:** - unit tests: preset key resolution, and that no entry lacks a key on either preset; - registry.test.ts: no preset binds a reserved key for that platform; - e2e: a User on a Linux user agent signs in first and sees Ctrl hints and F2 rename; they switch to Apple in Settings → Shortcuts and the hints change without a reload; a second sign-in from a Mac UA keeps the stored preset. - Attach screenshots of Settings → Shortcuts in both presets and both themes.
Author
Owner

Starting #542 on branch job/shortcuts-542, based on aa372eef6c (origin/dev). I am reading the existing registry, settings, and key handlers before the audit and implementation.

Starting #542 on branch job/shortcuts-542, based on aa372eef6c9312403f59a65d5b90cb3648ff52ed (origin/dev). I am reading the existing registry, settings, and key handlers before the audit and implementation.
Author
Owner

Owner correction (2026-09-30): a bare , was only a suggestion. Follow a widely used, published convention, and cite the sources:

  • Apple HIG / macOS standard menu: ⌘, opens Settings.
  • GNOME HIG standard shortcuts and KDE standard shortcuts: Ctrl+, opens Preferences. Microsoft apps (Office, VS Code, Teams) use the same.
    Rule: the primary key is ⌘, / Ctrl+, per preset (#542). Where a browser tab does not pass that key to the page, first test which browsers really reserve it (Safari, Chrome, Firefox on macOS, Windows and Linux; record the results). Use a fallback only for those, and pick it from a widely used web-app convention with a source (for example the "G then S" style go-to sequences), not an invention. Every choice in the Shortcuts audit follows the same rule.
**Owner correction (2026-09-30):** a bare `,` was only a suggestion. Follow a widely used, published convention, and cite the sources: - Apple HIG / macOS standard menu: **⌘,** opens Settings. - GNOME HIG standard shortcuts and KDE standard shortcuts: **Ctrl+,** opens Preferences. Microsoft apps (Office, VS Code, Teams) use the same. Rule: the primary key is ⌘, / Ctrl+, per preset (#542). Where a browser tab does not pass that key to the page, first test which browsers really reserve it (Safari, Chrome, Firefox on macOS, Windows and Linux; record the results). Use a fallback only for those, and pick it from a widely used web-app convention with a source (for example the "G then S" style go-to sequences), not an invention. Every choice in the Shortcuts audit follows the same rule.
Author
Owner

Audit finding: the current registry uses F2 as rename on every preset, Enter as open on every preset, and Cmd/Ctrl+Up as the parent-folder key. Apple Finder uses Return to rename, Command+Down to open, Command+Up for the parent, Space for Quick Look, and Command+Delete for Trash. Windows File Explorer and KDE Dolphin use F2, Enter, Alt+Up, and Delete. I am recording the source links in docs/shortcuts-audit.md and will make these bindings preset-specific.

Audit finding: the current registry uses F2 as rename on every preset, Enter as open on every preset, and Cmd/Ctrl+Up as the parent-folder key. Apple Finder uses Return to rename, Command+Down to open, Command+Up for the parent, Space for Quick Look, and Command+Delete for Trash. Windows File Explorer and KDE Dolphin use F2, Enter, Alt+Up, and Delete. I am recording the source links in docs/shortcuts-audit.md and will make these bindings preset-specific.
Author
Owner

Audit finding: Chrome and Edge reserve Ctrl+K for address-bar search, and Chrome documents the same key as search from anywhere on the page. The app registry used Ctrl+K for the Windows & Linux Search hint and action. I changed Windows & Linux app Search to / and selected-result actions to Shift+F10, and extended registry.test.ts with the sourced Ctrl+K reservation.

Audit finding: Chrome and Edge reserve Ctrl+K for address-bar search, and Chrome documents the same key as search from anywhere on the page. The app registry used Ctrl+K for the Windows & Linux Search hint and action. I changed Windows & Linux app Search to / and selected-result actions to Shift+F10, and extended registry.test.ts with the sourced Ctrl+K reservation.
Author
Owner

Shortcut audit finding (#542): AppToaster.svelte used unregistered Alt+T and F6 handlers. Browser source lists reserve F6 for browser focus, and Sonner Alt+T can move focus while the User types. The toaster now uses the Shift+T app.focusToasts registry entry, and its input guard matches that same entry.

Shortcut audit finding (#542): AppToaster.svelte used unregistered Alt+T and F6 handlers. Browser source lists reserve F6 for browser focus, and Sonner Alt+T can move focus while the User types. The toaster now uses the Shift+T `app.focusToasts` registry entry, and its input guard matches that same entry.
Author
Owner

Audit finding (2026-09-30): Firefox reserves / for Quick Find and Alt+1…9 for browser tabs; Edge reserves Ctrl+Y for History. Those bindings would have conflicted with the first Windows & Linux draft. I moved app Search to Ctrl+Shift+Space, Files list/grid to Ctrl+Shift+1/2, and redo to Ctrl+Shift+Z. The sourced reserved list and audit table now record these cases.

Audit finding (2026-09-30): Firefox reserves `/` for Quick Find and Alt+1…9 for browser tabs; Edge reserves Ctrl+Y for History. Those bindings would have conflicted with the first Windows & Linux draft. I moved app Search to Ctrl+Shift+Space, Files list/grid to Ctrl+Shift+1/2, and redo to Ctrl+Shift+Z. The sourced reserved list and audit table now record these cases.
Author
Owner

The first server OpenAPI build exposed a contract mismatch: ErrorCode has no InsufficientStorage variant, while existing User-settings routes return HTTP 507 with the shared Conflict code. I mapped the shortcut preference route to the same response shape. The corrected route is compiling now.

The first server OpenAPI build exposed a contract mismatch: `ErrorCode` has no `InsufficientStorage` variant, while existing User-settings routes return HTTP 507 with the shared `Conflict` code. I mapped the shortcut preference route to the same response shape. The corrected route is compiling now.
Author
Owner

The Files key audit found that the old Space selection branch ran before the registry's Quick Look binding, so Apple users could not use Finder's Space preview. The Files and Recent handlers now check the selected preset first: Apple opens Quick Look with Space; Windows & Linux keep Space for list selection and use Alt+P for preview.

The Files key audit found that the old Space selection branch ran before the registry's Quick Look binding, so Apple users could not use Finder's Space preview. The Files and Recent handlers now check the selected preset first: Apple opens Quick Look with Space; Windows & Linux keep Space for list selection and use Alt+P for preview.
Author
Owner

Audit finding: the registry comment and audit described macOS Command+Shift+5 as reserved for the screenshot toolbar, but registry.test.ts listed only Command+Shift+3 and Command+Shift+4. I added Command+Shift+5 to the sourced reserved list and added a regression assertion. No current app preset uses that key.

Audit finding: the registry comment and audit described macOS Command+Shift+5 as reserved for the screenshot toolbar, but `registry.test.ts` listed only Command+Shift+3 and Command+Shift+4. I added Command+Shift+5 to the sourced reserved list and added a regression assertion. No current app preset uses that key.
Author
Owner

Source scan found fixed app key handling outside the registry in focus trapping, resizable separators, floating-surface movement, form controls and editor menu/history code. The registry now has a Controls group and covers those handlers. I also moved Files paste into the registry so its modifier follows the saved preset.

The editor history handler accepted Ctrl+Y even though Edge reserves it for History. It now accepts the registered redo action only (Command+Shift+Z in Apple; Ctrl+Shift+Z in Windows & Linux). The collaborative-history regression test checks that Ctrl+Y is not consumed. Settings deep-link group coverage now includes Controls.

Evidence: apps/web/src/lib/shortcuts/registry.test.ts passes 15 tests; packages/editor/src/collaborationUndo.test.ts passes 4 tests; bun run check reports 0 errors and 0 warnings. Commit: c9c5b4f53.

Source scan found fixed app key handling outside the registry in focus trapping, resizable separators, floating-surface movement, form controls and editor menu/history code. The registry now has a Controls group and covers those handlers. I also moved Files paste into the registry so its modifier follows the saved preset. The editor history handler accepted Ctrl+Y even though Edge reserves it for History. It now accepts the registered redo action only (Command+Shift+Z in Apple; Ctrl+Shift+Z in Windows & Linux). The collaborative-history regression test checks that Ctrl+Y is not consumed. Settings deep-link group coverage now includes Controls. Evidence: `apps/web/src/lib/shortcuts/registry.test.ts` passes 15 tests; `packages/editor/src/collaborationUndo.test.ts` passes 4 tests; `bun run check` reports 0 errors and 0 warnings. Commit: c9c5b4f53.
Author
Owner

Found two stale key assumptions in the full web suite after the saved-preset behavior landed: the note shortcut binder test still expected hardware-relative Mod, and the 500-step collaborative redo storm still sent Ctrl+Y. The run reported 138/140 files and 921/923 tests passing. Updated the binder test to assert both saved presets and changed the stress test to send the Windows & Linux registry chord Ctrl+Shift+Z. Focused rerun passed: 2 files, 10 tests.

Found two stale key assumptions in the full web suite after the saved-preset behavior landed: the note shortcut binder test still expected hardware-relative `Mod`, and the 500-step collaborative redo storm still sent Ctrl+Y. The run reported 138/140 files and 921/923 tests passing. Updated the binder test to assert both saved presets and changed the stress test to send the Windows & Linux registry chord Ctrl+Shift+Z. Focused rerun passed: 2 files, 10 tests.
Author
Owner

The first production SPA E2E probe showed all 149 registry rows rendered, but the test timed out because CSS selectors such as #format.bold parse the registry ID's dot as a class separator. Replaced those selectors with a literal [id="format.bold"] locator helper. The stored preset and page content were correct; this was a test locator defect, not a UI defect.

The first production SPA E2E probe showed all 149 registry rows rendered, but the test timed out because CSS selectors such as `#format.bold` parse the registry ID's dot as a class separator. Replaced those selectors with a literal `[id="format.bold"]` locator helper. The stored preset and page content were correct; this was a test locator defect, not a UI defect.
Author
Owner

Production E2E passed against the real local server and production SPA: Linux first sign-in selected Windows & Linux with Ctrl and F2; a later Mac sign-in kept the stored preset; changing to Apple updated hints without a reload and changed rename to Return. CSP reports: 0.

Visual evidence is attached here at 390, 820 and 1440 px:

The initial UI probe also found that the E2E needed to wait for the shortcut row after route navigation; that readiness wait is now included.

Production E2E passed against the real local server and production SPA: Linux first sign-in selected Windows & Linux with Ctrl and F2; a later Mac sign-in kept the stored preset; changing to Apple updated hints without a reload and changed rename to Return. CSP reports: 0. Visual evidence is attached here at 390, 820 and 1440 px: - Apple, light: [390](https://git.kayg.org/attachments/49da39ff-94b8-4440-ad47-bc3e2fc39321), [820](https://git.kayg.org/attachments/408be34a-0477-43a2-897c-718c5d34367a), [1440](https://git.kayg.org/attachments/0f153de4-a2ac-496e-85bd-530bb24361a5) - Apple, dark: [390](https://git.kayg.org/attachments/446090a1-45a5-4586-8504-b56a3c86fc29), [820](https://git.kayg.org/attachments/f73139e7-619a-4fab-81ec-faa44434c949), [1440](https://git.kayg.org/attachments/277c3731-7bb4-494d-8e9c-291b48a43309) - Windows & Linux, light: [390](https://git.kayg.org/attachments/28669c8b-05e8-4ee6-b70b-8a0ad9ff471b), [820](https://git.kayg.org/attachments/81a29bcb-b5cb-4453-aa12-2221d7d0b9b0), [1440](https://git.kayg.org/attachments/9bf60fe5-0de9-4608-8631-296d37ca1bc8) - Windows & Linux, dark: [390](https://git.kayg.org/attachments/c345e57e-2329-4360-8791-8bb62a0e7f32), [820](https://git.kayg.org/attachments/6b60495a-09b0-4a0b-9221-dd0e691e0d91), [1440](https://git.kayg.org/attachments/86a599c9-32e6-4622-8c8b-ed7356173962) The initial UI probe also found that the E2E needed to wait for the shortcut row after route navigation; that readiness wait is now included.
Author
Owner

Adversarial finding: the new shortcut preference API operations were not classified in the fail-closed cross-User authorization matrix. The first adversarial run stopped before server probes at GET /api/v1/shortcuts/preferences (shortcuts_get_preferences). I added an explicit signed-in User policy for GET, PUT, and first-sign-in initialization, plus regression coverage that excludes anonymous, Share, and stale-session identities. The focused classification suite passes (5 tests); the real-server shortcut probe is running now.

Adversarial finding: the new shortcut preference API operations were not classified in the fail-closed cross-User authorization matrix. The first adversarial run stopped before server probes at `GET /api/v1/shortcuts/preferences (shortcuts_get_preferences)`. I added an explicit signed-in User policy for GET, PUT, and first-sign-in initialization, plus regression coverage that excludes anonymous, Share, and stale-session identities. The focused classification suite passes (5 tests); the real-server shortcut probe is running now.
Author
Owner

Completed

Implemented the shortcut audit and two saved presets for issue #542. First sign-in selects Apple on macOS/iOS/iPadOS and Windows & Linux on other platforms. Later sign-ins preserve the saved User preference. Settings → Shortcuts lets the User switch presets, search grouped registry entries, and copy deep links. Hints and key matching use the selected preset.

The audit is in docs/shortcuts-audit.md. The registry and platform resolution are in apps/web/src/lib/shortcuts/registry.ts, preset.ts, format.ts, and match.ts. Preference support is in crates/calternal-server/src/shortcuts.rs, the CLI/MCP integrations, and generated API contracts. The UI is in apps/web/src/routes/settings/shortcuts/ShortcutsSection.svelte and reuses KeyboardShortcutsCard.svelte. The change also updates app/editor key handlers, registry and sign-in e2e coverage, and the adversarial probe. No rebinding UI was added; the request leaves it out of scope.

Head: 0f797a4f9.

Gates

  • cargo fmt --check — exit 0; no output.
  • cargo clippy -p calternal-server --all-targets -- -D warnings — Finished \dev` profile [unoptimized + debuginfo] target(s) in 1m 35s`.
  • cargo test -p calternal-server — 96 passed; 0 failed; 3 ignored; tests finished in 16.67s.
  • cargo clippy -p calternal-cli --all-targets -- -D warnings — Finished \dev` profile [unoptimized + debuginfo] target(s) in 2.67s`.
  • cargo test -p calternal-cli — main tests: 28 passed; output-contract tests: 15 passed.
  • bun run check — svelte-check found 0 errors and 0 warnings.
  • bun run test — Test Files 140 passed (140); Tests 923 passed (923); Duration 174.93s.
  • Real-server shortcut adversarial run — exit 0; Cross-User classification gate: 331 operations classified; Shortcut preference adversarial probes passed. The probe found that the new endpoints lacked explicit cross-user authorization classification. Added the policy and a regression test before the successful run.

Visual and performance evidence

Attached 12 production-build screenshots: 390, 820, and 1440 px; both presets; light and dark themes. The Linux-first-sign-in e2e covers F2 rename, changing to Apple without reload, and retaining the selected preset on a later Mac sign-in.

The local route profile ran once. Shortcut preference GET: p50 11.9 ms / p95 33.5 ms over 50 successful requests. The shared Settings bundle is 507,888 bytes, 8.51% over the existing Settings route baseline of 468,067 bytes; follow-up issue #556 tracks reducing this growth. Route latency was measured on a heavily loaded local host (load averages 33.62/34.97/30.34 before and 28.73/28.68/28.75 after), so it is not a reliable comparison with the low-load baseline. Performance results and the follow-up are documented in the issue thread.

Decisions where DESIGN.md was silent

  • Store the preset at User.settings.shortcuts.preset through the existing User-settings writer; no schema migration is needed.
  • Map cmd to Command on Apple and Ctrl elsewhere; map alt to Option on Apple and Alt elsewhere. Do not use Ctrl+Alt because of AltGr.
  • Avoid browser-reserved Command/Ctrl+1…9: use Option-Command-1…5 for the Apple mode tray and Ctrl-Shift-1…5 for Windows & Linux; Files uses Ctrl-Shift-1/2.
  • Do not bind Command-W/Ctrl-W or either Preferences comma chord. Escape closes app surfaces; Settings stays available as a visible link.
  • Use Finder conventions for Apple rename/open/parent/delete (Return, Command-Down, Command-Up, Command-Delete) and Windows & Linux conventions (F2, Enter, Alt-Up, Delete). Quick Look is Space on Apple and Alt+P on Windows & Linux.
  • Use Shift-Command-Z for Apple redo and Ctrl-Shift-Z for Windows & Linux redo, avoiding Edge's Ctrl-Y History shortcut.
  • Use Ctrl-Shift-Space for Windows & Linux search. No shortcut depends on an installed-app window.

The final documentation-comment review and cargo fmt --check/bun run check passed after the last comment-only commits. No known functional gaps remain beyond rebinding being out of scope and the bundle-size follow-up in #556.

## Completed Implemented the shortcut audit and two saved presets for issue #542. First sign-in selects Apple on macOS/iOS/iPadOS and Windows & Linux on other platforms. Later sign-ins preserve the saved User preference. Settings → Shortcuts lets the User switch presets, search grouped registry entries, and copy deep links. Hints and key matching use the selected preset. The audit is in `docs/shortcuts-audit.md`. The registry and platform resolution are in `apps/web/src/lib/shortcuts/registry.ts`, `preset.ts`, `format.ts`, and `match.ts`. Preference support is in `crates/calternal-server/src/shortcuts.rs`, the CLI/MCP integrations, and generated API contracts. The UI is in `apps/web/src/routes/settings/shortcuts/ShortcutsSection.svelte` and reuses `KeyboardShortcutsCard.svelte`. The change also updates app/editor key handlers, registry and sign-in e2e coverage, and the adversarial probe. No rebinding UI was added; the request leaves it out of scope. Head: `0f797a4f9`. ## Gates - `cargo fmt --check` — exit 0; no output. - `cargo clippy -p calternal-server --all-targets -- -D warnings` — `Finished \`dev\` profile [unoptimized + debuginfo] target(s) in 1m 35s`. - `cargo test -p calternal-server` — `96 passed; 0 failed; 3 ignored`; tests finished in 16.67s. - `cargo clippy -p calternal-cli --all-targets -- -D warnings` — `Finished \`dev\` profile [unoptimized + debuginfo] target(s) in 2.67s`. - `cargo test -p calternal-cli` — main tests: `28 passed`; output-contract tests: `15 passed`. - `bun run check` — `svelte-check found 0 errors and 0 warnings`. - `bun run test` — `Test Files 140 passed (140); Tests 923 passed (923); Duration 174.93s`. - Real-server shortcut adversarial run — exit 0; `Cross-User classification gate: 331 operations classified`; `Shortcut preference adversarial probes passed`. The probe found that the new endpoints lacked explicit cross-user authorization classification. Added the policy and a regression test before the successful run. ## Visual and performance evidence Attached 12 production-build screenshots: 390, 820, and 1440 px; both presets; light and dark themes. The Linux-first-sign-in e2e covers F2 rename, changing to Apple without reload, and retaining the selected preset on a later Mac sign-in. The local route profile ran once. Shortcut preference GET: p50 11.9 ms / p95 33.5 ms over 50 successful requests. The shared Settings bundle is 507,888 bytes, 8.51% over the existing Settings route baseline of 468,067 bytes; follow-up issue #556 tracks reducing this growth. Route latency was measured on a heavily loaded local host (load averages 33.62/34.97/30.34 before and 28.73/28.68/28.75 after), so it is not a reliable comparison with the low-load baseline. Performance results and the follow-up are documented in the issue thread. ## Decisions where DESIGN.md was silent - Store the preset at `User.settings.shortcuts.preset` through the existing User-settings writer; no schema migration is needed. - Map `cmd` to Command on Apple and Ctrl elsewhere; map `alt` to Option on Apple and Alt elsewhere. Do not use Ctrl+Alt because of AltGr. - Avoid browser-reserved Command/Ctrl+1…9: use Option-Command-1…5 for the Apple mode tray and Ctrl-Shift-1…5 for Windows & Linux; Files uses Ctrl-Shift-1/2. - Do not bind Command-W/Ctrl-W or either Preferences comma chord. Escape closes app surfaces; Settings stays available as a visible link. - Use Finder conventions for Apple rename/open/parent/delete (Return, Command-Down, Command-Up, Command-Delete) and Windows & Linux conventions (F2, Enter, Alt-Up, Delete). Quick Look is Space on Apple and Alt+P on Windows & Linux. - Use Shift-Command-Z for Apple redo and Ctrl-Shift-Z for Windows & Linux redo, avoiding Edge's Ctrl-Y History shortcut. - Use Ctrl-Shift-Space for Windows & Linux search. No shortcut depends on an installed-app window. The final documentation-comment review and `cargo fmt --check`/`bun run check` passed after the last comment-only commits. No known functional gaps remain beyond rebinding being out of scope and the bundle-size follow-up in #556.
Author
Owner

Starting round 2 on job/shortcuts-542 at 0f797a4f9d3f38341e846c08565f0af38094c735, based on origin/dev cc25c441b7a974185622a1dee853cf38686d2b67 before the required final sync. I am tracing the current browser shortcut audit, preset UI and bundle entry points, then I will add the cross-browser reserved-key evidence and apply the requested UI/performance fixes.

Starting round 2 on `job/shortcuts-542` at `0f797a4f9d3f38341e846c08565f0af38094c735`, based on `origin/dev` `cc25c441b7a974185622a1dee853cf38686d2b67` before the required final sync. I am tracing the current browser shortcut audit, preset UI and bundle entry points, then I will add the cross-browser reserved-key evidence and apply the requested UI/performance fixes.
Author
Owner

Finding from the initial probe: the current audit labels Ctrl+K and Ctrl+E as browser-reserved, but a page-level capture listener received both real Playwright key presses in Chromium, Firefox and WebKit, set defaultPrevented, and kept the page open, focused, and on the same URL. This is headless Linux evidence; it does not exercise OS-level shortcuts or macOS browser chrome. I am adding the full reserved-list probe and will base the final audit rows on its recorded results.

Finding from the initial probe: the current audit labels Ctrl+K and Ctrl+E as browser-reserved, but a page-level capture listener received both real Playwright key presses in Chromium, Firefox and WebKit, set `defaultPrevented`, and kept the page open, focused, and on the same URL. This is headless Linux evidence; it does not exercise OS-level shortcuts or macOS browser chrome. I am adding the full reserved-list probe and will base the final audit rows on its recorded results.
Author
Owner

The headed Playwright probe ran 80 unique Windows & Linux chords in each of Chromium, Firefox and WebKit on Linux. Each browser delivered 77 to the page; the page called preventDefault() for all 77, and the probe observed no tab-count change, navigation, page close, page focus loss or window-size change. Ctrl+Shift+Delete, Ctrl+Tab and Ctrl+Shift+Tab did not reach the page in any of the three engines; the page cannot observe the browser or desktop action for those keys. The Apple probe ran Meta+K and Meta+comma in Chromium and WebKit on Linux; both keys reached the page and were canceled, with no page-visible action. This is not a native macOS or OS-shortcut test. The audit will list these results and keep the native/OS limits explicit.

The headed Playwright probe ran 80 unique Windows & Linux chords in each of Chromium, Firefox and WebKit on Linux. Each browser delivered 77 to the page; the page called `preventDefault()` for all 77, and the probe observed no tab-count change, navigation, page close, page focus loss or window-size change. Ctrl+Shift+Delete, Ctrl+Tab and Ctrl+Shift+Tab did not reach the page in any of the three engines; the page cannot observe the browser or desktop action for those keys. The Apple probe ran Meta+K and Meta+comma in Chromium and WebKit on Linux; both keys reached the page and were canceled, with no page-visible action. This is not a native macOS or OS-shortcut test. The audit will list these results and keep the native/OS limits explicit.
Author
Owner

The headed Playwright matrix has been rerun with eight sentinel tabs kept open for every chord. Chromium, Firefox, and WebKit each tested 80 Windows & Linux chords: 77 reached the page, and all 77 were canceled with preventDefault(); no page-visible browser action was observed. Ctrl+Shift+Delete, Ctrl+Tab, and Ctrl+Shift+Tab did not reach the page, so the page cannot cancel them and they remain reserved. Ctrl+K, Ctrl+E, Ctrl-comma, and Ctrl-slash reached and were canceled in every engine.

