Build fresh API session contexts instead of reusing persisted web sessions that may carry impersonation state.
Reject deactivated report export API key owners and strengthen regression coverage for API key, OAuth, and report export authentication paths.
Adds Provider::TinkoffInvest, a token-based securities provider built on the
public T-Invest REST gateway (invest-public-api.tinkoff.ru/rest). It serves
prices for Russian instruments (shares, ETF/БПИФ, bonds) and, crucially, brand
logos via the T-Invest CDN — the authoritative logo source for MOEX
instruments, which ISS (MoexPublic) does not provide.
- Registry: register `tinkoff_invest` under the :securities concept; token via
ENV TINKOFF_INVEST_API_KEY or encrypted Setting.tinkoff_invest_api_key.
- Logos independent of the price provider: Security#import_brand_logo consults
T-Invest for a logo whenever a token is configured (after the price-provider
metadata fetch, so it never short-circuits website_url backfill). Gated on
token presence, not the securities checklist.
- display_logo_url: with no website domain, a stored provider logo (T-Invest)
now beats the ticker-only Brandfetch lettermark; when a domain exists,
Brandfetch still wins (unchanged).
- MoexPublic no longer reports moex.com as the issuer website — it's the
exchange, not the issuer, and would make Brandfetch render the exchange logo
for every instrument and shadow the real brand logo.
- Prices: GetCandles (daily, paged) + GetLastPrices; Quotation units+nano/1e9;
bonds priced as percent-of-par x nominal (missing nominal raises, not 0).
- Settings: encrypted token field (always shown) + provider checkbox + en locale.
- Tests for search/info/logo-url/prices/bond/incomplete-candle and display logic.
Co-authored-by: Claude <noreply@anthropic.com>
* perf(reports): avoid residual category lazy loads
* test(reports): reuse SQL query capture helper
Move the reports SQL capture regression helper into test/support and document the category loading and budget reload choices called out in review.
* perf(dashboard): streamline investment activity totals
* fix(dashboard): skip empty investment totals cache writes
Short-circuit empty investment account totals before cache fetch and move the new SQL query capture regression helper into test/support.
* refactor(dashboard): address review on investment totals query
- Drop defensive ArgumentError guards in InvestmentStatement::Totals#initialize.
The sole caller (totals_query) always passes correct types, and the
empty_result early-return already handles the zero-accounts case.
- Remove the redundant accounts JOIN and its family_id/status filters from the
aggregation SQL. account_ids is already scoped to the family's visible
(draft/active) investment accounts, so the join back to accounts is
unnecessary work in the query plan. Drop the now-unused family_id param.
- Add a regression assertion that the aggregate no longer joins accounts.
* feat(prices): add Moscow Exchange (MOEX ISS) securities + FX provider
Add Provider::MoexPublic, a keyless provider built on the free MOEX ISS API
(https://iss.moex.com/iss), modeled on Provider::BinancePublic.
Securities: shares, funds/ETF/БПИФ (e.g. LQDT), and bonds (OFZ + corporate).
Bonds are priced clean — LAST% × FACEVALUE / 100 in the instrument currency,
with per-row FACEVALUE for amortizing issues; NKD/accrued coupon excluded.
Exchange rates: also implements ExchangeRateConcept for RUB↔{USD,EUR,CNY} via
selt TOM instruments (USD000UTSTOM/EUR_RUB__TOM/CNYRUB_TOM); the selt quote is
X/RUB, inverted for RUB→X, nil for non-RUB-crossed pairs.
Details:
- Board/engine resolution via the ISS primary-board flag with a hardcoded
priority fallback (TQBR, TQTF, TQOB, TQCB, …).
- Instrument currency from CURRENCYID/FACEUNIT (handles USD/CNY eurobonds &
FX funds), normalizing legacy SUR/RUR → RUB; default RUB.
- Full history via from/till + start= pagination; current price fallback chain
LAST → MARKETPRICE → LCURRENTPRICE → LCLOSEPRICE → PREVPRICE → latest history
close.
- Bare SECID identity, exchange_operating_mic=MISX, country_code=nil (wildcard
like Binance); search accepts .ME/.MOEX/.MISX/.MCX aliases and ISIN.
- RateLimitable throttling, SslConfigurable, Faraday retry/timeouts; all public
methods wrapped in with_provider_response.
Wired into Provider::Registry for both :securities and :exchange_rates, the
hosting provider-selection UI, locales, and config/exchanges.yml (MISX).
Docker-tested (devcontainer, Ruby 3.4.9): 29 new tests green, full provider
suite + i18n green, rubocop clean; smoke-tested against live ISS (SBER price,
OFZ clean price, USD/RUB FX).
