fix: resolve the P2 issues - #185
Conversation
Fixes wrong data, leaked values and broken setups found in the issue sweep: signal history, NgRx restore, forms selects, router labels and large route configs, pipe and Analog redaction, HTTP fault rules, Analog hydration and Nx routes, build-meta, mount path, popup server detection, extension panel after worker idle, Vite restart, HTTPS, WebSocket guard and base handling, hub restarts, static report scans and the build output guard. Docs are updated to match. Fixes santoshyadavdev#63, santoshyadavdev#64, santoshyadavdev#65, santoshyadavdev#66, santoshyadavdev#67, santoshyadavdev#68, santoshyadavdev#69, santoshyadavdev#70, santoshyadavdev#71, santoshyadavdev#72, santoshyadavdev#73, santoshyadavdev#74, santoshyadavdev#75, santoshyadavdev#76, santoshyadavdev#77, santoshyadavdev#78, santoshyadavdev#79, santoshyadavdev#80, santoshyadavdev#81, santoshyadavdev#82, santoshyadavdev#83, santoshyadavdev#84
Rebuilds extension/ui so the bundled panel matches the app changes for the NgRx restore banner, router truncation and server detection.
Restoring a state or pressing Back to latest removed the focused control, so focus fell to the page body. Focus now moves to the Back to latest button or the State tree, and the banner no longer repeats the status message.
At 360px the floating panel stayed 720px wide and cut off the no server message and the toolbar. The panel is now clamped to the window, the message scrolls, is announced through a status line and has a heading, and the setup link says it opens a new tab.
Rebuilds extension/ui so the bundled panel includes the store inspector focus fix.
Fixes wrong or missing data, accessibility gaps, redaction gaps and limits across forms, SSR and HTTP, injectors, NgRx, signals, components, overlay, router, Analog, pipes, the CLI and config, and adds panel tests and an axe check to CI. Also adds the features the P2 issues asked for: defer blocks, element picking, component properties, action origins, resource entries and change detection recording. Docs are updated to match. Refs santoshyadavdev#100, santoshyadavdev#102, santoshyadavdev#128 Fixes santoshyadavdev#85, santoshyadavdev#86, santoshyadavdev#87, santoshyadavdev#88, santoshyadavdev#89, santoshyadavdev#90, santoshyadavdev#91, santoshyadavdev#92, santoshyadavdev#93, santoshyadavdev#94, santoshyadavdev#95, santoshyadavdev#96, santoshyadavdev#97, santoshyadavdev#98, santoshyadavdev#99, santoshyadavdev#101, santoshyadavdev#105, santoshyadavdev#106, santoshyadavdev#107, santoshyadavdev#108, santoshyadavdev#109, santoshyadavdev#110, santoshyadavdev#111, santoshyadavdev#112, santoshyadavdev#113, santoshyadavdev#114, santoshyadavdev#115, santoshyadavdev#116, santoshyadavdev#117, santoshyadavdev#118, santoshyadavdev#119, santoshyadavdev#121, santoshyadavdev#122, santoshyadavdev#123, santoshyadavdev#124, santoshyadavdev#125, santoshyadavdev#126, santoshyadavdev#127, santoshyadavdev#129, santoshyadavdev#130, santoshyadavdev#131, santoshyadavdev#132, santoshyadavdev#133, santoshyadavdev#134, santoshyadavdev#135, santoshyadavdev#136, santoshyadavdev#137, santoshyadavdev#138, santoshyadavdev#139, santoshyadavdev#140, santoshyadavdev#141, santoshyadavdev#142, santoshyadavdev#143, santoshyadavdev#144, santoshyadavdev#145, santoshyadavdev#146, santoshyadavdev#147, santoshyadavdev#148, santoshyadavdev#149, santoshyadavdev#150, santoshyadavdev#151, santoshyadavdev#152, santoshyadavdev#153, santoshyadavdev#154, santoshyadavdev#155, santoshyadavdev#156, santoshyadavdev#158, santoshyadavdev#159
Rebuilds extension/ui so the bundled panel includes the P2 panel changes.