The Apple preset probe sent Meta+K and Meta-comma in Chromium and WebKit on Linux. Both reached and were canceled. This does not measure macOS browser chrome or OS shortcuts. The audit records these limits and uses Ctrl+K for Search, Ctrl+E for inline code, and Ctrl+K for editor links.

The headed Playwright matrix has been rerun with eight sentinel tabs kept open for every chord. Chromium, Firefox, and WebKit each tested 80 Windows & Linux chords: 77 reached the page, and all 77 were canceled with `preventDefault()`; no page-visible browser action was observed. Ctrl+Shift+Delete, Ctrl+Tab, and Ctrl+Shift+Tab did not reach the page, so the page cannot cancel them and they remain reserved. Ctrl+K, Ctrl+E, Ctrl-comma, and Ctrl-slash reached and were canceled in every engine. The Apple preset probe sent Meta+K and Meta-comma in Chromium and WebKit on Linux. Both reached and were canceled. This does not measure macOS browser chrome or OS shortcuts. The audit records these limits and uses Ctrl+K for Search, Ctrl+E for inline code, and Ctrl+K for editor links.
Author
Owner

Merge integration finding: #542 and #466 assigned files.move to different actions. I preserved the latest dev meaning (Move copied items here) and moved the focused arrow action to files.selection.move / files.selection.extend, with matching code, tests and audit rows. The incoming Files type-to-select work also changes New folder from C to Alt+Shift+N so letters stay available. This is the resolved behavior for the merged Settings registry.

Merge integration finding: #542 and #466 assigned `files.move` to different actions. I preserved the latest `dev` meaning (`Move copied items here`) and moved the focused arrow action to `files.selection.move` / `files.selection.extend`, with matching code, tests and audit rows. The incoming Files type-to-select work also changes New folder from C to Alt+Shift+N so letters stay available. This is the resolved behavior for the merged Settings registry.
Author
Owner

Adversarial round finding: the first run stopped before server startup because the merged authorization matrix had a bare if operation_id in SHORTCUT_PREFERENCE_OPERATIONS: at tests/adversarial/authz_matrix.py:304 (Python IndentationError). I added the missing signed-in User policy (standard, admin), matching the self-owned preference routes, and will rerun the matrix and real-server probes once.

Adversarial round finding: the first run stopped before server startup because the merged authorization matrix had a bare `if operation_id in SHORTCUT_PREFERENCE_OPERATIONS:` at `tests/adversarial/authz_matrix.py:304` (Python `IndentationError`). I added the missing signed-in User policy (`standard`, `admin`), matching the self-owned preference routes, and will rerun the matrix and real-server probes once.
Author
Owner

Adversarial update: the route-complete authorization check passed (334 OpenAPI operations classified; 39 admin operations matched Rust guards). The focused real-server shortcut profile passed: anonymous access, malformed/Unicode/extra-field inputs, oversized JSON, first-sign-in preservation, two-User isolation, and concurrent initialization and writes.

The default broad campaign exited 1 on unrelated merged-tree fixture issues: multiple older probes received 403 API is disabled in Settings → Apps before reaching their hostile-input assertions, and several browser sub-probes lacked CALTERNAL_SERVER_BIN in the first invocation. The broad run also recorded a Search staged-rebuild assertion expecting 200 while the server returned 202. I did not change those expectations or behavior in this issue. The #542-specific profile was then run with both server binary variables set and passed.

Adversarial update: the route-complete authorization check passed (334 OpenAPI operations classified; 39 admin operations matched Rust guards). The focused real-server shortcut profile passed: anonymous access, malformed/Unicode/extra-field inputs, oversized JSON, first-sign-in preservation, two-User isolation, and concurrent initialization and writes. The default broad campaign exited 1 on unrelated merged-tree fixture issues: multiple older probes received `403 API is disabled in Settings → Apps` before reaching their hostile-input assertions, and several browser sub-probes lacked `CALTERNAL_SERVER_BIN` in the first invocation. The broad run also recorded a Search staged-rebuild assertion expecting 200 while the server returned 202. I did not change those expectations or behavior in this issue. The #542-specific profile was then run with both server binary variables set and passed.
Author
Owner

Performance profile finding: the first route-profile run completed its measurement loops but failed while creating review screenshots. The Files readiness selector matched four rows, and the capture helper requires one target (apps/web/e2e/harness.mjs:247). I updated apps/web/e2e/route-perf.mjs to pass the first matching row to capture, with a short code comment, and committed it as 170b740f1. I am rerunning the profile once to collect the saved report.

Performance profile finding: the first route-profile run completed its measurement loops but failed while creating review screenshots. The Files readiness selector matched four rows, and the capture helper requires one target (`apps/web/e2e/harness.mjs:247`). I updated `apps/web/e2e/route-perf.mjs` to pass the first matching row to capture, with a short code comment, and committed it as `170b740f1`. I am rerunning the profile once to collect the saved report.
Author
Owner

Performance-profile finding: the measured global mode shortcut timed out when issued from Files. On this merged tree, #466 assigns Ctrl+Shift+1 to the focused Files view control, so the browser input reached the local Files action instead of nav.mode1. I changed the profile to issue the global mode chord from Calendar with focus cleared; this preserves the documented Files-local priority and keeps the mode-switch measurement meaningful.

Performance-profile finding: the measured global mode shortcut timed out when issued from Files. On this merged tree, #466 assigns `Ctrl+Shift+1` to the focused Files view control, so the browser input reached the local Files action instead of `nav.mode1`. I changed the profile to issue the global mode chord from Calendar with focus cleared; this preserves the documented Files-local priority and keeps the mode-switch measurement meaningful.
Author
Owner

Round 2 complete

Branch: job/shortcuts-542
Head: 8aeca0cd6142

Built

  • Added real Playwright key probes in Chromium, Firefox and WebKit. The audit now records the observed delivery results and cites GitHub, Slack and Linear’s Ctrl/Command+K convention. Search uses Ctrl+K on Windows/Linux and Command+K on Apple.
  • Matched the preset selector to Appearance with equal-width segments. Moved each group’s Copy link beside its heading; it appears on hover/focus and on touch.
  • Lazy-loaded the Settings Shortcuts section and the global shortcut help card. The shortcut section adds 4,296 gzip bytes over Appearance.
  • Preserved the latest origin/dev Files move behavior during integration. New-folder uses Alt+Shift+N so Ctrl+Shift+N remains available to the browser and C continues to type-to-select.
  • Attached screenshots for Apple and Windows & Linux at 390, 820 and 1440 px in both themes.

Bundle and local performance

The local route profile used 3 runs at 390/820/1440 px and 50 API samples. It ran on calternal-dev, not the perf VM. Load average rose from 17.43, 22.49, 21.24 to 31.51, 28.26, 24.92, so route timings are noisy.

  • Shared Settings (/settings/appearance): 508,963 gzip bytes (439,643 JS + 69,320 CSS), versus baseline 468,067: +40,896 bytes / +8.74%. This does not meet the requested ±1% target.
  • /settings/shortcuts: 513,259 gzip bytes, only 4,296 above Appearance. The section split works, but the shared Settings payload still exceeds the recorded baseline.
  • Shortcut preferences API: p50/p95 8.1/31.2 ms, 50/50 HTTP 200.
  • Local server idle: RSS 291,495,936 bytes, CPU 0.5%. Burst: 23,758 requests, all HTTP 200, p50/p95 8.7/34 ms; peak RSS 291,495,936 bytes, peak CPU 263.78%.
  • 5k-file folder route p50/p95: 390 px 3182/13434 ms, 820 px 3247/4197 ms, 1440 px 5621/7053 ms.

Browser and adversarial evidence

Windows/Linux probes ran 80 chords per browser. Chromium, Firefox and WebKit each delivered and canceled 77 page events; the page observed no browser actions. Ctrl+Shift+Delete, Ctrl+Tab and Ctrl+Shift+Tab were unobservable from page JavaScript in each engine. Apple’s Command+K and Command+, candidates were also dispatched in Chromium and WebKit, but this Linux run does not test macOS browser chrome or OS-reserved actions.

Shortcut E2E output:

PASS the global shortcut help capsule loads on demand and closes with Escape
PASS Linux first sign-in selects Windows & Linux, with Ctrl and F2 hints
PASS a Mac second sign-in preserves the User preset
PASS changing to Apple updates hints without reload, opens Search with Command+K, and uses Return for rename
CSP REPORTS shortcuts-542: 0 across 2 pages

The focused shortcut adversarial probe passed, including malformed/oversized input, Unicode fields, first-sign-in preset preservation, User isolation and concurrent initialization/writes. The merged-tree broad adversarial runner exited 1 on unrelated fixture setup/API-disabled responses and a Search probe expecting 200 but receiving 202; no existing expectation was changed. The authz classification gates passed: 334 operations classified; admin coverage: 39 reviewed operations.

Gates

$ cargo fmt --check
(exit 0; no output)

$ cargo clippy -p calternal-server --all-targets -- -D warnings
Finished dev profile [unoptimized + debuginfo] target(s) in 8m 20s

$ cargo test -p calternal-server
test result: ok. 96 passed; 0 failed; 3 ignored; 0 measured; 0 filtered out; finished in 16.07s

$ cargo clippy -p calternal-cli --all-targets -- -D warnings
Checking calternal-cli v0.0.1 (/home/kayg/Developer/calternal-wt/shortcuts-542/crates/calternal-cli)
Finished `dev` profile [unoptimized + debuginfo] target(s) in 34.77s

$ cargo test -p calternal-cli
test result: ok. 30 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.76s
test result: ok. 15 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.06s

$ bun run check
$ node scripts/check-type-tokens.mjs && node scripts/check-motion-tokens.mjs && svelte-kit sync && svelte-check --tsconfig ./tsconfig.json
Text sizes and UI shape values use shared role tokens.
UI transitions and animation options use shared motion tokens or documented exceptions.
Loading svelte-check in workspace: /home/kayg/Developer/calternal-wt/shortcuts-542/apps/web
Getting Svelte diagnostics...

svelte-check found 0 errors and 0 warnings

$ bun run test
Test Files  140 passed (140)
Tests  938 passed (938)
Duration 65.43s (transform 52%, import 18%, environment 16%, tests 10%, setup 3%)

Reserved-key E2E output:

SHORTCUT_PROBE {"engine":"windows-linux:chromium","host":"linux","probes":80,"pageReceived":77,"canceled":77,"pageVisibleBrowserActions":[],"unobservableFromPage":["control+delete+shift","control+tab","control+shift+tab"]}
SHORTCUT_PROBE {"engine":"windows-linux:firefox","host":"linux","probes":80,"pageReceived":77,"canceled":77,"pageVisibleBrowserActions":[],"unobservableFromPage":["control+delete+shift","control+tab","control+shift+tab"]}
SHORTCUT_PROBE {"engine":"windows-linux:webkit","host":"linux","probes":80,"pageReceived":77,"canceled":77,"pageVisibleBrowserActions":[],"unobservableFromPage":["control+delete+shift","control+tab","control+shift+tab"]}
SHORTCUT_PROBE {"engine":"apple:chromium","host":"linux","probes":2,"pageReceived":2,"canceled":2,"pageVisibleBrowserActions":[],"unobservableFromPage":[]}
SHORTCUT_PROBE {"engine":"apple:webkit","host":"linux","probes":2,"pageReceived":2,"canceled":2,"pageVisibleBrowserActions":[],"unobservableFromPage":[]}
PASS real-key probes for Windows & Linux reserved chords and explicit search/preferences candidates
LIMIT Mac preset chords were sent with Meta on Linux; this run does not test macOS browser chrome or OS-reserved actions.

Screenshots

Files and decisions

Main files: apps/web/src/lib/shortcuts/, apps/web/src/routes/settings/, apps/web/src/routes/+layout.svelte, apps/web/e2e/shortcuts-542.mjs, apps/web/e2e/shortcuts-reserved-keys-542.mjs, apps/web/e2e/route-perf.mjs, Files shortcut integrations in apps/web/src/lib/files/ and packages/ui/src/components/, crates/calternal-server/src/shortcuts.rs, CLI/MCP/API contract files, docs/shortcuts-audit.md, and tests/adversarial/.

Decisions beyond DESIGN: use the cited Ctrl/Command+K convention for Search; use Alt+Shift+N for New folder to avoid Chrome’s Ctrl+Shift+N and preserve type-to-select; retain the latest origin/dev meaning of files.move for copied items and give selected-list movement distinct IDs. Native macOS browser-chrome behavior remains untested in this Linux environment. Shared Settings bundle size is the known unresolved gap above.

Web build succeeded (✓ built in 59.17s). cargo clean removed 23558 files, 11.4GiB total; web build output was deleted. No screenshots were committed.

## Round 2 complete Branch: `job/shortcuts-542` Head: `8aeca0cd6142` ### Built - Added real Playwright key probes in Chromium, Firefox and WebKit. The audit now records the observed delivery results and cites GitHub, Slack and Linear’s Ctrl/Command+K convention. Search uses Ctrl+K on Windows/Linux and Command+K on Apple. - Matched the preset selector to Appearance with equal-width segments. Moved each group’s Copy link beside its heading; it appears on hover/focus and on touch. - Lazy-loaded the Settings Shortcuts section and the global shortcut help card. The shortcut section adds 4,296 gzip bytes over Appearance. - Preserved the latest `origin/dev` Files move behavior during integration. New-folder uses Alt+Shift+N so Ctrl+Shift+N remains available to the browser and C continues to type-to-select. - Attached screenshots for Apple and Windows & Linux at 390, 820 and 1440 px in both themes. ### Bundle and local performance The local route profile used 3 runs at 390/820/1440 px and 50 API samples. It ran on `calternal-dev`, not the perf VM. Load average rose from `17.43, 22.49, 21.24` to `31.51, 28.26, 24.92`, so route timings are noisy. - Shared Settings (`/settings/appearance`): **508,963 gzip bytes** (439,643 JS + 69,320 CSS), versus baseline **468,067**: **+40,896 bytes / +8.74%**. This does not meet the requested ±1% target. - `/settings/shortcuts`: **513,259 gzip bytes**, only 4,296 above Appearance. The section split works, but the shared Settings payload still exceeds the recorded baseline. - Shortcut preferences API: p50/p95 **8.1/31.2 ms**, **50/50 HTTP 200**. - Local server idle: RSS **291,495,936 bytes**, CPU **0.5%**. Burst: **23,758** requests, all HTTP 200, p50/p95 **8.7/34 ms**; peak RSS **291,495,936 bytes**, peak CPU **263.78%**. - 5k-file folder route p50/p95: 390 px **3182/13434 ms**, 820 px **3247/4197 ms**, 1440 px **5621/7053 ms**. ### Browser and adversarial evidence Windows/Linux probes ran 80 chords per browser. Chromium, Firefox and WebKit each delivered and canceled 77 page events; the page observed no browser actions. Ctrl+Shift+Delete, Ctrl+Tab and Ctrl+Shift+Tab were unobservable from page JavaScript in each engine. Apple’s Command+K and Command+, candidates were also dispatched in Chromium and WebKit, but this Linux run does not test macOS browser chrome or OS-reserved actions. Shortcut E2E output: ```text PASS the global shortcut help capsule loads on demand and closes with Escape PASS Linux first sign-in selects Windows & Linux, with Ctrl and F2 hints PASS a Mac second sign-in preserves the User preset PASS changing to Apple updates hints without reload, opens Search with Command+K, and uses Return for rename CSP REPORTS shortcuts-542: 0 across 2 pages ``` The focused shortcut adversarial probe passed, including malformed/oversized input, Unicode fields, first-sign-in preset preservation, User isolation and concurrent initialization/writes. The merged-tree broad adversarial runner exited 1 on unrelated fixture setup/API-disabled responses and a Search probe expecting 200 but receiving 202; no existing expectation was changed. The authz classification gates passed: `334 operations classified`; admin coverage: `39 reviewed operations`. ### Gates ```text $ cargo fmt --check (exit 0; no output) $ cargo clippy -p calternal-server --all-targets -- -D warnings Finished dev profile [unoptimized + debuginfo] target(s) in 8m 20s $ cargo test -p calternal-server test result: ok. 96 passed; 0 failed; 3 ignored; 0 measured; 0 filtered out; finished in 16.07s $ cargo clippy -p calternal-cli --all-targets -- -D warnings Checking calternal-cli v0.0.1 (/home/kayg/Developer/calternal-wt/shortcuts-542/crates/calternal-cli) Finished `dev` profile [unoptimized + debuginfo] target(s) in 34.77s $ cargo test -p calternal-cli test result: ok. 30 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.76s test result: ok. 15 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.06s $ bun run check $ node scripts/check-type-tokens.mjs && node scripts/check-motion-tokens.mjs && svelte-kit sync && svelte-check --tsconfig ./tsconfig.json Text sizes and UI shape values use shared role tokens. UI transitions and animation options use shared motion tokens or documented exceptions. Loading svelte-check in workspace: /home/kayg/Developer/calternal-wt/shortcuts-542/apps/web Getting Svelte diagnostics... svelte-check found 0 errors and 0 warnings $ bun run test Test Files 140 passed (140) Tests 938 passed (938) Duration 65.43s (transform 52%, import 18%, environment 16%, tests 10%, setup 3%) ``` Reserved-key E2E output: ```text SHORTCUT_PROBE {"engine":"windows-linux:chromium","host":"linux","probes":80,"pageReceived":77,"canceled":77,"pageVisibleBrowserActions":[],"unobservableFromPage":["control+delete+shift","control+tab","control+shift+tab"]} SHORTCUT_PROBE {"engine":"windows-linux:firefox","host":"linux","probes":80,"pageReceived":77,"canceled":77,"pageVisibleBrowserActions":[],"unobservableFromPage":["control+delete+shift","control+tab","control+shift+tab"]} SHORTCUT_PROBE {"engine":"windows-linux:webkit","host":"linux","probes":80,"pageReceived":77,"canceled":77,"pageVisibleBrowserActions":[],"unobservableFromPage":["control+delete+shift","control+tab","control+shift+tab"]} SHORTCUT_PROBE {"engine":"apple:chromium","host":"linux","probes":2,"pageReceived":2,"canceled":2,"pageVisibleBrowserActions":[],"unobservableFromPage":[]} SHORTCUT_PROBE {"engine":"apple:webkit","host":"linux","probes":2,"pageReceived":2,"canceled":2,"pageVisibleBrowserActions":[],"unobservableFromPage":[]} PASS real-key probes for Windows & Linux reserved chords and explicit search/preferences candidates LIMIT Mac preset chords were sent with Meta on Linux; this run does not test macOS browser chrome or OS-reserved actions. ``` ### Screenshots - Apple, light: [390](https://git.kayg.org/attachments/cdfccc7f-07f1-4d22-8030-fb1a09ebd281), [820](https://git.kayg.org/attachments/f05f55f5-6c92-49d1-88f6-0eac9bb8bb1f), [1440](https://git.kayg.org/attachments/88ddf76f-5755-4e47-9cb4-1457e55ad6cf) - Apple, dark: [390](https://git.kayg.org/attachments/016a8a85-4b67-4254-9950-2c9c0c8294de), [820](https://git.kayg.org/attachments/9e95f610-0cc6-430a-9cd6-8994ec2fcb9f), [1440](https://git.kayg.org/attachments/4f272eab-5d8e-4a10-b2c3-6c22d11782fd) - Windows & Linux, light: [390](https://git.kayg.org/attachments/8d1da20f-c079-4b0e-b072-9f767f1c1fe6), [820](https://git.kayg.org/attachments/873348f0-65d4-4aa4-89e4-7a03c81185d0), [1440](https://git.kayg.org/attachments/69874b89-1d6e-42b2-9af4-b717c336dea8) - Windows & Linux, dark: [390](https://git.kayg.org/attachments/22066e4f-c165-4343-a1a8-54a5a272615f), [820](https://git.kayg.org/attachments/c5c59737-911a-4cab-9737-c3e8c143f0ff), [1440](https://git.kayg.org/attachments/92af057a-321a-4c12-a063-da732bb0459c) ### Files and decisions Main files: `apps/web/src/lib/shortcuts/`, `apps/web/src/routes/settings/`, `apps/web/src/routes/+layout.svelte`, `apps/web/e2e/shortcuts-542.mjs`, `apps/web/e2e/shortcuts-reserved-keys-542.mjs`, `apps/web/e2e/route-perf.mjs`, Files shortcut integrations in `apps/web/src/lib/files/` and `packages/ui/src/components/`, `crates/calternal-server/src/shortcuts.rs`, CLI/MCP/API contract files, `docs/shortcuts-audit.md`, and `tests/adversarial/`. Decisions beyond DESIGN: use the cited Ctrl/Command+K convention for Search; use Alt+Shift+N for New folder to avoid Chrome’s Ctrl+Shift+N and preserve type-to-select; retain the latest `origin/dev` meaning of `files.move` for copied items and give selected-list movement distinct IDs. Native macOS browser-chrome behavior remains untested in this Linux environment. Shared Settings bundle size is the known unresolved gap above. Web build succeeded (`✓ built in 59.17s`). `cargo clean` removed `23558 files, 11.4GiB total`; web build output was deleted. No screenshots were committed.
Author
Owner