* fix(moex): address review — FX weekend lookback, dead branch, translated hints
- fetch_exchange_rate now fetches a 10-day lookback window (not just the exact
day) so a weekend/holiday request resolves to the prior trading day's close,
matching Yahoo's behavior (Codex P2).
- Remove dead identical if/else branches in history_row_price (CodeRabbit).
- Translate moex_public_hint into ca/fr/hu/vi/zh-CN instead of English copy
(CodeRabbit).
- Add a test covering the FX prior-trading-day lookback.
* fix(moex): guard ISS date parsing; doc TQTE in board priority
Address maintainer review (jjmata):
- parse_iss_date wraps Date.parse so a malformed ISS TRADEDATE skips just that
row (with a contextual log warning) instead of failing the whole history/FX
fetch. Used in history_row_price and fx_history.
- Add TQTE to the BOARD_PRIORITY doc comment (it was in the constant but missing
from the comment).
- Add a test covering the unparseable-date skip.
* fix(prices): resolve dashed crypto tickers (BTC-USD, TRX-USD) via BinancePublic
Provider::BinancePublic is the dedicated crypto price provider, but its
search_securities only matched bare base assets ("BTC") or unseparated
Binance pairs ("BTCUSDT"/"BTCUSD"). The canonical "<BASE>-USD" form that
Yahoo emits and users paste (e.g. "TRX-USD", "USDT-USD") never matched, so
those holdings fell through to an unpriced offline security whenever the
stock provider didn't also return the coin.
Collapse the base/quote separator in the search query (and strip it in
parse_ticker) so "BTC-USD" / "TRX/USDT" are treated like "BTCUSD" and
resolve to live Binance pricing. Stablecoins pasted as "USDT-USD" resolve
to the synthetic USD price via their stripped base.
* fix(prices): only synthesize stablecoin search for USD quote
Address review: gate the synthetic stablecoin result on a USD quote (bare
coin or "<coin>USD" form). A non-USD quote like "USDTEUR" / "USDT-EUR"
has a real Binance pair and now falls through to normal matching instead of
being replaced by the USD synthetic. Drops the now-unused base_asset_query
helper. Adds a USDT-EUR regression test.
Import::UploadsController#update persists CSV uploads with
save!(validate: false), which skips the before_validation
:ensure_utf8_encoding callback. Non-UTF-8 files (e.g. ISO-8859-1 /
Windows-1252 exports from Brazilian banks) were written to the text
column as-is and rejected by Postgres with PG::CharacterNotInRepertoire,
surfacing as a 500 during upload.
Also register ensure_utf8_encoding on before_save so the existing
normalization (rchardet detection + Latin-1/Windows fallback) still runs
when validations are skipped. The callback is idempotent and no-ops on
valid UTF-8, so the validated path is unchanged.
Fixes#2294
* fix(assistant): include transaction name in get_transactions MCP output
get_transactions already loads `entry = txn.entry` but only emits
`merchant`, which is null unless a merchant is assigned. As a result MCP
clients receive transactions with no identifying name. Add `entry.name`
(the description shown in the UI and returned by the REST API) at zero
extra query cost.
* fix(assistant): include transaction name in get_transactions MCP output
get_transactions already loads `entry = txn.entry` but only emits
`merchant`, which is null unless a merchant is assigned. As a result MCP
clients receive transactions with no identifying name. Add `entry.name`
(the description shown in the UI and returned by the REST API) at zero
extra query cost.
Replaces window.location.href with Turbo.visit for SPA-consistent
navigation, matching the pattern used across internal navigation in
the codebase (selectable_link_controller, trade_form_controller, etc.).
* feat(mobile): in-app update prompt via upgrader package
- Add upgrader ^13.5.0 dependency for automatic update checks
- Show UpgradeAlert after authentication, with a 5-minute delay so
users can settle in before being prompted
- Dialog shows at most once every 7 days per store version
- Only "Later" and "Update now" buttons — ignore button removed via showIgnore: false
- Custom _SureUpgraderMessages with mustache body template (v13 API)
- Add "Check for updates" tile in Settings for manual checks:
calls updateVersionInfo() and shows an AlertDialog with store URL
if an update is available, or a snackbar if already up to date
- Timer resets on logout so the delay restarts on next sign-in
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* fix(mobile): address upgrader review comments
- Mount UpgradeAlert unconditionally so MainNavigationScreen is never
remounted when the timer fires, preserving navigation state
- Dispose _manualUpgrader in SettingsScreen to remove its lifecycle
observer when the screen is torn down
- Show update dialog even when store version metadata is incomplete
(falls back to 'a newer version'); disable Update now button rather
than silently no-oping when store URL is unavailable
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* fix(mobile): show snackbar when store URL cannot be opened
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* fix(mobile): dispose manual upgrader if unmounted after initialize
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
The Account#subtype= writer delegates to accountable&.subtype=, which is a
silent no-op while the accountable is nil. On create the accountable is built
from accountable_attributes via accepts_nested_attributes_for, but the form
submits subtype as a top-level account attribute. Mass-assignment applies
subtype before accountable_attributes, so the selected subtype was dropped on
create (update worked because the accountable already exists).
