Skip to content

fix(share): copied feedback and Open button on Active Shares rows - #2806

Merged
giswqs merged 1 commit into
opengeos:mainfrom
deniial00:deniial00/copy-link-button-fix
Oct 2, 2026
Merged

giswqs merged 1 commit into
opengeos:mainfrom
deniial00:deniial00/copy-link-button-fix

Conversation

@deniial00

@deniial00 deniial00 commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

Closes #2804.

  • The Copy button on an Active Shares row now swaps to a checkmark for 2s after a successful clipboard write, like the post-create Copy button. copied is now copiedKey, so only the clicked button changes.
  • Each row gets an Open button (share.open) that opens the share's projectUrl, the same URL the post-create Open button uses.

Not changed: the "View" role label. normalizeShareRole deliberately fails closed to view when /api/shares omits or sends an unknown role; whether the server returns role for Edit shares needs checking against the real payload.

Verified in headless Chromium against the dev build with a mocked /api/shares (stubbed clipboard.writeText, since headless denies it): clicking row 2 shows a check on row 2 only, reset after ~2s; each row has Copy, Open and Revoke. tsc --noEmit and oxfmt --check pass.

Summary by CodeRabbit

  • New Features
    • Added an option to open an active share’s project link externally.
  • Bug Fixes
    • Copy confirmation now appears on the specific button used and clears after two seconds.

Copilot AI balanced review requested due to automatic review settings October 2, 2026 20:34

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: f04569f6-a98d-4fc4-bc01-09695c771b78

📥 Commits

Reviewing files that changed from the base of the PR and between ba45845 and 2be184d.

📒 Files selected for processing (1)
  • apps/geolibre-desktop/src/components/layout/ShareProjectDialog.tsx

Included review availability: This review used your included allowance. Your plan provides up to 8 included reviews per hour; 6 remain after this review.


📝 Walkthrough

Walkthrough

The share dialog now tracks clipboard success separately for the create-result button and each active-share row. Active-share rows also include a button that opens the project URL externally.

Changes

Share dialog

Layer / File(s) Summary
Per-button copy feedback and active-share links
apps/geolibre-desktop/src/components/layout/ShareProjectDialog.tsx
Copy feedback is keyed to the result button or active share ID and clears after two seconds. The dialog resets the key when it opens. Active-share rows also include a button to open the share URL externally.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

Suggested reviewers: giswqs

Merge Risk: ⚪ Minimal · up to 2be18

Each successful copy receives its intended two-second feedback interval, and the reviewed change presents no concrete issue that should block merging.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 2be18

The Open action requires a click and preserves existing URL-scheme protections. No vulnerability was established, but the allowed destination hosts for listed shares could not be confirmed.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The evidenced new exposure is user-triggered navigation to the selected share URL in that user's browser or system URL handler. The inspected path does not add bulk navigation, share-state mutation, or API-token forwarding.

Security Findings and Attack Paths

  • inferred — Steering this action to a malicious HTTP(S) destination would require influence over the returned projectUrl and a user click. The client permits cross-origin destinations, but ordinary-user influence over that field was not established; this is an unresolved trust-contract question, not a verified attack path.

Trust Boundaries and Controls

  • observed — Share-list access rejects missing tokens and authorization failures. Navigation separately validates URL syntax and scheme. Authentication of the list request does not itself constrain the destination origin supplied in its response.

Hardening Proposals

  • proposed — If active-share links are intended to remain on approved service origins, define that producer contract and validate destinations against it before navigation. This is conditional hardening, not a finding that arbitrary origins violate the current contract.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 1 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly and concisely describes both primary changes: per-row copied feedback and an Open button for Active Shares rows.
Description check ✅ Passed The description covers the change, testing performed, and related issue. It does not use the template headings, but it provides the required information and includes relevant implementation context.
  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit taps Copy, then waits,
A green check appears at the right place.
Each share gets its own little sign,
A link opens beyond the dialog line.
The rabbit hops off, pleased with the design.

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Confirms share.open already exists and is correctly used (it's already used for the post-create Open button, so this PR reuses it rather than introducing a new string). No i18n gap.

This PR is small and clean. I found no real bugs, security issues, or CLAUDE.md violations. I won't post any inline comments since I have no findings worth flagging even at low confidence.

Code review

Bugs: None found. copiedKey correctly scopes the checkmark to the clicked button, the "result" sentinel and s.id keys are rendered in mutually-exclusive tabs so no collision is observable, and existing timeout-clearing/reset logic (lines 527, 674-678, 418) is preserved correctly.

Security: None found. The new Open button reuses the existing openExternalLink helper (already used for the post-create Open button on result.projectUrl), which validates the URL scheme is http(s): before handing it to the Tauri opener or window.open, so no new unsafe-URL surface is introduced (confidence: high).

Performance: None found. No new re-renders or expensive work introduced.

Quality: Clean, minimal diff that mirrors existing patterns (same icon, same openExternalLink call style, same button styling as the post-create row) rather than introducing new abstractions. The copiedKey comment clearly documents the one-slot design. share.open and share.copyLink i18n keys already existed and are reused correctly — no missing translation keys (confidence: high).

CLAUDE.md: No violations. UI strings use existing t() keys rather than hardcoding text, and layout uses the existing gap-1/flex classes consistent with the surrounding RTL-aware styling (no new physical ml-/left- utilities introduced).

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

🔍 Cloudflare PR preview

Item Value
Site https://574708ff.geolibre-preview.pages.dev
Demo app https://574708ff.geolibre-preview.pages.dev/demo/
Commit 2be184d

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

🔍 GitHub Pages PR preview

Item Value
Site https://opengeos.org/pages-preview/GeoLibre/pr-2806/
Demo app https://opengeos.org/pages-preview/GeoLibre/pr-2806/demo/
Commit 2be184d

Note

GitHub Pages built this preview successfully, but its serving edge returned HTTP 403 when checked. The links may still be propagating.

@giswqs
giswqs merged commit e716b3e into opengeos:main Oct 2, 2026
26 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: Copy link button in Active Shares does not show copied/checkmark feedback or View link

3 participants