Fix plant placement + add a Seed Tray (#39) #42

Merged
steve merged 2 commits from fix/plant-placement-and-seed-tray into main 2026-07-19 06:09:51 +00:00
3 changed files with 52 additions and 38 deletions
Showing only changes of commit 30e8d3e56c - Show all commits
+6 -6
View File
@@ -5,17 +5,17 @@ import type { Plant } from '@/lib/plants'
/** /**
* The Seed Tray strip in the focus-mode toolbar: a row of the garden's * The Seed Tray strip in the focus-mode toolbar: a row of the garden's
* kept-at-hand plants. Tap a chip to arm that plant for tap-to-place (the armed * kept-at-hand plants. Tap a chip to arm that plant for tap-to-place (the armed
* chip is highlighted); ✕ removes it from the tray; the trailing chip opens * chip is highlighted); ✕ removes it from the tray; the trailing "+ Plant" chip
* the full catalog picker. See useSeedTray for persistence. * opens the full catalog picker. See useSeedTray for persistence.
*/ */
export function SeedTray({ export function SeedTray({
plants, trayPlants,
armedPlantId, armedPlantId,
onArm, onArm,
onRemove, onRemove,
onOpenPicker, onOpenPicker,
}: { }: {
plants: Plant[] trayPlants: Plant[]
armedPlantId: number | null armedPlantId: number | null
onArm: (plant: Plant) => void onArm: (plant: Plant) => void
onRemove: (id: number) => void onRemove: (id: number) => void
@@ -23,7 +23,7 @@ export function SeedTray({
}) { }) {
return ( return (
<div className="flex flex-wrap items-center gap-1.5"> <div className="flex flex-wrap items-center gap-1.5">
{plants.map((p) => { {trayPlants.map((p) => {
const active = p.id === armedPlantId const active = p.id === armedPlantId
return ( return (
<span <span
Review

Chip styled span wrapping two buttons splits interactive affordance awkwardly

maintainability · flagged by 1 model

  • web/src/editor/SeedTray.tsx:29-54 — Each chip is a styled <span> wrapping two sibling <button>s, with the active-state border/bg on the outer span while each button carries its own rounded-full/focus ring. The interactive affordance is split across a non-interactive wrapper and two buttons; a single button with an inner ✕ (or role="group" on the span) would be cleaner. Not blocking — purely structural readability.

🪰 Gadfly · advisory

⚪ **Chip styled span wrapping two buttons splits interactive affordance awkwardly** _maintainability · flagged by 1 model_ - `web/src/editor/SeedTray.tsx:29-54` — Each chip is a styled `<span>` wrapping two sibling `<button>`s, with the active-state border/bg on the outer span while each button carries its own `rounded-full`/focus ring. The interactive affordance is split across a non-interactive wrapper and two buttons; a single button with an inner ✕ (or `role="group"` on the span) would be cleaner. Not blocking — purely structural readability. <sub>🪰 Gadfly · advisory</sub>
@@ -59,7 +59,7 @@ export function SeedTray({
onClick={onOpenPicker} onClick={onOpenPicker}
className="inline-flex items-center gap-1 rounded-full border border-dashed border-border px-2.5 py-1 text-xs font-medium text-muted outline-none transition-colors hover:border-accent hover:text-accent-strong focus-visible:ring-2 focus-visible:ring-accent/40" className="inline-flex items-center gap-1 rounded-full border border-dashed border-border px-2.5 py-1 text-xs font-medium text-muted outline-none transition-colors hover:border-accent hover:text-accent-strong focus-visible:ring-2 focus-visible:ring-accent/40"
> >
Plant + Plant
</button> </button>
</div> </div>
) )
+6 -4
View File
@@ -16,7 +16,8 @@ const TRAY_MAX = 24 // a working set, not a catalog; caps pathological growth
function loadIds(gardenId: number): number[] { function loadIds(gardenId: number): number[] {
Review

🟠 Unbounded localStorage read bypasses TRAY_MAX cap on load

error-handling, maintainability · flagged by 2 models

  • web/src/lib/seedTray.ts:16 — Unbounded localStorage read, no TRAY_MAX cap on load loadIds filters and returns every numeric ID stored in localStorage, but never applies TRAY_MAX. If the key is corrupted or manually edited to hold thousands of IDs, the component will attempt to render an unbounded number of chips on first mount, degrading or freezing the UI. The TRAY_MAX slice is only enforced inside add, so a malicious/corrupted payload bypasses the safeguard entirely. **Fix:…