Build the accountable from the delegated type inside the writer when it is not
yet present, so the value is preserved; the later accountable_attributes
assignment (update_only) updates the same record.
Add regression tests covering the create flow and the assignment ordering.
Extend mobile/tool/generate_sure_tokens.mjs to emit, from the canonical design/tokens/sure.tokens.json: a mode-aware box-shadow scale (shadowXs..shadowXl, parsed from shadow.xs..xl into List<BoxShadow>), plus the focus-ring (color.focus-ring) and bg-inverse (utility.bg-inverse) colors on SureTokenPalette. Regenerates mobile/lib/theme/sure_tokens.dart (import dart:ui -> package:flutter/painting.dart for BoxShadow/Offset); keeps the --check parity gate; adds token tests for the new values incl. the negative xl spread.
Radii are already complete (the source only defines md/lg); a type-scale is not in the token source, so both are intentionally untouched. The shadow-border composites are deferred (derivable in-widget as a shadow + a 1px border from existing border tokens). This unblocks SureCard/elevated surfaces.
Part of #2235.
On screens not yet redesigned with SureColors (the Chats list, etc.), Material's
primary/secondary *container* roles were unset, so they fell back to defaults
that read as blue on the FAB, unread-badge, and avatar surfaces.
- Pin `primaryContainer`/`secondaryContainer` to a neutral Sure surface
(`surfaceInset` + `textPrimary`), and add a `FloatingActionButtonThemeData` so
FABs use Sure's neutral primary action color (`buttonPrimary`). `primary` /
`secondary` stay `link` / `info`, so existing link/accent callers are unchanged.
- Add a `SureLogo` widget that renders `logomark.svg` with the wordmark's
`currentColor` strokes tinted to the theme's secondary text color, and route
every logomark consumer (nav bar, login) through it — so the mark stays legible
in dark mode (the hardcoded grey was too dim) and no caller renders the strokes
as the flutter_svg default (black). The green brand mark keeps its fill.
Refs #2235.
Introduce a SureIcon design-system primitive that renders bundled Lucide SVGs via flutter_svg (already a dependency — no new dep), mirroring the web `icon` helper / DS::FilledIcon: tokenized size (SureIconSize xs–2xl = 12–32), color inherited from the ambient IconTheme by default, and accessibility that distinguishes decorative icons (excluded from the semantics tree) from meaningful ones (semanticLabel). A SureIcons registry keeps call sites typo-safe and limited to bundled assets.
Migrate the dashboard surface off Material Icons.* onto SureIcon — 24 call sites across net_worth_card, account_card, and dashboard_screen (account-type glyphs, asset/liability trend icons, sync/empty/error states, refresh, collapsible section headers, expand chevrons). Bundle the 17 Lucide SVGs the surface needs under assets/icons/lucide/ with the ISC license. The swipe Undo control and the rest of the app's icons follow in later slices.
Part of #2235.
Signed-off-by: Juan José Mata <juanjo.mata@gmail.com>
Co-authored-by: Juan José Mata <juanjo.mata@gmail.com>
Migrate the dashboard text tier off the off-convention bold (700) and semibold (600) to the design-system Medium (500): 14 weight-only sites across 5 files — net-worth headline + breakdown modal + asset/liability filter balances, account-card name + balance, collapsible-type section header + count badge, the stale "Outdated" badge, and the recent + list transaction names + amounts.
The web DS uses font-medium/500 for emphasis (essentially no bold or semibold), so this lands one uniform Medium tier and removes the inverted hierarchy where a money amount rendered lighter than its own label. Sizes, colors, and structure are untouched (zero layout shift); money keeps SureMoney.tabular and semantic color. The swipe "Undo" button affordance (w600 + hardcoded color) is intentionally left for a future button-primitive slice.
Part of #2235.
#2237 named the Sure font families (SureTokens.fontSans 'Geist', fontMono
'Geist Mono') from design/tokens/sure.tokens.json but deferred bundling the
fonts, so the app declared fontFamily 'Geist' yet rendered the platform system
font. Bundle the canonical Geist family so it actually renders -- the typography
half of the mobile facelift (#2235).
- mobile/assets/fonts/: Geist Regular/Medium/SemiBold/Bold + Geist Mono (.ttf),
with SIL OFL-1.1 (OFL.txt).
- mobile/pubspec.yaml: declare the families under flutter > fonts (Geist
400/500/600/700; Geist Mono 400).
No code/layout changes -- every text surface inherits Geist via SureTheme.
Validated: flutter analyze --no-fatal-infos clean, flutter test 95 pass,
iOS + Android builds include Geist in the font manifest; real iOS-sim
before/after x light/dark screenshots confirm system font -> Geist.
Adds YnabImport (mirroring ActualImport) for YNAB "Export budget" register CSVs:
- Amount — combines the split Outflow/Inflow columns into a single signed amount
(inflow - |outflow|), stripping currency symbols and thousands separators. A
single signed Amount column takes precedence when present.
- Category — resolves across export shapes: the combined "Category Group/Category"
column, the split "Category Group" + "Category", or legacy YNAB 4
"Master Category" + "Sub Category".
- Names — falls back from a blank Payee to the Memo, then the default row name.
- Validation — requires at least one amount source (Outflow/Inflow or Amount); a
file exposing none leaves rows un-clean instead of importing zero-dollar entries.
Enables the previously-disabled YNAB option on the imports screen (using the YNAB
logo, like Mint) with its configuration partial, and removes the now-dead
imports.new.coming_soon locale key. Documents the type in the API import-type
enums (rswag request spec + swagger_helper + generated openapi.yaml).
Closes#1255.
* feat(security): warn when ActiveRecord encryption is not configured
Self-hosted instances without explicit ACTIVE_RECORD_ENCRYPTION_* keys (or Rails credentials) store sensitive columns - API keys, provider/bank tokens, the MFA (TOTP) secret, and PII - unencrypted at rest. The app boots and works normally so this plaintext at rest state is easy to miss.
Change: Make it visible:
- log a clear startup warning (config/initializers/encryption_warning.rb)
- show a warning banner on /settings/security when encryption is unconfigured
* refactor(security): apply review feedback on encryption warning
- list the three ACTIVE_RECORD_ENCRYPTION_* keys in the banner, rendered via the DS::Alert content block to match the log
- drop the redundant respond_to?(:self_hosted?) guard in the initializer so it matches the controller check
- add a managed-mode test asserting the banner is hidden
Introduce a custom (non-Material) SureButton mirroring the web DS::Button: variants (primary, secondary, destructive, outline, ghost), sizes (sm/md/lg ≈ 28/36/48), optional leading widget, fullWidth, loading, and disabled. Colors resolve from the SureColors palette and the shape from radius tokens (radiusMd/radiusLg); flat custom press feedback (no Material ripple). Dimensions mirror the web DS::Buttonish::SIZES (the web composes these from Tailwind's standard scale rather than brand tokens, so they're not in sure.tokens.json).
Migrate the three main-view login buttons onto it — Sign In (primary, lg, loading), Sign in with Google (outline + SVG leading), and API-Key Login (ghost). The two buttons inside the API-key modal dialog are left for a follow-up.
Part of #2235.
When a rule is re-applied from the UI, RulesController passes
ignore_attribute_locks: true, but Enrichable#enrich_attributes still
rejected locked attributes unconditionally, so locked (manually edited
or import-locked) transactions were silently skipped and reported as
blocked.
Thread the flag through enrich_attribute/enrich_attributes as a new
ignore_locks keyword (default false, so provider syncs and AI
enrichment keep respecting locks) and pass it from the six synchronous
rule action executors.
Fixes#2051
* fix(jobs): enqueue jobs after transaction commit to fix SyncJob deserialization race
Syncable#sync_later creates a Sync row and enqueues SyncJob inside the
same transaction. Rails 7.2 deferred such enqueues until commit by
default; Rails 8.0 changed the default to enqueue immediately and 8.1
left the global config toggle non-functional, so a worker could dequeue
the job before COMMIT, fail to resolve the Sync GlobalID
(ActiveJob::DeserializationError), and have it silently dropped by
discard_on -- surfacing as stuck syncs after the Rails 8.1 upgrade.
Set enqueue_after_transaction_commit = true on ApplicationJob (the
Rails 8.2 default, inherited by every job) and drop the dead :never
symbol override on DestroyJob. Add regression and invariant tests.
* test(jobs): use OpenStruct for DestroyJob failure case
Replace the bare mock and the respond_to? expectation (an implementation
detail of how DestroyJob probes the model) with an OpenStruct that genuinely
responds to scheduled_for_deletion. Keeps only the command-facing assertions:
destroy raises and update! is called with scheduled_for_deletion: false.
Matches the repo convention of preferring OpenStruct for mock instances.
