Repository navigation
feat(merge_requests): publish entire pending reviews with visible recovery - #615
Conversation
…overy Confirm complete account-bound saved notes before one bulk publication and require two-sided inspection plus renewed consent after uncertain outcomes. Signed-off-by: sjungwon03 <sjungwon03@gmail.com>
sjungwon03-ai
left a comment
There was a problem hiding this comment.
Review of commit 5d78fdd: Reviewed the full diff and publication contract; no actionable blockers remain. The account-scoped bulk endpoint sends one body-free POST, disables redirects and OAuth replay, requires 204, and preserves sanitized typed failures before decoding. The immutable confirmation is bound to the account, client/repositories, route and authoritative global MR identity; final complete-page comparison and queued cancellation prevent stale dispatch. Shared discussion reservations prevent overlapping private/public commands.
Uncertain publication blocks private create/edit/delete and another publication. Private-only inspection cannot clear that gate; recovery waits for the real write to settle and stages every private and public page before applying current-session state. Renewed consent and a fresh comparison are required for a manual publication. Reviewed the reproduced final-success account race, last-page recovery cancellation and cross-dialog recovery guidance fixes, along with 143 new behavioral regressions, 6,718 passing local tests, clean analysis and twelve synthetic captures covering three widths and both themes. Five locales include large-text/keyboard interactions. No new dependency, model, telemetry, disk cache, summary/reviewer-state, approval or merge command is introduced.
The dialog and documentation correctly limit the guarantees: bulk publication can include notes saved externally after comparison; offset pagination is not atomic and text/absence cannot identify a prior uncertain attempt. Recovery is in-memory only. The final required CI checks and unresolved-review-thread gate are verified on this exact head before this approval. Live GitLab/device validation is not claimed.
Summary
Saved private MR notes now offer Publish pending review. The confirmation reads all private pages, shows every note, and requires explicit consent to make the entire pending review public. Added/removed notes or changed modeled metadata fail a fresh complete comparison before the sole bulk-publication request. Publication does not approve or merge the MR.
An uncertain outcome blocks every private mutation until explicit complete inspection of both saved notes and current public discussions. The inspection waits for a dispatched request to actually settle and stages all pages before adopting any result. Reopening or refreshing does not authorize replay; a new publication requires new consent and another full comparison. Private compose/edit/delete dialogs direct the user to this recovery flow.
Closes #614
Validation
dart format .: 934 files, no outstanding changesflutter analyze: no warningsflutter test: 6,718 tests across all five packages (app 3,821; design system 127; API 2,589; models 176; secure storage 5)flutter gen-l10nChecklist
dev, links one issue, Conventional Commit with DCO sign-offScreenshots
All twelve captures
Notes for reviewers
The official Draft Notes API bulk endpoint publishes all pending notes for the authenticated user. The request sends no summary, reviewer-state, internal flag, selected-ID list, approval or merge command. It uses one POST, disables redirects and OAuth replay, preserves typed status errors before decoding, and acknowledges only 204.
The preflight compares modeled saved-note state, not an atomic or conditional server snapshot. Notes saved from another client after comparison may also be included; the dialog explicitly explains this. Identical text or missing notes cannot prove which uncertain attempt succeeded. Dispatched server writes cannot be undone, and recovery remains session-scoped memory without durable or exactly-once claims. Single-note publication, summary/reviewer-state controls and positioned/reply/commit draft creation remain separate slices. MW-07 stays in progress.