Skip to content

feat(merge_requests): create private drafts on original commit text diffs - #625

Merged
sjungwon03 merged 1 commit into
devfrom
feat/624-commit-text-review-drafts
Oct 6, 2026
Merged

sjungwon03 merged 1 commit into
devfrom
feat/624-commit-text-review-drafts

Conversation

@sjungwon03

Copy link
Copy Markdown
Member

Summary

The draft-note client can save regular/text MR notes and discussion replies, but cannot explicitly associate a new private note with a selected commit. This adds createCommitDraftNote and account-bound MrDraftNotesRepository.createCommit for original commit text diffs.

One private POST preserves exact Markdown, commit SHA and original position, with explicit non-resolution. Strict HTTP 201 confirmation rejects changed bodies, commits, reply targets, identities or positions; the repository checks the captured author and authoritative global MR separately from the route IID. Invalid or mismatched inputs cannot dispatch. Error status mapping precedes plain-body decoding, and no redirect, authentication replay, automatic retry or public fallback is enabled.

Closes #624

Validation

  • dart format .: 953 Dart files, zero outstanding changes
  • flutter analyze: no issues
  • 7,344 full tests: app 4,217; design system 127; API 2,811; models 184; secure storage 5
  • 98 new behavior tests: API 92; repository 6. Tests written first; missing methods and then unimplemented behavior both failed before implementation
  • Live GitLab/device manual validation (synthetic unit tests only)
  • Models/generated files unchanged; build runner is not applicable
  • No UI or localization changes; layout/theme captures are not applicable

Checklist

  • Linked issue, feature branch into dev, Conventional Commit and DCO
  • Test-first behavior and updated API/parity documentation
  • No dependencies, storage, persistence or telemetry added
  • Dummy credentials and synthetic notes/hashes only; code/docs/reviews in English

Notes for reviewers

The official creation contract permits commit_id plus position. This method deliberately restricts inputs to a full lowercase SHA-1 and a complete original text position whose head matches the selected commit. Added/deleted/context lines and validated text ranges are supported. Image/file positions and other hash formats remain separate.

The primary GitLab draft model copies commit/diff attributes on publication only for complete diff positions, so unpositioned commit drafts are excluded. Private creation confirms the returned association; later publication-target preservation across GitLab versions is not asserted.

This is an API/repository foundation with no new user action. A future controller/UI must verify MR membership and literal original diff coordinates, capture current session/resource/origin, share the command reservation, await actual settlement and visibly inspect pending notes plus original context before retry. Low-level methods do not provide those guards. GitLab permissions/capabilities remain authoritative; creation may implicitly mark review started. No approval/publication command, atomic snapshot, durable recovery, conditional-write or exactly-once guarantee is introduced. MW-07 remains in progress.

…iffs

Confirm the exact commit and original text position on one private write, with captured author and global MR validation before future guarded UI integration.

Signed-off-by: sjungwon03 <sjungwon03@gmail.com>
@sjungwon03
sjungwon03 marked this pull request as ready for review October 6, 2026 03:46
@github-actions github-actions Bot added area:api packages/gitlab_api — GitLab REST/GraphQL client area:ui Screens and feature UI area:docs AGENTS.md, .agents/, README and friends feat New feature labels Oct 6, 2026

@sjungwon03-ai sjungwon03-ai left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review of commit 65ac196: Reviewed the API/repository implementation, behavior-first tests and documentation against the documented draft-note creation contract. The original commit/head binding, exact private payload, strict acknowledgement/identity checks, status-first sanitized errors and single-attempt authentication/transport behavior are consistent. No actionable findings in this scope.

Local validation: 7,344 full tests passed (98 new API/repository tests), clean analysis and formatting. This remains an API/repository foundation with no exposed user action: MR membership, literal diff selection, session freshness, command reservations, settlement/recovery and publication-target validation still belong to future guarded controller/UI integration. Complete text positions and full lowercase SHA-1 are deliberate supported-input restrictions. Final merge must also wait for every required CI check on this exact head.

@sjungwon03
sjungwon03 merged commit dafb89f into dev Oct 6, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:api packages/gitlab_api — GitLab REST/GraphQL client area:docs AGENTS.md, .agents/, README and friends area:ui Screens and feature UI feat New feature

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Create private review drafts on original commit text diffs

2 participants