* test(snaptrade): assert connection-cleanup enqueue defers until commit
SnaptradeAccount#after_destroy enqueues SnaptradeConnectionCleanupJob, which
references the item/account by id. Before the ApplicationJob fix, Rails 8.1
enqueued it immediately inside the destroy transaction, so a worker could run
before COMMIT, see the not-yet-deleted row in its shared-authorization guard,
skip the provider call, and leak the SnapTrade connection. This regression
test destroys an account inside a transaction and asserts the job is not
enqueued until the transaction commits.
* feat(dashboard): masonry packing + per-widget size controls
In two-column mode the dashboard used a row-based CSS grid, so cards
stretched to equal row height and left dead space (e.g. the Net Worth
chart padded out to match the tall Balance Sheet table). Replace the
row-based layout with masonry packing and add per-widget size guardrails.
- Masonry: CSS grid with computed row-spans + grid-auto-flow: dense, driven
by a dashboard-masonry Stimulus controller (ResizeObserver + turbo:frame-load).
The DOM stays a single flat list, so drag/keyboard reorder is unaffected.
Active only in multi-column mode; single column falls back to normal flow.
- Internal sizing: the net worth chart height is now driven by a
--dash-widget-h CSS var (fixes an inert flex-1) so the card no longer pads
out below the chart.
- Guardrails: per-widget layout metadata (col_span, grow, min_height,
width_toggle) in PagesController, with per-user overrides persisted under
preferences["dashboard_section_layout"], deep-merged so width and height coexist.
- Size menu: a hover control on size-capable cards — Width (Half/Full) for the
cashflow sankey and net worth chart, Height (Compact/Auto/Tall) for grow
widgets. The sankey defaults to full width.
Adds model + controller tests for preference persistence and i18n keys.
* refactor(dashboard): redesign size menu with segmented controls
The size menu used a plain radio list and a diagonal maximize-2 trigger that
collided with the cashflow sankey's modal-expand button. Replace it with a
layout-config popover: a sliders-horizontal trigger plus two labeled axis
groups (Width, Height), each rendered as a DS::SegmentedControl with the
active option filled. Clearer, more compact, and it reads as a card-layout
control. The widget-size controller now mirrors the segmented control's
active-class + aria-pressed contract.
* feat(dashboard): expose width toggle on balance sheet and investments
Tables benefit from horizontal room, so give Balance Sheet and Investments
the same Width (Half/Full) control as the sankey and net worth chart. Height
presets stay chart-only — a table sized to a fixed height would just add
whitespace or force scrolling. The Outflows donut is intentionally left out
(full width is mostly whitespace for a donut).
* fix(dashboard): address review feedback on size controls
- Only apply the full-width col-span and show the Width control when the
two-column layout is enabled. A full widget previously leaked
2xl:col-span-2 into the single-column grid, creating an implicit second
column at 2xl widths and breaking the single-column preference. This also
keeps the Width control coherent with the Appearance two-column setting
(it now appears only where it does something). [Codex]
- Stop size-menu keydowns from bubbling to the section reorder handler, so
keyboard users can open the menu and pick options without entering
grab/reorder mode. [Codex]
- Harden preferences params: ignore a malformed (non-hash)
dashboard_section_layout / collapsed_sections instead of raising a 500,
and require section_order to be an array. [CodeRabbit]
- Localize the dashboard sections aria-label. [CodeRabbit]
* chore(settings): mention per-widget size controls in two-column copy
Surface the new per-widget width/height controls in the Appearance
"Two-column layout" description so the capability is discoverable.
* test(dashboard): assert non-mutation for malformed layout input
Addresses review feedback: asserting assert_nil made the test depend on
the fixture happening to have no dashboard height for net_worth_chart.
Capture the pre-PATCH value and assert it is unchanged, so the test
stays valid (malformed input ignored) even if the fixture later gets a
default height.
---------
Signed-off-by: Juan José Mata <juanjo.mata@gmail.com>
Co-authored-by: Guillem Arias <guillem.arias@col.vueling.com>
Co-authored-by: Juan José Mata <juanjo.mata@gmail.com>
* test: cover CoinStats missing-wallet balance preservation
* fix: preserve CoinStats balances when wallet data is missing
* chore: route CoinStats sync warnings to debug log
* docs: make debug log guidance timeless
---------
Signed-off-by: Juan José Mata <juanjo.mata@gmail.com>
Co-authored-by: Juan José Mata <juanjo.mata@gmail.com>
* chore(i18n): complete zh-CN locale coverage
Translate all 903 missing zh-CN keys, following the per-module locale
file structure mirroring the en baseline:
- New locale files: goals, goal_pledges, akahu_items (views), and
goal, goal_pledge, merchant_import (models)
- Fill remaining gaps across imports, settings/hostings, components,
transfers, transactions, categories, and 30+ other modules
- Fix interpolation mismatches against the en baseline (%{moniker},
%{product_name}, %{action_verb}, %{count} in pluralized one-keys)
- Quote the "on" key in valuations so it parses as a string key
instead of a YAML boolean, matching en
- Add zh-CN date formats month_year / short_month_year used by
reports and budgets
Brand names, protocol names, and product-specific terms (Plaid, QIF,
YNAB, PSD2, HSA, API keys) are intentionally kept in English.
