Skip to content

Add bounded selector actions with checked target identity - #55

Merged
wolfiesch merged 2 commits into
mainfrom
selector-actions
Sep 19, 2026
Merged

wolfiesch merged 2 commits into
mainfrom
selector-actions

Conversation

@wolfiesch

Copy link
Copy Markdown
Owner

Summary

  • Split selector actions out of Add safe local extension deployment and health checks #54.
  • Add unique CSS selectors for click, type, and fill across the public protocol and adapters.
  • Preserve revision, sensitive-field, and Commit checks; execute against the checked backend node.
  • Normalize and bound selector text on operation display paths.

Verification

Workspace typechecks, SDK build, extension action contracts, adapter contracts, and rendering regressions passed.

@wolfiesch
wolfiesch merged commit bc4d358 into main Sep 19, 2026
8 checks passed

@omp-maintainer omp-maintainer Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 — coherent public mutation-surface feature, so merge timing needs maintainer sign-off.
Blocking: selector resolution can cross a document replacement after the revision check and mutate the replacement page.
Maintainer call: after that race is closed, is selector-addressed mutation intended for the 2.0 surface?
Thanks for the scoped split and contract coverage.

}
}
const resolvedBackendNodeId = hasSelector
? await this.backendNodeIdFromSelector(tabId, String(action.selector), String(action.kind))

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

blocking: act() checks expected_page_revision on line 569, then awaits DOM.getDocument/DOM.querySelectorAll here and executes the returned backend node without revalidating the document identity. If a navigation replaces the document during those awaits before the asynchronous tabs.onUpdated revision bump is observed, this selector resolves in the replacement page and performAction() mutates that new page; ref-addressed actions instead fail when their old backend node disappears. This violates the documented invariant that document replacement rejects rather than selects a new target. Capture/compare the page identity around selector resolution (and cover the in-flight replacement case) before executing or staging it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant