fix(frontend): harden owner action confirmation
This commit is contained in:
@@ -49,3 +49,17 @@
|
||||
- E2E remains environment-blocked until the Playwright Chromium browser is installed.
|
||||
- Existing Vitest runs emit pre-existing MSW unmatched-request and dialog-ref warnings; all
|
||||
assertions pass and this task does not modify those shared test/UI primitives.
|
||||
|
||||
## Review remediation
|
||||
|
||||
- A post-commit review correctly identified that matching `displayName` must never establish
|
||||
ownership. The predicate now skips confirmation only when `session.author` exactly equals
|
||||
`principal.subject`; all display-name matches and missing authors are conservative
|
||||
cross-owner actions.
|
||||
- Added RED/GREEN regressions where two principals share display name `Alice` but have distinct
|
||||
subjects: both delete (with another session present, so select-all cannot mask the guard) and
|
||||
archive require confirmation.
|
||||
- Added `aria-pressed` to the My sessions / All sessions controls and asserts their selected state
|
||||
before and after switching.
|
||||
- Remediation verification: focused regressions passed; full frontend Vitest (44 files / 305
|
||||
tests), `npx tsc -b`, `npm run build`, and `git diff --check` all passed.
|
||||
|
||||
Reference in New Issue
Block a user