Skip to content

Various Fixes - #259

Merged
Redth merged 3 commits into
aritchie/apple-devid-installerfrom
aritchie/secret-fixes
Sep 23, 2026
Merged

Redth merged 3 commits into
aritchie/apple-devid-installerfrom
aritchie/secret-fixes

Conversation

@aritchie

Copy link
Copy Markdown
Collaborator

This pull request introduces several improvements across the UI and service layers, focusing on enhanced error handling, more robust loading and state management, and better user experience for edge cases (such as locked vaults or demo mode). The most significant changes are grouped below:

Error Handling and Resilience

  • Improved CloudSecretsService.InitializeAsync to gracefully handle locked or unavailable Local Vaults, logging a warning and allowing the page to render so users can unlock the vault later. This prevents the app from failing to load when secure storage is inaccessible. [1] [2]
  • Updated the Apple identity picker and certificates page to display actionable error messages if loading identities or initializing cloud secrets fails, instead of leaving the UI blank or stuck. [1] [2] [3]

Loading and State Management

  • Added flags (identitiesLoaded, _loadedIdentityId) to suppress flickering or redundant loads and to ensure UI only prompts for missing profiles after the first load attempt, not during initial loading. [1] [2] [3] [4] [5] [6]
  • Ensured pages and components re-render and reload data when the Local Vault state changes, so unlocking the vault or changing identities updates the UI and data appropriately.

UI/UX Improvements

  • Enhanced error and loading states in AppleIdentityPicker.razor to provide clearer feedback and actionable prompts, including styling for error messages. [1] [2]
  • Improved secrets and picker UI to handle long text gracefully with overflow-wrap, line clamping, and better responsive layout. [1] [2]

Demo Mode Support

  • Added support for demo mode in secrets and secret picker pages, visually blurring secret descriptions and hiding details as appropriate. [1] [2] [3] [4] [5] [6]

API and Interface Enhancements

  • Added a RequestCancellation method to the operation interface, allowing consumers to request cancellation of running operations if supported.

These changes collectively make the application more robust in the face of errors and improve the overall user experience, especially in scenarios involving secure storage and cloud secrets.Make cloud secret initialization tolerate an unreadable Local Vault so Apple pages can render instead of staying blank. Update Apple identity and certificates flows to handle async identity resolution, show actionable load errors, reopen settings correctly on native desktop heads, and refresh when vault access changes. Also improve secret list/picker rendering for demo mode and long descriptions, and add an operation modal cancellation request hook.

Copilot AI lite review requested due to automatic review settings September 10, 2026 22:28

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Unresolved vault initialization, refresh, stale-load coordination, and error-state issues remain.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

This pull request improves Local Vault resilience, Apple identity and certificate loading, secret rendering, and operation cancellation support.

Changes:

  • Adds actionable error handling and vault-state refresh behavior.
  • Improves identity and certificate load coordination.
  • Adds demo-mode masking and responsive text handling.
  • Adds operation cancellation request support.
File summaries
File Summary
tests/MauiSherpa.Core.Tests/Services/CloudSecretsServiceTests.cs Tests unreadable-vault initialization.
src/MauiSherpa/Pages/Secrets.razor Adds demo-mode masking and long-text handling.
src/MauiSherpa/Pages/Modals/SecretPickerModal.razor Adds demo-mode masking and text wrapping.
src/MauiSherpa/Pages/Certificates.razor Updates vault refresh, error handling, and identity-load coordination.
src/MauiSherpa/Components/AppleIdentityPicker.razor Adds loading and actionable error states.
src/MauiSherpa.Core/Services/CloudSecretsService.cs Handles unavailable vault initialization.
src/MauiSherpa.Core/Interfaces.cs Adds operation cancellation request support.
Review details

Suppressed comments (3)

src/MauiSherpa/Pages/Certificates.razor:727

  • When the initial initialization was deferred because the Local Vault was locked, unlocking it reaches this handler, but this callback only refreshes certificates. It never reruns CloudSecretsService.InitializeAsync, so ActiveProvider remains null and LoadSyncStatuses permanently skips cloud copies until another page happens to initialize the service. Reinitialize the cloud service here before refreshing, using the same error handling as the initial load.
        InvokeAsync(async () =>
        {
            await RefreshData();
            StateHasChanged();

src/MauiSherpa/Pages/Certificates.razor:658

  • This catch only logs the initialization failure; it never exposes it in the page state. When an unexpected cloud-secrets initialization error occurs, ActiveProvider stays unavailable and the UI can misleadingly show the normal provider-configuration hint while silently skipping sync status loading. Surface a user-facing error or warning here (separate from errorMessage, which RefreshData resets) so the failure is actionable.
        catch (Exception ex)
        {
            // Never let this leave the page stuck on its first (empty) render.
            Logger.LogError("Failed to initialize cloud secrets on the certificates page", ex);
        }

src/MauiSherpa/Pages/Certificates.razor:759

  • Once a certificate load succeeds, _loadedIdentityId is retained. If the vault is locked, this method returns before clearing it; after unlock, OnLocalVaultStateChanged calls RefreshData, but this guard returns for the same identity, so the list is not reloaded and can remain stale after the vault transition. Clear _loadedIdentityId whenever RequiresUserAction causes an early return.
        // Both the initial load and OnIdentityChanged can fire for the same identity;
        // only the explicit Refresh action re-fetches one we already have.
        if (!forceRefresh && _loadedIdentityId == identity.Id)
            return;
  • Files reviewed: 7/7 changed files
  • Comments generated: 2
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/MauiSherpa/Pages/Certificates.razor
Comment thread src/MauiSherpa.Core/Services/CloudSecretsService.cs
@Redth
Redth force-pushed the aritchie/secret-fixes branch from 9be90f4 to 37f7cad Compare September 21, 2026 12:35
@Redth
Redth changed the base branch from main to aritchie/apple-devid-installer September 21, 2026 12:36
aritchie and others added 3 commits September 22, 2026 15:11
Make cloud secret initialization tolerate an unreadable Local Vault so Apple pages can render instead of staying blank. Update Apple identity and certificates flows to handle async identity resolution, show actionable load errors, reopen settings correctly on native desktop heads, and refresh when vault access changes. Also improve secret list/picker rendering for demo mode and long descriptions, and add an operation modal cancellation request hook.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@Redth
Redth force-pushed the aritchie/secret-fixes branch from 37f7cad to 18c668f Compare September 22, 2026 19:11
@Redth
Redth added this pull request to stack #268 September 22, 2026 20:18
@Redth
Redth merged commit 12a059c into main Sep 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants