Skip to content

Latest commit

 

History

History
86 lines (74 loc) · 65.5 KB

File metadata and controls

86 lines (74 loc) · 65.5 KB

GitLab mobile-web parity tracker

This is the working inventory for the maintainer-approved expansion beyond the original 1.0 scope. It is not a claim that LabFox matches every GitLab web screen. GitLab behavior varies by version, tier, role, project settings, and feature flags. A route or API method proves only the named slice, not a whole feature area.

Baseline: dev at 32fe6e1 (2026-09-27). The roadmap records the original scope; AGENTS.md §9 records the expansion. Use GitLab's project feature catalog, project settings, and permissions to discover and verify work, not as a fixed denominator.

Progress accounting

  • Shipped baseline below means the named app slice is on dev. It does not mean the entire GitLab feature area is complete.
  • Known work packages are broader than PRs. Split each package into issue-sized slices before coding; add more packages as gaps are discovered.
  • Status moves Queued → In progress → In review → Shipped. Shipped requires tests, review approval, passing CI, and merge into dev. Use Blocked with a reason when tier, permission, API, or design constraints prevent progress.
  • Update the snapshot, evidence, and issue/PR links in the same PR that changes a row. Do not calculate a GitLab parity percentage from this incomplete list.

Snapshot (2026-10-05): 21 known work packages, 1 shipped, 11 in progress, 9 queued. This is a lower bound on remaining work, not 20 PRs or an ETA. The shipped baseline is excluded from that count.

Shipped baseline by workflow

Area Confirmed slice on dev Evidence Boundary
Accounts PAT/OAuth sign-in, self-hosted instance, account switching auth More version/role validation.
Productivity Home, to-do inbox/completion, issue notification subscriptions, project/issue/MR search home, inbox, issues, search Search scopes and broader notification settings.
Groups and projects Group/subgroup/project browsing, project overview and activity groups, projects Settings and management.
Repository Tree/files, branches, tags, commits; branch/tag creation repository, branches, tags Advanced repository operations.
Protection Project protected branch, tag, and environment rule browsing; group protected environment browsing branches, tags, project/group environments Rule writes.
Collaboration Issues, linked issues, issue title/description, due-date, label, assignee, milestone, confidentiality, and discussion-lock editing; MRs, comments, diff, approval/merge/rebase actions issues, MRs, diff Remaining metadata editing, boards, advanced review.
CI/CD execution Pipelines/jobs/logs/actions; schedules/run; environments/deployments pipelines, jobs, schedules Configuration, variables, runners, schedule edits.
Planning metadata Project/group milestones and labels; project/group member browsing milestones, labels, members Editing and administration.
Content and distribution Releases/assets, snippet reading, single-file project snippet creation and deletion, title and description editing, wiki page reading, Markdown creation and editing, packages/files, container repositories/tags releases, snippets, wiki, packages, registry Snippet file and visibility management; wiki deletion, history, and other management.

Known work packages

P0 preserves the developer workflow; P1 completes adjacent mobile-web tasks; P2 covers broad administrative surfaces. A package can need several issues and PRs. Keep it open until its full acceptance boundary is verified.

ID Priority Work package and acceptance boundary Status Tracking
MW-01 P1 Group protected environments: list/detail, deploy/approval rules, role/tier errors, narrow/wide tests. Shipped #326, PR #328
MW-02 P1 Project protection-rule creation, update, and removal with permission checks. In progress Protected tag unprotection #511, PR #512 shipped; protected tag creation #513, PR #514; protected branch creation #515, PR #516; protected branch unprotection #517, PR #518; force-push setting edit #519, PR #520 shipped; single-role merge access editing #521, PR #522 shipped; single-role push access editing #523, PR #524 shipped; project environment role-only creation #525, PR #526 shipped; project environment unprotection #527, PR #528 shipped; project environment deploy-role addition #529, PR #530 shipped; project environment deploy-role removal #531, PR #532. Other access-level editing and environment rule writes remain separate slices.
MW-03 P1 Project/group settings inventory and authorized general/repository/CI changes. Queued Issue needed
MW-04 P1 Member invitations, role/expiry changes, and removal for groups/projects. Queued Issue needed
MW-05 P0 Issue/work-item editing, metadata, types, and validated state transitions. In progress #329, PR #330 shipped title and description editing; #339, PR #340 shipped due-date editing; #341, PR #342 shipped issue-label editing; #343, PR #344 shipped assignee editing; #345, PR #346 shipped milestone editing; #347, PR #348 shipped confidentiality; #349, PR #350 shipped discussion locking. Type-conversion compatibility and remaining work-item actions need separate issues.
MW-06 P1 Boards and iterations: discover mobile-web behavior, then list/detail/mutations. Queued Issue needed
MW-07 P0 Advanced MR review: audit inline discussions/suggestions and finish missing review/approval flows. In progress #552, PR #553 prevent overlapping approval, merge, and other MR commands per project/IID, including while the repository resolves; failures release the reservation for explicit retry. #554, PR #555 add repository-session observation, pre-dispatch cancellation and late-result/error isolation, success-only current-session refresh/analytics/inbox effects, cancelled to-do outcomes without current-account toasts, and generation-owned duplicate reservations. Already dispatched server writes cannot be undone. #556, PR #557 add localized approval-read loading/error states, disabled approval toggles until successful reads, read-only retry, retained-data refresh protection, reactive new-session reads with stale-result isolation, and current-state toggle selection while preserving unavailable endpoint compatibility and independent merge controls. #558, PR #559 derives approval ownership from the authenticated account user ID and documented approved_by membership, ignores conflicting legacy current-user flags, and refreshes membership on account replacement. Regression coverage checks real toggle dispatch on mobile/desktop in both themes. #560, PR #561 validates successful approval responses before model parsing: explicit approver lists, complete user wrappers, positive integral user IDs, and nonnegative integral counts when present. Malformed reads become sanitized domain errors; status mapping precedes payload parsing. End-to-end widget tests verify blocked approval toggles and read-only recovery in both widths/themes, while unavailable endpoint compatibility remains intact. #562, PR #563 adds an account-bound, one-page MR discussion reader with generated grouped-note models and nullable resolution metadata. It preserves next-page headers without assuming totals or fetching ahead, rejects incomplete groups and nonadvancing cursors, and keeps HTTP failures distinct from sanitized parsing errors. Building on the API/models foundation, #564, PR #565 connects grouped MR replies to the detail-screen comments flow and aggregates resolution across all resolvable notes without claiming unknown states are resolved. The shared top-level composer refreshes discussion page one after posting; explicit load-more and read/page retries preserve groups and cursors. Account-bound reads/posts ignore late results, drafts reset when the session or resource changes, and resizing preserves the current draft. Five locales and narrow/compact/wide light/dark layouts are covered. #566, PR #567 adds the MR discussion reply API foundation: encoded thread/project paths, explicit IID routing, exact nonempty Markdown bodies, validated generated note responses, sanitized typed errors and no automatic authentication replay for the write. #568, PR #569 connects a localized inline reply composer to the selected discussion. One active reply preserves the top-level draft; cancel and write reservations prevent accidental overlaps. Replies preserve Markdown, retain failed drafts for explicit retry, refresh authoritative discussion page one and ignore old-session completions. Account/MR replacement resets the selection, resizing and pagination preserve current drafts, and a removed target restores top-level submission. Five locales and three widths in both themes are covered. #570, PR #571 adds known-state Resolve/Reopen controls and a strict account-bound mutation: encoded identity, explicit resolution, no redirects/authentication replay, and updated thread/state confirmation. Resolution shares comment/reply write reservations, preserves the top-level draft, retains localized permission/failure feedback for explicit retry, and refreshes discussions and MR detail only on current-session success. Unknown/nonresolvable states offer no toggle, and an active reply draft prevents resolution. #572, PR #573 preserves generated diff-note position metadata: original version SHAs, renamed paths, old/new text lines, multiline range endpoints and image/file types. Discussion reads, replies and resolution responses reject malformed or fractional coordinates before parsing; absent legacy fields remain unknown. #574, PR #575 adds paginated diff-version reads and an explicitly selected original unified-diff snapshot. Generated version/file models retain SHA triplets, renamed paths, raw text and nullable omission flags; absent files differ from empty snapshots. Identity/payload validation, status-first typed failures and no eager pagination or current-diff fallback are covered. #576 / PR #577 adds an expandable original-diff context beside positioned notes. It matches complete SHA triplets, both file paths and exact old/new single-line text coordinates; explicit older-page reads and read-only retries preserve drafts. The matched original hunk/line has an