• feat(web): address Heid code-review findings — issue #16 (v0.16.0)

    vh released this 2026-05-27 20:53:13 -07:00 | 236 commits to main since this release

    Heid panel review (Gróa + Hulda, thread 01KSP5P6CSJH) on v0.15.0/
    v0.15.1 surfaced one load-bearing bug + several precision items. This
    pass closes them.

    Load-bearing fix — cancel paths targeted the wrong turn_id:

    • _TURN_COUNTER allocates browser-local ids (1, 2, 3…); the real
      upstream Worldtree turn_id (e.g. 799) only arrives in the first SSE
      event. The v0.15.x cancel/disconnect/shutdown paths posted to
      /sessions/{sid}/turns/{LOCAL_ID}/cancel — wrong URL upstream.
    • TurnHandle.upstream_response (dead field) → upstream_turn_id: int|None.
      Captured from the first event's sse_id.turn_id in the stream
      generator. All cancel paths now target it. Cancel before the upstream
      stream starts (upstream_turn_id None) is a no-op
      ({"cancelled": false, "reason": "not_started"}).
    • The old cancel tests mocked the local-id URL, so they encoded the bug;
      rewritten to assert the UPSTREAM id is targeted.

    Behavior change (minor-bump driver) — server-side end_user_id:

    • create_app gains end_user_id kwarg; entrypoint reads
      RATATOSKR_END_USER_ID and threads it in. POST /api/sessions uses
      app.state.end_user_id, IGNORING any browser-supplied value (a client
      can't impersonate an arbitrary end-user partition). JS no longer
      sends end_user_id.

    Precision fixes:

    • Entrypoint missing-extras ImportError catch scoped to starlette/
      uvicorn ONLY; baseline-dep / first-party import failures now
      propagate as real tracebacks instead of masking as exit-12.
    • Lifespan shutdown logs per-pending session_id + upstream_turn_id
      (was a single aggregate count).

    Tests (+18; 376 total):

    • disconnect_triggers_upstream_cancel (INV-005 load-bearing — drives
      the stream generator directly + cancels the consuming task; would
      have caught the turn_id bug)
    • cancel_targets_upstream_turn_id, cancel_before_started_is_noop,
      cancel_failed_500
    • server-side end_user_id: uses / ignores-body / omits-when-unset
    • create_app: routes_registered / state_attached / factory_stored
    • entrypoint: default_host / port_zero / happy_argv / open / no-open
    • real_import_bug_propagates (precision guard)
    • full_event_vocab at the stream-endpoint layer

    Contract #16 amended: v0.16.0 amendment banner + INV-005/006 reworded
    for upstream_turn_id + FN sketches corrected (server-side end_user_id,
    upstream_response→upstream_turn_id, manual client lifecycle vs the
    non-executable async-with sketch, not-started cancel branch).

    Downloads