|
Important Review skippedToo many files! This PR contains 195 files, which is 45 over the limit of 150. To get a review, reduce the PR to 150 files or fewer by splitting it into smaller PRs or changing its base branch. Upgrade to Team to raise the limit. This review couldn't start because sufficient usage credits or metered capacity aren't available. Add credits or update usage-based reviews in the billing tab, then retry. ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Essentials Run ID: ⛔ Files ignored due to path filters (3)
📒 Files selected for processing (195)
You can disable this status message by setting the
Comment |
|
View your CI Pipeline Execution ↗ for commit 1edc1a4
💡 Verify your cache is correct by running tasks in a sandbox. Read docs ↗ ☁️ Nx Cloud last updated this comment at |
Canonicalizes paths in the build output guard, keeps select writes on the option-matching path for multiple and object-valued selects, redacts text before clipping it, counts left-out child routes and warns about truncation in every router tool mode, stops treating an Nx root Analog dependency as proof an app uses Analog, finds the Nx workspace output on its own, replaces any types in build-meta, checks values before reusing a signal history binding, and keeps focus after restoring the newest NgRx action.
Rebuilds extension/ui for the store inspector focus change.
Brings in the review fixes from santoshyadavdev#184. Keeps the P2 panel test setup and moves the P1 store inspector test onto it.
…aces The Routes tab, get-routes and the Dashboard SSR and Analog fields resolved the Analog app from the working directory, so in an Nx workspace with several Analog apps they described the first app under apps/ instead of the one Vite serves. They now share the Vite root with the Analog tab through servedAnalogRoot().
Redacts the page URL and title in component tree reports, holds change detection instances weakly, stops visibility reports after pagehide so closed tabs are not counted as background tabs, points aria-controls at the response preview only while it is open, focuses the URL pattern after adding a rule, lets the panel find __connection.json next to itself so the CLI Panel URL and a report served at / connect, keeps refusing the folder the build was run from when --root is set, and fixes the tool count in the tools docs.
Rebuilds extension/ui for the network inspector and base URL changes.
Brings in the Vite root fix for Analog routes and build meta, keeping the P2 server function names.
Decides the Back to latest focus from the finished restore response, accepts pending select values on controls that update on blur or submit, names the served Analog app in Nx workspaces, and marks strings cut by the redaction window as truncated.
Rebuilds extension/ui for the store inspector focus change.
Brings in the second round of santoshyadavdev#184 review fixes and rebuilds extension/ui.
Brings in the squashed santoshyadavdev#184 and the santoshyadavdev#187 and santoshyadavdev#188 docs changes. P2 already held every santoshyadavdev#184 commit, so the conflicts keep this branch's side.
Brings in the squashed santoshyadavdev#184 and santoshyadavdev#185 and the santoshyadavdev#187 and santoshyadavdev#188 docs changes. This branch already held every santoshyadavdev#184 and santoshyadavdev#185 commit, so the conflicts keep this branch's side.
Fixes the open P2 issues from the September sweep, with tests for each fix and docs updated to match. Based on #184 (the P1 fixes), so review and merge that first.
Closes #85
Closes #86
Closes #87
Closes #88
Closes #89
Closes #90
Closes #91
Closes #92
Closes #93
Closes #94
Closes #95
Closes #96
Closes #97
Closes #98
Closes #99
Refs #100
Closes #101
Refs #102
Closes #105
Closes #106
Closes #107
Closes #108
Closes #109
Closes #110
Closes #111
Closes #112
Closes #113
Closes #114
Closes #115
Closes #116
Closes #117
Closes #118
Closes #119
Closes #121
Closes #122
Closes #123
Closes #124
Closes #125
Closes #126
Closes #127
Refs #128
Closes #129
Closes #130
Closes #131
Closes #132
Closes #133
Closes #134
Closes #135
Closes #136
Closes #137
Closes #138
Closes #139
Closes #140
Closes #141
Closes #142
Closes #143
Closes #144
Closes #145
Closes #146
Closes #147
Closes #148
Closes #149
Closes #150
Closes #151
Closes #152
Closes #153
Closes #154
Closes #155
Closes #156
Closes #158
Closes #159
Forms
SSR and HTTP
ufield, which leaves out HttpParams, so /api/feed?page=2 claimed the entry stored for page=1. It now matches on Angular's cache key (method, response type, URL, body and sorted params), computed for every key format Angular has used from v20 to v22.1+. Analog entries still match on URL.faulted. The interceptor now recordscancelled,mocked,delayMsandrulePattern, and setsfaultedonly for status 400 and up. The panel shows cancelled requests in a neutral tone, splits the note into delayed N ms, mocked and faulted, and shows the matched rule in the row and in the preview.redaction.secretNamesapplies there too.Injectors
