Skip to content

fix: prevent duplicate history actions and stale retries - #469

Open
cristim wants to merge 1 commit into
mainfrom
fix/history-action-guard
Open

cristim wants to merge 1 commit into
mainfrom
fix/history-action-guard

Conversation

@cristim

@cristim cristim commented Oct 1, 2026

Copy link
Copy Markdown
Member

History actions could open multiple confirmations and submit duplicate requests, including through a second view of the same recommendation. A successful action followed by a failed refresh could also expose stale actions again.

Acquire per-ID ownership before the first asynchronous operation for Approve, Retry, Revoke, Sell, Cancel and Marketplace Cancel. Invalidate the completed ID in both history caches and ignore reads started before the mutation. Dismissal and failed requests release ownership and restore focus; later legitimate actions remain available.

Closes #249

Independent local review approved exact commit a30aca9 with no actionable findings. Fresh verification passed 78 focused Jest tests and 10 production-browser tests under the corrected persistent resource lock. Committed source and production source-map identity match. Parent-code and guard-removal probes reproduce duplicate requests and stale action recovery; dismissal, retry, focus and later-action positive controls pass.

Verification exercises the production frontend with synthetic HTTP responses. No provider purchases were made. The larger diff remains one concern: six action handlers and the necessary regression and positive-control coverage.

Lock each execution before details loading and confirmation so repeated
clicks cannot submit duplicate or conflicting purchase actions.

Invalidate completed action caches and ignore older history responses
while preserving later authoritative actions and dismissal focus.

Closes #249
@cristim cristim added severity/medium Moderate harm urgency/this-sprint Within the current sprint triaged Item has been triaged priority/p1 Next up; this sprint impact/many Affects most users effort/s Hours type/bug Defect labels Oct 1, 2026
@coderabbitai

coderabbitai Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

  • Run on-demand review

This review includes 7 billable files and costs up to $1.75.

  • Ask an admin to make reviews automatic

Open in CodeRabbit

Reviews can continue after your included limit without a manual trigger. An admin must approve usage-based billing.

Or wait 7 minutes for your next included review.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available. Your 75 included PR review attempts over the past 7 days set your current allowance at 1 review per hour.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository: LeanerCloud/cloud-commitments-platform/.coderabbit.yaml

Review profile: CHILL

Plan: Essentials

Run ID: 2269171a-9439-49b7-8919-01ccf26ba253

📥 Commits

Reviewing files that changed from the base of the PR and between 6d9a70f and a30aca9.

📒 Files selected for processing (7)
  • frontend/src/__tests__/history-approve-button.test.ts
  • frontend/src/__tests__/history-cancel-button.test.ts
  • frontend/src/__tests__/history-marketplace-sell-button.test.ts
  • frontend/src/__tests__/history-retry-button.test.ts
  • frontend/src/__tests__/history-revoke-button.test.ts
  • frontend/src/history.ts
  • frontend/tests-e2e/history-action-confirmation.spec.ts
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

effort/s Hours impact/many Affects most users priority/p1 Next up; this sprint severity/medium Moderate harm triaged Item has been triaged type/bug Defect urgency/this-sprint Within the current sprint

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(frontend): money-mutation buttons are disabled only after the confirm dialog resolves

1 participant