Skip to content

fix(components): action:menu consumes autoTrigger, so an overflowed deep link still runs (#4162) - #4195

Merged
yinlianghui merged 1 commit into
mainfrom
claude/issue-4162-autotrigger-menu
Aug 10, 2026
Merged

fix(components): action:menu consumes autoTrigger, so an overflowed deep link still runs (#4162)#4195
yinlianghui merged 1 commit into
mainfrom
claude/issue-4162-autotrigger-menu

Conversation

@yinlianghui

@yinlianghui yinlianghui commented Aug 10, 2026

Copy link
Copy Markdown
Collaborator

Fixes #4162

autoTrigger — the client-composed "run this action as soon as a renderer receives it" flag behind the #844 welcome-page deep link — was consumed only by action:button. action:bar splits its post-gate list at maxVisible (3 desktop / 1 mobile) and hands the tail to action:menu, which had no handling for the flag at all. An auto-triggered action that sorted past that threshold was therefore rendered as an ordinary "More" entry and never ran, while the caller had already spent the one-shot signal it stood for: consumption of ?runAction=create_environment is modelled as stripping it from the URL, so the end state was urlParam=null execute=0 — no dialog, and no URL left to retry from.

This is #4123's signature one layer deeper, and PR #4166 does not close it: arming keys on the post-gate list, which INCLUDES the actions the bar is about to move into the menu, so arming is correct and the strip happens exactly as intended. Verified on this branch's tip before implementing — the app-shell probe in this PR fails on origin/main with the card's measurement.

The ruling, as implemented

The delegated ruling on the card: the flag's contract is "execute once on mount by whichever renderer receives the action". So action:menu consumes it by EXECUTING, through the same handleExecute a click on that item takes — not by rendering an affordance and hoping, and not by opening the dropdown, so a transport flag never moves what the user sees.

No safety reason against execution-from-menu turned up in the structure, so the ruling's premise stands: the menu already owns a full execute path (confirm text, params, resultDialog, toasts all forwarded), and the runner applies its own confirm / param-collection / entitlement gates identically for both renderers.

Two placement decisions the structure forced, both documented at the call site:

  • The consumption point is the menu renderer, not the item. Items live inside DropdownMenuContent, which Radix mounts only when the dropdown OPENS — an effect there would wait on the very click the flag exists to avoid, and would make the trigger's open state, not the action, decide whether a deep link runs.
  • Once-ness has exactly one implementation. The guard and the flag test moved to packages/components/src/renderers/action/auto-trigger.ts; action:button now calls the same useAutoTriggerOnce, and the menu instantiates it per action through a headless ActionAutoTrigger that renders nothing (hooks cannot be called in a loop). One guard ref per action, mounted for every action rather than only the flagged ones, so the ref outlives a flag that flips — which is what keeps a true → false → true action firing once, as the button's long-lived ref does.

Where the boundary sits: container visibility governs mounting (a hidden action:bar or action:menu renders no children and auto-triggers nothing), while the action's own visible gate does not suppress the trigger. That second half is parity, not a new choice — action:button declares its effect before its visible early return, so a gated-invisible action executes anyway (measured on origin/main: rendered="" execute=1). Diverging here would have re-created this card's defect one predicate over, so the two renderers now agree and the question of whether what they agree on is right is filed as #4191.

Tests

New pins in packages/components/src/renderers/action/__tests__/action-overflow-autotrigger.test.tsx (12) and packages/app-shell/src/environment/__tests__/EnvironmentListToolbar.deepLinkOverflow.test.tsx (4), the latter driving the real toolbar end-to-end on the card's exact shape (create action 4th, add_development state so no variant: 'primary' floats it up). #4166's arming file is untouched and still green.

Covered: the overflow probe executes exactly once; the dropdown stays closed (aria-expanded="false", no menu content in the DOM); re-renders do not re-fire; a flag flipping true later fires once; systemActions (always in the menu, whatever the viewport) are honoured; the guard is per action, so two flagged actions each run once; and the refusal half — an overflow action WITHOUT the flag runs nothing, no deep link runs nothing, the inline path still belongs to action:button alone (no double-fire).

