refactor(desktop): move session settings ownership below AppShell - #5509
Conversation
eeb463e to
8df8b98
Compare
Astro-Han
left a comment
There was a problem hiding this comment.
Adversarial review at 8df8b988e — line-by-line semantic diff of the moved controller plus a worktree build (20/20 focused tests, renderer tsc, architecture checks all green). No P0–P2.
Verified: writeSessionPlanMode is a faithful move of commitPlanMode — same fresh getPlanState IPC read (no snapshot), same refusal ordering, and Plan confirmation still targets the parameter sessionId with abandonPlanProposal keyed to the proposal id — the original-Session-target guarantee holds mid-await. Optimistic rollback and revision retirement live in the unchanged shared intent hook; captured-owner permission confirmation keeps its exact ordering (owner-change-mid-confirm is covered by a test). The equality-selected read covers exactly the four fields the shell consumed, with a stable reference — foreign-session writes wake neither shell nor frame. The provider's all-sessions catalog subscription is correct (it's the write owner and must observe retirement for any session). controllerOwners registration, bridge paths 18→17, and hook-site counts all check out.
Two P3s, both deferrable: ui/use-session-setting-intent.ts:57-67 hand-rolls the state-keyed snapshot cache + isEqual carry-forward that useExternalStoreSelector already provides with identical semantics — swapping deletes ~30 lines and one parallel mechanism; and (pre-existing) a write refusal still double-toasts — the specific refusal message plus the generic onWriteError failure — faithfully preserved from main, only worth touching if refusal-shouldn't-report-failure is considered a bug.
Move setting write intents and Plan transition policy into the feature owner. Keep a selected-session overlay read and stable commands in the shell, with ownership and render-scope coverage. Generated-by: Codex
8df8b98 to
83a7a35
Compare
Summary
Session-setting write intents currently live in AppShell, so writes for inactive Sessions also re-render the shell. Move their controller into a feature-owned
SessionSettingsProvider, registered incontrollerOwners, and leave the shell one equality-selected read of the active Session's model/thinking, permission, Plan and orchestration overlays plus stable commands.Move the Plan transition policy and its authoritative
getPlanStateread behind feature services. Preserve optimistic rollback, revision-based retirement, captured-owner permission confirmation and the original Session target during Plan confirmation. Shell bridge paths drop from 18 to 17; the existing settings hook remains as a necessary read. Session Collaboration and Plan panel subscriptions remain outside this slice.Refs #4582.
Verification
Rebased onto
mainfeb9cf22f. Preserve #5532's direct Session catalog subscription inside the feature-owned controller, adapting the provider contract and tests to the current API. Regenerate the architecture ledger and Astryx inventory from the resolved source.build:test, Desktoptest:dist2820/2820, Desktop typecheck (including stories), production renderer build.git diff --check.No UI layout or intended user-visible behavior change. Interactive Electron/manual UI acceptance was not run; the behavior and render-scope evidence above comes from feature-level React tests.
AI use
Select exactly one:
Tool(s) and scope: OpenAI Codex implemented the ownership migration, tests and documentation, performed source review and validation, and prepared this PR under the contributor's direction. The commit includes
Generated-by: Codex.Checklist
Does this PR entail a change in behavior?