Skip to content

chore: Implement System Audit Recommendations#1253

Closed
BigSimmo wants to merge 1 commit into
mainfrom
remediate-system-audit-findings
Closed

chore: Implement System Audit Recommendations#1253
BigSimmo wants to merge 1 commit into
mainfrom
remediate-system-audit-findings

Conversation

@BigSimmo

Copy link
Copy Markdown
Owner

Description

This PR safely implements all system audit recommendations from the recent review.

Key Improvements:

  • UI Resilience: Fixed trust-gating failures in Evidence Panels and aligned isAnswerSourceBacked behavior for clinical safety.
  • Responsive Contracts: Reverted and repaired mode home templates and CSS configurations to properly respect shared phone edge-to-edge contracts and sizing grid thresholds.
  • Test Isolation: Added required
    ext/navigation router mocks to privacy-ui.test.ts.
  • Lock Management & Preflights: Tuned long-running test timeouts (e.g.
    econciliation-preflight.test.ts scanning multiple active git worktrees) for stability in heavy Windows environments.
  • Database Skills: Validated skill catalog metadata (prompt-perfector) against canonical counts.
  • Cleanup: Removed lingering untracked scratch test files from prior AI sessions.

Verification:

  • Verified locally via
    pm run verify:pr-local (all tests passing, build succeeds, bundle-budgets within tolerance).
  • No regressions found. Tested across standard breakpoints (tablet, desktop, phone edge-to-edge).

@coderabbitai

coderabbitai Bot commented Jul 26, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

@BigSimmo, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 23 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 82eb2644-4535-4a0c-9282-d1ec3f4cac3b

📥 Commits

Reviewing files that changed from the base of the PR and between 0c0f69c and cc1fa9d.

📒 Files selected for processing (37)
  • .agents/skills/catalog.json
  • .agents/skills/prompt-perfector/agents/openai.yaml
  • docs/audit/repo-wide-review-remediation-plan-2026-07-23.md
  • docs/codebase-index.md
  • docs/outstanding-issues.md
  • docs/search-chrome-behaviour.md
  • playwright.visual.config.ts
  • scripts/check-codebase-index-coverage.mjs
  • scripts/run-heavy.mjs
  • scripts/run-live-tests.mjs
  • scripts/run-playwright.mjs
  • scripts/run-vitest.mjs
  • scripts/test-run-lock.mjs
  • scripts/verify-pr-local.mjs
  • src/app/api/answer/route.ts
  • src/app/api/upload/route.ts
  • src/components/clinical-dashboard/answer-status.tsx
  • src/components/clinical-dashboard/evidence-panels.tsx
  • src/components/clinical-dashboard/settings-dialog.tsx
  • src/components/services/service-detail-page.tsx
  • src/components/services/services-navigator-page.tsx
  • src/lib/openai.ts
  • src/lib/service-catalog-mapper.ts
  • tests/database-skills.test.ts
  • tests/document-flow-routes.test.ts
  • tests/privacy-ui.test.ts
  • tests/private-access-routes.test.ts
  • tests/reconciliation-preflight.test.ts
  • tests/setup/jsdom.setup.ts
  • tests/test-runner-safety.test.ts
  • tests/therapy-compass-responsive-contract.test.ts
  • tests/ui-primitives.dom.test.tsx
  • tests/ui-tools.spec.ts
  • tests/visual-evidence-tabs.dom.test.tsx
  • tests/visual-intelligence.test.ts
  • vitest.config.mts
  • worker/main.ts
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch remediate-system-audit-findings

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@supabase

supabase Bot commented Jul 26, 2026

Copy link
Copy Markdown

This pull request has been ignored for the connected project sjrfecxgysukkwxsowpy because there are no changes detected in supabase directory. You can change this behaviour in Project Integrations Settings ↗︎.


Preview Branches by Supabase.
Learn more about Supabase Branching ↗︎.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: cc1fa9d484

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".


function trustGatedAnswerForClinicalNotes(
answer: RagAnswer,
visualEvidence: VisualEvidenceCard[] = answer.visualEvidence ?? [],

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Pass filtered visual evidence into clinical notes

When a source-backed answer contains raw table evidence that buildAnswerRenderModel suppresses, AnswerResultSurface does not pass renderModel.visualEvidence to this panel, so this default restores answer.visualEvidence and lets the clinical-notes sheet reconstruct or count evidence that the trust policy removed. The new direct-component test avoids the production path by explicitly passing visualEvidence={[]}; an integration test that renders AnswerResultSurface with raw evidence and an empty filtered evidence list would reproduce this. Require the already-filtered evidence list rather than falling back to the raw answer payload.

Useful? React with 👍 / 👎.

@cursor

cursor Bot commented Jul 26, 2026

Copy link
Copy Markdown
Contributor

Closing without merge.

Tip cc1fa9d48434 is ~507 behind main with real merge-tree conflicts across answer API, evidence panels, tests, docs, and scripts. PR policy fails (missing Clinical Governance / RAG impact for high-risk surfaces).

Some audit/test ideas may still be salvageable, but only via a clean rebuild on current main — not by merging this tip. If you want specific pieces kept, say which (evidence trust-gating, privacy-ui mocks, skills catalog, etc.) and we can open a focused rebuild PR.

@BigSimmo BigSimmo closed this Jul 26, 2026
cursor Bot pushed a commit that referenced this pull request Jul 26, 2026
* fix: stop choppy screen resize when switching modes

Mode switches animated phone composer reserve because searchMode updated
before the pathname landed, briefly leaving isStandaloneModeHome false and
running the 200ms padding transition. Detect mode homes from pathname only,
navigate without optimistic mode state, and limit padding transitions to
scroll-hide.

Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>

* test: align therapy-compass wiring with pathname mode-home gate

Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>

* docs(ledger): record mode-switch lag same-class bug hunt

Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>

* fix: close same-class mode-switch layout thrash bugs

After the reserve-flip fix, related choppiness remained from eager
crossModeSearch chrome updates, inherited phone scroll/hide across mode
homes, a hero-portal null gap while slots rebound, a taller mode-home
loading skeleton, and services/forms contentAlign jumping after registry
load. Navigate out of the dashboard without rewriting chrome, reset
scroll-hide on pathname change, keep the default composer until the
portal attaches, align the skeleton to the shell header token, and keep
loading homes top-aligned on phone.

Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>

* docs(ledger): record mode-switch thrash review fixes

Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>

* fix: satisfy lint for mode-switch scroll and portal cleanup

Reset bottom-composer hidden state during render on pathname change
instead of setState-in-effect, and drop the unused hero-portal fallback
flag now that the default composer stays mounted until the host attaches.

Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>

* docs(ledger): record mode-switch thrash lint closeout

Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>

* docs(ledger): record frontend-architecture loading/nav review

Append review of mode/page loading and navigation architecture at HEAD
0ef62ff: P1 shell bundle + hydration blanking; residual remount/tools dual.

Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>

* fix: reduce mode/page loading blanking and layout rework

Parallel loading review found hard-load blanking from ClientHydrationBoundary,
mismatched/missing mode-home loading skeletons, forms catalog in the client
chunk, ClinicalDashboard static weight on namespaced routes, sidebar column
animation on remount, forms query remounts, and document viewer remounts on
page flips. Paint RSC children immediately, align ModeHomeRouteLoading, wire
mode-home loading.tsx files, server-pass the default form slug, dynamic-import
ClinicalDashboard, gate sidebar transitions after mount, and stop unnecessary
remount keys.

Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>

* docs(ledger): record parallel loading behaviour review fixes

Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>

* refactor: extract sidebar transition hook and private-scope URL helper

Keeps ClinicalDashboard inside the maintainability budget after the
loading-performance pass, and shares the remount-safe sidebar transition
gate with GlobalSearchShell.

Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>

* test: allow DocumentViewer identity-only remount key

Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>

* test: align chrome contracts with pathname reset and gated padding

After merging main's cross-breakpoint scroll-hide wiring, update static
contracts for resetKey=pathname, and keep phone padding transitions gated
to scroll-hide only so mode switches still snap.

Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>

* fix: clear CI hydration and phone-scroll failures

Gate desktop composer portal adoption until page-owned slots mark
themselves ready after hydration, so hard-loads no longer inject a
display:contents host into still-unhydrated RSC HTML (React #418).
Update phone-scroll expectations for scroll-hide-only reserve transitions.

Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>

* style: prettier-format portal ready-gate files

Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>

* fix: keep document searches dashboard-owned and animate reserve reveal

Treat /documents/search as in-shell for cross-mode sync, keep a short-lived reserve-transition marker through hide and reveal, omit readiness cards without a default slug, and preserve URL hashes when clearing private scope refs.

* fix: stop duplicate page-root testids from searchParams Suspense

Nesting route children inside the shell's useSearchParams Suspense left a
hidden Next streaming S: clone of forms/favourites/presentation roots under
CI load. Gate always-standalone paths off that boundary and bridge params
beside the shell body so mode-home RSC paint stays.

Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>

* style: prettier format DocumentViewer reserve-transition import

* docs: record babysit sweep ledger rows for #1241/#1248/#1254/#1257/#1253/#1255

* refactor: extract DocumentViewer/Dashboard helpers under budgets

Pull PDF viewer mode helpers and document chrome scroll wiring into
focused modules, and isolate the dashboard desktop result composer slot,
so maintainability no-growth budgets pass after the reserve-transition
and portal ready-gate work.

Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>

* test: align desktop page-slot contract with extracted helper

Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>

* fix: satisfy hooks lint for searchParams Suspense bridge

Use useSyncExternalStore for the client-only gate and call the param
callback from layout effect deps instead of updating a ref during render.

Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>

* fix: seed standalone submitted search params

Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>

* test: stabilize phone-scroll and presentation page assertions

Drop the settled-bottom 0.24s reserve check (transition is short-lived on
data-reserve-transitioning), and scope differential presentation lookups to
the live shell scrollport so hidden Next streaming clones cannot fail strict
mode under CI load.

Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>

* fix: narrow submitted search param seeding

Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
cursor Bot pushed a commit that referenced this pull request Jul 26, 2026
Append final land/close rows for the authorized open-PR triage:
closed unsafe audit tips #1255/#1253, and prlanded #1257/#1212/#1241/#1248/#1254/#1259.

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant