Keep @papi/frontend out of the comment list's host-reachable model - #2851
Merged
mattgetgen merged 1 commit intoSep 23, 2026
Merged
Conversation
comment-list-filters.model.ts is shared: main.ts imports presetToLabelKey
and scopeFilterToLabelKey for its menu contributions, while the web views
import the rest. Its top-level `import { logger } from '@papi/frontend'`
therefore landed in the backend bundle, and @papi/frontend is a webpack
external the extension host's require shim rejects — so activation threw
"Requiring other than papi is not allowed in extensions!" and neither the
comment list nor the Comments panel registered its commands or web views.
Only development builds were affected: the production minifier drops the
unreachable presetFromLegacyAxes and its import, so CI (which builds
extensions in production mode) stayed green while the plain `npm run build`
the README documents produced a dead comment list.
presetFromLegacyAxes/applyFilterOverrides now take a WarnFn parameter, and
the two web-view callers supply logger.warn. Verified against the real dev
bundle: legacy-comment-manager/src/main.js required @papi/frontend before
and requires only @papi/backend and platform-bible-utils after.
Also copies extension-host-import-boundary.test.ts from platform-scripture,
which walks main.ts's value-import graph against an allowlist with no build
step. It fails on the unfixed tree naming this exact import, and passes
after. A sweep of every extension's dev backend bundle confirmed this was
the only real instance.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
rolfheij-sil
approved these changes
Sep 23, 2026
mattgetgen
deleted the
chore/legacy-comment-manager-host-import-boundary
branch
September 23, 2026 12:30
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Since #2840 merged,
legacyCommentManagerfails to activate in development builds. The extension host throwsRequiring other than papi is not allowed in extensions! Rejected require('@papi/frontend'), so the comment list and the Comments panel never register their commands or web views.comment-list-filters.model.tsis shared:main.tsimportspresetToLabelKeyandscopeFilterToLabelKeyfor its menu contributions, while the web views import the rest. #2840 added a top-levelimport { logger } from '@papi/frontend'for twologger.warncalls inpresetFromLegacyAxes, which only the web-view side reaches.@papi/frontendis a webpack external the host'srequireshim rejects, so the import landed in the backend bundle.Production builds are fine — the minifier drops the unreachable function and its import — which is why CI never noticed:
test.yml,package-main.ymlandpublish.ymlall runbuild:extensions:production. The plainnpm run buildthe README documents builds extensions in development mode, so anyone following it gets a dead comment list.Why review this
Not part of current epic. It unblocks the three cross-kind zoom e2e specs in #2849 (PT-4585), which cannot run until the comment list opens again, and fixes the pre-existing
comment-list-content-zoom.spec.tsfailing the same way. Until it lands, anyone developing against the comment list in a dev build is working blind — the only signs are one error-level log line and a small "extension failed to start" notification.Changes
presetFromLegacyAxes/applyFilterOverridestake aWarnFn((message: string) => void) instead of importing a logger. The two web-view callers —comment-list.web-view.tsxandcomment-list-web-view-message.util.ts— supplylogger.warn.extension-host-import-boundary.test.ts, copied fromplatform-scripture(the newer of the two existing copies) and adapted. It walksmain.ts's transitive value-import graph against an allowlist with no build step.vi.fn()sink rather than mocking@papi/frontend; the message-util test gains a case pinning that the caller actually wires the sink to a real logger.Testing
comment-list-filters.model.ts -> @papi/frontend, and passes after.extensions/dist/legacy-comment-manager/src/main.jsbuilt withnpm run build:extensions:@papi/backend,@papi/frontend,platform-bible-utils@papi/backend,platform-bible-utils(both supplied by the shim'sEXTENSION_INTERFACE_MODULES)legacy-comment-managertests pass; extensions lint and prettier clean;npm run typecheckpasses.Two notes for reviewers:
*.test.ts(x)files are excluded from every extension tsconfig, sonpm run typechecknever sees them. I typechecked the changed test files separately against a temporary config; they are clean.@eten-tech-foundation/scripture-utilities, which I allowlisted rather than "fixed": it is not a webpack external (so it is bundled, never reaching the shim) and has no dependency on react or any other external. This is the same entry, with the same justification, thatplatform-scripturealready carries.Scope
Only 3 of the 10 extensions with a
main.tsnow carry this guard. I deliberately did not extend it to the other seven — a sweep of every extension's dev backend bundle found no other real instance, so it would be a pure regression guard with nothing to fix today. (hello-rock3andhello-someoneflag under a naive bundle grep, but those matches sit inside inlined HTML web-view<script>strings, which run in the renderer.) Happy to add it more widely in a follow-up if reviewers want it.AI Involvement
AI-assisted. Claude diagnosed the dev-vs-production divergence, made the
WarnFnchange and the test updates, and adapted the guard fromplatform-scripture. I reviewed the diff and the verification evidence above, including the before/after dev bundle comparison.Risk Level
Low — one extension, no behavior change. The legacy-axes mapping and its two warning messages are byte-identical; only the sink they are written to moved from a module-level import to a parameter. The rest is test-only.
🤖 Generated with Claude Code
This change is