UI/UX sweep: web #182

closed cmc opened this on 2026-09-07 18:04 UTC

Discussion

cmc 2026-09-07 18:04 UTC

The stylesheet has a token system and a contrast test, so the sweep is about flows, not colour. Known shapes to review:

  • The settings page is a stack of <details> boxes and inline forms. Destructive controls (key remove, PGP remove, email remove) have no confirmation. Find every such control and decide one rule.
  • Forms return to the page with a flash line; errors from a refused control command are shown verbatim, in CLI wording.
  • Walk every page in the web UI as a first-time visitor and record what is unclear or inconsistent, one finding per line, before changing anything.

Output: a list of findings on this issue, then MRs per page or per pattern. Update the wiki's Parity page where a control moves.

cmc 2026-09-12 03:27 UTC

Findings from walking every route in internal/httpd/routes.go on gitbay.org, anonymous and then logged in as cmc, at v1.20.1. One per line, grouped by pattern; nothing changed yet.

Destructive controls with no confirmation. Every one is a plain POST button; the only stated rule is on the org page, which says deleting a repository "wants a typed confirmation rather than a button" and leaves the rest as buttons.

  • account.html: SSH key Remove (including the key behind the current session; removing the last full key locks the account out of writes), email Remove, Make primary, PGP key Remove.
  • settings.html (repository): Unprotect branch, Unprotect tag glob, Detach runner.
  • owner.html (org admin): member Remove, team member Remove, Delete this team.
  • labels.html: Remove, on labels attached to up to 48 issues.
  • releases.html: Delete release, assets included.
  • snippet.html: Remove file, Delete snippet.
  • Reversible state changes on the same footing: Close issue / Reopen, Merge, Close without merging, Cancel build, Resolve / Reopen thread, Commit to main.

Decision wanted: one rule. Suggested split: a typed name for anything that destroys data nothing else holds (release, snippet, team, key, email, PGP key); a plain button for state that can be put back (close/reopen, protect/unprotect, attach/detach, resolve).

Refusals shown verbatim. 22 templates render the flash line with the control command's stderr. The wording is the CLI's: it names flags and commands the form cannot supply (--yes, --force, gitbay org label set …). Decide whether the web rewrites these per exit code or the commands learn a surface-neutral phrasing.

Wrong command in copy. account.html "On SSH only" says gitbay auth token mint --name laptop; the command is auth token create. A first-time visitor who types it gets an error.

Login has no return-to. Anonymous /settings, /new, /admin, /{repo}/issues/new, /{repo}/edit/… all land on /login with no sentence saying why, and a successful login goes to the dashboard, not where the visitor was going.

Four date formats. Relative ("40 minutes ago") on tree and blob; date-only ("2026-09-12") on log and compare; "2026-09-12 02:18" with no zone on issues, MRs, builds, releases and the dashboard; full ISO with milliseconds on the commit page and in repository settings ("Last checked 2026-09-11T12:20:16.046Z", "last poll …"). All are UTC and only the ISO ones say so.

Refs page sorts tags as strings. v1.10.0 sits before v1.2.0 and v1.20.1 before v1.3.0; the newest release is in the middle of the list. The repo home's "latest v1.20.1" is right.

Edit form offered where it cannot succeed. On krz/gitbay the file editor says "this commit will be unsigned and authored as cmc" and offers "Commit to main", but the repository requires signed commits and require_mr refuses a direct push to main; the commit is refused after typing. Parity records the limitation; the page should say it before the textarea, or not offer the form.

Repository settings: a Save per row. Twelve Save buttons on one page, each scoped to its own field, plus Apply and Protect; a first-time visitor cannot tell which Save applies to what they typed. One form per section, or a single Save, or label each button with its field.

Labels page. Logged in, every row carries an empty colour input and a Save; anonymous, a "colour" column of dashes. No label on the instance has a colour, so the column is noise until one does.

