fix(host,client): require fully qualified browse paths; clear the picker kind on close

ds-review-bot round 4. On Windows, isAbsolute admits rooted drive-less
forms (\foo, /foo) that resolve() then rebases onto the process's current
drive; both browse primitives now gate on a fullyQualified check (drive
letter or UNC on win32, POSIX-absolute elsewhere) with a platform test
seam, per-platform unit cases, and the contract wording updated on the
seam, the backend README pair, and the error messages.

The picker-kind effect also kept a resolved 'dialog' across close, so a
backend swapped while the menu was closed could paint the stale entry for
one frame on reopen; the close arm now clears the state, pinned by a
reopen-under-pending-read race test.
This commit is contained in:
creatixchu
2026-07-28 18:13:20 +08:00
parent c4bf919895
commit b211a80b1f
9 changed files with 74 additions and 22 deletions
@@ -2,5 +2,5 @@
# side as of the last confirmed-consistent state. Both languages carry equal authority;
# after editing either side, bring the other along and re-record with:
# pnpm run verify-translation-pairing --write packages/host/directory-picker-browse/README.md
README.md: 81357269e1d4b075f7e31b5f3ac5d4721811024a
README.zh.md: 06a7f7651b2abc0aa73eba41042f3d1a86661b76
README.md: 160a12a8594400c9e6c565881d8e9ca0517b4e24
README.zh.md: 4cfc4a611fb17cb30ac841c8af8498b51a6388b0