Repository navigation
Conversation
Code Review SummaryStatus: No Issues Found | Recommendation: Merge Executive SummaryAll five prior findings are fixed in the current commit range, and the incremental changes introduce no new issues: the iOS rebuild now clears the live Files Reviewed (6 files)
Previous Review Summaries (9 snapshots, latest commit f1cb484)Current summary above is authoritative. Previous snapshots are kept for context only. Previous review (commit f1cb484)Status: 5 Issues Found | Recommendation: Address before merge Executive SummaryThe incremental widget redesign leaves the iOS widget clearing a renamed-away key (so a failed-approve line survives background rebuilds) and the Android retry card showing the failure line instead of "Approving…", while the added publisher test still does not exercise its session-change case; two lower-value test/markup nits round it out. Overview
Issue Details (click to expand)WARNING
SUGGESTION
Files Reviewed (5 files)
Fix these issues in Kilo Cloud Previous review (commit a8b9a78)Status: 1 Issue Found | Recommendation: Address before merge Executive SummaryThe new incremental test in Overview
Issue Details (click to expand)SUGGESTION
Files Reviewed (1 file)
Fix these issues in Kilo Cloud Previous review (commit dc6d969)Status: No Issues Found | Recommendation: Merge Executive SummaryIncremental pass over commit Files Reviewed (2 files)
Previous review (commit 5d741c5)Status: No Issues Found | Recommendation: Merge Executive SummaryIncremental pass over commit Files Reviewed (5 files)
Previous review (commit 19773e2)Status: No Issues Found | Recommendation: Merge Executive SummaryThe only change since the previous review is a Files Reviewed (1 file)
Previous review (commit 6e51e64)Status: No Issues Found | Recommendation: Merge Executive SummaryThe incremental changes size the Android card's stacked support rows to the room the cell actually has, clamp the hero to a floor of Files Reviewed (3 files)
Previous review (commit f8bcd2e)Status: 2 Issues Found | Recommendation: Address before merge Executive SummaryThe incremental redesign adds a negative-height path in the Android card layout and a fixture approval key that is not schema-valid; both are correctness issues on changed lines. Overview
Issue Details (click to expand)WARNING
Files Reviewed (13 files)
Fix these issues in Kilo Cloud Previous review (commit 6c18d66)Status: 1 Issue Found | Recommendation: Address before merge Executive SummaryThe incremental fix set resolves all seven prior findings; the only new concern is an unexplained deletion of an existing profiles-copy test that removes coverage present on the base branch. Overview
Issue Details (click to expand)WARNING
Files Reviewed (27 files)
Fix these issues in Kilo Cloud Previous review (commit 1d73214)Status: 7 Issues Found | Recommendation: Address before merge Executive SummaryNo blocking bug, but a new 30-day widget credential issuance path does not enforce the organization-scope invariant its sibling issuance paths enforce, and that credential is newly published to the Kilo MCP catalog without a stated rationale. Overview
Issue Details (click to expand)WARNING
SUGGESTION
Files Reviewed (160+ files)Reviewed the full changed set sharded across web auth/security, web snapshot/sessions, shared package, notifications/cloud-agent service, MCP catalog, mobile core lib, Android and iOS native modules, glanceable Android/iOS UI, i18n catalogs, and tests. No memory leaks were identified on changed lines; teardown for listeners, timers, URLSession, and WorkManager was present. Reviewed by deepseek-v4.1-flash · Input: 72.9K · Output: 11.2K · Cached: 982.3K Review guidance: REVIEW.md from base branch |
Android widget cells — Pixel 6 (API 35), light and dark, portrait and landscape, English and ArabicEvery launcher cell the widget can occupy (2x1 through 4x4, plus landscape rows), the locked state, and the Arabic (RTL) mirroring. The fixtures cover the empty, scheduled, stale, long-title and large-count states; the full 36-fixture × 10-cell × 2-theme × 2-orientation capture set lives in the E2E evidence. |
In-place Approve and cold New agentLeft: with a live pending permission the Android widget draws the Approve control, and the press reaches the server (the binding is SHA-256 of the session and permission ids). Right: on iOS, after terminating the app, tapping the widget |




















































Summary
Home widgets no longer show "Status expired" or a zero ledger. They keep the last known work with an honest
Checkedtime, refresh natively in the background on both platforms, and every size and family was redesigned.Shared rules —
@kilocode/app-shared/home-widgetHomeWidgetDetails.Fresh data without the app open
kilo-home-widget, 30 days, bound to the device session) authenticates onlyGET /api/mobile/widgetsandPOST /api/mobile/widgets/push-token(docs/token-issuance-policy.md).WidgetPushHandlerfed by APNs widget reload hints from the notifications service.Safe approval
approvalKey= SHA-256 of[kiloSessionId, permissionId], minted by a new internal Cloud Agent route, so a stale tap cannot approve a newer request.Design
Checkedfooter.Verification
E2E on an isolated GCP VM (web app, workers, Android emulator API 35) and an owned iOS 26.5 simulator on the Mac, both signed in through native device auth as a fake account. Nothing is committed as an image.
Help improve Kilooff and only the required consent accepted.GET /api/mobile/widgets(200) and the widget'sCheckedtime advanced.GET /api/mobile/widgets(200) with the app backgrounded and theCheckedtime advanced.Checkedtime on both platforms; a later refresh updates it.protectedContext, iOS Keychain item) and drives those fetches.Last knownwith a real time.evidence/android-approve3/10-widget-approve.png), and the press reached the server (cloudAgentNext.answerPermission200, worker "Permission answer forwarded to wrapper"). TheapprovalKeyin the stored payload is exactly SHA-256 ofJSON.stringify([kiloSessionId, permissionId])for that ask.+was tapped, and the app cold-started into the New session composer. The marker is now carried across the press's own widget reload with a 5-minute TTL, and a stale marker is cleared without running. On Android the same press cold-starts the app process, but an Expo dev-client cold start cannot load its bundle without the dev launcher, so the composer is reached there only in a real build.Screenshots
Attached in the comment below: iOS (all six families, light and dark, Tinted, Clear, German, Arabic) and Android (all ten cells, portrait and landscape, light and dark, Arabic).
Reviewer Notes
apps/mobile/plugins/withHomeWidgetRefresh.jspatches the Expo widget extension afterexpo-widgetsgenerates it. The push-handler body uses statement returns so Swift accepts the iOS 26-only opaque type (SE-0360), and the refresh sources join the target's existing Sources phase (a second phase makes Xcode report duplicate tasks).nullinside an object argument (a Personal scope'sorganizationId, a row without an approval key), which previously rejected everyconfigureand left the widget with no credential.user_activity_tokens.kindgainsios_widgetin the TypeScript union only; the column istext, so no migration.agent_*sessions carry no approval key, so they show no in-place Approve.