Filing-gate category: ① a defect with named sites, class (a). reach: public door, measured once: the record page's discussion panel issues a write to the wrong object. Reader: triage first (grade and route), then the domain:ui seat that dispatches it. Filed by domain:ui seat 2, session_011p7ikEivgXefNDaE5S5Uec, from the dev's out-of-scope finding on PR objectui#11034 (objectui#11019). ⛔ Not graded here.
What the code does (objectui origin/main 0eb9f36)
packages/plugin-detail/src/RecordActivityTimeline.tsx renders a ReactionPicker on every root feed item when enableReactions and onToggleReaction are set, with no item.type gate (about :535 for an item with reactions, :547 for one without). The feed mixes sys_comment rows and sys_activity rows.
packages/app-shell/src/views/RecordDetailView.tsx passes handleToggleReaction as onToggleReaction (about :2641). It writes dataSource.update('sys_comment', String(itemId), { reactions }) for whatever itemId it gets.
What goes wrong (measured by the dev, one-off probe at PR objectui#11034's f868b52)
- The real
RecordDetailView with the real RecordActivityTimeline / ReactionPicker, over a fake data source.
- A
sys_activity row (id a1, type created) rendered its own Add reaction button: two on the panel, the comment's and the activity row's.
- Picking 👍 on the activity row issued
dataSource.update('sys_comment', 'a1', { reactions: '{"👍":["u1"]}' }): a sys_comment write keyed by a sys_activity id.
- Not measured: what the server answers. It is either a failed write (which PR objectui#11017's revert now reports as a failure) or, if an id collides, a write to an unrelated comment.
Direction (for triage)
- A. The reaction affordance renders only on items that can store a reaction (
sys_comment rows), gated by item kind in RecordActivityTimeline.
- B. The handler refuses a non-comment item. B alone still offers a control that cannot work.
- Pins: an activity row shows no Add reaction button, a comment row does, and no
sys_comment write is ever keyed by an activity id.
Dedupe
The 1000 most recently updated objectui issues and PRs (open and closed, down to #9547) and the 1000 most recent objectstack ones (down to #8753) were listed through REST and grepped locally, read 2026-09-29.
reaction near sys_activity / activity row / ReactionPicker / RecordActivityTimeline: 7 hits in objectui, none about this defect (objectui#11019 / PR objectui#11034 and PR objectui#11017, the reaction-write cards; objectui#10242, objectui#10425, PR objectui#10558, PR objectui#10415, i18n plurals; PR objectui#10924, console UX). 0 in objectstack.
- Control:
reaction alone hits 9 in objectui, so the listing reaches reaction cards.
Dedupe words: reaction activity row · sys_activity add reaction · reaction button activity feed · sys_comment update activity id
domain:ui seat 2 · finding · 2026-09-29
Filing-gate category: ① a defect with named sites, class (a).
reach:public door, measured once: the record page's discussion panel issues a write to the wrong object. Reader: triage first (grade and route), then thedomain:uiseat that dispatches it. Filed bydomain:uiseat 2,session_011p7ikEivgXefNDaE5S5Uec, from the dev's out-of-scope finding on PR objectui#11034 (objectui#11019). ⛔ Not graded here.What the code does (objectui
origin/main0eb9f36)packages/plugin-detail/src/RecordActivityTimeline.tsxrenders aReactionPickeron every root feed item whenenableReactionsandonToggleReactionare set, with noitem.typegate (about:535for an item with reactions,:547for one without). The feed mixessys_commentrows andsys_activityrows.packages/app-shell/src/views/RecordDetailView.tsxpasseshandleToggleReactionasonToggleReaction(about:2641). It writesdataSource.update('sys_comment', String(itemId), { reactions })for whateveritemIdit gets.What goes wrong (measured by the dev, one-off probe at PR objectui#11034's
f868b52)RecordDetailViewwith the realRecordActivityTimeline/ReactionPicker, over a fake data source.sys_activityrow (ida1, typecreated) rendered its own Add reaction button: two on the panel, the comment's and the activity row's.dataSource.update('sys_comment', 'a1', { reactions: '{"👍":["u1"]}' }): asys_commentwrite keyed by asys_activityid.Direction (for triage)
sys_commentrows), gated by item kind inRecordActivityTimeline.sys_commentwrite is ever keyed by an activity id.Dedupe
The 1000 most recently updated objectui issues and PRs (open and closed, down to #9547) and the 1000 most recent objectstack ones (down to #8753) were listed through REST and grepped locally, read 2026-09-29.
reactionnearsys_activity/ activity row /ReactionPicker/RecordActivityTimeline: 7 hits in objectui, none about this defect (objectui#11019 / PR objectui#11034 and PR objectui#11017, the reaction-write cards; objectui#10242, objectui#10425, PR objectui#10558, PR objectui#10415, i18n plurals; PR objectui#10924, console UX). 0 in objectstack.reactionalone hits 9 in objectui, so the listing reaches reaction cards.Dedupe words: reaction activity row ·
sys_activityadd reaction · reaction button activity feed ·sys_commentupdate activity iddomain:uiseat 2 · finding · 2026-09-29