Skip to content

fix(http): stop client fault rules when http is turned off - #227

Merged
erkamyaman merged 1 commit into
pangular-inspector:mainfrom
erkamyaman:fix/http-client-rules-off
Oct 7, 2026
Merged

erkamyaman merged 1 commit into
pangular-inspector:mainfrom
erkamyaman:fix/http-client-rules-off

Conversation

@erkamyaman

@erkamyaman erkamyaman commented Oct 7, 2026 •

Copy link
Copy Markdown
Member

Summary

  • The overlay now clears stored client fault rules when inspectors.http or actions.http is off (it used to check only inspectors.http).
  • Once the config is known to be off, the interceptor ignores stored rules, even if something writes them later in that load.
  • With http on, rules still persist in sessionStorage across reloads.
  • The server part (clearing server rules at setup, seeding shared state, stopping SSR rules on dispose) landed in fix(http): stop SSR fault rules once their devtools server closes #219.
  • Docs: "When rules apply" on the SSR & HTTP inspector page.

Tests

  • http inspector off, then reload: stored rules are gone and requests are not faulted.
  • http action off, even with a stale server reply: same.
  • Rules written after the config turned http off are ignored.
  • http on: rules survive a reload and keep faulting requests.

Closes #69

Summary by CodeRabbit

  • Bug Fixes

    • Stored HTTP fault rules are now cleared and ignored when either the HTTP inspector or HTTP actions are disabled. Rules saved while disabled won’t take effect.
    • When HTTP rules remain enabled, they continue to apply across reloads. Requests made before the overlay connects may still fail once.
  • Documentation

    • Clarified when stored HTTP rules are removed and how requests can behave before the overlay connects.

When the overlay connects with the http inspector or actions.http off,
it deletes the client fault rules stored in sessionStorage and the
interceptor stops applying stored rules for the rest of that load.
With both on, rules still persist across reloads. Requests made before
the overlay connects can still use stale rules once.

Closes pangular-inspector#69
@github-actions github-actions Bot added area: package The ng-devtools package (packages/ng-devtools) area: docs The documentation site labels Oct 7, 2026
@coderabbitai

coderabbitai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 0b74b49b-2462-4b19-91bd-cebe68dae872
📥 Commits

Reviewing files that changed from the base of the PR and between d25a3a6 and f241c1f.

📒 Files selected for processing (4)
  • apps/docs/src/content/inspectors/ssr-http.md
  • packages/devtools/src/__tests__/overlay-config.test.ts
  • packages/devtools/src/http-rules.ts
  • packages/devtools/src/overlay.ts

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review.


📝 Walkthrough

Walkthrough

The overlay now disables stored client HTTP fault rules when HTTP inspection or HTTP actions are off. The rule registry ignores rules stored while disabled and continues to retain and apply enabled rules across reloads. The documentation and tests cover these cases.

Changes

HTTP client rule gating

Layer / File(s) Summary
Client rule gating
packages/devtools/src/http-rules.ts
HttpRegistry tracks whether client rules are disabled. The registry clears stored rules when disabled and returns no client rules while disabled.
Overlay configuration and validation
packages/devtools/src/overlay.ts, packages/devtools/src/__tests__/overlay-config.test.ts, apps/docs/src/content/inspectors/ssr-http.md
Overlay startup allows client rules only when both HTTP inspection and HTTP actions are enabled. Tests cover disabled and enabled rule behavior across reloads. Documentation states that either setting removes stored client rules.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~12 minutes

Change: Bug fix · Severity of issue fixed: Medium

Merge Risk: ⚪ Minimal · up to f241c

Client HTTP fault rules now stop applying when either HTTP inspection or HTTP actions are off. Rules still persist across reloads when both are on. The change is small and tested, and no merge-blocking risk is evident.

Security Architecture Review

Security architecture risk: 🔵 Low · up to f241c

The change strengthens the development-time HTTP rule disable control. No new privilege escalation or cross-service exposure was established. Remaining uncertainty concerns existing startup, persistence-failure, and replacement-overlay behavior.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • observed — The changed enforcement operates on the browser document's shared registry and sessionStorage rules. Its sensitive outcomes are faulted, mocked, or delayed requests passing through the development-mode Angular interceptor.

Trust Boundaries and Controls

  • inferred — The disable flag is a configuration-enforcement convention, not a security boundary against arbitrary code executing in the page. Although the new public setter can re-enable rules, the base already exposed mutable registry state and unrestricted rule writes. This does not establish a newly gained privilege or independently attackable scope.

Resilience and Maintainability Implications

  • observed — The current document remains gated despite storage errors, but durable removal is best-effort. Overlay disposal does not revoke already-selected request rules or cancel an outstanding rule reply. These inherited lifecycle limits are not introduced concerns; replies arriving after successful disabling are now rejected, while reply ordering after re-enabling remains unspecified.
🚥 Pre-merge checks | ✅ 3 | ❌ 1 | ❓ 1

❌ Failed checks (1 warning, 1 inconclusive)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 16.67% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 6 functions across 3 files. (1 skipped: 1… Write docstrings for the functions missing them to satisfy the coverage threshold.
Linked Issues check ❓ Inconclusive The client requirements in #69 are implemented: allowClientRules() disables and clears stored rules, clientRules() returns no rules while disabled, and overlay.ts disables rules when either `ins… Provide reviewable evidence at the reviewed head for the server setup and dispose behavior, shared-state initialization from registry.rules, and automated tests for both restart paths.
✅ Passed checks (3 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: disabling client HTTP fault rules when HTTP is turned off.
Out of Scope Changes check ✅ Passed The changed files are within the scope of #69. http-rules.ts and overlay.ts implement client rule disabling and clearing. The overlay-config tests verify the behavior. The SSR and HTTP inspector d…
Full details: Linked Issues check

Explanation

The client requirements in #69 are implemented: allowClientRules() disables and clears stored rules, clientRules() returns no rules while disabled, and overlay.ts disables rules when either inspectors.http or actions.http is off. The added tests cover the reported client restart and persistence cases. Issue #69 also requires server-rule clearing, shared-state seeding from registry.rules, and both restart paths. The available server-file output is truncated, and the PR description's reference to #219 does not establish that the required server behavior and tests are present at this head.

Full details: Docstring Coverage

Explanation

Docstring coverage is 16.67% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 6 functions across 3 files. (1 skipped: 1 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@erkamyaman
erkamyaman merged commit 7760136 into pangular-inspector:main Oct 7, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: docs The documentation site area: package The ng-devtools package (packages/ng-devtools)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

HTTP fault rules survive restarts and keep applying after http is turned off

1 participant