Reverse verification — the menu consumption reverted to origin/main, everything else kept:

× the card's probe: an autoTrigger action that spills past maxVisible still executes, exactly once
× executes WITHOUT opening the menu — the dropdown stays closed
× re-renders do not re-fire it
× the flag flipping true LATER still triggers exactly once
× systemActions — always overflow, never inline — are honoured the same way
× the once-guard is per ACTION, not per menu: two flagged overflow actions each run once
× the ACTION's own declared visible gate does not suppress it — and inline agrees with overflow
× [app-shell] the card's probe: create action 4th → rendered by action:menu → still executes, once
× [app-shell] and it does not open the menu to do it
✓ an overflow action WITHOUT the flag is untouched — nothing runs on mount
✓ an autoTrigger action that fits inline is still run by action:button, once
✓ a CONTAINER that renders nothing mounts nothing: a hidden action:bar fires neither path
✓ [app-shell] no deep link → the overflowed create action just sits in the menu
✓ 10/10 of #4166's arming pins
Tests  9 failed | 17 passed (26)

The failure is the filing's signature verbatim — AssertionError: expected "vi.fn()" to be called 1 times, but got 0 times on the app-shell probe, i.e. execute=0 with the param already stripped. Only the menu-side assertions move; every control pin stays green in both directions.

Local runs (repo root, --maxWorkers=2 under the shared verification lock):

vitest run packages/components/src/renderers/action/ packages/components/src/__tests__/ packages/app-shell/src/environment/
  Test Files  76 passed (76)      Tests  833 passed (833)

vitest run [the other action:menu consumers: plugin-grid RowActionMenu*, plugin-detail record-quick-actions, data-table-row-action-visible, MetadataTypeActions]
  Test Files  6 passed (6)        Tests  83 passed (83)

pnpm --filter @object-ui/components type-check    → tsc --noEmit && tsc -p tsconfig.typetests.json, clean
pnpm --filter @object-ui/app-shell   type-check    → clean (both after building each package's `^...` closure)
pnpm --filter @object-ui/components --filter @object-ui/app-shell lint  → exit 0, 0 errors
node scripts/check-changeset-presence.mjs / check-changeset-no-major.mjs / check-control-bytes.mjs → all green

Out of scope, filed

Changeset: @object-ui/components patch. The app-shell change is a test file only.


Generated by Claude Code

…eep link still runs (#4162)

`autoTrigger` was consumed only by `action:button`. `action:bar` splits its
post-gate list at `maxVisible` (3 desktop / 1 mobile) and hands the tail to
`action:menu`, which had no handling for the flag — so an auto-triggered action
that sorted past the threshold was rendered as an ordinary "More" entry and
never ran, while the caller had already spent the one-shot signal it stood for
(measured `urlParam=null execute=0`, unrecoverable because the URL strip IS the
consumption).

Per the ruling on the card, the flag's contract is "execute once on mount by
whichever renderer receives the action": the menu now consumes it by executing,
through the same path a click takes, without opening the dropdown. The
consumption point is the menu renderer (where the action provably arrives), not
the items — Radix mounts those only once the dropdown opens.

Once-ness has one implementation, lifted to `renderers/action/auto-trigger.ts`
and shared by both renderers.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017Qqyix2QcnpUC9XeYVDzx3
@vercel

vercel Bot commented Aug 10, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated (UTC)
objectui Ignored Ignored Aug 10, 2026 8:04pm

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

Metric Value Budget
Main entry (gzip) 28.3 KB 350 KB
Entry file index-BmHQY3GD.js
Status PASS

📦 Bundle Size Report

Package Size Gzipped
app-shell (index.js) 8.88KB 3.25KB
app-shell (runtime-config.js) 7.42KB 2.32KB
app-shell (types.js) 0.01KB 0.04KB
app-shell (urlParams.js) 7.57KB 2.97KB
auth (AuthContext.js) 0.31KB 0.24KB
auth (AuthGuard.js) 1.17KB 0.53KB
auth (AuthProvider.js) 22.10KB 4.37KB
auth (AuthShell.js) 3.49KB 1.40KB
auth (ForgotPasswordForm.js) 12.21KB 3.45KB
auth (LoginForm.js) 18.13KB 5.39KB
auth (PreviewBanner.js) 0.90KB 0.50KB
auth (RegisterForm.js) 6.64KB 2.21KB
auth (SocialSignInButtons.js) 9.60KB 3.89KB
auth (UserMenu.js) 3.40KB 1.22KB
auth (auth-gate-events.js) 1.29KB 0.66KB
auth (authStyles.js) 5.04KB 1.72KB
auth (createAuthClient.js) 35.76KB 9.11KB
auth (createAuthenticatedFetch.js) 4.37KB 1.69KB
auth (index.js) 2.35KB 1.07KB
auth (org-roles.js) 6.66KB 2.78KB
auth (phone-identifier.js) 1.11KB 0.66KB
auth (types.js) 0.59KB 0.35KB
auth (useAuth.js) 4.91KB 0.87KB
auth (useIsWorkspaceAdmin.js) 1.61KB 0.85KB
collaboration (CommentThread.js) 26.07KB 7.56KB
collaboration (LiveCursors.js) 3.17KB 1.27KB
collaboration (PresenceAvatars.js) 6.49KB 2.64KB
collaboration (PresenceProvider.js) 2.79KB 1.13KB
collaboration (index.js) 1.65KB 0.73KB
collaboration (useCollaborationTranslation.js) 6.05KB 2.52KB
collaboration (useCommentSearch.js) 1.98KB 0.88KB
collaboration (useConflictResolution.js) 7.75KB 1.86KB
collaboration (useMentionNotifications.js) 1.81KB 0.68KB
collaboration (usePresence.js) 6.33KB 1.84KB
collaboration (useRealtimeSubscription.js) 7.91KB 2.01KB
components (index.js) 486.12KB 107.45KB
core (index.js) 3.04KB 1.15KB
create-plugin (index.js) 10.08KB 3.26KB
data-objectstack (index.js) 140.66KB 36.25KB
fields (index.js) 226.96KB 56.30KB
i18n (LocalizationContext.js) 1.76KB 0.96KB
i18n (currency.js) 1.22KB 0.64KB
i18n (i18n.js) 4.32KB 1.77KB
i18n (index.js) 2.65KB 1.06KB
i18n (pickLocalized.js) 1.70KB 0.83KB
i18n (provider.js) 9.48KB 3.27KB
i18n (useObjectLabel.js) 27.59KB 6.63KB
i18n (useSafeTranslation.js) 4.52KB 1.96KB
layout (index.js) 38.87KB 10.80KB
mobile (MobileProvider.js) 0.92KB 0.49KB
mobile (ResponsiveContainer.js) 0.94KB 0.38KB
mobile (breakpoints.js) 1.51KB 0.70KB
mobile (createOfflineDataSource.js) 5.61KB 1.74KB
mobile (index.js) 1.50KB 0.62KB
mobile (offlineQueue.js) 3.91KB 1.35KB
mobile (pwa.js) 0.97KB 0.49KB
mobile (serviceWorker.js) 1.48KB 0.62KB
mobile (serviceWorkerSource.js) 3.41KB 1.48KB
mobile (useBreakpoint.js) 1.54KB 0.65KB
mobile (useGesture.js) 6.96KB 1.98KB
mobile (useOfflineSync.js) 1.99KB 0.72KB
mobile (usePullToRefresh.js) 2.53KB 0.85KB
mobile (useResponsive.js) 0.71KB 0.42KB
mobile (useResponsiveConfig.js) 1.36KB 0.63KB
mobile (useSpecGesture.js) 4.32KB 1.64KB
mobile (useTouchTarget.js) 1.01KB 0.54KB
permissions (MePermissionsProvider.js) 8.75KB 3.06KB
permissions (PermissionContext.js) 0.31KB 0.25KB
permissions (PermissionGuard.js) 0.89KB 0.45KB
permissions (PermissionProvider.js) 3.67KB 1.12KB
permissions (evaluator.js) 4.41KB 1.44KB
permissions (index.js) 0.91KB 0.41KB
permissions (store.js) 0.91KB 0.42KB
permissions (useFieldPermissions.js) 1.28KB 0.52KB
permissions (usePermissions.js) 1.55KB 0.71KB
plugin-ai (index.js) 15.71KB 3.79KB
plugin-calendar (index.js) 45.23KB 12.45KB
plugin-charts (index.js) 61.52KB 17.49KB
plugin-chatbot (index.js) 180.33KB 42.79KB
plugin-dashboard (index.js) 118.52KB 30.68KB
plugin-designer (index.js) 210.51KB 42.51KB
plugin-detail (index.js) 237.80KB 59.48KB
plugin-editor (index.js) 2.46KB 1.10KB
plugin-form (index.js) 114.58KB 27.68KB
plugin-gantt (index.js) 162.81KB 39.67KB
plugin-grid (index.js) 188.04KB 49.91KB
plugin-kanban (index.js) 48.60KB 13.41KB
plugin-list (index.js) 110.04KB 26.67KB
plugin-map (index.js) 17.00KB 5.32KB
plugin-markdown (index.js) 13.72KB 4.69KB
plugin-report (index.js) 40.58KB 10.58KB
plugin-timeline (index.js) 26.21KB 7.52KB
plugin-tree (index.js) 8.50KB 2.88KB
plugin-view (index.js) 84.03KB 20.55KB
providers (DataSourceProvider.js) 0.75KB 0.39KB
providers (MetadataProvider.js) 1.37KB 0.59KB
providers (ThemeProvider.js) 1.90KB 0.85KB
providers (UploadProvider.js) 11.71KB 3.53KB
providers (index.js) 0.44KB 0.22KB
providers (types.js) 0.01KB 0.04KB
react-runtime (index.js) 5.67KB 2.37KB
react (LazyPluginLoader.js) 3.77KB 1.33KB
react (SchemaRenderer.js) 23.71KB 7.95KB
react (data-invalidation.js) 5.05KB 2.08KB
react (index.js) 1.23KB 0.66KB
react (spec-input.js) 0.20KB 0.18KB
sdui-parser (codegen.js) 4.09KB 1.74KB
sdui-parser (index.js) 4.47KB 2.03KB
sdui-parser (parse.js) 10.04KB 2.82KB
sdui-parser (types.js) 0.29KB 0.24KB
sdui-parser (validate.js) 4.69KB 1.48KB
types (ai.js) 0.20KB 0.17KB
types (api-types.js) 0.20KB 0.18KB
types (app.js) 2.87KB 0.99KB
types (base.js) 0.20KB 0.18KB
types (blocks.js) 0.20KB 0.18KB
types (complex.js) 0.20KB 0.18KB
types (crud.js) 0.20KB 0.18KB
types (data-display.js) 0.20KB 0.18KB
types (data-protocol.js) 0.20KB 0.19KB
types (data.js) 0.20KB 0.18KB
types (designer.js) 1.87KB 0.85KB
types (disclosure.js) 0.20KB 0.18KB
types (error-code.js) 1.54KB 0.88KB
types (feedback.js) 0.20KB 0.18KB
types (field-types.js) 0.20KB 0.18KB
types (form.js) 0.20KB 0.18KB
types (http-retry.js) 4.32KB 2.02KB
types (index.js) 2.71KB 1.34KB
types (layout.js) 0.20KB 0.18KB
types (managed-by.js) 0.19KB 0.18KB
types (mobile.js) 2.59KB 1.31KB
types (navigation.js) 0.20KB 0.18KB
types (objectql.js) 0.20KB 0.18KB
types (overlay.js) 0.20KB 0.18KB
types (permissions.js) 0.20KB 0.18KB
types (plugin-scope.js) 0.20KB 0.18KB
types (record-components.js) 0.20KB 0.19KB
types (record-semantics.js) 1.28KB 0.67KB
types (registry.js) 0.20KB 0.18KB
types (reports.js) 0.20KB 0.18KB
types (spec-report.js) 5.05KB 1.93KB
types (system-fields.js) 3.33KB 1.54KB
types (theme.js) 0.20KB 0.18KB
types (ui-action.js) 3.40KB 1.71KB
types (views.js) 0.20KB 0.18KB
types (widget.js) 0.20KB 0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@yinlianghui
yinlianghui marked this pull request as ready for review August 10, 2026 20:17
@yinlianghui
yinlianghui added this pull request to the merge queue Aug 10, 2026
Merged via the queue into main with commit debad27 Aug 10, 2026
21 checks passed
@yinlianghui
yinlianghui deleted the claude/issue-4162-autotrigger-menu branch August 10, 2026 20:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

2 participants