Verification:
- i18n-tasks missing -l zh-CN: 0 (the 4 remaining entries are
i18n-tasks scanner artifacts also reported for the en baseline)
- i18n-tasks check-consistent-interpolations: clean for zh-CN
- bin/rails test: 4875 runs, 0 failures
- bin/rubocop: no offenses
* chore(i18n): address review feedback on zh-CN terminology
- Unify Lunch Flow branding (two words) and use API 密钥 consistently
in lunchflow_items
- Use API 密钥 instead of API Key in settings/api_keys create/destroy
messages, matching the rest of the file
- Use 循环 for recurring transfers, matching the recurring wording
used by transactions
* fix(i18n): keep zh-CN user family labels literal to avoid moniker interpolation error
Unlike Account, User has no human_attribute_name override injecting
the moniker option, so %{moniker} in user attribute labels raises
I18n::MissingInterpolationArgument whenever errors.full_messages
formats a family/family_id validation error.
Keep the labels literal (家庭), consistent with de/es/fr/nb/nl/pt-BR/
ro/tr/zh-TW which also use literal words here.
Note: en/ca/hu/pl/vi carry the same latent issue with %{moniker} in
user attribute labels; left untouched as fixing the en baseline is
out of scope for this locale PR.
* fix(i18n): 补齐运行时作用域翻译键
* fix(i18n): 移除失效目标切换文案
Commit 5d0eb7f4 replaced the color picker's DS::Disclosure with a raw
<details> because DS::Disclosure wraps its body in an mt-2 div, and that
normal-flow margin shoved the form down ~8px whenever the absolutely-
positioned picker popover opened. DS Drift Patrol flagged the raw
<details> in #2272 and #2316.
Add a body_class: option to DS::Disclosure (default mt-2) so callers can
drop the body margin, and migrate the color picker back onto the
component with body_class: nil. The summary's accessible name moves from
aria-label to an sr-only span in the summary content (verified: the
summary still reads as "Choose color and icon").
The LLM usage table (Settings → AI usage) and the rules recent-runs table
used hardcoded color classes instead of design-system tokens:
- `divide-gray-100` separators — a fixed light gray with no dark-theme
variant, so the row dividers render wrong in dark mode.
- Raw reds for failed rows (`bg-red-50`/`bg-red-950`, `text-red-500/600`).
Swap to the canonical tokens used by every other table (settings/debugs,
admin/users, …):
- divide-gray-100 -> divide-alpha-black-200 theme-dark:divide-alpha-white-200
- bg-red-50 / bg-red-950/30 -> bg-red-tint-5 / bg-red-tint-10
- text-red-* -> text-destructive (via the icon helper's color: param)
Token-only; no structural or behavior change.
Co-authored-by: Guillem Arias <guillem.arias@col.vueling.com>
The transfer and transaction forms render the exchange-rate tab UI via
shared.exchange_rate_tabs.* exclusively, so transfers.form.calculate_rate_tab,
convert_tab, exchange_rate, and exchange_rate_help are never looked up. Remove
these four dead keys from every locale file that carries them (en, fr, es, ca,
hu, vi). The live siblings (exchange_rate_display, destination_amount, etc.) are
left intact. No view or code references change.
Fixes#1508
The dialog close button rendered as a :md icon button (44x44px with a
20px glyph) — noticeably larger than the dialog's own action buttons
(36px tall) and visually heavy next to the title. Pass size: :sm so the
close control is 32x32px with a 16px glyph, matching the action row's
weight. 32px still clears the WCAG 2.5.8 (AA) 24px minimum target.
* fix(chat): clear the assistant message bubble when a turn is destroyed
When an assistant turn fails before any text streams (e.g. a provider
auth/model/network error on the first call), Assistant::Builtin#respond_to
destroys the still-pending message. Message only broadcast on create and
update, never on destroy, so the rendered 'Thinking…' bubble was never
removed — the chat appeared stuck thinking forever even though the job
had already errored (and appended an error via chat#add_error below it).
Add after_destroy_commit broadcast_remove_to so a destroyed message is
removed from the page.
