Skip to content

fix(agent): reopen a saved SDUI Easy Apply draft from its Continue link (#403); 1.66.3 - #405

Merged
CryptoJones merged 1 commit into
mainfrom
fix/linkedin-sdui-continue-403
Oct 4, 2026
Merged

CryptoJones merged 1 commit into
mainfrom
fix/linkedin-sdui-continue-403

Conversation

@CryptoJones

Copy link
Copy Markdown
Owner

Part of #403 (follow-up to #404)

On 1.66.2 the first runs walked the SDUI dialog, saved drafts for the new questions, and handed those questions back for drafting. The next run then failed with "no Easy Apply button on the posting" (Photon, Bright Matrix). On the SDUI page, a saved draft's way back in is an <a> to the posting itself reading Continue, with no aria-label and no /apply/, so none of the Entry selectors matched it.

Change: Entry also matches a[href*='/jobs/view/'] whose text is exactly "Continue". Probed on the live Photon posting: one match, and clicking it opens the SDUI dialog at 1/5.

Tests: new Easy_apply_sdui_dialog_reopens_a_saved_draft_from_its_continue_link; all 12 Easy Apply tests pass locally.

🤖 Generated with Claude Code

https://claude.ai/code/session_01SXYffreKMhXLNgc2wdhsiw

Proudly Made in Nebraska. Go Big Red! 🌽 https://xkcd.com/2347/

…ue link (#403); 1.66.3

The first runs on 1.66.2 saved drafts for new questions, and the next run
found "no Easy Apply button": on the SDUI page a draft's way back in is
an <a> to the posting itself reading "Continue", with no aria-label and
no /apply/. Checked against the live page.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SXYffreKMhXLNgc2wdhsiw
@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: d45bac22-90a1-4f56-88b5-d0b72a77e13f
📥 Commits

Reviewing files that changed from the base of the PR and between 9f30b7e and 2a7c888.

⛔ Files ignored due to path filters (1)
  • uv.lock is excluded by !**/*.lock
📒 Files selected for processing (5)
  • api/ApplyTrack.Api.Tests/BrowserSubmitterTests.cs
  • api/ApplyTrack.Api/Agent/Browser/LinkedInEasyApply.cs
  • api/ApplyTrack.Api/ApplyTrack.Api.csproj
  • pyproject.toml
  • src/applytrack/__init__.py

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (4)
  • GitHub Check: Web — WCAG checks
  • GitHub Check: Image — agent starts Playwright as uid 1654
  • GitHub Check: .NET — test + audit
  • GitHub Check: Python — lint + test + audit
🔇 Additional comments (5)
api/ApplyTrack.Api/Agent/Browser/LinkedInEasyApply.cs (1)

52-55: LGTM!

api/ApplyTrack.Api.Tests/BrowserSubmitterTests.cs (1)

79-83: LGTM!

Also applies to: 3104-3115

api/ApplyTrack.Api/ApplyTrack.Api.csproj (1)

8-8: LGTM!

pyproject.toml (1)

7-7: LGTM!

src/applytrack/__init__.py (1)

5-5: LGTM!


📝 Summary

Summary by CodeRabbit

  • Bug Fixes

    • Improved handling of LinkedIn saved drafts opened through a “Continue” link, allowing the application flow to reach the submission step.
  • Chores

    • Updated the application version to 1.66.3.

Walkthrough

LinkedInEasyApply.Entry now recognizes SDUI saved-draft links labeled “Continue” on job-view pages. A browser test exercises the existing dialog flow in dry-run mode. The .NET and Python project versions are updated to 1.66.3.

Changes

SDUI Saved-Draft Continue Link

Layer / File(s) Summary
Recognize the saved-draft link
api/ApplyTrack.Api/Agent/Browser/LinkedInEasyApply.cs, api/ApplyTrack.Api.Tests/BrowserSubmitterTests.cs
Entry matches bare “Continue” links to /jobs/view/ pages. The test fixture opens the existing dialog when the link is clicked.
Verify the dry-run and update versions
api/ApplyTrack.Api.Tests/BrowserSubmitterTests.cs, api/ApplyTrack.Api/ApplyTrack.Api.csproj, pyproject.toml, src/applytrack/__init__.py
A dry-run test checks that the flow reaches submit, has no unmapped questions, and discards the draft. The .NET and Python project versions are updated to 1.66.3.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to 2a7c8

The saved-draft entry point is narrowly matched, its dry-run flow is exercised by a test, and the project version declarations are aligned. No concrete issue blocks merging.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 2a7c8

The new Continue link uses the existing application flow and retains its navigation, sign-in, and submission safeguards. No introduced vulnerability was established. Posting identity and interrupted draft recovery remain only partially verified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • observed — The newly recognized entry operates within the existing packet and browser-account context. Session cookies are selected for the initial target host; the change introduces no separate credential selection or additional account authority.

Trust Boundaries and Controls

  • observed — BrowserSession restricts top-level navigation through the existing host policy, including same-site, configured ATS, and explicit account exceptions. This is not a strict single-origin policy and does not bind navigation to one posting.
  • inferred — A different same-host posting link could qualify under the new Continue patterns and reach the shared fill flow. Posting-ID binding was also absent from prior selectors. Attacker ability to place such a link in the relevant LinkedIn page was not established, so this remains an assurance limitation rather than a verified attack path.

Resilience and Maintainability Implications

  • observed — Cancellation checks and failure handling remain shared with existing entry paths, and the caller disposes the browser session. Failure does not always explicitly leave the dialog; external draft persistence after interruption is not established by repository evidence.

Hardening Proposals

  • proposed — Consider binding the selected entry or opened application to the requested posting identity before filling personal answers. This would strengthen the existing page-trust assumption without treating a hypothetical alternate-link scenario as an observed vulnerability.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 4 functions across 3 files. (2 skipped: 2 … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the main change: reopening a saved SDUI Easy Apply draft from its Continue link. The issue number and version do not obscure the summary.
Description check ✅ Passed The description explains the saved-draft failure, the selector change, and the added test. It is directly related to the changeset.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 4 functions across 3 files. (2 skipped: 2 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@CryptoJones
CryptoJones merged commit 9ecbaac into main Oct 4, 2026
6 checks passed
@CryptoJones
CryptoJones deleted the fix/linkedin-sdui-continue-403 branch October 4, 2026 04:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant