Skip to content

feat: add database version history previews and restore - #549

Merged
appflowy merged 26 commits into
mainfrom
codex/database-version-history
Sep 28, 2026
Merged

appflowy merged 26 commits into
mainfrom
codex/database-version-history

Conversation

@appflowy

@appflowy appflowy commented Sep 11, 2026 •

Copy link
Copy Markdown
Contributor

Description

Adds database version history to the web client. Users can preview saved views and row values in eight read-only layouts, then restore with a recovery checkpoint. Restoring from another tab or device also replaces the open database and its rows, refreshes mounted sidebar views, and preserves independent row-page documents.

  • Load historical roots and complete row payloads into isolated preview sessions without falling back to live data. Database and document history share the dialog and timeline presentation.
  • Persist restore jobs and idempotency keys before requests, resume accepted work, and close history only after a restore explicitly confirmed during that opening finishes. Completing an earlier restore does not dismiss a newly opened dialog.
  • Fence websocket/HTTP traffic, IndexedDB caches, asynchronous row seeds, and pending updates by the committed restore generation. Repeated restores to the same saved version remain distinct.
  • Honor trusted restore notifications, root collab-version changes and persisted restore markers even when the receiving client's history UI capability is disabled or unresolved. A notification invalidates older in-flight authority reads and reload failures before queued traffic can resume. Permission denials keep synchronization blocked.
  • Revalidate sidebar roots and expanded branches after restore. Server Folder membership determines mounts; clients preserve ordinary deletions and never-mounted definitions. Session/revision guards reject stale loads, and transient navigation failures retry independently of the database reset.

Dependencies: history server #1156, restore reconciliation #1231 for sidebar reconciliation, permission/publication cleanup and committed Folder projection revisions. Companion desktop: #1386, using the native synchronization also consolidated in #1231. The history menu remains controlled by the server capability.

Implementation contract: Database version history.

Validation

  • Current remote-restore changes: 111 tests across five suites covering restore tracking, aggregate recovery, incoming frames and batch synchronization; full TypeScript checking; ESLint including changed tests; diff checks.
  • Regression cases include disabled/unresolved history capabilities, persisted generations, two restores to one target, delayed pre-notification responses/errors, partial reloads, transient retries, permission denial, missed-notification root-version recovery, legacy batch behavior, and root/row replacement with row-document isolation.
  • Existing feature validation included 413 tests across 43 suites, repository lint, application/Storybook builds, and Chromium checks of previews, virtualization and scrolling. Sidebar/dialog suites also cover retry, cancellation, stale navigation loads, mount recovery and first-open dialog persistence. These broader builds/browser checks were not repeated for the current remote-restore change.
  • No Firefox/Safari or new browser end-to-end restore run for this change.

Feature Preview

Actual history components with synthetic project data:

Database version history preview

Checklist

  • Documented the restore and synchronization contract.
  • Added regression tests and preserved document-history behavior.
  • Tested across multiple browsers/operating systems.

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @appflowy, your pull request is larger than the review limit of 150,000 diff characters

appflowy and others added 24 commits September 14, 2026 17:07
Preserve Formula selectors and caches while keeping historical previews isolated from live relation, rollup, and member data.
Invalidate relation and rollup caches after restores and rebind mounted dependent observers. Guard stale asynchronous loads and cover repeated restores across relation labels, formulas, filters, and sorts.
…n-history

# Conflicts:
#	src/components/app/hooks/useServerInfo.ts
#	src/components/app/layers/AppAuthLayer.tsx
#	src/components/document/history/DocumentHistoryVersionList.tsx
#	src/proto/messages.d.ts
#	src/proto/messages.js
#	src/proto/notification.proto
- Enable the database history restore permission fence in web CI so the
  backend advertises database history to the e2e suite
- Expect the initial-hydration flag when rediscovering a restored database
- Allow the first feed discussion mount more time on cold CI workers
- Apply lint padding fixes to database test files

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…n-history

# Conflicts:
#	src/application/database-yjs/context.ts
#	src/application/database-yjs/formula/read-context.ts
#	src/application/database-yjs/hooks/useRollupFieldObservers.ts
#	src/application/database-yjs/rollup/cache.ts
#	src/application/database-yjs/selector.ts
A peer restore can remount the in-progress cell editor after the
"Database restored" notice opens. The editor's autofocus takes focus,
and MUI's focus trap returns it to the dialog frame rather than the
acknowledgement button, so Enter no longer dismisses the notice.

Forward focus that lands on the dialog frame to the confirm button.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Drop the separate enable_database_history_version_ui flag. The web
client now enables database history (menu entry, preview and restore)
from enable_database_history alone; a missing flag still means disabled.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Hover controls: until the editor's mousemove handler positions the
strip, it sits invisible at its static position over the first block
and still receives pointer events, swallowing clicks and hovers there
(subpage-creation hover timed out on it). Ignore pointer events until
the handler enables them.

rollup-final-parity: wait for the auto-expanded conditions bar instead
of clicking the filter button when the chip is not yet visible, which
collapsed the bar while it was still expanding.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The database restore barrier gated every collab type: with beforeSend
configured, enqueueOutboxUpdate skipped its synchronous sibling-tab
fan-out and immediate send for documents too, broadcasting only after
the IndexedDB commit. Keystrokes then reached follower tabs in bursts,
and the follower read BroadcastChannel collab messages through
last-value React state, which keeps only the final message of a burst.
Yjs parked every later update behind the lost one, freezing the
follower at a prefix (tab_sync.spec.ts failed on 7 of 14 PR runs vs 0
of 39 on main).

- Apply the restore barrier only to Database and DatabaseRow updates.
- Deliver every BroadcastChannel collab message to the per-object
  incoming queue in arrival order instead of through last-value state.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
* fix: report web bundle version to server-info

* fix: set web client fallback version to 0.18.6
@appflowy
appflowy merged commit d6cfd27 into main Sep 28, 2026
18 of 19 checks passed
@appflowy
appflowy deleted the codex/database-version-history branch September 28, 2026 09:29
appflowy added a commit that referenced this pull request Sep 28, 2026
Resolve conflicts with database version history (#549) and formula
editor placement (#588). Chart row observers are skipped for history
snapshots so the bounded history row store is not pinned.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant