Skip to content
Draft
Show file tree
Hide file tree
Changes from 27 commits
Commits
Show all changes
64 commits
Select commit Hold shift + click to select a range
8f7ff8b
fix(email-detail): make responsive evidence actions functional
seonghobae Aug 5, 2026
e907955
ci: repair PR 1245 review findings test-first
seonghobae Aug 5, 2026
43d09e7
chore(ci): remove completed PR 1245 repair workflow
seonghobae Aug 5, 2026
abd2967
test(email-detail): stage selected-source writeback regressions
seonghobae Aug 5, 2026
3819eb9
ci: verify PR 1245 selected-source repair
seonghobae Aug 5, 2026
64fd961
fix(ci): target the EmailDetail conflict panel precisely
seonghobae Aug 5, 2026
40d43bc
ci: retry PR 1245 repair with precise panel anchor
seonghobae Aug 5, 2026
400b281
ci: rerun PR 1245 selected-source repair
seonghobae Aug 5, 2026
77b9185
fix(ci): align PR 1245 regressions with explicit confirmation
seonghobae Aug 5, 2026
940cc9a
ci: rerun PR 1245 explicit-confirmation repair
seonghobae Aug 5, 2026
8df011f
fix(ci): repair PR 1245 transformer quoting
seonghobae Aug 5, 2026
4b17725
ci: rerun verified PR 1245 repair
seonghobae Aug 5, 2026
a80c2b5
fix(ci): avoid synchronous effect state resets
seonghobae Aug 5, 2026
7802b51
ci: finalize PR 1245 selected-source repair
seonghobae Aug 5, 2026
a1a6460
chore(pr1245): remove obsolete repair workflow
seonghobae Aug 5, 2026
d750465
chore(pr1245): remove obsolete repair workflow v2
seonghobae Aug 5, 2026
2d15ea4
chore(pr1245): remove obsolete repair workflow v3
seonghobae Aug 5, 2026
b51999d
chore(pr1245): remove obsolete repair workflow v4
seonghobae Aug 5, 2026
7717cec
chore(pr1245): remove completed repair workflow v5
seonghobae Aug 5, 2026
592d91e
chore(pr1245): remove temporary patch transformer
seonghobae Aug 5, 2026
b042b21
chore(pr1245): remove temporary effect lint
seonghobae Aug 5, 2026
d1fa097
chore(pr1245): remove temporary repair patcher
seonghobae Aug 5, 2026
55e4573
chore(pr1245): remove completed repair script
seonghobae Aug 5, 2026
4d5f4e3
test(email-detail): stage selected-source calendar contract
seonghobae Aug 5, 2026
354f6c3
ci(email-detail): verify selected-source repair
seonghobae Aug 5, 2026
15137eb
ci(email-detail): repair deterministic helper state
seonghobae Aug 5, 2026
60e1afc
chore(ci): finalize verified EmailDetail review repair
seonghobae Aug 5, 2026
e48581f
chore(pr): remove completed PR 1245 finalizer
seonghobae Aug 5, 2026
cb5f3e9
chore(pr): remove completed PR 1245 repair workflow
seonghobae Aug 5, 2026
d83a175
chore(pr): remove completed PR 1245 repair helper
seonghobae Aug 5, 2026
e086f75
test(email-detail): require explicit calendar source writeback
seonghobae Aug 6, 2026
70959ee
test(ci): stage bounded PR 1245 calendar source repair
seonghobae Aug 6, 2026
05b9122
ci: verify PR 1245 explicit calendar source boundary
seonghobae Aug 6, 2026
281ef2e
ci: finalize PR 1245 calendar source on reopen
seonghobae Aug 6, 2026
3b21327
fix(ci): enable pnpm after Node setup
seonghobae Aug 6, 2026
4ef7082
fix(ci): make PR 1245 repair indentation-safe
seonghobae Aug 6, 2026
1dcd1b8
ci: bind PR 1245 repair to corrected transformer
seonghobae Aug 6, 2026
c6cb203
fix(ci): target the unique rendered action-item block
seonghobae Aug 6, 2026
8499f3f
fix(ci): normalize PR 1245 render anchors
seonghobae Aug 6, 2026
3fec4e9
ci: repair exact calendar-source panel transform
seonghobae Aug 6, 2026
41e1f92
fix(ci): remove malformed PR 1245 reopen workflow
seonghobae Aug 6, 2026
482725e
fix(ci): retrigger bounded calendar-source repair
seonghobae Aug 6, 2026
f9e7a02
fix(ci): make PR 1245 repair workflow valid YAML
seonghobae Aug 6, 2026
71a96ea
ci: activate pinned pnpm before setup-node caching
seonghobae Aug 6, 2026
67be57e
ci(pr1245): finalize explicit calendar source repair
seonghobae Aug 6, 2026
38d5e77
ci(pr1245): finalize calendar source repair v3
seonghobae Aug 6, 2026
a4f02a9
chore(ci): add fail-closed PR 1245 finalizer
seonghobae Aug 6, 2026
bb8caf6
fix(ci): finalize PR 1245 with fail-closed exact-head verification
seonghobae Aug 6, 2026
f40b377
ci(email-detail): execute fail-closed PR 1245 finalizer
seonghobae Aug 6, 2026
886220d
fix(ci): allow exact-head checkout in PR 1245 finalizer
seonghobae Aug 6, 2026
f430376
fix(ci): enable pnpm before cache initialization
seonghobae Aug 6, 2026
aa5c4b3
fix(ci): make PR 1245 status repair multiplicity explicit
seonghobae Aug 6, 2026
f76e1b2
test(email-detail): require explicit source after shell command
seonghobae Aug 6, 2026
d4574ba
fix(ci): remove invalid superseded PR 1245 workflow
seonghobae Aug 6, 2026
5aae303
test(email-detail): select the rendered writeback action
seonghobae Aug 6, 2026
6b4f2ba
fix(email-detail): key calendar sources to active context
seonghobae Aug 6, 2026
9aaea8e
fix(ci): preserve generated TypeScript indentation
seonghobae Aug 6, 2026
5bf17ff
fix(email-detail): require explicit calendar source
github-actions[bot] Aug 6, 2026
e45fc3b
docs(email-detail): record fail-closed source lifecycle
seonghobae Aug 6, 2026
4a6f339
test(email-detail): cover calendar action disabled states
seonghobae Aug 20, 2026
af81b67
Merge remote-tracking branch 'origin/develop' into HEAD
seonghobae Aug 20, 2026
796b34c
Merge remote-tracking branch 'origin/develop' into fix/pr1245-current
seonghobae Aug 21, 2026
885ee0c
fix: await EmailDetail input updates and retain callback dependencies
seonghobae Sep 6, 2026
38c375e
merge(ui): inherit complete dependency security prerequisite
seonghobae Sep 6, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
128 changes: 128 additions & 0 deletions .github/workflows/finalize-pr1245-selected-source.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,128 @@
name: Finalize PR 1245 selected-source writeback