accessible non-color marker. Unsupported, omitted, truncated or ambiguous contexts remain unavailable without a current-diff fallback; account/resource replacement resets panels and stale reads cannot dispatch follow-up snapshots or affect the new session. Five locales, three widths and both themes are covered. Multiline context, positioned thread creation and suggestion application remain separate slices. #578, PR #580 adds the single-line positioned discussion creation API foundation: exact original SHA/path/line anchors, Markdown preservation, pre-dispatch argument validation, no redirects or authentication replay, created-thread confirmation and sanitized typed failures. The line selector/composer, multiline creation and suggestions remain separate. #579, PR #581 connects the latest authoritative diff-version snapshot to localized single-line selection and discussion creation. Exact original coordinates, indexed eligibility, shared write reservations, retained drafts, session/resource isolation and visible authoritative discussion inspection before uncertain-write retry are covered. The existing MR Changes route restores from project/IID; commit diffs stay read-only. Multiline context/creation and suggestion application remain separate. #582 / PR #583 adds typed immutable suggestion metadata to MR discussion responses, preserving original/replacement code, inclusive ranges, applied status and both documented applicability spellings. Missing states remain unknown; positive integral identities/coordinates, range order, response-wide uniqueness, content/flag types and alias agreement are validated before generated parsing. Suggestion presentation/application and multiline context/creation remain separate. #584 / PR #585 adds read-only suggestion previews beside user notes with exact selectable original/replacement code, nullable application/applicability states, localized ranges and empty/unavailable content, bounded code panes, retained drafts across resize/theme, and account/resource/metadata isolation. Suggestion application and batching remain separate. #586 / PR #587 adds the single-suggestion application API foundation with a positive global identity, exact optional commit messages, strict HTTP 200 and matching applied=true confirmation, shared metadata validation, typed sanitized failures, and no redirect/authentication replay. Application UI/session reservations and batch application remain separate. #588 / PR #589 adds explicit single-suggestion confirmation with literal code and optional commit messages, a fresh exact-discussion preflight, shared reservations including pagination, current-view/account isolation, confirmed-success detail/discussion/review-snapshot refreshes, and draft-preserving read-only recovery before uncertain-write retry. Five locales, three widths, both themes, keyboard insets and large text are covered. Batch application and multiline context/creation remain separate. #590 / PR #591 adds the batch suggestion API foundation: one account-bound request with immutable positive unique global IDs, exact optional messages, strict complete matching applied-state confirmation, preserved server order/nullable metadata, status-first sanitized failures, and no redirects, authentication replay or single-write fallback. Building on that API, #592 / PR #593 adds explicit loaded-target selection and multi-patch confirmation, deduplicated all-thread preflight before one batch, immutable selected identities, shared reservations, current-account/view isolation, complete staged read-only recovery, exact retained drafts and success-only refreshes. Five locales, three widths, both themes and compact keyboard/large-text layouts are covered; see the batch UI. #594 / PR #595 adds exact original multiline context with inclusive side-aware per-line markers, full filename-hash/raw-counter endpoint identity, optional coordinate support, complete contiguous hunk checks, duplicate/reversed/gapped-span rejection and retained draft/session behavior. Five locales, three widths, both themes and compact keyboard/large-text layouts are covered; see original context. #596 / PR #597 adds explicit original multiline selection and positioned creation, indexed complete contiguous range eligibility, exact endpoint request/response confirmation, inclusive accessible markers, retained drafts and complete-range recovery inspection. Repository identity is checked before dispatch and after completion to isolate replaced-session outcomes. Five locales, three widths, both themes and compact keyboard/large-text layouts are covered; see multiline creation. #598 / PR #599 adds the read-only pending-review draft foundation: generated private note/global MR/author identities, exact Markdown and nullable original position/reply/resolution metadata; strict one-page draft_notes reads with immutable server order, header pagination, sanitized malformed/status failures and normal read-only OAuth refresh. Account-bound repositories reject other-author pages; auto-disposed page consumers prevent stale pre-dispatch reads and ignore late outcomes. Presentation removes retained private rows immediately during account/client/instance changes, sign-out, loading and failed refresh. Draft mutations, aggregation and pending-review UI remain separate; no live GitLab/device validation is claimed. #600 / PR #601 adds the unpublished regular/original text-range draft creation API prerequisite: exact Markdown and recursive null omission, strict HTTP 201 and original-position/body confirmation, no redirect/OAuth replay/automatic retry/public-comment fallback, and sanitized typed/status-preserving failures. Account-bound repositories require and confirm captured author plus explicit global MR identity separately from route IID. Shared text/range validation preserves published discussion behavior. Replies, commit/image/file drafts, editing/deletion, publication and the pending-review controller/UI remain follow-up work; uncertain writes require authoritative inspection before an explicit retry, and no live GitLab/device validation is claimed. #602 / PR #603 adds read-only pending-review pagination with an authoritative global MR identity separate from route IID, immutable server order, explicit cursors through empty pages, optional totals and duplicate-load prevention. Mismatched author/MR identities, duplicate drafts and backward cursors reject the full result. Account/repository generations cancel obsolete dispatch and isolate initial/pagination success/errors. Presentation immediately removes retained private rows during account/client/instance/sign-out, refresh