fix(desktop): hide docked native views under the extension prompt - #1380
Merged
Merged
Conversation
The prompt a trusted extension raises (`ui.confirm` / `ui.select` / `ui.input`) is a centered modal over the whole shell, but it only stepped the plugin layers aside (`useHostSafetySurface`). A docked WebContentsView kept compositing above it, which is the same occlusion #879 reported for the project dialogs and #1378 fixed there. Register `useBlockingOverlay` while the prompt is mounted: the dialog is mounted exactly while a prompt is queued, so that window is the one that must block the panel. The mounted dialog fixture now asserts the native preview is suppressed while the prompt is up and released once it closes; without the registration the new suppression check fails.
This branch was previously deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Same occlusion as #879 (fixed for the project dialogs in #1378), still present for the
prompt a trusted extension raises.
Symptom
With a docked native view in the work panel (work-panel browser, file manager, …),
ui.confirm/ui.select/ui.inputprompts from a trusted extension renderedunder the
WebContentsView: the modal and its backdrop were covered on the rightside and the panel kept taking input.
Root cause
ExtensionPromptDialogdeclared onlyuseHostSafetySurface(), which makes therenderer-side plugin layers step aside. It never registered
useBlockingOverlay(),the only mechanism that hides a native view (
WorkPanel→PluginViewTab blocked→pluginViewSetVisible(false)).Change
useBlockingOverlay()inExtensionPromptDialog. The dialog mounts onlywhile a prompt is queued, so mounting is exactly the window that must block the
panel — no wrapper split or prop needed.
host-safety-layer.test.mjswith a source assertion for the registration.dialog-overflow) to assert the native preview issuppressed while the prompt is up and released after it closes.
Why only this dialog
I audited every other surface that renders
role="dialog"/aria-modalwithout thehook:
ProviderSetupDialog,VendorAccountDialog,OAuthLoginDialog,SkillEditorSheet,SubagentEditorSheet,McpEditorSheet,McpMarketPanel,SkillMarketPanel,prompt-enhancement-card,ReleaseNotesDialog):those pages hide the work panel (
useAppShellRuntime→pageHidesWorkPanel), so thedock and its native view are unmounted before the modal opens.
SearchDialog: already equivalent —AppShellpassespanelBlocked={searchOpen}toWorkPanel, which hides the same native view.NotificationCenter,SessionHoverCard,ContextUsageInspector,ScopeControl,ScheduledWeekdaySelect,LiveVoiceControls,LiveVoiceDetails: anchored popoversthat do not overlay the dock (
ContextUsageInspectoreven clamps to.main-pane).StartupRecovery: only up before the shell mounts.Verification
node --test test/*.test.mjs: 3488 pass, 0 fail.node scripts/test-dialog-overflow.mjs(real Electron + Chromium, mounted productiondialogs): 41/41 pass, including the two new checks.
extension prompt suppresses native preview while openfail (40/41), so the newcheck really guards the fix.
tsc -p apps/desktop/tsconfig.json --noEmit: clean.