name = inject(...)with a flat generic, only read@Inject(Token)parameters, and readprovidedIn: nullas a string. inject() calls now use a bracket-matched generic scan and credit bare calls to the enclosing const, function or class. Typed constructor parameters of decorated classes are read, and a null providedIn is left out.selectoronly labelled the answer. A new rpc/injector-tools.ts filters byselector(tag, class or id, with the lookup path resolved to names and tokens), adds atokenargument (which injectors provide it and what injects it), and caps output at 20,000 characters with a hint to narrow the query.truncatedflag and the types had no field for it. The flag is now in the types, kept per page and at the top of the shared state, shown as a notice on the Injectors page, and stated in inspect-providers and the injector-tree resource description.<ng-container>and listed in the tree and lookup path. A token listed in a provider list on the lookup path counts as provided. Optional deps show a neutral 'optional, not provided' label.NgRx
messagewas only ever set, never cleared. Fix: opening now focuses Cancel inside the labelled group, Cancel or Escape (which also calls preventDefault so the popup stays open) returns focus to Restore this state, restore keeps the P1 focus on the State tree or Back to latest, and selectPage, selectStore and selectEntry clearmessage.serialize()snapshots, which keep only the first 100 items or keys, so changes past that limit looked like no change. Fix:logClassickeeps the previous raw state and falls back toreferenceDiffon live values when the serialized diff is empty but the state reference changed. This matches the signal store path.Store.dispatchandStore.nextand tags each action in a WeakMap asdispatch,effect(Store.next) orreactive. Forreactive, it wraps the function given todispatch(fn).stopputs the original methods back. The log entry has anorigin, the panel shows it as a badge and an Origin row, and the ngrx-store resource description and docs are updated.Signals
Components
Overlay and popup
Router
waitFor: 'stable'waited a fixed 300 ms after the navigation ended. Fix: newwaitForStable()in router-actions.ts waits on the Router's rootPendingTasksInternal(the same signalApplicationRef.whenStable()reads), within the 10s WAIT_MS. The result now includesstable: true,stable: falsewith a note, orstable: 'unknown'. The tool schema also describeswaitFornow.loop-a/loop-broutes whose guards redirect to each other five times and then to summary?from=loop (a bounded module counter), a Guard loop link, RenderMode.Client entries for both routes, a root-app spec, and docs in demo-apps.md and router.md.redirectedTo. The panel message and the tool description report this too.platformNavigationfeature (NavigationStateManager), and fall back to the 'Router Scroller' token. Real-Router tests now cover every with* feature and the forRoot options.{checked:false, reason}or{checked:true, findings}. The panel shows 'No checks ran' with events-only or no-config wording, and an error with Retry. Re-runs are keyed on the last navigation's id and outcome, findings stay visible during automatic re-runs, and a sequence token drops stale answers.Analog
touched(), and an--errortoken with an invalid border (light #b91c1c, dark #f87171 for AA contrast). Invalid states are still reachable for the Forms inspector.redact()in analog-runtime.ts hid any key containing a secret substring (auth,pass,cardand so on), soauthorandpassengerswere hidden. Fix: it now uses the whole-wordisSecretKeyfrom analog-server-log.ts, plus the customredaction.secretNames, the same check server call previews use./x/**matched by string prefix, and onlyssr: falseroute rules were read. Fix: requests are matched to rows withexplainUrl, matching follows Nitro (/x/**covers/xand below,*is one segment, the most specific rule wins), every rule kind is parsed (ssr, prerender, isr, swr, cache, redirect, Cache-Control) and cited as the reason,CachedandRedirectmodes are new, andprerender: truerules feed the Prerender plan.classify()mapped every method on/_analog/pagestoload. Fix: a newactionkind for non-GET/HEAD requests, with a success, redirect (redacted Location), invalid (X-Analog-Errors, redacted preview) or error outcome. It is in the Server filter,analog-server-callsand itskindenum, andduplicateLoads()now pairs GET loads only..server.tsfiles for load/action, calls showed opaque ids, SSR calls skip HTTP, and__analog_fn_seeds were unlabeled. Fix: scan everysrc/**/*.server.tsforserverFnexports with Analog's sha256 id and method, show names in the Server list,analog-server-callsand payload labels, record SSR reads from their TransferState