Skip to content

ux.unbounded async flag

github-actions[bot] edited this page Sep 6, 2026 · 2 revisions

ux.unbounded-async-flag

Rule ID: ux.unbounded-async-flag Severity: ERROR Category: ux Target Standards: Mental Model Continuity & Deadlock Prevention, Nielsen Heuristic #1: Visibility of System Status, ISO 9241-110 Ergonomics of Human-System Interaction (Error Tolerance)


1. Overview & Core Invariant

Detects async handlers setting loading flags without guaranteed reset in finally/catch exit paths

Core Invariant:

"Async operations setting loading state before 'await' must guarantee state reset in all exit paths or a 'finally' block."


2. Technical Grounding & Engine Realities

When asynchronous functions activate loading state (e.g. 'setLoading(true)') before awaiting a network operation and fail to ensure that the flag is reset in a 'finally' block or error handler, any unexpected rejection (500 internal server error, timeout, network dropout) leaves the UI permanently frozen in a loading spinner.

Users can neither re-try the action nor interact with adjacent controls, creating an unrecoverable dead end.


3. Vulnerability & Risk Taxonomy

Risk Vector Severity Impact
Permanent UI Lockup & Infinite Spinner Deadlock HIGH Failed API requests leave spinners active indefinitely, blocking subsequent interactions and forcing users to hard-refresh.
Silent Failure Masking HIGH Users believe an operation is still in flight even after the underlying request failed and aborted.

4. Non-Compliant Code Patterns (Bad Examples)

TSX (Loading state activated before await without reset in catch/finally block):

<button
  onClick={async () => {
    setLoading(true);
    try {
      await api.fetchUsers();
    } catch (err) {
      console.error(err);
      // setLoading(false) terlupakan! Spinner berputar selamanya saat API gagal.
    }
  }}
>
  Muat Data
</button>

5. Compliant Implementation Patterns (Good Examples)

TSX (Guaranteed loading reset in finally block ensuring UI unlock under all outcomes):

<button
  onClick={async () => {
    setLoading(true);
    try {
      await api.fetchUsers();
    } finally {
      setLoading(false);
    }
  }}
>
  Muat Data
</button>

6. Detection & Verification Pipeline (How The Rule Evaluates Code)

This rule evaluates source code through the standard AST inspection pipeline:

flowchart TD
    Node["AST Node (Astro / TSX element)"] --> Inspect["1. Inspect Element & Attributes"]
    Inspect --> Invariant{"2. Evaluate Rule Invariant"}
    Invariant -- "Compliant" --> Safe["Pass"]
    Invariant -- "Non-Compliant" --> IgnoreCheck{"3. Check charites:ignore directive"}
    IgnoreCheck -- "Ignored" --> Safe
    IgnoreCheck -- "Not Ignored" --> Diag["4. Emit Diagnostic: ux.unbounded-async-flag"]
Loading

Step-by-Step Evaluation:

  1. AST Traversal: Visits normalized ir.Node structures during AST streaming.
  2. Invariant Check: Compares node attributes against rule invariants.
  3. Directive Suppression Check: Honors inline charites:ignore ux.unbounded-async-flag directives.
  4. Diagnostic Emission: Emits compiler-grade diagnostic on invariant violation.

7. Verification & Test Harness (How The Test Works: 1-SSOT Tri-Corpus)

This rule is rigorously tested and validated across the canonical 1-SSOT Tri-Corpus in tests/correctness/ux.unbounded-async-flag/:

flowchart TD
    subgraph GoldenCorpus ["1-SSOT Tri-Corpus Test Matrix for ux.unbounded-async-flag"]
        subgraph P ["Positive Corpus (tests/correctness/ux.unbounded-async-flag/positive/)"]
            P1["P1: Obvious Direct Violation"]
            P2["P2: Indirect / Variant Concatenation"]
            P3["P3: Helper / clsx / cn Wrapper"]
            P4["P4: Deeply Nested Elements"]
            P5["P5: Aliased Imports / Re-exports"]
        end
        subgraph N ["Negative Corpus (tests/correctness/ux.unbounded-async-flag/negative/)"]
            N1["N1: Valid Design Tokens"]
            N2["N2: Explicit charites:ignore Directive"]
            N3["N3: Third-Party / Vendor Components"]
            N4["N4: Clean Semantic HTML"]
            N5["N5: Untokenized Custom Values (Banana Test)"]
        end
        subgraph A ["Adversarial Corpus (tests/correctness/ux.unbounded-async-flag/adversarial/)"]
            A1["A1: Template Literal Interpolations"]
            A2["A2: Ternary Conditional Expressions"]
            A3["A3: Spread Properties & Dynamic Overrides"]
            A4["A4: Dynamic Object Class Syntax"]
            A5["A5: Shadowed Variable Identifiers"]
            A6["A6: Nested Closures & HOC Wrappers"]
            A7["A7: Obfuscated Classes & Cyclic Tokens"]
        end
    end

    P --> TestRunner["Automated Runner (rule_test.go)"]
    N --> TestRunner
    A --> TestRunner
    TestRunner --> Gates["Quality Gates: Zero Panic, Zero False-Positive, Zero Bypass"]
Loading
  • Positive Fixtures (P1-P5): Verified to trigger diagnostics at exact lines and column spans.
  • Negative Fixtures (N1-N5): Verified to produce zero diagnostics on valid tokens and legitimate exemptions.
  • Adversarial Fixtures (A1-A7): Verified to prevent evasion across dynamic expressions, string interpolations, and cyclic references.

8. How to Suppress (Ignore Directives)

If this pattern is required for an intentional exception, suppress the diagnostic using the canonical Charites Rule ID:

<!-- charites:ignore ux.unbounded-async-flag intentional exception -->
// charites:ignore ux.unbounded-async-flag intentional exception

9. Configuration Reference (charites.yaml)

rules:
  ux.unbounded-async-flag:
    severity: error # error | warn | info | off

Rule Categories

A11y (16 rules)
Browser (12 rules)
Cls (16 rules)
Design (1 rules)
Ergonomy (5 rules)
Inp (16 rules)
Lcp (16 rules)
Mobile (5 rules)
Performance (16 rules)
Pwa (10 rules)
Responsive (18 rules)
Semantic (1 rules)
Theme (32 rules)
Ux (20 rules)

Clone this wiki locally