Add the web preview performance panel - #168
Conversation
📊 PR Size: size/XLTotal changes: 1707 lines (6 files) Top files changed:
Size calculated as additions + deletions. Labels: XS (<10), S (<50), M (<250), L (<1000), XL (1000+) |
clholgat
left a comment
There was a problem hiding this comment.
Review of the web-preview Performance panel. Rendering is safe: every dynamic value (trace names, metric values, labels, search box, duration, paint names, counts) is routed through escapeHtml before innerHTML, and preparePerformanceForTargetChange nulls data/lastTrace/samples on every target change, so no XSS and no cross-generation data bleed. Polling is guarded by pending/snapshotPending, skips when document.hidden, and stops on pagehide. One identity concern inline, plus two low notes below.
Note: please carry this feedback into the squashed PR when the stack is collapsed.
- 🟢 Low — one-shot Capture sets
traceActive/ownerIdentitybefore issuing the request and does not reset them if the request throws. After a failed Capture the panel is wedged in "Result pending" / Stop-only until the next ~1200 ms poll recomputes owner state from/status— and only while the user stays on the Performance tab. Consider resetting owner state in acatchon the capture path. - 🟢 Low — the
completionErrorbranch issues its trace/stop call against the currently selected identity, not necessarilyperf.ownerIdentity. If the owner belongs to a previous target, the stop clears the wrong session's server state. Local owner state is guarded, but the network call is misdirected; route the stop toperf.ownerIdentitywhen present.
| return `${formatNumber(numeric / 60_000)} min`; | ||
| } | ||
|
|
||
| function performanceIdentity(target = state.target) { |
There was a problem hiding this comment.
🟠 Med — the frontend "exact identity" guarantee is effectively sessionId-only. inspectedUrl and inspectedTargetNonce are module-level constants read once from the panel URL, so performanceIdentity() rebuilds them identically on every call and performanceIdentityIsCurrent() can never observe an inspectedUrl/targetNonce mismatch — only sessionId can ever differ.
Failure scenario: the panel advertises that Start/Stop/polling/results are bound to the exact inspectedUrl and per-tab targetNonce and "fail closed", but that enforcement lives entirely server-side. If a stale/rebound tab shares a sessionId, the client-side guard would not catch it; safety currently rests solely on #167's server-side nonce validation. Either derive the identity from the actual live target (so the fields can genuinely differ) or drop/soften the client-side guarantee in the docs so it isn't mistaken for real cross-check.
|
Superseded by #180, which consolidates this patch into the reviewed debugger capabilities landing unit. The replacement carries forward the feedback and fixes discussed here. Closing this draft to reduce the active stack; this PR and its discussion remain the historical review record. |
Description
Adds a generation-safe Performance panel over the preceding bounded capture API.
Type of Change
Testing
bazel test //...)Testing Details
npm testpassed 436/436; the CLI production build passed.//src/valdi_modules/src/valdi/web_renderer:testpassed.bazel query //...passed.Checklist
Related Issues
Relates to #154
Additional Context
Stack 15/22. Stacked on #167 (
bjd/debugger-web-performance-api). Review this PR as the single incremental commitc1d9db42against that base; do not merge it before its parent.