#!/usr/bin/env bash

# Every "open the settings for this" jump must land somewhere real.
#
# ShellState.openSettings() validates its argument against an allow-list and
# falls back to Home for anything unknown. That fallback is sensible and it is
# also completely silent: a typo, or a page renamed later, turns a right-click
# into "opens Settings on the wrong page" with nothing logged and no error.
#
# Before this, exactly four places in the entire shell could reach Settings, so
# the risk was small. The bar now offers a jump on every widget, which makes the
# fallback worth guarding.

set -uo pipefail

repo_dir="$(cd "$(dirname "${BASH_SOURCE[0]}")/../.." && pwd)"
shell_state="$repo_dir/config/dot/quickshell/services/ShellState.qml"
modules="$repo_dir/config/dot/quickshell/modules"
dock_menu="$modules/dock/DockContextMenu.qml"
notification_card="$modules/notifications/NotificationCard.qml"
osd="$modules/osd/Osd.qml"

fail() {
    printf 'settings jump contract: %s\n' "$1" >&2
    exit 1
}

allowed_line="$(grep -m1 'const allowed = \[' "$shell_state")" \
    || fail 'could not find the allow-list in ShellState'

jumps="$(grep -rhoE 'openSettings\("[a-z-]+"\)' "$modules" 2>/dev/null \
    | sed 's/openSettings("//; s/")//' | sort -u)"
[[ -n "$jumps" ]] || fail 'found no settings jumps at all -- this contract is not reading the modules correctly'

count=0
while read -r page; do
    [[ -n "$page" ]] || continue
    grep -qF "\"$page\"" <<<"$allowed_line" \
        || fail "a jump opens \"$page\", which ShellState does not allow -- openSettings falls back to Home silently, so this reads as a right-click that goes to the wrong page"
    count=$((count + 1))
done <<<"$jumps"

# The bar is where a person looks first, and Pill has offered a right-click
# signal all along that nothing connected -- so the gesture did nothing on every
# widget in the bar. Anything built on Pill that can be configured should say so.
for widget in Clock WeatherWidget VitalsWidget StatusCluster MediaWidget; do
    file="$modules/bar/$widget.qml"
    [[ -r "$file" ]] || continue
    grep -q 'onSecondaryActivated' "$file" \
        || fail "$widget has no right-click jump; Pill routes right-click to secondaryActivated, so leaving it unconnected makes the gesture silently inert"
done

# These surfaces do not have a bar-style secondary-click signal. Their
# contextual affordances must retain the original interaction and route to the
# setting page that owns the controls.
[[ -r "$dock_menu" ]] || fail 'dock has no contextual menu, so application actions cannot keep a final Dock settings action'
grep -qF 'ShellState.openSettings("desktop")' "$dock_menu" \
    || fail 'dock context menu does not open Desktop settings'
grep -qF 'entry.actions' "$dock_menu" \
    || fail 'dock context menu dropped application actions'
actions_line="$(grep -nF 'entry.actions' "$dock_menu" | head -1 | cut -d: -f1)"
settings_line="$(grep -nF 'Dock settings' "$dock_menu" | head -1 | cut -d: -f1)"
[[ -n "$actions_line" && -n "$settings_line" && "$actions_line" -lt "$settings_line" ]] \
    || fail 'Dock settings is not the final contextual action after application actions'

grep -qF 'Notification settings' "$notification_card" \
    || fail 'notification card has no overflow Settings action'
grep -qF 'ShellState.openSettings("notifications")' "$notification_card" \
    || fail 'notification overflow does not open Notifications settings'
grep -qF 'Popover {' "$notification_card" \
    || fail 'notification Settings action is not contained in an overflow menu'

grep -qF 'acceptedButtons: Qt.RightButton' "$osd" \
    || fail 'OSD does not accept its contextual secondary click'
grep -qF 'ShellState.openSettings("accessibility")' "$osd" \
    || fail 'OSD secondary click does not open Accessibility settings'
grep -qF 'OsdState.hide()' "$osd" \
    || fail 'OSD remains visible after its Settings jump'

printf 'settings jump contract: PASS (%d distinct destinations)\n' "$count"
