Goal
Fix the issues found in the v0.2.0 pre-release review that were deferred to keep the release small. Each was confirmed by code tracing; none blocks normal use.
Context
Found by an independent read-only review (Codex gpt-6.1-sol) of focus, Touch ID and all user-visible v0.2 changes, then verified by the planner. Fixed in v0.2.0 (#157): Touch ID focus handoff race, focus restore after the user switched apps, overlapping prompt Dock state, stranded approval queue after an expired retry, timers in common run-loop modes, repeated Unlock clicks, import replacement permission, unverified caller label, denied-record wording, welcome step 3 by permission, Agent access subtitle, expired sample credential.
Scope
Approval and Touch ID
- Closing, denying or expiring a request (or closing management, cancelling onboarding) does not cancel its running Touch ID prompt; later prompts wait behind it (
ManagementAuthenticationProcess.swift, AppDelegate+Approval.swift, FrozenWriteApprovalContent.swift). Add per-prompt cancellation.
- Timeout termination skips the focus-return handshake (
ManagementAuthenticationProcess.swift). Add graceful cancellation.
- Authentication failures are reported as "You cancelled authentication" (approval) or cancellation (onboarding). Keep authenticated / cancelled / failed distinct.
- Long commands, names or purposes can push the approval buttons off screen (
FrozenAgentApprovalPrompt.swift, AppDelegate+Approval.swift). Cap the panel to the visible frame, scroll content, keep actions visible; resize when Details expand.
- "Pending requests" / "Review and decide" cannot bring an open approval forward or switch to another request (
presentingApproval guard).
- An approval arriving while an app-modal file picker is open may be visible but not interactive. Use sheets or defer presentation.
- Approval placement does not follow the display the user is working on.
Window and Dock
8. Opening a file picker or alert from management drops the Dock icon (ManagementDockPolicy.swift): treat management-owned dialogs as foreground.
9. Locked-screen fallback badge is invisible when the app is accessory-only (AppDelegate+Approval.swift).
10. Notification clicks do not open the matching page (no UNUserNotificationCenterDelegate).
11. askkey:// is a documented identifier but is neither registered nor handled.
12. Check whether clicking the menu-bar item brings an open management window forward. Checked on the maintainer's Mac during the v0.2.0 acceptance: it does not (only the Dock icon does, as expected).
Integrations and content
13. claude mcp add-json that writes and then times out is reported as not written (ClaudeCodeMCPAdapter.swift). Re-inspect and report uncertainty.
14. Claude Code readiness ignores disableAllHooks: true (verify with an isolated real client).
15. Any Claude hook command containing askkey/hook claude is treated as owned and blocks setup; match the exact helper invocation.
16. Approvals show no location when an MCP caller omits cwd; show the effective directory or require cwd.
17. The sample prompt can pick a credential whose components are all kept in the app, and shows a generic prompt with an empty library; select a deliverable credential or show a create/change-permission action.
Acceptance
swift build, filtered tests for changed code, hygiene and module checks; CI green; focus items verified on the maintainer's Mac with the release checklist.
Goal
Fix the issues found in the v0.2.0 pre-release review that were deferred to keep the release small. Each was confirmed by code tracing; none blocks normal use.
Context
Found by an independent read-only review (Codex
gpt-6.1-sol) of focus, Touch ID and all user-visible v0.2 changes, then verified by the planner. Fixed in v0.2.0 (#157): Touch ID focus handoff race, focus restore after the user switched apps, overlapping prompt Dock state, stranded approval queue after an expired retry, timers in common run-loop modes, repeated Unlock clicks, import replacement permission, unverified caller label, denied-record wording, welcome step 3 by permission, Agent access subtitle, expired sample credential.Scope
Approval and Touch ID
ManagementAuthenticationProcess.swift,AppDelegate+Approval.swift,FrozenWriteApprovalContent.swift). Add per-prompt cancellation.ManagementAuthenticationProcess.swift). Add graceful cancellation.FrozenAgentApprovalPrompt.swift,AppDelegate+Approval.swift). Cap the panel to the visible frame, scroll content, keep actions visible; resize when Details expand.presentingApprovalguard).Window and Dock
8. Opening a file picker or alert from management drops the Dock icon (
ManagementDockPolicy.swift): treat management-owned dialogs as foreground.9. Locked-screen fallback badge is invisible when the app is accessory-only (
AppDelegate+Approval.swift).10. Notification clicks do not open the matching page (no
UNUserNotificationCenterDelegate).11.
askkey://is a documented identifier but is neither registered nor handled.12.
Check whether clicking the menu-bar item brings an open management window forward.Checked on the maintainer's Mac during the v0.2.0 acceptance: it does not (only the Dock icon does, as expected).Integrations and content
13.
claude mcp add-jsonthat writes and then times out is reported as not written (ClaudeCodeMCPAdapter.swift). Re-inspect and report uncertainty.14. Claude Code readiness ignores
disableAllHooks: true(verify with an isolated real client).15. Any Claude hook command containing
askkey/hook claudeis treated as owned and blocks setup; match the exact helper invocation.16. Approvals show no location when an MCP caller omits
cwd; show the effective directory or requirecwd.17. The sample prompt can pick a credential whose components are all kept in the app, and shows a generic prompt with an empty library; select a deliverable credential or show a create/change-permission action.
Acceptance
swift build, filtered tests for changed code, hygiene and module checks; CI green; focus items verified on the maintainer's Mac with the release checklist.