on:
push:
branches:
- fix/email-detail-responsive-surface-maintainer
paths:
- .github/workflows/finalize-pr1245-selected-source.yml

permissions:
contents: read

concurrency:
group: finalize-pr1245-selected-source
cancel-in-progress: false

env:
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true

jobs:
verify-and-publish:
if: >-
github.repository == 'ContextualWisdomLab/naruon' &&
github.actor != 'github-actions[bot]' &&
github.ref == 'refs/heads/fix/email-detail-responsive-surface-maintainer'
permissions:
contents: write
runs-on: ubuntu-latest
timeout-minutes: 60
steps:
- name: Harden runner
uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
with:
egress-policy: audit

- name: Check out exact trigger without persisted credentials
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
ref: ${{ github.sha }}
fetch-depth: 20
persist-credentials: false

- name: Verify repository and bounded repair source
shell: bash --noprofile --norc -e -o pipefail {0}
run: |
test "$(git rev-parse HEAD)" = "$GITHUB_SHA"
test -f frontend/src/components/EmailDetail.tsx
test -f frontend/src/components/EmailDetail.test.tsx
test -f docs/doctoring/email-detail-responsive-action-surface.md
if ! grep -q 'email-detail-calendar-source' frontend/src/components/EmailDetail.tsx; then
test -f scripts/ci/repair_pr1245_review.py
python3 -m py_compile scripts/ci/repair_pr1245_review.py
python3 scripts/ci/repair_pr1245_review.py tests
python3 scripts/ci/repair_pr1245_review.py production
fi
grep -q 'email-detail-calendar-source' frontend/src/components/EmailDetail.tsx
grep -q 'target_source_id' frontend/src/components/EmailDetail.tsx
grep -q 'role="region"' frontend/src/components/EmailDetail.tsx
grep -q 'selected-source meeting action' frontend/src/components/EmailDetail.test.tsx
grep -q 'writeback is pending' frontend/src/components/EmailDetail.test.tsx
grep -q 'selected-source conflict' frontend/src/components/EmailDetail.test.tsx
grep -q 'target_source_id' docs/doctoring/email-detail-responsive-action-surface.md
git diff --check

- name: Enable pinned pnpm
shell: bash --noprofile --norc -e -o pipefail {0}
run: corepack enable pnpm

- name: Set up Node.js
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
with:
node-version: "26"
cache: pnpm
cache-dependency-path: frontend/pnpm-lock.yaml

- name: Install frozen frontend dependencies
working-directory: frontend
shell: bash --noprofile --norc -e -o pipefail {0}
run: pnpm install --frozen-lockfile

- name: Verify focused and full frontend contracts
working-directory: frontend
shell: bash --noprofile --norc -e -o pipefail {0}
run: |
pnpm exec vitest run src/components/EmailDetail.test.tsx
pnpm test
pnpm run typecheck
pnpm run lint
pnpm run coverage

- name: Build production frontend
working-directory: frontend
env:
NEXT_TELEMETRY_DISABLED: "1"
NODE_OPTIONS: "--max-old-space-size=4096"
NEXT_BUILD_CPUS: "2"
POSTCSS_WORKERS: "1"
DISABLE_POSTCSS_WORKERS: "true"
shell: bash --noprofile --norc -e -o pipefail {0}
run: pnpm run build

- name: Publish only verified product changes
env:
PUSH_TOKEN: ${{ github.token }}
shell: bash --noprofile --norc -e -o pipefail {0}
run: |
rm -f \
.github/workflows/finalize-pr1245-selected-source.yml \
.github/workflows/repair-pr1245-selected-source.yml \
.github/workflows/repair-pr1245-selected-source-v2.yml \
.github/workflows/repair-pr1245-review.yml \
scripts/ci/repair_pr1245_review.py \
scripts/ci/patch_pr1245_repair_script.py
test -z "$(git ls-files | grep -E '(^|/)(finalize|repair)-pr1245|repair_pr1245|patch_pr1245' || true)"
git diff --check
git config user.name "github-actions[bot]"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
git add -A
git diff --cached --quiet && {
echo '::error::No verified product or cleanup change remains to publish.'
exit 1
}
git diff --cached --check
git commit -m "fix(email-detail): require selected writeback source"
auth_header="$(printf 'x-access-token:%s' "$PUSH_TOKEN" | base64 | tr -d '\n')"
echo "::add-mask::$auth_header"
git -c http.extraheader="AUTHORIZATION: basic ${auth_header}" \
push origin "HEAD:refs/heads/fix/email-detail-responsive-surface-maintainer"
143 changes: 143 additions & 0 deletions .github/workflows/repair-pr1245-selected-source-contract.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,143 @@
name: Repair PR 1245 selected calendar source contract

on:
push:
branches:
- fix/email-detail-responsive-surface-maintainer
paths:
- scripts/ci/repair_pr1245_selected_source_contract.py
- .github/workflows/repair-pr1245-selected-source-contract.yml

permissions:
contents: read

concurrency:
group: pr-1245-selected-source-contract
cancel-in-progress: true

env:
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true

jobs:
repair:
if: >-
github.repository == 'ContextualWisdomLab/naruon' &&
github.actor == 'seonghobae'
runs-on: ubuntu-24.04
timeout-minutes: 45
permissions:
contents: write
steps:
- name: Harden runner with blocking egress
uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
with:
egress-policy: block
allowed-endpoints: >
github.com:443
api.github.com:443
codeload.github.com:443
objects.githubusercontent.com:443
release-assets.githubusercontent.com:443
registry.npmjs.org:443

- name: Checkout exact repair trigger
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
with:
ref: ${{ github.sha }}
fetch-depth: 2
persist-credentials: false

- name: Verify immutable trigger and repair helper idempotence
run: |
set -euo pipefail
expected_parent="354f6c3413bf0efde9e059e002b2f9864d6a3460"
test "$(git rev-parse HEAD^)" = "$expected_parent"
python3 - <<'PY'
from pathlib import Path

path = Path("scripts/ci/repair_pr1245_selected_source_contract.py")
text = path.read_text(encoding="utf-8")
old = ''' old_count = text.count(old)\n new_count = text.count(new)\n if old_count == 1 and new_count == 0:\n path.write_text(text.replace(old, new, 1), encoding="utf-8")\n return\n if old_count == 0 and new_count == 1:\n return\n'''
new = ''' old_count = text.count(old)\n if new == "":\n if old_count == 1:\n path.write_text(text.replace(old, new, 1), encoding="utf-8")\n return\n if old_count == 0:\n return\n new_count = 0\n else:\n new_count = text.count(new)\n if old_count == 1 and new_count == 0:\n path.write_text(text.replace(old, new, 1), encoding="utf-8")\n return\n if old_count == 0 and new_count == 1:\n return\n'''
if text.count(old) != 1:
raise SystemExit("replace_once helper anchor not found exactly once")
path.write_text(text.replace(old, new, 1), encoding="utf-8")
PY
python3 -m py_compile scripts/ci/repair_pr1245_selected_source_contract.py

- name: Enable pinned pnpm
run: corepack enable pnpm

- name: Set up Node.js
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v7.0.0
with:
node-version: "24"
cache: pnpm
cache-dependency-path: frontend/pnpm-lock.yaml

- name: Install frozen frontend dependencies
run: cd frontend && pnpm install --frozen-lockfile

- name: Install regression first and prove a meaningful red state
run: |
set -euo pipefail
python3 scripts/ci/repair_pr1245_selected_source_contract.py --tests
set +e
cd frontend
pnpm exec vitest run src/components/EmailDetail.test.tsx >"${RUNNER_TEMP}/pr1245-selected-source-red.log" 2>&1
status=$?
cd ..
set -e
cat "${RUNNER_TEMP}/pr1245-selected-source-red.log"
test "$status" -ne 0
grep -F 'requires an explicit server-authorized calendar source' "${RUNNER_TEMP}/pr1245-selected-source-red.log"
if grep -Eq '(Timeout|Fatal|Denied)' "${RUNNER_TEMP}/pr1245-selected-source-red.log"; then
echo '::error::Red-stage failure contained forbidden infrastructure evidence.'
exit 1
fi

- name: Apply production repair
run: |
set -euo pipefail
python3 scripts/ci/repair_pr1245_selected_source_contract.py --production
git diff --check

- name: Run focused EmailDetail regression
run: cd frontend && pnpm exec vitest run src/components/EmailDetail.test.tsx

- name: Run complete frontend quality gate
run: |
set -euo pipefail
cd frontend
pnpm test
pnpm run typecheck
pnpm run lint
pnpm run coverage

- name: Build production frontend
env:
NEXT_TELEMETRY_DISABLED: "1"
NODE_OPTIONS: --max-old-space-size=4096
NEXT_BUILD_CPUS: "2"
POSTCSS_WORKERS: "1"
DISABLE_POSTCSS_WORKERS: "true"
run: cd frontend && pnpm run build

- name: Publish verified product repair and remove temporary machinery
env:
PUSH_TOKEN: ${{ github.token }}
run: |
set -euo pipefail
rm -f \
.github/workflows/repair-pr1245-selected-source-contract.yml \
scripts/ci/repair_pr1245_selected_source_contract.py
git diff --check
git config user.name "github-actions[bot]"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
git add -A
git diff --cached --quiet && exit 1
git commit -m "fix(email-detail): require selected calendar source"
auth_header="$(printf 'x-access-token:%s' "$PUSH_TOKEN" | base64 | tr -d '\n')"
echo "::add-mask::$auth_header"
git -c http.extraheader="AUTHORIZATION: basic ${auth_header}" \
push origin "HEAD:fix/email-detail-responsive-surface-maintainer"
6 changes: 6 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,4 +1,10 @@
## [Unreleased]
### EmailDetail 반응형 실행 표면

- 참여자와 첨부파일 증거를 모바일·데스크톱에서 동일하게 확인할 수 있도록 반응형 스크롤 레일과 명시적 접근성 이름을 추가했습니다.
- 일정 충돌 패널의 `일정 조율` 버튼을 기존 calendar writeback intent에 연결하고 loading·disabled·live-status 상태를 검증합니다.
- UI PR에 섞인 thread ID, SMTP allowlist, `.msg` import, tenant scope backend 변경은 정확한 `develop` 기준으로 제거했습니다.

### 보안 패치 (CodeQL extended current-head)

- `cryptography`를 `50.0.0`으로 갱신해 공격자 제공 PKCS#7 EnvelopedData 복호화 결과의 오류·타이밍 차이로 발생하는 Bleichenbacher oracle(`CVE-2026-69247`, `GHSA-g6cj-pr64-35w5`)을 제거하고, backend·uv lock·hash lock·Strix CI 의존성 증거를 같은 버전으로 동기화했습니다. Strix 잠금은 `google-cloud-aiplatform==1.160.0`의 `<7` 제약을 위반하던 `protobuf==7.35.1`을 이미 검증된 `6.33.6`으로 복구해 다시 해석·설치 가능하게 했습니다.
Expand Down
49 changes: 49 additions & 0 deletions docs/doctoring/email-detail-responsive-action-surface.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,49 @@
# EmailDetail responsive action surface doctoring

## Decision

The email detail view exposes participants and attachment names at every viewport
size. Attachments use a horizontally scrollable, explicitly named region so a
small viewport does not silently remove source evidence. The meeting-conflict
panel reuses the existing calendar writeback-intent handler rather than rendering
an inert call-to-action. Loading, disabled, and polite live-status states remain
in the same product surface.

Unrelated backend changes are excluded from this UI slice. Thread identifier,
SMTP destination, import-format, and tenant-scope policy changes require their
own security rationale and regression contracts rather than hitchhiking on a
presentation PR.

## Accessibility boundary

The implementation preserves native button semantics and the repository's
keyboard-visible focus system, gives the attachment evidence region an
accessible name, and exposes asynchronous status through `role=status` and
`aria-live=polite`. WCAG 2.2 is used as the current normative target. The focused
regression proves discoverability and activation in the DOM, but this record does
not claim full WCAG conformance without contrast, zoom, assistive-technology, and
manual usability evidence.

## Verification contract

- The participant list renders without an unsafe type assertion.
- The attachment rail is present and not hidden on small viewports.
- The meeting action is disabled when no extracted action item exists.
- Activating the meeting action sends the exact writeback-intent request.
- Successful writeback intent produces a polite live status.
- The three unrelated backend files are byte-identical to the exact PR base.
- Frontend focused tests, full tests, lint, type checking, coverage collection,
and production build run before the verified commit is published.

## References

World Wide Web Consortium. (2023). *Web Content Accessibility Guidelines
(WCAG) 2.2*. https://www.w3.org/TR/WCAG22/

World Wide Web Consortium. (n.d.). *Understanding success criterion 2.4.7:
Focus visible*. Retrieved August 5, 2026, from
https://www.w3.org/WAI/WCAG22/Understanding/focus-visible.html

World Wide Web Consortium. (n.d.). *Understanding success criterion 4.1.3:
Status messages*. Retrieved August 5, 2026, from
https://www.w3.org/WAI/WCAG22/Understanding/status-messages.html
Loading
Loading