Skip to content

feat(merge_requests): publish entire pending reviews with visible recovery - #615

Merged
sjungwon03 merged 1 commit into
devfrom
feat/614-publish-pending-review
Oct 5, 2026
Merged

sjungwon03 merged 1 commit into
devfrom
feat/614-publish-pending-review

Conversation

@sjungwon03

Copy link
Copy Markdown
Member

Summary

Saved private MR notes now offer Publish pending review. The confirmation reads all private pages, shows every note, and requires explicit consent to make the entire pending review public. Added/removed notes or changed modeled metadata fail a fresh complete comparison before the sole bulk-publication request. Publication does not approve or merge the MR.

An uncertain outcome blocks every private mutation until explicit complete inspection of both saved notes and current public discussions. The inspection waits for a dispatched request to actually settle and stages all pages before adopting any result. Reopening or refreshing does not authorize replay; a new publication requires new consent and another full comparison. Private compose/edit/delete dialogs direct the user to this recovery flow.

Closes #614

Validation

  • dart format .: 934 files, no outstanding changes
  • flutter analyze: no warnings
  • flutter test: 6,718 tests across all five packages (app 3,821; design system 127; API 2,589; models 176; secure storage 5)
  • No model changes; localization delegates regenerated with flutter gen-l10n
  • 143 new behavioral regressions: strict-204 transport, captured repository/global identity, complete snapshot comparison, shared discussion reservation, stale account/client/repository/view cancellation, uncertainty across refresh, settlement waits, staged private/public recovery, consent and cross-dialog recovery direction
  • Test-first missing endpoint/control failures reproduced. Initial public-read recovery, final-success account-change, last-page recovery cancellation and missing cross-dialog guidance failures reproduced before fixes
  • Five locales, 390/800/1200 widths in both themes, large text and keyboard insets; twelve synthetic publication/recovery captures rendered and inspected. No live-instance or physical-device validation

Checklist

  • Targets dev, links one issue, Conventional Commit with DCO sign-off
  • Test-first behavior and documentation updated
  • Narrow/wide layouts and light/dark themes checked
  • No dependencies, models, disk persistence or analytics added
  • Dummy identities/tokens only; no real credentials, private instance addresses or confidential code
  • English repository source/docs/review; other languages only in translations and generated delegates

Screenshots

All twelve captures

Publication, mobile light Recovery, desktop dark
Publication Recovery

Notes for reviewers

The official Draft Notes API bulk endpoint publishes all pending notes for the authenticated user. The request sends no summary, reviewer-state, internal flag, selected-ID list, approval or merge command. It uses one POST, disables redirects and OAuth replay, preserves typed status errors before decoding, and acknowledges only 204.

The preflight compares modeled saved-note state, not an atomic or conditional server snapshot. Notes saved from another client after comparison may also be included; the dialog explicitly explains this. Identical text or missing notes cannot prove which uncertain attempt succeeded. Dispatched server writes cannot be undone, and recovery remains session-scoped memory without durable or exactly-once claims. Single-note publication, summary/reviewer-state controls and positioned/reply/commit draft creation remain separate slices. MW-07 stays in progress.

…overy

Confirm complete account-bound saved notes before one bulk publication and require two-sided inspection plus renewed consent after uncertain outcomes.

Signed-off-by: sjungwon03 <sjungwon03@gmail.com>
@sjungwon03
sjungwon03 marked this pull request as ready for review October 5, 2026 13:02
@github-actions github-actions Bot added area:api packages/gitlab_api — GitLab REST/GraphQL client area:ui Screens and feature UI area:docs AGENTS.md, .agents/, README and friends feat New feature labels Oct 5, 2026

@sjungwon03-ai sjungwon03-ai left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review of commit 5d78fdd: Reviewed the full diff and publication contract; no actionable blockers remain. The account-scoped bulk endpoint sends one body-free POST, disables redirects and OAuth replay, requires 204, and preserves sanitized typed failures before decoding. The immutable confirmation is bound to the account, client/repositories, route and authoritative global MR identity; final complete-page comparison and queued cancellation prevent stale dispatch. Shared discussion reservations prevent overlapping private/public commands.

Uncertain publication blocks private create/edit/delete and another publication. Private-only inspection cannot clear that gate; recovery waits for the real write to settle and stages every private and public page before applying current-session state. Renewed consent and a fresh comparison are required for a manual publication. Reviewed the reproduced final-success account race, last-page recovery cancellation and cross-dialog recovery guidance fixes, along with 143 new behavioral regressions, 6,718 passing local tests, clean analysis and twelve synthetic captures covering three widths and both themes. Five locales include large-text/keyboard interactions. No new dependency, model, telemetry, disk cache, summary/reviewer-state, approval or merge command is introduced.

The dialog and documentation correctly limit the guarantees: bulk publication can include notes saved externally after comparison; offset pagination is not atomic and text/absence cannot identify a prior uncertain attempt. Recovery is in-memory only. The final required CI checks and unresolved-review-thread gate are verified on this exact head before this approval. Live GitLab/device validation is not claimed.

@sjungwon03
sjungwon03 merged commit 3c40130 into dev Oct 5, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:api packages/gitlab_api — GitLab REST/GraphQL client area:docs AGENTS.md, .agents/, README and friends area:ui Screens and feature UI feat New feature

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Publish saved MR review notes with confirmed snapshots and visible recovery

2 participants