* refactor(chat): trim destroy-broadcast comment to one line
Project convention asks for comments only when the why is non-obvious; the
behaviour is already covered by the commit/PR description. Per review feedback.
---------
Co-authored-by: Guillem Arias <guillem.arias@col.vueling.com>
* fix(settings): give the MCP copy button success feedback
The MCP server URL Copy button copied to the clipboard but showed no
feedback. It is a DS::Button (single icon), but clipboard_controller's
showSuccess() unconditionally toggled iconDefault/iconSuccess targets —
which that markup does not have — so it threw right after the copy and
the user saw nothing.
Guard the icon-swap path (still used by invite codes, MFA and profiles)
and add a fallback that briefly flips the button's own label to Copied!
via a new copiedText value. Wire it up on the MCP page.
* fix(settings): capture copy button before async clipboard resolve
event.currentTarget is null by the time the writeText().then() callback
runs (it's only valid during event dispatch), so showSuccess received
null and the label never flipped. Capture the button synchronously in
copy() and pass it through. Verified in-browser: Copy -> Copied! -> Copy.
* refactor(clipboard): unify feedback reset delay, harden label lookup
Extract a shared RESET_DELAY_MS so the icon-swap and label-flash paths last the
same duration when both copy buttons render on one page. Scope the label lookup
to span.truncate (the DS::Button text node) so it ignores any future icon span.
Per review feedback.
---------
Co-authored-by: Guillem Arias <guillem.arias@col.vueling.com>
The four inline (non-DS::Tooltip) tooltips had drifted: three used
p-2 rounded w-64, one used p-3 rounded w-72 with shadow-lg, and all used
rounded (4px) where DS::Tooltip uses rounded-md (6px). Unify them on
p-2 rounded-md w-64 — radius now matches DS::Tooltip and the lone
p-3/w-72/shadow-lg outlier is gone, so the dark tooltips read
consistently.
The cashflow sankey zoom-out button sat in a bare flex justify-start
row. Because the dashboard section body has no horizontal padding (just
py-4), the button rendered flush against the card's left edge — 16px
left of the section header title and out of line with the rest of the
widget. Add px-4 to the button row so it aligns with the header,
matching the _net_worth_chart widget's px-4 header row.
The dashboard two-column layout preference only added 2xl:grid-cols-2
(>=1536px), but the setting copy promises two columns on large screens.
On any display narrower than 1536px (most laptops, ~1280-1440px) the
toggle did nothing. Lower the breakpoint to xl (>=1280px) so it engages
on the screens users actually have while keeping widgets wide enough to
stay usable.
The goals status callout colored its entire body (icon, label and
context) with text-warning / text-success / text-secondary, so a
behind goal rendered as all-yellow text. That diverges from the
DS::Alert recipe, where tinted boxes keep neutral body text
(text-primary) and only the icon carries the status color. Drop the
text-* tokens from the container, add text-primary, and move the
warning/success color onto the icon via color:.
* chore(deps): upgrade Rails 7.2 → 8.1
Rails 7.2 reaches end of life on 2026-08-09. Bump the framework to the
current 8.1.x line.
- Gemfile: rails "~> 8.0" (resolves 8.1.3); bundle update rails pulls the
Rails 8 framework gems plus the bumps it requires — ViewComponent
3.23 → 4.x (Rails 8 support), rails-i18n 7 → 8, rswag, and transitive deps.
- app/models/transfer.rb: make Transfer#date nil-safe
(inflow_transaction&.entry&.date). Rails 8's date_field evaluates the
field default on a new/unpersisted Transfer (the new-transfer form), where
the association is nil; without this, TransfersController#new raises
"undefined method 'entry' for nil". Matches the &. pattern already used in
Transfer#sync_account_later.
Framework behavioral defaults are unchanged (config.load_defaults stays as-is).
Validated on Rails 8.1.3: zeitwerk:check passes, full suite green
(4904 runs, 0 failures, 0 errors), rubocop and brakeman clean.
* fix(rails8): style textarea + deterministic property edit system test
The Rails 8 gem bump kept config.load_defaults at 7.2, but Rails 8 renamed
two ActionView::Helpers::FormBuilder field helpers regardless of defaults:
:text_area → :textarea and :check_box → :checkbox. StyledFormBuilder builds
its styled helpers from `field_helpers`, so `form.text_area` (e.g. the
account "Notes" field) silently fell through to the unstyled base helper and
rendered without a label — failing 8 system tests with
`Unable to find field "Notes"`.
- app/helpers/styled_form_builder.rb: exclude both spellings of the
non-text helpers (:check_box and :checkbox) and alias the legacy
`text_area` to the Rails 8 `textarea` so existing call sites stay styled.
Harmless on Rails 7.2 (old names present instead).
- test/system/property_test.rb: open the property edit dialog via the
account menu with a retry. The account page issues a Turbo morph refresh
shortly after load (turbo_refreshes_with :morph + a family-stream
broadcast); opening the modal while that refresh is in flight let the
morph re-render the page and wipe the just-loaded #modal turbo-frame.
Rails 8 timing made the race deterministic. Retrying once the refresh has
settled makes the test stable (confirmed via Turbo frame-load vs
full-page morph event traces; 3x green in isolation).
- config/brakeman.ignore: the added comment block shifted the pre-existing
(already-ignored, Weak) class_eval Dangerous Eval warning from line 5 -> 10,
changing its fingerprint. Re-point the existing suppression to the new
fingerprint/line so scan_ruby stays green.
Validated on Rails 8.1.3: full system suite green
(92 runs, 355 assertions, 0 failures, 0 errors), rubocop clean,
brakeman 0 warnings, CodeRabbit no findings.
* chore(deps): pin rails to the 8.1 minor line (~> 8.1.0)
Tighten the constraint from `~> 8.0` to `~> 8.1.0` (>= 8.1.0, < 8.2) so a
future `bundle update rails` tracks the 8.1.x line rather than silently
jumping to 8.2 when it ships. Matches the upgrade plan's stated intent
(target 8.1.x for the EOL runway) and a review note on #2301.
No resolved-version changes: bundle install keeps rails at 8.1.3 and every
other locked gem unchanged — only the Gemfile.lock DEPENDENCIES constraint
line moves. zeitwerk:check still passes; the already-green unit/system
suites ran on this exact resolved tree.
* chore(rails8): adopt Rails 8.1 framework defaults (config.load_defaults 8.1)
The gem bump above kept config.load_defaults at 7.2 so the change set could be
reasoned about in stages; this finalizes the upgrade by adopting the modern
framework defaults now that the suite is green on Rails 8.1.
Rails 8.0 added no new framework defaults (there is no new_framework_defaults_8_0
template), so 7.2 -> 8.1 is the single meaningful step. No incremental
new_framework_defaults_8_1.rb opt-in file is needed: the full suites pass with all
8.1 defaults enabled at once.
The 8.1 defaults this turns on include action_on_path_relative_redirect=:raise
(open-redirect hardening), raise_on_missing_required_finder_order_columns,
escape_json_responses=false / escape_js_separators_in_json=false (JSON perf), and
Ruby-parser template-dependency tracking.
Validated with no application code changes: bin/rails test 4904/0/0,
bin/rails test:system 92/0/0, rubocop + brakeman clean.
* chore(ci): restore brakeman CheckEOLRails now that the app is on Rails 8.1
config/brakeman.yml existed only to skip brakeman's CheckEOLRails. That check
fires on the calendar (it warns 60 days before a framework's EOL and escalates
as the date nears), so Rails 7.2's 2026-08-09 EOL turned `bin/brakeman` red
(exit 3) on every branch and on main regardless of the diff. The skip carried a
TODO to remove it once Sure upgraded off 7.2.
This PR puts the app on Rails 8.1 (EOL well in the future), so the skip is
obsolete; remove the file (its sole content was the skip) in the same change that
makes it unnecessary -- no stale-config window. brakeman auto-loads the file when
present and falls back to defaults when absent, and nothing references it
explicitly. CheckEOLRuby was already enabled and is unchanged; config/brakeman.ignore
is untouched.
Validated on Rails 8.1: bin/brakeman runs EOLRails + EOLRuby, 0 warnings,
0 errors, exit 0.
* feat(mobile): standardize money typography and semantic amount color
Add a brightness-aware SureColors theme extension and a MoneyText/SureMoney
primitive (semantic success/destructive/subdued tokens + tabular figures for
column-aligned digits), then migrate the transaction lists and balance cards
off raw Colors.green/red/grey.
Step 2 of the mobile design-system sequence (#2235), after #2237's theme
foundation. Primitive-first: screens consume shared tokens/typography.
* fix: review feedback — brightness-aware token fallback, de-flake Setting tests, Pipelock localhost FP
- SureColors.of falls back to the palette matching the active brightness (not
always light) when the extension is missing, so dark surfaces stay correct.
- Clear the rails-settings-cached cache before each test; its in-memory cache
survives the per-test transaction rollback, leaking Setting.* across tests and
flaking Settings::HostingsControllerTest (stale empty string vs nil).
Full unit suite: 4952 runs, 0 failures.
- Suppress the localhost test-DB DATABASE_URL false positive with line-level
`# pipelock:ignore` in ci.yml + llm-evals.yml instead of excluding whole files,
so those workflows stay scanned for real secrets.