Skip to content

UI: expose network ACL replacement from VPC tiers - #13794

Draft
Dogface2k wants to merge 4 commits into
apache:mainfrom
Dogface2k:draft/ui-vpc-tier-acl
Draft

UI: expose network ACL replacement from VPC tiers#13794
Dogface2k wants to merge 4 commits into
apache:mainfrom
Dogface2k:draft/ui-vpc-tier-acl

Conversation

@Dogface2k

@Dogface2k Dogface2k commented Aug 4, 2026

Copy link
Copy Markdown

Summary

Expose the existing replaceNetworkACLList operation directly from the VPC tiers overview.

This is an additional UI entry point. The existing replace-ACL action on an individual tier's detail page remains unchanged.

Scope

  • VPC tiers UI only
  • Uses the existing replaceNetworkACLList API
  • No server, API, database schema, or ACL-semantics changes
  • No workflow or CI configuration changes
  • ACL choices are loaded for the VPC that owns the selected tier
  • The action is disabled when replaceNetworkACLList is unavailable to the current user
  • Existing default-allow/default-deny warnings and asynchronous-job feedback are reused

Behaviour

A replace-ACL action is shown beside the current ACL for each tier in the VPC tiers overview.

Selecting the action opens a dedicated replacement modal preselected with the tier's current ACL.

The replacement flow has its own:

  • form reference;
  • form data;
  • validation rules;
  • ACL list;
  • selected ACL;
  • target tier identifier;
  • fetch loading state;
  • submission loading state;
  • interaction generation.

It does not reuse or mutate the create-tier form state.

showReplaceAclModal remains the boolean modal-visibility state.

handleOpenReplaceAclModal() starts a replacement interaction, captures the owning VPC identifier, initializes replacement-only state, and loads the ACL lists belonging to that VPC.

handleCloseReplaceAclModal() handles user cancellation. It hides the modal, invalidates the cancelled interaction, and clears replacement-only state so a pending request cannot later update a closed or newer interaction.

A validated submission hides the modal without invoking the cancellation handler, allowing the already captured operation to continue.

Each interaction is protected by its generation and owning VPC identifier. Closing the modal, opening another tier, or navigating to another VPC invalidates older ACL-list and validation completions.

This prevents stale asynchronous work from:

  • overwriting a newer tier's ACL list or selection;
  • mutating the create-tier form;
  • submitting after the interaction has been cancelled;
  • clearing the loading state of a newer interaction.

Before submission, the selected ACL, owning VPC, target tier, interaction generation, and form reference are captured for that operation.

The encoded request uses the existing API parameters:

  • aclid;
  • networkid.

An older submission completing after another replacement interaction has started continues to report its own captured tier identifier and cannot clear the newer interaction's loading state.

Successful asynchronous completion refreshes the VPC view through the existing parentFetchData callback.

The existing create-tier ACL-loading and selection path remains unchanged.

Validation

Focused tests in VpcTiersTab.spec.js cover:

  • a closed replacement request not mutating create-tier state;
  • an older tier ACL response not overwriting a newer tier interaction;
  • stale responses being ignored when the parent VPC changes;
  • the replacement interaction closing when the parent VPC changes;
  • cancellation while form validation is pending;
  • cancelled validation not submitting an API request;
  • captured ACL and tier identifiers across overlapping submissions;
  • an older submission completion not clearing a newer interaction's loading state;
  • the replacement form reference remaining outside reactive data();
  • the mounted template populating the replacement form reference before submission;
  • the encoded POST payload containing the selected aclid and captured networkid;
  • the asynchronous-job notification using the captured tier identifier;
  • the overview replacement action remaining disabled without API permission.

The shallow-mounted component tests explicitly render stub default slots so the nested replacement form and overview action are present in the mounted template.

The current-head repository checks should be reviewed before merge.

@DaanHoogland

Copy link
Copy Markdown
Contributor

@blueorangutan ui

@blueorangutan

Copy link
Copy Markdown

@DaanHoogland a Jenkins job has been kicked to build UI QA env. I'll keep you posted as I make progress.

@codecov

codecov Bot commented Aug 5, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 20.92%. Comparing base (4f11707) to head (4f9b7ea).

Additional details and impacted files
@@             Coverage Diff              @@
##               main   #13794      +/-   ##
============================================
+ Coverage     19.65%   20.92%   +1.27%     
+ Complexity    19792    19791       -1     
============================================
  Files          6368     5881     -487     
  Lines        574881   533014   -41867     
  Branches      70351    62439    -7912     
============================================
- Hits         112970   111537    -1433     
+ Misses       449639   409403   -40236     
+ Partials      12272    12074     -198     
Flag Coverage Δ
uitests ?
unittests 20.92% <ø> (-0.01%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@weizhouapache

Copy link
Copy Markdown
Member

@Dogface2k
can you share a screenshot ?

there is already an icon to replace ACL list
image

@blueorangutan

Copy link
Copy Markdown

UI build: ✔️
Live QA URL: https://qa.cloudstack.cloud/simulator/pr/13794 (QA-JID-970)

@DaanHoogland

DaanHoogland commented Aug 5, 2026

Copy link
Copy Markdown
Contributor
Screenshot 2026-08-05 at 11 42 42

@weizhouapache there is now also a button in the vpc tiers overview list. I think that is fine as well.

(edit: your sshot is from the tiers details page, this is extra)

@Dogface2k

Copy link
Copy Markdown
Author

isolating VPC tier ACL replacement state

@Dogface2k
Dogface2k marked this pull request as ready for review August 6, 2026 02:49
@DaanHoogland

Copy link
Copy Markdown
Contributor

Now you have me worried @Dogface2k . there is a lot of new code while the functionality was already there in a different place. Do we now have two implementations of the same function?

@Dogface2k

Dogface2k commented Aug 6, 2026

Copy link
Copy Markdown
Author

Now you have me worried @Dogface2k . there is a lot of new code while the functionality was already there in a different place. Do we now have two implementations of the same function?

Investigating it looks like we got duplicate stuff, agents went rouge in their new environments not sure why it continued to touch this PR xD

My agents will return back to their main environments soon. Currently maxed out but over next few days will have full reasoning back and this duplicate shit won't happen it has pin pointed it and is rectifying it as we speak. Was always a risk setting up new environments. The constant auditing I have on every PR even when approved seem to of triggered another review that then led Two independent UI workflows and Duplicate form/API/polling logic @DaanHoogland

@Dogface2k
Dogface2k marked this pull request as draft August 6, 2026 09:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants