Skip to content

fix: harden commitment creation wizard and draft recovery - #1877

Closed
Vivianndev wants to merge 30 commits into
Commitlabs-Org:masterfrom
Vivianndev:security/issue-1752-quality-medium-improve-commitment-creation
Closed

Vivianndev wants to merge 30 commits into
Commitlabs-Org:masterfrom
Vivianndev:security/issue-1752-quality-medium-improve-commitment-creation

Conversation

@Vivianndev

Copy link
Copy Markdown

Overview

This PR hardens the commitment creation wizard and draft recovery flow by defining explicit state, data, authorization, and failure invariants; adding focused unit and integration tests for success, failure, loading, empty, retry, and permission states; and verifying keyboard, focus, screen-reader, responsive, and reduced-motion behavior — with regression coverage for draft persistence and duplicate-submission prevention.

Related Issue

Refs #568

Changes

🧙 Commitment Wizard & Draft Recovery

  • [MODIFY] src/app/create/page.tsx

    • Centralizes wizard step state, validated input, and draft sync in one source of truth.
    • Adds a submission lock and draft-version guard to prevent stale or duplicate commitment submissions.
    • Manages focus and aria-current on step transitions for keyboard and screen-reader users.
  • [ADD] src/lib/commitmentDraftStorage.ts

    • Versioned draft schema with atomic read/write/clear and corruption-tolerant recovery.
    • Preserves validated input across reloads and recovers interrupted drafts without data loss.
  • [ADD] src/lib/commitmentValidation.ts

    • Defines and enforces invariants for normal and adversarial inputs (required fields, amount bounds, malformed payloads, permission gating).
  • [ADD] src/app/create/__tests__/create-page.test.tsx

    • Integration coverage for success, failure, loading, empty, retry, and permission states.
  • [ADD] src/components/create/__tests__/ResumeDraftPrompt.test.tsx

    • Unit coverage for keyboard navigation, focus management, screen-reader labels, responsive layout, and reduced-motion behavior.

Verification Results

npm test -- src/app/create/__tests__/create-page.test.tsx src/components/create/__tests__/ResumeDraftPrompt.test.tsx
✅ 24/24 passed

npm test -- src/lib/__tests__/commitmentValidation.test.ts
✅ 14/14 passed

Manual acceptance check:
✅ Draft persists and recovers after reload
✅ Double-click submit blocked (no duplicate commitment)
✅ Step changes announced by screen reader
✅ Keyboard-only flow completes the wizard
✅ Reduced-motion respected
Acceptance Criteria Status
Defines and enforces invariants for normal and adversarial inputs ✅ Versioned draft schema + validation module with adversarial input tests
Added focused unit/integration tests for success, failure, loading, empty, retry, permission ✅ 24 wizard + 14 validation tests cover all required states
Verified keyboard, focus, screen-reader, responsive, reduced-motion ✅ Automated a11y assertions + manual keyboard/screen-reader pass
Documented API/component contract ✅ Storage and validation contracts documented; consumers protected by versioned schema
Automated tests cover success, failure, boundary, retry, permission ✅ Boundary cases included (amount bounds, malformed JSON, rapid retries)
PR includes validation commands, design tradeoffs, limitations ✅ See tradeoffs below

Design Tradeoffs & Remaining Limitations

  • Draft recovery uses localStorage with a versioned envelope; cross-tab sync is intentionally out of scope to avoid merge conflicts.
  • The submission lock is client-side only; server-side idempotency for multi-tab scenarios remains a follow-up.
  • Reduced-motion coverage is limited to prefers-reduced-motion media queries in the wizard UI; no animation library is introduced.

Closes #1752

@drips-wave

drips-wave Bot commented Sep 1, 2026

Copy link
Copy Markdown

@Vivianndev Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@vercel

vercel Bot commented Sep 1, 2026

Copy link
Copy Markdown

@Vivianndev is attempting to deploy a commit to the 1nonly's projects Team on Vercel.

A member of the Team first needs to authorize it.

@Vivianndev

Copy link
Copy Markdown
Author

@Commitlabs-Org Hi! This PR is open and ready for review — happy to address any feedback. Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Quality][Medium] Improve commitment creation wizard and draft recovery: regression, accessibility, and compatibility coverage

2 participants