and failed reads; explicit retry restarts page one. Offset traversal is not an atomic snapshot and cannot authorize publication. The controller exposes no UI or mutation; see private pagination. #604 / PR #605 adds a read-only private pending-review panel on MR detail with exact selectable saved Markdown, known original metadata, localized loading/empty/partial/error states and explicit paging/refresh/retry. Guarded queries await fresh MR detail and verify route/global identity before dispatch, closing account/instance/client replacement requests ahead of detail; old private rows disappear during detail refresh and failed reads. Five locales, three widths, both themes, large text, long content and resize/theme preservation are covered with six synthetic captures. The panel sends no mutation or embedded image request and never infers/re-anchors original positions; see private review panel. Creation orchestration, uncertain-write recovery and publication remain follow-ups; no live GitLab/device validation is claimed. #606 / PR #607 adds regular private review save orchestration with fresh account-bound detail/global identity, shared discussion write/pagination reservations, exact Markdown and one confirmed create before route-scoped private-reader refresh. Uncertain writes block replay across ordinary refreshes and same-account client/repository replacement; explicit complete read-only inspection follows empty-page cursors, validates ownership/identity/uniqueness/order and waits for any dispatched write to settle. Old-session/view results and errors cannot expose private rows or dispatch further pages. The controller has no composer UI, positioned/reply save orchestration, editing/deletion or publication; see guarded saves. Recovery is in-memory and offset inspection cannot promise exactly-once creation after a client timeout; no live-instance/device validation is claimed. #608 / PR #609 adds a localized regular private-note composer on MR detail with exact Markdown, guarded one-save orchestration, retained failed input, complete visible inspection and separate acknowledgement before manual retry. Account/client/repository/resource replacement discards private input and snapshots; obsolete results cannot toast or expose data. Public drafts stay intact, and same-account reopen retains uncertain-write gating. Five locales, three widths, both themes and keyboard/large-text recovery are covered with twelve synthetic captures; see private composer. Positioned/reply/commit saves, editing/deletion and publication remain separate; no exactly-once or live-instance/device validation is claimed. #610 / PR #611 adds private draft update/delete API and account-bound repository foundations: exact Markdown, explicit original text-position preservation, strict 200 target/body/position confirmation and 204 deletion acknowledgement, positive project/IID/draft identities, captured author/global-MR checks and unchanged non-body metadata. Status-first plain-wire decoding preserves typed failures even for malformed JSON; redirects, authentication replay, fallback writes and automatic retry are disabled. Original line-code-only and unsupported update anchors fail before dispatch; owned opaque/image/file drafts can be deleted by identity. See maintenance contract. Fresh target/controller reservations, localized edit/delete confirmation/recovery and publication remain follow-ups; no live-instance/device validation is claimed. #612 connects private draft editing and confirmed deletion to the existing pending review panel. Shared discussion reservations, fresh detail/global identity and complete private-page comparison refuse stale or missing selected targets before one write. Uncertain results gate every private write; complete visible inspection and acknowledgement adopt a current target only for explicit retry, with obsolete session/view input and outcomes discarded. Five locales, keyboard/large text and twelve synthetic captures cover three widths and both themes; see maintenance UI. Publication and positioned/reply/commit creation remain separate; no atomic snapshot, conditional-write, durable recovery or live-instance/device guarantee is claimed. #614 adds whole-review publication: complete visible private-note confirmation and consent, a fresh full-set comparison before one strict-204 account-scoped bulk POST, and uncertainty that blocks private mutations until complete private/public inspection. Manual retries require new consent; session/view changes discard old confirmation and outcomes. Five locales and three widths in both themes are covered; see publication flow. Single-note publication, summary/reviewer-state controls and positioned/reply/commit creation remain separate. No automatic approval/merge, atomic server snapshot, durable recovery or live-instance/device guarantee is claimed. #616 adds private text line/range draft creation from the MR changes screen, fresh authoritative diff selection checks, immutable selected text, session/snapshot/origin isolation, preserved public input and explicit uncertain-save inspection. See private inline review. #618 adds selected saved-note publication through one strict-204 PUT, fresh exact target comparison, explicit consent and shared two-sided recovery. Unrelated saved notes remain private; a missing selected ID cannot publish another note. See single-note publication. #620 adds whole-review submission with an exact public summary, explicit reviewed/request-changes outcomes, complete current-reviewer reads, fresh reviewer preflight comparison and postwrite outcome verification. Partial or obsolete outcomes require private/public/reviewer inspection after actual write settlement and renewed consent, including selected-note recovery entry. Five locales, three widths, both themes and keyboard/large text are covered; see review submission. Formal approval remains separate; additional draft creation types are follow-ups. No atomic, durable recovery or live-instance/device guarantee is claimed. #622 adds private reply drafts on existing public discussion groups, exact target/body and non-resolution confirmation, a fresh selected-thread preflight, shared command reservations, and actual-settlement recovery that stages every private page together with the original public target. Missing targets stay missing; scoped recovery cannot clear publication/reviewer uncertainty. The localized shared composer preserves unsent public comments/replies and survives its own detail refresh or target removal. Five locales, keyboard/large text and twelve synthetic captures cover three widths and both themes; see private