Empty-state wording varies. Issue sidebar: "None yet", "Nobody yet", "None". MR sidebar: "Nobody asked yet", "No reviews yet". Notifications: "nothing unread — show all". MR list: names the CLI command; issue list: not seen empty. Snippets and org labels: "No … yet." Pick one shape.

Issue close event line. "closed by commit 92e025a4f6 by cmc: config: …" reads with two "by"s, and its timestamp renders on its own line below.

Issues list. Every row repeats the state chip ("open") under the "open" filter; a milestone shows as "· mobile" while labels show as chips, so the two read as the same kind of thing.

Merged MR page. "SOURCE krz/gitbay:snippets into main at e44fbbb059" after the branch was deleted, with no sign it is gone; "at" reads as the target's commit rather than the merged head.

Global search. No result count, no echo of the query beside the tabs, and each hit is a title with a state chip and no context line. The repository search does better: "200 matches (capped — refine the query) on main" with the matching line.

Clone line. The repository home shows one clone URL, HTTPS, while the landing page teaches ssh://. Check what a logged-in owner sees; either way the SSH form belongs next to it for anyone with a key.

Small. Landing page: "mint a browser session" is jargon for "log in". Account settings: the Body markup radio sits under the About textarea rather than beside its label. Repo home for an anonymous visitor shows "1 bookmark" as a stat with nothing to do about it.

Not walked: /settings/export (a download), archive/{file}, badge/*, the Atom feeds, and every POST, which this issue says to leave until the rule above is decided.

closed by commit 8ed8a91a52 by cmc: CHANGELOG: web UI/UX sweep

2026-09-12 05:37 UTC

referenced in commit 95325d5b48 by cmc: web: no result count beside a query error

2026-09-12 05:37 UTC

referenced in commit ce9df03eda by cmc: web: a merged MR names its merged head and a deleted source branch; both clone URLs

2026-09-12 05:37 UTC

referenced in commit 7dd9852ea5 by cmc: e2e: gofmt snippetweb_test

2026-09-12 05:37 UTC

referenced in commit 070b443e46 by cmc: web: the editor answers 404 for a missing branch and names a new file

2026-09-12 05:37 UTC

referenced in commit 7149e0bd2e by cmc: web: global search counts its results and echoes the query

2026-09-12 05:37 UTC

referenced in commit 4c876b7895 by cmc: web: list rows show the state only under all, and name the milestone

2026-09-12 05:37 UTC

referenced in commit 7cefd457fd by cmc: web: one shape for empty sidebars

2026-09-12 05:37 UTC

referenced in commit a9eb95e41b by cmc: web: the labels page hides an empty colour column

2026-09-12 05:37 UTC

referenced in commit 6009cab89c by cmc: web: every Save on repository settings names its field

2026-09-12 05:37 UTC

referenced in commit d79139214b by cmc: web: the settings page names the real token command

2026-09-12 05:37 UTC

referenced in commit c074c8aa48 by cmc: control, web: the close event reads closed by in commit

2026-09-12 05:37 UTC

referenced in commit 478bd0c00c by cmc: control: merge refusals name the strategy, not the flag

2026-09-12 05:37 UTC

referenced in commit 6a1ce6c2c8 by cmc: web: the editor explains a refusal before the textarea

2026-09-12 05:37 UTC

referenced in commit 85ec9f4218 by cmc: web: refs and the release form order tags by version

2026-09-12 05:37 UTC

referenced in commit 568741bf32 by cmc: web: one timestamp format, with the zone named

2026-09-12 05:37 UTC

referenced in commit 1a274bec3b by cmc: web: resolve a snippet before checking its confirmation

2026-09-12 05:37 UTC

referenced in commit b53740ec50 by cmc: web: login returns to the page that needed it

2026-09-12 05:37 UTC

referenced in commit e2dec5d9ff by cmc: web: type the name to confirm a destructive control

2026-09-12 05:37 UTC

referenced in commit 5b3973e138 by cmc: docs: web UI/UX sweep spec and plan

2026-09-12 05:37 UTC