🪰 Gadfly · advisory

🟠 **Unbounded localStorage read bypasses TRAY_MAX cap on load** _error-handling, maintainability · flagged by 2 models_ - **`web/src/lib/seedTray.ts:16` — Unbounded `localStorage` read, no `TRAY_MAX` cap on load** `loadIds` filters and returns every numeric ID stored in localStorage, but never applies `TRAY_MAX`. If the key is corrupted or manually edited to hold thousands of IDs, the component will attempt to render an unbounded number of chips on first mount, degrading or freezing the UI. The `TRAY_MAX` slice is only enforced inside `add`, so a malicious/corrupted payload bypasses the safeguard entirely. **Fix:… <sub>🪰 Gadfly · advisory</sub>
try { try {
const v: unknown = JSON.parse(localStorage.getItem(KEY(gardenId)) ?? '[]') const v: unknown = JSON.parse(localStorage.getItem(KEY(gardenId)) ?? '[]')
return Array.isArray(v) ? v.filter((n): n is number => typeof n === 'number') : [] const ids = Array.isArray(v) ? v.filter((n): n is number => typeof n === 'number') : []
return ids.slice(-TRAY_MAX) // honor the cap even if storage was hand-edited
} catch { } catch {
return [] return []
} }
@@ -30,17 +31,18 @@ function saveIds(gardenId: number, ids: number[]) {
} }
} }
Review

🟡 SeedTray interface name collides with the SeedTray component in editor/SeedTray.tsx

maintainability · flagged by 2 models

  • web/src/lib/seedTray.ts:33 vs web/src/editor/SeedTray.tsx:11Name collision: SeedTray is both the presentational component (export function SeedTray) and the hook's return type (export interface SeedTray). They live in separate modules so it compiles, but GardenEditorPage.tsx:10 imports the component while the hook's return shape flows in indirectly via useSeedTray, making "SeedTray" ambiguous across searches/stack traces. Renaming the interface (e.g. SeedTrayApi) would d…

🪰 Gadfly · advisory

🟡 **SeedTray interface name collides with the SeedTray component in editor/SeedTray.tsx** _maintainability · flagged by 2 models_ - `web/src/lib/seedTray.ts:33` vs `web/src/editor/SeedTray.tsx:11` — **Name collision**: `SeedTray` is both the presentational component (`export function SeedTray`) and the hook's return type (`export interface SeedTray`). They live in separate modules so it compiles, but `GardenEditorPage.tsx:10` imports the component while the hook's return shape flows in indirectly via `useSeedTray`, making "SeedTray" ambiguous across searches/stack traces. Renaming the interface (e.g. `SeedTrayApi`) would d… <sub>🪰 Gadfly · advisory</sub>
export interface SeedTray { export interface SeedTrayState {
/** Tray plants in insertion order, resolved against the live catalog. */ /** Tray plants in insertion order, resolved against the live catalog. */
trayPlants: Plant[] trayPlants: Plant[]
/** Add a plant to the end of the tray (no-op if already present). */ /** Add a plant to the end of the tray (no-op if already present; when the tray
* is full the oldest entry is evicted). */
add: (plant: Plant) => void add: (plant: Plant) => void
/** Remove a plant from the tray. */ /** Remove a plant from the tray. */
remove: (id: number) => void remove: (id: number) => void
} }
/** Per-garden Seed Tray backed by localStorage and the plant catalog. */ /** Per-garden Seed Tray backed by localStorage and the plant catalog. */
Review

🟡 useSeedTray doesn't surface plants.isPending/isError, so a catalog fetch failure silently empties the tray with no indication to the user

error-handling · flagged by 1 model

  • web/src/lib/seedTray.ts:44useSeedTray never checks plants.isPending/plants.isError from usePlants() (plants.ts:67-69). If the catalog fetch is loading or fails, byId stays empty and trayPlants silently resolves to [], leaving only the bare "+ Plant" chip with no indication anything went wrong — unlike PlantPicker, which explicitly renders "Loading plants…" and "Couldn't load plants." on isPending/isError (PlantPicker.tsx:136-137). Not data loss (ids stay in `localS…