replies. Commit/image/file draft creation remains separate; no atomic, durable recovery or live-instance/device guarantee is claimed. #624 adds the private commit-text draft API/repository foundation: exact commit/body/original text position, matching head SHA, strict private acknowledgement and captured author/global MR validation, with no redirect/auth replay/retry. No user action is exposed; guarded commit selection, membership/freshness, shared reservations and recovery remain follow-ups. See commit-text draft API. Image/file creation and MW-07 remain in progress. #626 adds MR-scoped commit reads and complete advertised-page traversal, preserving unknown/root/ordered parent metadata. Strict SHA-1 identities, offset and same-resource Link cursor checks, cross-page duplicate rejection, immutable results and origin currency guards prevent partial or obsolete membership exposure. Read-only OAuth refresh remains account-bound. See MR commit membership reads. Original commit diff selection and guarded private-save/recovery UI remain follow-ups; no atomic snapshot or live-instance guarantee is claimed. #628 adds fixed-SHA literal commit diff pages and guarded advertised-page traversal, retaining raw paths/text and unknown omission flags. Shared offset validation preserves MR membership and confirms unified format plus exact route echoes. Diff file limits can stop pagination before full coverage; no original coordinate, membership or private-write preflight is inferred. See original commit diff reads. Authoritative fork/parent context and guarded literal selection/save/recovery UI remain follow-ups. #630 preserves separate nullable fork project identities and adds a fresh captured MR detail context read. Strict integer and route/global identity checks reject malformed or mismatched responses; unknown target context is never inferred, while unknown source metadata stays unknown. Currency guards discard obsolete results and typed failures; read-only authentication remains captured. See MR commit review context. Original parent/reference validation and guarded literal selection/save/recovery UI remain follow-ups; no atomic snapshot, original-coordinate or write-eligibility guarantee is claimed.
MW-08 P1 CI/CD configuration: pipeline editor, variables, triggers, schedule editing, and execution history. In progress #423, PR #424 cover timing editing; #425, PR #426 cover deletion; #427, PR #428 cover creation; #429, PR #430 cover ownership transfer; #431, PR #432 cover ref/active editing. These slices await review or maintainer merge. #433, PR #434 cover schedule-specific execution history in review: newest-first header pagination, retained rows/cursor on failed next pages, retry, run-now/refresh reload with inline errors, stale-request protection, and identifier-only pipeline navigation. History filters, variables/inputs, pipeline configuration editing, and triggers remain separate slices.
MW-09 P1 Wiki creation/editing/deletion and history with conflict handling. In progress #351, PR #352 shipped Markdown page creation; #353, PR #354 shipped editing with best-effort stale-draft detection; #373, PR #374 shipped deletion with confirmation and best-effort stale-page detection; #375, PR #376 shipped Markdown template selection. #377, PR #378 cover template listing and creation in review. Page history and atomic conflict protection remain. The documented wiki REST API can retrieve a page by version SHA but does not list page history.
MW-10 P1 Snippet creation/editing/deletion, files, and visibility. In progress #355, PR #356 shipped single-file project snippet creation; #357, PR #358 shipped deletion with confirmation; #359, PR #360 shipped title and description editing; #361, PR #362 shipped single-file content editing; #363, PR #364 shipped private/public visibility editing; #365, PR #366 shipped multi-file content editing; #367, PR #368 shipped adding a file; #369, PR #370 shipped deleting a file; #371, PR #372 shipped moving and renaming a file. Broader visibility management remains.
MW-11 P1 Release and milestone creation/editing/closure/deletion. In progress #379, PR #380 shipped project milestone creation with optional dates; #381, PR #382 shipped project milestone editing; #383, PR #384 shipped close/reactivate actions; #385, PR #386 shipped project milestone deletion; #387, PR #388 shipped group creation; #389, PR #390 shipped group editing; #391, PR #392 shipped group close/reactivate; #393, PR #394 shipped group deletion; #395, PR #396 shipped basic release creation. #397, PR #398 shipped release name and description editing. #399, PR #400 shipped release deletion. #401, PR #402 shipped asset link creation; #403, PR #404 shipped asset link deletion; #405, PR #406 shipped asset link name and URL editing. #407, PR #408 shipped asset link type editing. #409, PR #410 add direct download paths; #411, PR #412 add milestone association editing; #413, PR #414 add publication date editing; #415, PR #416 add creation dates; #417, PR #418 add creation-time milestone title entry; #419, PR #420 add an independent searchable project milestone picker. These six PRs are approved awaiting maintainer merge. #421, PR #422 cover direct-group milestone discovery infrastructure using typed namespace identity, server search, and retryable pagination in review; no group picker UI is connected yet. Project/group picker and form integration, plus direct path removal, remain.
MW-12 P1 Package/container management, cleanup, and protection by tier. In progress #439, PR #440 cover project package deletion in review with exact name/version confirmation, irreversible file-removal and conditional request-forwarding risk warnings, server-authoritative permission/protection errors, retained confirmation and retry, in-flight dismissal/duplicate blocking, success-only list/detail invalidation and list navigation, and generation protection against old package/file pages restoring deleted caches. #441, PR #442 cover individual file deletion in review: filename/package/version confirmation, irreversible removal and package-corruption warning, protected-package/permission errors with retry, pending dismissal/duplicate blocking, success-only parent/list refresh without leaving package detail, and stale page success/error protection. #443, PR #444 cover individual container tag deletion in review with exact tag/image-path confirmation, irreversible removal and retained-blob warning, server-authoritative protection/permission errors with retry, pending dismissal/duplicate blocking, success-only tag/repository refresh and repository navigation, and stale pagination success/error protection. #445, PR #446 cover asynchronous container repository deletion in review with exact path/all-tags confirmation, acceptance-only scheduled messaging (not completed removal), server/local scheduled-state resubmission guards, rejection retry, success-only parent cache refresh, and stale pagination protection. #447, PR #448 cover read-only container repository protection-rule browsing in review: encoded project-path API, generated nullable/unknown-role DTO, ID-restorable route and registry entry, push/delete minimum roles without inferring current access, refreshable empty/data states, permission/version errors with retry, and viewport/theme/privacy tests. #449, PR #450 cover explicit bulk tag cleanup criteria, safe retention defaults, typed retry errors, strict asynchronous acceptance, duplicate/dismissal guards, success-only refresh and stale-page protection in review. #451, PR #452 cover read-only tag protection rule browsing with generated nullable/unknown-role DTOs, encoded project paths, a static ID-restorable route, registry entry, conservative minimum-role labels, refreshable empty/data states, permission/version retry and viewport/theme/privacy coverage in review. #453, PR #454 cover read-only project-wide cleanup policy inspection using project GET, generated nullable settings, modern/legacy pattern precedence, explicit absent/empty/unknown values, localized timing/count/date displays, account-aware refresh, static ID-restorable routing and viewport/theme/privacy/error coverage in review. #455, PR #456 cover enabled-only activation changes with explicit project/criteria confirmation, best-effort stale-settings checks, a reported-criteria enable guard, pending duplicate/dismissal blocking, typed reload/retry and acceptance-only success/policy refresh in review. #457, PR #458 cover cadence-only editing with five documented intervals, explicit current criteria confirmation, unknown-current preservation, unreported-criteria blocking, best-effort stale-settings checks, retained retry selection, pending dismissal/duplicate blocking and acceptance-only refresh in review. #459, PR #460 cover integer keep-count-only editing with six documented choices, explicit current criteria and lower-retention risk confirmation, unknown-current preservation, unreported-criteria blocking, best-effort stale-settings checks, retained retry selection, pending dismissal/duplicate guards and acceptance-only policy refresh in review. #461, PR #462 cover age-limit-only editing with eleven documented duration codes, explicit current criteria and shorter-age risk confirmation, unknown-current preservation, unreported-criteria blocking, best-effort stale-settings checks, retained retries, pending dismissal/duplicate guards and acceptance-only policy refresh in review. #463, PR #464 cover modern delete-pattern-only editing with explicit current criteria and broadening-risk confirmation, exact whitespace/backslash preservation, legacy effective-pattern comparison, server-authoritative RE2 validation with retained editable drafts, best-effort stale-settings checks, pending duplicate/dismissal guards and acceptance-only policy refresh in review. #465, PR #466 cover nonblank keep-pattern-only replacement with narrowing-protection risk confirmation, exact RE2 input preservation, server-authoritative validation with editable retry, reported-empty versus unreported-pattern guards, best-effort stale-settings checks, pending duplicate/dismissal blocking and acceptance-only policy refresh in review. #467, PR #468 cover explicit keep-pattern clearing with empty-string-only project PUT, project-wide deletion risk acknowledgement, complete reported nonempty-pattern guards, stale-policy reload/reconfirmation, pending dismissal/duplicate blocking, retained retry and acceptance-only policy refresh in review. #469, PR #470 cover disabled-first policy creation with complete documented criteria, conservative visible defaults, exact pattern preservation, explicit risk acknowledgement reset by edits, generated field-presence snapshots distinguishing null from omitted data, best-effort re-read guards against overwriting existing policies, pending duplicate/dismissal blocking, retained validation retries and acceptance-only snapshot refresh in review. #471, PR #472 cover repository protection-rule deletion with exact project/rule/pattern and minimum-role confirmation, explicit protection-loss acknowledgement, best-effort stale/missing/ambiguous rule checks, explicit reload and renewed acknowledgement, pending duplicate/dismissal guards, permission/version retry, strict 204 acceptance and success-only rule-list refresh in review. #473, PR #474 cover repository protection-rule creation with exact pattern preservation, explicit optional push/delete role selection and at-least-one-role validation, wildcard/operation-scope acknowledgement reset by edits, pending dismissal/duplicate guards, retained editable validation and permission retries, strict 201 acceptance with confirmed response criteria, safe malformed-response errors and success-only rule-list refresh in review. #475, PR #476 cover path-pattern-only rule editing with exact rule/current-role confirmation, preserved role fields, exact draft text and impact acknowledgement reset by edits, best-effort full-rule stale checks, explicit reload/reconfirmation, pending dismissal/duplicate guards, retained editable server validation and permission retry, strict 200 with confirmed response criteria and success-only rule-list refresh in review. The review follow-up maps malformed successful list payloads to safe domain errors and rejects partially parsed rule lists. #477, PR #478 cover minimum-push-role-only editing with three supported choices, retained path/delete settings, lower-role risk acknowledgement reset by edits, conservative unknown-current blocking, best-effort full-rule preflight checks, explicit reload/reconfirmation, pending input/dismissal/duplicate guards, retained validation/permission retries, strict 200 with confirmed response criteria and success-only rule-list refresh in review. PR #478 is approved but remains unmerged. #479, PR #480 cover minimum-delete-role-only editing with supported choices, exact path/push-role preservation, deletion-access and cleanup-workflow risk acknowledgement reset by edits, conservative unknown-current blocking, best-effort full-rule preflight checks, explicit reload/reconfirmation, pending input/dismissal/duplicate guards, retained validation/permission retries, strict 200 response confirmation and success-only rule-list refresh in review. PR #480 is approved but remains unmerged. #481, PR #482 cover push-role-only restriction clearing with supported current/remaining-delete guards, exact path/delete-role retention, protection-loss acknowledgement, best-effort frozen-rule preflight checks, explicit reload/reconfirmation, pending dismissal/duplicate guards, retained validation/permission retries, strict 200 and explicit cleared-field confirmation accepting null/empty values, and success-only rule-list refresh in review. PR #482 is approved but remains unmerged. #483, PR #484 cover delete-role-only restriction clearing with supported current/remaining-push guards, all nine supported-role combinations, exact path/push-role retention, deletion-protection-loss acknowledgement, best-effort frozen-rule preflight checks, explicit reload/reconfirmation, pending dismissal/duplicate guards, retained validation/permission retries, strict 200 and explicit cleared-field confirmation accepting null/empty values, and success-only rule-list refresh in review. PR #484 is approved but remains unmerged. #485, PR #486 cover tag protection-rule creation (GitLab 18.8+) with exact tag-glob preservation, both explicitly required roles, all nine supported-role combinations, project-wide wildcard/workflow-impact acknowledgement reset after edits, pending edit/dismissal/duplicate guards, retained editable validation/permission retries, strict 201 and exact response confirmation, safe malformed create/list response errors, and success-only tag-rule-list refresh in review. PR #486 is approved with passing CI but remains unmerged. #487, PR #488 cover tag protection-rule deletion in review (GitLab 18.9+) with exact project/rule/glob and minimum-role confirmation, explicit project-wide protection-loss acknowledgement, best-effort full-rule re-read checks, stale/missing/duplicate blocking with explicit reload and renewed acknowledgement, pending dismissal/duplicate guards, retained validation/permission retries, strict HTTP 204 and success-only tag-rule-list refresh. It does not delete images or tags. #489, PR #490 cover tag-glob-only editing in review (GitLab 18.9+) with exact project/rule/current-glob and retained-role confirmation, project-wide protection-impact acknowledgement reset after edits, exact draft preservation, best-effort frozen full-rule preflight checks, explicit reload/reconfirmation, pending edit/dismissal/duplicate guards, retained editable validation/permission retries, strict HTTP 200 with exact response confirmation, and success-only tag-rule-list refresh. #491, PR #492 cover minimum-push-role-only editing in review (GitLab 18.9+) with three supported choices, exact tag-glob/delete-role preservation, lower-role and workflow-impact acknowledgement reset after edits, unknown-current blocking with explicit reload recovery, best-effort frozen full-rule preflight checks, explicit reload/reconfirmation, pending input/dismissal/duplicate guards, retained editable validation/permission retries, strict HTTP 200 with complete response confirmation, and success-only tag-rule-list refresh. #493, PR #494 cover minimum-delete-role-only editing in review (GitLab 18.9+) with three supported choices, exact tag-glob/push-role preservation, deletion-access and cleanup-workflow impact acknowledgement reset after edits, unknown-current blocking with explicit reload recovery, best-effort frozen full-rule preflight checks, explicit reload/reconfirmation, pending input/dismissal/duplicate guards, retained editable validation/permission retries, strict HTTP 200 with complete response confirmation, and success-only tag-rule-list refresh. Saving a role does not delete tags or images. #495, PR #496 cover push-restriction-only clearing in review (GitLab 18.9+) with supported current/remaining-delete guards, all nine supported-role combinations, exact tag-glob/delete-role preservation, project-wide protection-loss acknowledgement, best-effort frozen full-rule preflight checks, explicit reload/reconfirmation and unsupported-rule reload recovery, pending dismissal/duplicate guards, retained validation/permission retries, strict HTTP 200 with an explicitly present cleared push field (null/empty) and exact retained criteria, and success-only tag-rule-list refresh. #497, PR #498 cover delete-restriction-only clearing in review (GitLab 18.9+) with supported current/remaining-push guards, all nine supported-role combinations, exact tag-glob/push-role preservation, project-wide deletion-protection-loss acknowledgement, best-effort frozen full-rule preflight checks, explicit reload/reconfirmation and unsupported-rule reload recovery, pending dismissal/duplicate guards, retained validation/permission retries, strict HTTP 200 with an explicitly present cleared delete field (null/empty) and exact retained criteria, and success-only tag-rule-list refresh. Clearing does not delete tags or images. #499, PR #500 cover authenticated read-only GraphQL query transport in review as the immutable-tag prerequisite: instance/subpath-derived endpoint, shared Dio and OAuth refresh, endpoint-scoped PAT-to-Bearer header conversion without changing REST defaults, explicit named-query selection and JSON variables, strict HTTP 200 with fail-closed error/partial/malformed envelopes, preserved nullable resource fields, and sanitized typed HTTP/transport failures. #501, PR #502 cover read-only immutable-tag rule browsing in review with REST project-ID/full-path identity resolution, a GraphQL projection retaining opaque IDs and required immutable flags, complete cursor scanning before filtering, repeated-cursor/duplicate-ID/partial-page rejection, nullable-resource unavailable handling, an ID-restorable static route and registry entry even for empty image lists, refreshable loading/data/empty/error states, reactive account isolation, and viewport/theme/privacy tests. #503, PR #504 cover the mutation-transport safety prerequisite in review: explicitly selected named mutation documents and JSON variables, shared instance/subpath/authentication routing, no automatic OAuth refresh/replay, no followed mutation redirects, strict response envelopes and sanitized single-attempt HTTP/transport/partial failures while query/REST refresh stays unchanged. Resource-specific immutable creation and deletion remain separate slices; no creation UI, rule mutation endpoint, or per-tag access inference is shipped by these foundations. #505, PR #506 cover immutable-rule creation in review: exact RE2 draft preservation and a 100-character limit, project-wide overwrite/deletion/cleanup and manifest-deletion impact acknowledgement, explicit null push/delete mutation roles, duplicate-pattern preflight, session checks before dispatch and after completion, pending input/dismissal/duplicate blocking, strict empty payload errors and exact immutable response confirmation, retained drafts with mandatory fresh-list inspection before any manual retry, account-change dialog locking, and five-locale mobile/tablet/desktop light/dark coverage. Independent read/mutation prerequisites are included; 1,085 app/API/model tests pass and analysis is clean. Review, CI, and maintainer merge are still required. #507, PR #508 cover immutable-rule deletion in review with exact project/global-rule-ID/pattern confirmation, project-wide overwrite/delete/cleanup and last-rule manifest-protection-loss acknowledgement, complete frozen-rule preflight, no automatic mutation replay or redirect, strict empty payload errors and exact deleted-rule confirmation, mandatory fresh reload/reconfirmation after any failed or uncertain request, missing/changed/ambiguous/mutable-rule guards, pre-dispatch and completion session isolation, pending input/dismissal/duplicate blocking, and five-locale viewport/theme tests. No images or tags are deleted. All 1,087 app/API/model tests pass and analysis is clean; CI, review, and maintainer merge remain required. #509, PR #510 cover optional activation in review at cleanup-policy creation: disabled defaults, exact criteria, project-wide scheduled deletion acknowledgement reset by edits, session-bound confirmation and preflight/completion guards, pending input/dismissal/duplicate blocking, retained validation retries with fresh absence checks, sanitized malformed responses, and five-locale viewport/theme coverage. Atomic create-only semantics remain a separate limitation.
MW-13 P2 Security: inventory and implement vulnerability, policy, and scan views by role. Queued Issue needed
MW-14 P2 Analytics: inventory project/group reports and implement mobile layouts. Queued Issue needed
MW-15 P2 Infrastructure/Kubernetes: inventory current pages and API capabilities first. Queued Issue needed
MW-16 P2 Instance/group administration and runner inventory/actions, role-gated. Queued Issue needed
MW-17 P1 Broader search scopes, filters, and deep-link coverage. Queued Issue needed
MW-18 P0 Cross-cutting comparison by role, tier, self-hosted version, and viewport; record every missing action. Queued Issue needed
MW-19 P0 Issue/MR notification subscriptions and to-do shortcuts, including idempotent actions and error states. In progress #331, PR #332 shipped issue subscriptions; #333, PR #334 shipped issue to-do creation; #335, PR #336 cover MR subscriptions; #337, PR #338 shipped MR to-do creation.
MW-20 P0 Project pipeline browsing: pagination, filters, and child-pipeline discovery. In progress #435, PR #436 shipped newest-first header pagination, load more through empty pages, retained rows/cursor on failure, retry, duplicate/stale-request protection, refreshable empty state, and identifier-only detail navigation. #437, PR #438 shipped retry/cancel list refresh, success-only invalidation, pending duplicate-command blocking, and real retry after failure. #536, PR #537 add eight stable server-side status filters with a clearable All statuses option, project-scoped selection, page-one reset, filtered continuation/retry/refresh, late response isolation, preserved selection after retry/cancel, and five-locale narrow/tablet/wide light/dark tests. #538, PR #539 add exact branch/tag filtering combined with status, explicit Apply/Clear/Cancel draft controls, preserved pagination/retry/refresh/action filters, stale-response isolation, and localized responsive coverage. #540, PR #541 add eight common source filters, explicit child-pipeline discovery via parent_pipeline, a GitLab 17.0 compatibility hint, and preserved status/ref/source selection with race protection. #542, PR #543 add paginated downstream traversal from pipeline detail using trigger jobs, 404-only legacy route compatibility, nullable target metadata, identifier-only navigation to the correct project, independent loading/error/retry states, stale-response protection, and refresh after successful actions. #544, PR #545 add immediate upstream/parent lookup through the authenticated GraphQL transport, source project/global-pipeline identity validation, typed global-ID navigation without iid or URL inference, nullable visibility handling, independent loading/error/retry states, account isolation, and successful action/pull refresh. Recursive relationship graph rendering remains separate.
MW-21 P0 Pipeline job browsing: status filtering, retry-attempt visibility, and recovery/navigation across large pipelines. In progress #546, PR #547 add eight common server-side job status filters, clearable unfiltered browsing, scope preservation across every header page, project/pipeline-scoped selection, explicit error retry, filtered-empty state, preserved refresh/action filters, stale-response/account isolation, and localized responsive coverage, including bounded long status labels with full semantic names. #548, PR #549 add optional all-attempt browsing with include_retried=true on every jobs page, combined status filtering, distinct localized job IDs and exact-attempt navigation, retained refresh/retry/action selection, stale-response isolation, and five-locale responsive coverage. Latest jobs remains the default and omits the parameter. Returned attempts are never collapsed by name or assigned inferred retry labels; #550, PR #551 add one-page initial job loading, explicit cursor-based continuation through empty pages, partial-list guidance, retained rows/cursors and sanitized retry after continuation failure, ID-only deduplication, both filter preservation, generation checks before dispatch and after completion, stale success/error/account/logout/disposal isolation, and localized responsive coverage. Live-instance validation across roles and versions remains.

Procedure for the next slice

  1. Verify current GitLab documentation and mobile-web behavior. Record tier, role, API, and feature-flag requirements in an issue and refine its row here.
  2. Use one issue, one branch from dev, and one PR into dev. Write a failing behavior test before implementation. Keep one responsive UI across platforms.
  3. Test parsing, pagination, domain errors, empty states, deep links, and narrow and wide widths as applicable. Run formatting, analysis, and package/app tests.
  4. Link the PR and move the row to In review. Move it to Shipped only after approval, passing CI, and merge. Add discovered gaps as new rows rather than silently expanding the definition of done.