seeds in the page HTML, flag a seeded read called again after hydration (lintfn-fetched-twice, a callout, notes), stop the two false warnings, and add theanalog-server-functionsMCP tool plus a Server functions table.send()kept the old response and left Send enabled. Fix: the result now stores the URL it explains, shows empty-input and RPC errors, and has an Explaining state. The playground has asendingstate that clears the old response and turns Send off. Send also stays off for POST/PUT/PATCH/DELETE until the checkbox is ticked, with a hint that points to it.lintCardskept onlyfileandpathfor each finding and droppedmessage. Fix: each card item keeps the per-finding message and shows it (skipped for rules whose message only repeats the summary), and identical items are deduped.Pipes
CLI, config and security
highlightandinspect-signalshad no page argument,findComponentswalked pages oldest first, and an unknownpageId/pagefell back silently or blamed stdio. Fix: a sharedpageargument (rpc/pages.tsPAGE_ARGUMENT,inspect-providerskeepspageIdas an alias), oneunknownPageTextmessage that lists the reporting pages newest first (used by the routernoPage, forms, highlight, inspect-signals, inspect-providers and navigate), names resolved on the newest page with a note for other matches, and a newlist-pagestool.createCac, somcpregistered every tool, including page-only and write tools. Fix: a newcreateNgDevtoolsCli()in cli.ts adds--config <file>/NG_DEVTOOLS_CONFIG/ng-devtools.config.jsonand--read-onlytodev,buildandmcp, and passes the config throughcreateNgDevtools(). Its newpageToolshost option drops the tools listed inPAGE_AGENT_ENTRIESfrommcp.ctx.cwd = process.cwd(), and nothing could change it. Fix:--root <dir>/NG_DEVTOOLS_ROOTchanges into the folder before the server starts and refuses a missing folder. If the folder has no angular.json and no package.json that depends on@angular/core, it prints a warning on stderr.isAllowedHubOrigincompared rawallowedOriginsentries with the browser origin, whileallowsRemoteOriginsstill counted them. Fix: newnormalizeAllowedOrigins()reduces each entry tonew URL(entry).originonce, warns throughserver.config.loggerwhen it changes or drops an entry, and feeds the same list to both checks. A newblockedOriginReporterwarns once per refused origin, for HTTP and WebSocket.resolveNgDevtoolsConfig()silently dropped unknown keys and wrong types and clamped limits. Fix: newngDevtoolsConfigProblems()/ngDevtoolsConfigWarning()list unknown keys (with a "did you mean"), wrong types (with the value used instead) and clamped limits.createNgDevtools()prints one[ng-devtools]warning.configFromConnectionstays silent.createCachardcodes version 0.0.0, bin.mjs passed noonReady, and parse errors were unhandled. Fix:createNgDevtoolsCli()setscli.globalCommand.versionNumberfrom package.json. It prints the version, panel URL and MCP URL on ready, plus a note when port 9999 was taken. It registers a realdevcommand, rejects unknown positionals, and catches every error as one[ng-devtools]line with exit code 1.isSecretKey(or their own regexes) and ignored mask/unmask, the NgRx serializer skippedredactMessage, and Analog had its own word list. Fix: oneisRedactedKey()(the built-in words, secretNames, mask and unmask) used everywhere, one merged word list (adds cookie, authorization, jwt, sessionId, sessionKey), andredactMessageon NgRx strings and Error messages.Performance and limits
CI
pnpm test:panel, 32 tests) and an axe CI job (pnpm test:axe, all tabs and hub views, light and dark). The job found a duplicate region landmark on Routes, now fixed..tsimport paths (TS5097). Also, nothing in the demo program importsdevframeitself, so TS never loaded it as the augmentation target (TS2664). Fixed withrewriteRelativeImportExtensionsin examples/analog/tsconfig.app.json andimport type {} from 'devframe'in types.ts. Widened the include to src/server/**, so API routes are checked too, and added the demo'sngccheck topnpm typecheck.pnpm typecheckran plaintscon app/, which never reads templates. It now runsngc -p app/tsconfig.json --noEmit, and app/tsconfig.json turns onstrictTemplates(it passes with 0 errors).Left open
canMatchredirect is fixed; whetheractions: {router: false}should also block the probe needs a decisionChecks
pnpm test:devtools: 997 tests passpnpm test:panelandpnpm test:axe(new, from Add unit tests and an automated axe check for the devtools panel in CI #97): passpnpm exec nx test angular-devtools,pnpm typecheck(now with template and Analog checks),pnpm format:check,pnpm skills:check, docs build: passextension/uirebuilt in its own commitNotes for review
test:devtoolsnow runs the package tests only; the panel tests and the axe check are separate scripts, and CI runs all three@ngrx/storeand@ngrx/store-devtoolsare new dev dependencies, and the demo has a new/examples/storepage