Static audit evidence for DESIGN §57 Shortcut presets:

The shortcut registry is shared, but its keys are interpreted for the current host: apps/web/src/lib/shortcuts/format.ts:13-18,150-161 maps the primary modifier using the detected platform, and apps/web/src/lib/shortcuts/match.ts:91-95 defaults matching to getPlatform(). The settings section list in apps/web/src/routes/settings/sections.ts has no Shortcuts page or shortcut preset group. There is no per-User preset stored or selected.

Expected: store an Apple or Windows & Linux preset per User and use it to render hints and match keys across devices. Regression idea: set Apple on one device, sign in from Linux, and confirm Apple hints and bindings remain active until the User changes the preset.

Static audit evidence for DESIGN §57 Shortcut presets: The shortcut registry is shared, but its keys are interpreted for the current host: apps/web/src/lib/shortcuts/format.ts:13-18,150-161 maps the primary modifier using the detected platform, and apps/web/src/lib/shortcuts/match.ts:91-95 defaults matching to getPlatform(). The settings section list in apps/web/src/routes/settings/sections.ts has no Shortcuts page or shortcut preset group. There is no per-User preset stored or selected. Expected: store an Apple or Windows & Linux preset per User and use it to render hints and match keys across devices. Regression idea: set Apple on one device, sign in from Linux, and confirm Apple hints and bindings remain active until the User changes the preset.
Author
Owner

Copy audit finding for Settings shortcut help

apps/web/src/lib/shortcuts/settingsShortcut.ts:74 returns In macOS Safari or Chrome, press {keys} if the browser takes Command+Comma. This names third-party browsers in a user-facing hint.

Use neutral wording, for example: If your browser uses Command+Comma, press {keys} instead. Keep the platform-specific key glyphs.

Test idea: on macOS, open the shortcut help where this fallback is needed and confirm the hint uses the Mac glyphs without a browser brand.

Copy audit finding for Settings shortcut help `apps/web/src/lib/shortcuts/settingsShortcut.ts:74` returns `In macOS Safari or Chrome, press {keys} if the browser takes Command+Comma.` This names third-party browsers in a user-facing hint. Use neutral wording, for example: `If your browser uses Command+Comma, press {keys} instead.` Keep the platform-specific key glyphs. Test idea: on macOS, open the shortcut help where this fallback is needed and confirm the hint uses the Mac glyphs without a browser brand.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#542
No description provided.