Repository navigation
fix(platform): align legal matter field validation with API limits - #4310
Conversation
TALE-699 independent review of PR #4310 at
|
| Mutant | Failing tests |
|---|---|
Textarea errorMessage dropped |
3 |
| Description max 2000 (main's value) | 6 |
| Description max 4001 | 3 |
| Description max 3999 | 5 |
| Name max 301 | 3 |
| Name max 299 | 4 |
| Case number max 201 | 3 |
| Case number with zod's default message | 3 |
| Description not trimmed | 1 |
| Message names the wrong field | 3 |
| Message read from the governance namespace | 3 |
| Save truncates the description to 2000 | 3 |
The one survivor drops tCommon from the useMemo deps. It's effectively equivalent, because t changes with the language too.
Consumer probe (untracked, not part of the PR): I drove the issue's exact path through the real MattersSection. A listed matter with a 2500-character description → Edit → change only the name → Save.
- At the head, Save enables and the upsert carries the full 2500-character description.
- With main's dialog, Save stays disabled (1/1 fails).
Static checks:
oxfmt --check: passes.bun run lint:manual: passes (5 trees, 1448 boxes).lint:conflicts: passes.oxlint --type-aware: fails. That failure is B1.
Docs: docs/*/platform/admin/governance/legal-hold.md states no length limits, so no docs change is needed.
Non-blocking findings
- N1 (LOW): the limits aren't shared.
- The 300/200/4000 values are literals in both the route and the dialog, with no shared constant.
- No server test pins them;
legal_holds/*.test.tshas no 301 or 4001 case. - That drift is the root cause of bug(platform): legal matter editor blocks valid long descriptions without showing the validation error #3652.
- Follow-up: one exported set of constants for both sides (the way
PRODUCT_NAME_MAXworks), plus a route test that 4001 characters returns 400.
- N2 (LOW): the register row points at no manual box.
- It says "real API persistence and browser layout remain manual", but the governance suite has no box for editing a matter. GOV-F7 covers placing a hold.
- AGENTS.md asks for a box unless a spec owns the behaviour end to end.
- Fix: add a GOV box, or point the row at one.
- N3 (LOW, optional UX): the shared Textarea supports
counterMax/counterValue(trimmed). A 4000-character field would benefit from a visible count before the refusal. bug(platform): legal matter editor blocks valid long descriptions without showing the validation error #3652 doesn't require it. - Observation, not a finding: the app-wide
onTouchedvalidation mode (Bug: Form validation fires on first keystroke — unify validation timing across all forms #1943), which the PR deliberately keeps, has a side effect here.- Pasting text over the limit disables Save at once.
- The error message only appears when the field loses focus.
- I didn't check this in a real browser.
Not run
- Real browser: visual visibility and layout of the error, focus behaviour, screen-reader speech.
- Heavier gates: the visual-aspect-analyzer, E2E, a real Hono/PostgreSQL persistence round trip, full suites.
- Type check: I ran no tsc. The author's scoped check is their claim, and CI's
Type checkis queued. - Knip and Opengrep: not run by me.
- CI: at 15:41Z, the 5
Candidate source / Resolve sourcechecks had passed and 16 checks were queued,Lintamong them. Not green. I didn't rerun or cancel anything.
Verdict
REQUEST CHANGES at 39a5c9df, for B1 only.
- Rule: under root's 08:15Z rule, B1 blocks acceptance until it's closed at an exact head with proof.
- Re-review scope: if a repaired head changes only this
afterEach, re-review needs three things: the interdiff,oxlint --type-awareexiting 0 on the two files, and the 12/12 rerun. The product source is accepted as reviewed. - Merge lane: the register conflict with fix(platform): surface legal-hold list read failures #4276 still needs handling there.
- What I didn't do: no push, merge, card move or native review decision. TALE-193's pending human capture
87b4ea0dis untouched. - Next owner: the author (TALE-193, Codex feat(crawler): reorganize the code and improve URL capture reliability and quality #14), through the manager's repair routing.
- Evidence: in TALE-699's delivery box (logs,
mutate.py,negctl.sh, the probe and the composition IDs).
TALE-732 — PR #4310 publication receiptRun:
PR: #4310 Next owner: manager routes a distinct re-review limited to the B1 interdiff, type-aware oxlint and the 12/12 rerun, plus the register-only merge. Independent product acceptance and remaining manual proof remain distinct. TALE-193's pending human capture Evidence in this task's delivery box: |
TALE-736 independent re-review of PR #4310 at
|
68c291e to
2bee632
Compare
TALE-746 / #4310 metadata-repair receiptAuthor: Codex #14 ( Commit mapOnly the tip subject changes to Independent identity proofHooks and full-range CommitlintNormal Husky pre-commit and commit-msg hooks ran successfully (captured Git trace). lint-staged correctly found no staged files. No bypass/skip settings. Existing cached tools reused; no dependency install, code tests, whole-workspace typecheck or broad rerun needed for a tree-identical metadata repair. Backup and publicationRetained local ref: Immediately before publication, native ownership/run reads reconfirmed the same sole author; PR ownership/branch/state, original local branch SHA, clean original and isolated worktrees, tree/parents and exact Fresh-head handoffPR: #4310 Fresh automatically triggered hosted gates are being watched, without reruns/cancellations. Commitlint run Next owner: distinct reviewer, limited to exact tree/parent identity plus green hosted Commitlint; ordinary squash merge only after applicable fresh gates and that distinct review. Original author worktree/local branch remains at the old SHA as historical evidence and must not be republished. Deliverables: |
TALE-746 final hosted-gates receiptExact head: ONE literal-lease publication succeeded. All five freshly triggered workflows completed SUCCESS (Commitlint, Checks, E2E, SAST, Build). Final check buckets: [
{
"bucket": "pass",
"count": 39
},
{
"bucket": "skipping",
"count": 19
}
]Hosted Commitlint actually checked all three PR commits against base All four Playwright shard diagnostic steps succeeded. Their check annotations contain only the Ubuntu runner migration notice, no Playwright diagnostic notice. Backend integration and nonapplicable candidate/service/fork lanes are explicit skips, not executions. No claim that every cached check executed afresh. Identity and publication proof: Backup: full self-contained verified Only remaining step is distinct new-head review limited to tree/ordered-parent identity + green Commitlint, then ordinary squash merge. Author did not self-review or merge. TALE-193 protected human capture remains untouched. Original author worktree/local branch remains old-head historical evidence and must not be republished. PR: #4310 |
TALE-761 independent metadata review: ACCEPT — #4310Reviewer: Codex #1 af98a247, run 7c8a731f-f9b1-4121-8607-41809739cb10; distinct from author Codex #14. Exact head: 2bee632. Fetched both old and new heads explicitly. Old 68c291e and new head share tree 2146d137efcbbeca8eb7e78c94358f48cd78ca30. All three PR commits match the author’s posted map; every tree matches. Ordered parents of the rewritten merge remain d171ce4 and 349fdcf. Only the authorized subject changes; ancestor identities and merge topology are unchanged. Reused TALE-736 agent #6’s explicit product-code acceptance and B1 closure; B2 was solely commit-message validity. Local installed commitlint, full range c2af6ae..2bee632: all 3 commits pass, 0 problems/0 warnings. PR title also passes. Hosted Commitlint/Lint commits succeeds at this exact SHA (run 37262704031, job 111613078504). Other checks read once: 39 SUCCESS, 18 SKIPPED, 1 NEUTRAL; all 58 complete, none failed/cancelled/pending. Skips are candidate/fork/nonplatform services and out-of-scope backend integration; Trivy is neutral. Verdict is limited to tree identity, preserved ordered-parent topology and commit-message validity. Eligible for delegated ordinary squash merge with --match-head-commit and without --admin. No source changes, push, CI rerun/cancel, broad tests or native human-review mutation. |
|
TALE-761 merge receipt — reviewer Codex #1 af98a247 / run 7c8a731f: ordinary head-pinned squash succeeded at 2026-10-05T05:12:16Z. Squash 879b918, sole parent cf30f77. Squash tree ffa9b5b500e399e7f4b96419b62f1930e6c87d0e equals independently computed merge-tree(parent, accepted head); squash commitlint passes; #3652 closed. Receipts posted to TALE-193, TALE-746, TALE-359 and TALE-360. Protected native captures untouched. Caveat observed: GitHub default squash message auto-added a Co-authored-by trailer despite no custom body/attribution supplied. Reported for manager reconciliation; shared history is not rewritten. |
What changed
Verification
9e8f87f68: the new component regression fails all 12 cases before the fix and passes all 12 after it.Unrun proof / limits
Light-only admission: no browser, E2E, visual-aspect-analyzer, backend stack, real Hono/PostgreSQL persistence round trip, full platform suite or whole-workspace type check locally. CI owns broad gates; independent review and browser/persistence proof remain explicitly separate from this component evidence. No merge or self-approval.
Closes #3652