🪰 Gadfly · advisory

🟡 **useSeedTray doesn't surface plants.isPending/isError, so a catalog fetch failure silently empties the tray with no indication to the user** _error-handling · flagged by 1 model_ - `web/src/lib/seedTray.ts:44` — `useSeedTray` never checks `plants.isPending`/`plants.isError` from `usePlants()` (`plants.ts:67-69`). If the catalog fetch is loading or fails, `byId` stays empty and `trayPlants` silently resolves to `[]`, leaving only the bare "+ Plant" chip with no indication anything went wrong — unlike `PlantPicker`, which explicitly renders "Loading plants…" and "Couldn't load plants." on `isPending`/`isError` (`PlantPicker.tsx:136-137`). Not data loss (ids stay in `localS… <sub>🪰 Gadfly · advisory</sub>
export function useSeedTray(gardenId: number): SeedTray { export function useSeedTray(gardenId: number): SeedTrayState {
const plants = usePlants() const plants = usePlants()
const [ids, setIds] = useState<number[]>(() => loadIds(gardenId)) const [ids, setIds] = useState<number[]>(() => loadIds(gardenId))
+40 -28
View File
1
@@ -244,18 +244,26 @@ export function GardenEditorPage() {
setArmedPlant(plant) setArmedPlant(plant)
} }
// Removing the armed plant from the tray also disarms it, so placement doesn't
// silently continue for a plant the user just cleared out.
function removeFromTrayAndDisarm(id: number) {
removeFromTray(id)
if (armedPlant?.id === id) setArmedPlant(null)
}
// The picker hands back the full Plant (from the whole catalog), so use it // The picker hands back the full Plant (from the whole catalog), so use it
// directly rather than re-resolving against the garden's referenced-plant map — // directly rather than re-resolving against the garden's referenced-plant map —
// a not-yet-placed plant isn't in that map, which used to silently abort the // a not-yet-placed plant isn't in that map, which used to silently abort the
// pick (nothing armed, picker left open). // pick (nothing armed, picker left open). Picking (place OR change) makes sure
// the plant renders and drops it into this garden's tray for quick reuse.
function onPickPlant(plant: Plant) { function onPickPlant(plant: Plant) {
if (!canEdit) return // defense in depth: viewers can't reach the picker anyway if (!canEdit) return // defense in depth: viewers can't reach the picker anyway
ensurePlant(plant)
addToTray(plant) addToTray(plant)
if (picker === 'change' && selectedPlop) { if (picker === 'change' && selectedPlop) {
ensurePlant(plant)
updatePlanting.mutate({ id: selectedPlop.id, version: selectedPlop.version, plantId: plant.id }) updatePlanting.mutate({ id: selectedPlop.id, version: selectedPlop.version, plantId: plant.id })
} else { } else {
armPlant(plant) // 'place' mode: arm for repeat placement setArmedPlant(plant) // 'place' mode: arm for repeat placement
} }
setPicker(null) setPicker(null)
} }
@@ -284,30 +292,34 @@ export function GardenEditorPage() {
{garden.name} {garden.name}
</button> </button>
<span className="max-w-[8rem] truncate text-muted">{objectDisplayName(focusedObject)}</span> <span className="max-w-[8rem] truncate text-muted">{objectDisplayName(focusedObject)}</span>
{canEdit && !focusedObject.plantable && <span className="text-xs text-muted">Not plantable</span>} {canEdit &&
{canEdit && focusedObject.plantable && ( (focusedObject.plantable ? (
<SeedTray <>
plants={trayPlants} <SeedTray
armedPlantId={armedPlant?.id ?? null} trayPlants={trayPlants}
onArm={armPlant} armedPlantId={armedPlant?.id ?? null}
onRemove={removeFromTray} onArm={armPlant}
onOpenPicker={() => setPicker('place')} onRemove={removeFromTrayAndDisarm}
/> onOpenPicker={() => setPicker('place')}
)} />
{canEdit && focusedObject.plantable && armedPlant && ( {armedPlant && (
<Button variant="ghost" className="px-2 py-1 text-xs" onClick={() => setArmedPlant(null)}> <Button variant="ghost" className="px-2 py-1 text-xs" onClick={() => setArmedPlant(null)}>
Done Done
</Button> </Button>
)} )}
{canEdit && focusedObject.plantable && focusedPlops.length > 0 && ( {focusedPlops.length > 0 && (
<Button <Button
variant="ghost" variant="ghost"
className="px-2 py-1 text-xs text-red-600 dark:text-red-400" className="px-2 py-1 text-xs text-red-600 dark:text-red-400"
onClick={() => setClearing(true)} onClick={() => setClearing(true)}
> >
Clear ({focusedPlops.length}) Clear ({focusedPlops.length})
</Button> </Button>
)} )}
</>
) : (
<span className="text-xs text-muted">Not plantable</span>
))}
</div> </div>
)} )}
<GardenCanvas garden={garden} objects={objects} plantings={plantings} plantsById={plantsById} canEdit={canEdit} /> <GardenCanvas garden={garden} objects={objects} plantings={plantings} plantsById={plantsById} canEdit={canEdit} />
@@ -355,7 +367,7 @@ export function GardenEditorPage() {
<PlantPicker <PlantPicker
unit={garden.unitPref} unit={garden.unitPref}
onClose={() => setPicker(null)} onClose={() => setPicker(null)}
onSelect={(p) => onPickPlant(p)} onSelect={onPickPlant}
/> />
)} )}