Contributions
Shaping the tools I use every day, one pull request at a time
A hand-picked selection: only the contributions worth reading about, not every merged pull request. Articles about Magento and Adobe Commerce are on the blog.
Coalesce app-event invalidations in the messages inbox — on GitHub
The inbox reloaded its message list on every messages.message.* broadcast, so one mail-poll cycle that ingested 52 messages triggered 52 full reloads, each a stack of decrypting queries straight to Postgres. Added useAppEventCoalesced, a leading-plus-trailing variant of useAppEvent: the first event still refreshes immediately, and the rest of a burst collapses into one trailing call.
Resolve the CRUD mutation guard in published builds — on GitHub
Awilix in CLASSIC mode reads dependency names from the factory’s source, and esbuild renamed a shadowed em parameter to em2, so every published build failed to resolve the guard and silently dropped optimistic locking on CRUD updates and deletes. The factory is now parameterless, and a new check:classic-di-injection CI step inspects the built dist output, since no source-level test can see this class of bug.
Implement history import for the Gmail channel — on GitHub
The import-history endpoint, worker and dialog all shipped, but only the IMAP adapter implemented importHistory, so Gmail users got an HTTP 400 after filling in the form. The Gmail adapter now walks users.messages.list with a cursor of a few hundred bytes regardless of mailbox size, and the hub’s 365-day and 5000-message clamps no longer make a multi-year import impossible.
Classify unexpected CRUD failures with a stable error code — on GitHub
API clients had no way to tell a database error from an application bug without server log access. The generic 500 now carries DATABASE_ERROR, PERSISTENCE_ERROR or INTERNAL_ERROR, the transient-database 503 gains DATABASE_UNAVAILABLE plus a requestId, and SQLSTATE parsing rejects Node error codes such as ECONNREFUSED, with nothing from the raw error leaking into the body.
Cache active webhook subscriptions per tenant — on GitHub
The wildcard outbound-dispatch subscriber ran a decrypting SELECT over webhooks for every event in the system, even for tenants with no webhooks at all, and under write load that query dominated the trace. Subscriptions are now cached per tenant and organization (an empty list counts as a hit), invalidated inline at every webhook write, and secrets and URLs never enter the cache.
Memoize information_schema table probes across requests — on GitHub
DefaultDataEngine and HybridQueryEngine queried information_schema.tables on every call, and both are built fresh per request container, so their instance state never helped. Added a module-scoped bounded TTL memo that keeps positive answers for an hour by default, with env knobs for the TTL and entry cap.
Set a timeout on the Shield rules fetch — on GitHub
Magento\Framework\HTTP\Client\Curl sets no default timeout, so a stalled connection to the rules endpoint blocked fetchRules() indefinitely. That call runs from a cron job in a separate process, and Magento’s schedule lifetime only prunes stale rows after the fact — it never kills the hung worker.
Cache the WAF rules in front of the flag lookup — on GitHub
The plugin injects the WAF eagerly, so every request paid for a point SELECT on the flag table before it could decode the rules — a round trip for a value that only changes when the five-minute cron writes it. Caching in front of that lookup, without reintroducing the cache-only storage the module had deliberately dropped, since cache:flush or a disabled cache type must not leave the WAF ruleless.
Accept option label "0" in EAV Select/Multiselect validation — on GitHub
Select::validateValue and Multiselect::validateBySource used a loose falsy check on the source’s return value, so an option whose label was literally "0" got rejected with “Attribute X does not contain option with Id Y” since PHP treats the string "0" as false. Swapped in a strict === false comparison so only the real “not found” sentinel triggers the error.
Only merged work is listed here, and only the parts worth a comment — the full history, including everything still in review, lives on GitHub.
Claude Code ran without
--printand--include-partial-messages, so the cockpit only showed a reply once the whole block was complete, 17 to 20 seconds into a 300-word answer. Nowcontent_block_deltaframes map toitem.deltaevents on the same item id the final block later completes, and text reaches the screen seven to eight seconds before the block finishes, with no cockpit change needed.