Skip to content

Leftovers from #8352 / #8367 / #8369 after per-finding fixes landed #8598

Description

@koala73

These are the leftovers from #8352, #8367 and #8369. All three issues were checked on 2026-09-24, finding by finding, against main at 952db28. Most findings had landed through separate per-finding PRs. The items below are what is still open on main. Their parent issues are being closed with a comment that maps each finding to the PR that fixed it.

Being ported from the closed #8379 (follow-up PR)

  • /pro DebugBear queue has no size limit. pro-test/src/debugbear-rum.ts:52-60 still has the original Browser bootstrap, config and utility defects (5 findings) #8369 bug:

    • its queue has no size limit;
    • it stores live Event objects;
    • it has no cleanup when the script fails to load.

    The dashboard copy was fixed in fix: bound DebugBear error buffering and preserve live forwarding #8249; this one was not.

  • Dashboard DebugBear still holds live objects. src/bootstrap/debugbear-rum.ts stores live Event objects, not primitive snapshots. Its error/unhandledrejection listeners stay attached after the vendor script loads.

  • Theme "Auto" with nothing stored does not follow the OS. Settings shows Auto, but applyStoredTheme attaches the prefers-color-scheme listener only when 'auto' is stored, so the page never follows OS changes. getStoredTheme() also still turns 'auto' into dark.

  • Live Channels page ignores Auto. The pre-paint script in live-channels.html ignores Auto and the OS theme, and src/live-channels-main.ts never calls applyStoredTheme().

  • webmcp docs show the old pattern. docs/webmcp.mdx:132 and docs/zh/webmcp.mdx:132 still document the lowercase-only set_panel_enabled pattern; the code has accepted mixed case since fix: accept mixed-case dashboard catalog IDs #8255.

Still open, not in that PR

Product decision, not a bug

  • sanctions:pressure:v1 is still served anonymously through /api/bootstrap (shared/bootstrap-tier-keys.js), and the client reads it for non-premium users on purpose. Only sanctions:entities is Pro-only in practice. Decide whether this is intended.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions