Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 11 additions & 0 deletions .changeset/plugin-dev-provenance-anchors.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
---
'@objectstack/plugin-dev': patch
---

Provenance comments in `@objectstack/plugin-dev` were re-anchored

Comment and docblock lines under `src/` that cited tracker numbers which no
longer resolve on GitHub now cite the commit in this repository's history that
decided the matter, and say in their own words what was decided. Comments
only: no service, boot-log line, warning text, type, export or runtime
behaviour changes.
Original file line number Diff line number Diff line change
Expand Up @@ -50,7 +50,7 @@ import { DevPlugin } from './dev-plugin';
// the next transform that lands in this file.
import '@objectstack/plugin-security';

// [#10036] The state under test is "SecurityPlugin LOADED but its start()
// [commit 7552e0337] The state under test is "SecurityPlugin LOADED but its start()
// bailed", so `@objectstack/plugin-security` is deliberately NOT mocked here —
// the real plugin's real `init()`/`start()` phase split is what constructs the
// state. Every OTHER optional dependency is mocked away for the same reason as
Expand Down
4 changes: 2 additions & 2 deletions packages/plugins/plugin-dev/src/dev-plugin.test.ts
Original file line number Diff line number Diff line change
Expand Up @@ -87,7 +87,7 @@ describe('DevPlugin', () => {

const plugin = new DevPlugin({ seedAdminUser: false });
await plugin.init(ctx);
// [#10036] `start()` too: the "nothing is enforcing security" warning
// [commit 7552e0337] `start()` too: the "nothing is enforcing security" warning
// asserted at the bottom of this test moved to the start phase, because
// `security` — the published service that means enforcement, as opposed
// to the `init()`-registered internals that only mean "plugin loaded" —
Expand Down Expand Up @@ -124,7 +124,7 @@ describe('DevPlugin', () => {
);
expect(securityWarn).toBeDefined();
// …and with the plugin genuinely absent it says so, rather than reporting
// the loaded-but-failed-to-start state (#10036).
// the loaded-but-failed-to-start state (the two told apart since commit 7552e0337).
expect(securityWarn![0]).toContain('SecurityPlugin is not loaded');
});

Expand Down
6 changes: 3 additions & 3 deletions packages/plugins/plugin-dev/src/dev-plugin.ts
Original file line number Diff line number Diff line change
Expand Up @@ -1060,7 +1060,7 @@ export class DevPlugin implements Plugin {
);
}
// Same reasoning, same surface: "nothing is enforcing security" belongs
// next to the banner, not buried in the init log (#10036, #3900).
// next to the banner, not buried in the init log (#3900; commit 7552e0337 moved this check here from init()).
this.warnIfNothingIsEnforcingSecurity(ctx);
ctx.logger.info('');
ctx.logger.info(' API: /api/v1/data/:object');
Expand All @@ -1075,7 +1075,7 @@ export class DevPlugin implements Plugin {
* so the slots stay empty — but silence about unenforced RBAC/RLS/masking
* would be its own kind of fake).
*
* ## Why this asks for `security`, and why it asks in `start()` (#10036)
* ## Why this asks for `security`, and why it asks in `start()` (commit 7552e0337)
*
* This used to probe `security.permissions` / `security.rls` /
* `security.fieldMasker` from `init()`. Both halves of that were wrong, and
Expand All @@ -1094,7 +1094,7 @@ export class DevPlugin implements Plugin {
* internal handles and enforces nothing, so the warning stayed silent in
* the one state where its text is literally true. (The same presence
* signal misled `plugin-hono-server`'s `/auth/me/permissions`, fixed in
* #10035 by this same move — two consumers, two packages, one misread:
* commit c1731d023 by this same move — two consumers, two packages, one misread:
* that is a property of the signal, not of either reader.)
*
* - **Wrong phase.** `security` is registered in `SecurityPlugin.start()`,
Expand Down
Loading