Skip to content

fix(app-shell): derive the condition editor's subject vocabulary per metadata type (objectui#9953) - #10023

Merged
os-tesla merged 1 commit into
mainfrom
claude/issue-9953-condition-widget-context-derivation
Sep 19, 2026
Merged

os-tesla merged 1 commit into
mainfrom
claude/issue-9953-condition-widget-context-derivation

Conversation

@os-tesla

Copy link
Copy Markdown
Collaborator

Fixes #9953

What this changes

CONDITION_SCOPE_BY_METADATA_TYPE rules action, hook and validation all 'record', and each
verdict is right — every one of those evaluators binds the row as the record root. But that table
answers how a predicate is linted, not what its host binds, and on that second question the
three disagree. The generic ConditionWidget mount is polymorphic over all of them, so it took the
default subject vocabulary — record.id plus user.id / user.email / user.role /
user.isAdmin — for every type.

conditionSubjectsForMetadataType, the sibling of conditionScopeForMetadataType, now derives that
vocabulary from the type on screen, over a table of which host evaluates each type's condition.
Server-evaluated types get the narrowed list the two curated inspectors already declare
(RECORD_CONDITION_SUBJECTS); the client-evaluated tier keeps the default; a type with no measured
host declares nothing and is byte-for-byte unchanged. ⛔ Not a third copy of the one-line declaration
objectui#9949 gave the curated mounts.

⭐ Reachability — the card's first deliverable, measured

The card and its triage both left open whether a server-evaluated condition reaches this generic
mount today. It does. hook has a registered default inspector (HookDefaultInspector, which
hides condition from its own fallback form) but no registered preview — and in
ResourceEditPage the inspector panel that would host it exists only inside the
PreviewComponent ? branch
. With no preview the page takes its plain branch: the whole-draft
SchemaForm carrying the derived WidgetContext, where condition routes to ConditionWidget by
name convention with conditionScope: 'record' and the default user.* dropdown.

The measurement is not recorded in prose — the first case in the new file mounts the real host and
re-takes it on every run, so it reddens if that route ever changes.

Binding sets, re-derived at source (read-only) in objectstack

metadata type host what it binds the expression read
hook server record, previous wrapDeclarativeHook's pre-compiled condition: ExpressionEngine.evaluate(expr, { record: record ?? {}, previous }), throwing when the result is not ok
validation server record, previous checkPredicate (a rule's condition) and checkConditional (its when), both evaluating against { record, previous } and returning unevaluableRuleError otherwise — the log line's own words are "rejected, not skipped"
action client row plus user buildExpressionScope (ExpressionProvider) returning a bag carrying user, current_user, ctx, os and features; the row arrives via usePredicateRecordContext

user.* is a working subject on the client tier and an unbound one on the server tiers. That is
why this is a per-type derivation and not one declaration.

Tests

New: ConditionWidget.conditionSubjects.test.tsx — the reachability case at the real host, the
narrowing gate (derived from RECORD_CONDITION_ROOTS, never from a copy of the narrowed list), the
must-not-break client-tier case, and three pins on the derivation including one that requires a
measured host for every type the scope table rules 'record'.

pnpm exec vitest run   ConditionWidget.conditionSubjects.test.tsx
                       ConditionWidget.conditionScope.test.tsx
                       ResourceEditPage.conditionScope.test.tsx
                       inspectors/ConditionBuilder.contextSubjects.test.tsx
  → Test Files  4 passed (4) · Tests  27 passed (27)

Control reading (ablation, on the committed fix, restore proven)

Deleting the single forwarding line in ConditionWidget and re-running:

anchor "          subjects={conditionSubjects ? { context: conditionSubjects } : undefined}" x1 -> x0
blob   ddf6946ec249 -> 6223b7916c3c          (mutation proven on disk, not by an exit code)

FAIL  ConditionWidget.conditionSubjects.test.tsx > ... > offers no subject whose root the server
      host leaves unbound
      AssertionError: expected [ 'user.id', 'user.email', 'user.role', 'user.isAdmin' ] to deeply equal []

Test Files  1 failed | 1 passed (2) · Tests  1 failed | 17 passed (18)

restore: blob == HEAD (ddf6946ec249) · `git diff HEAD` empty

Two readings in that one run: the new gate reddens against today's behaviour and names the exact
subjects an author is offered at a hook mount — and ConditionWidget.conditionScope.test.tsx stays
green through the ablation, which is the reading that says the existing pins were blind to this
door.

No build was needed for the ablation: every import under test is an intra-package relative specifier
resolved from source by vitest, so nothing here reads a package exports entry or a dist/ artifact.

Acceptance notes

  • ⛔ Nothing in objectstack was changed. That repository was read only, to derive the binding sets
    above.
  • Not repaired here, reported instead (class c): EmbeddedItemEditor renders its SchemaForm
    with no widgetContext at all, and the __object_validation anchor's editAs: 'validation'
    is what opens it — so an object's embedded validation rule's condition is authored with no lint
    scope (falling through to celAuthoring's hint.scope ?? 'flattened' default, which lints the
    retired bare shorthand clean) and with the full user.* dropdown, against a server rule validator
    that binds record / previous and is fail-closed. conditionScope.ts names that repair as this
    table's successor in its own words. It is a separate card: giving that editor a WidgetContext
    moves every embedded child — field and index as well as validation — and neither of those
    tiers has a reading behind it.
  • Noted, not filed: a flattened-scoped generic mount still receives ConditionBuilder's default
    fieldPrefix of 'record.', so its row builder compiles record.FIELD subjects at a tier whose
    scope claims bare field names. ⛔ Not measured whether any such type reaches the generic form with
    a condition-named field today, so it is not filed as a defect. Carrier: the next change to the
    flattened tiers' generic mount.
  • The validation row of the scope table still has no legitimate live host through
    ResourceEditPage — but if one ever arrives it now lands on the derivation rather than on the
    default vocabulary.

Generated by Claude Code

…metadata type

The generic `ConditionWidget` mount is polymorphic over every metadata type, so it
took the default subject vocabulary — `record.id` plus `user.*` — for all of them.
`CONDITION_SCOPE_BY_METADATA_TYPE` cannot separate them: it rules `action`, `hook`
and `validation` all `record`, which is a claim about how a predicate is LINTED and
not about what its host BINDS. A hook's condition and a validation rule's guard are
evaluated on the server against `record` and `previous` alone; an action's `visible`
is evaluated in the browser, where `user` is bound.

Measured: `hook` has a registered default inspector but no registered preview, so
`ResourceEditPage` renders its plain whole-draft form and the curated
`HookDefaultInspector` — which hides `condition` from its own fallback — never runs.
So a server-evaluated condition does reach the generic mount today.

`conditionSubjectsForMetadataType`, the sibling of `conditionScopeForMetadataType`,
derives the vocabulary from the type on screen over a table of which host evaluates
each type's condition. Server-evaluated types get the list the two curated
inspectors already declare; the client-evaluated tier keeps the default, because
narrowing it would take a working subject away. A type with no measured host
declares nothing and is unchanged.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018HrVaotisyhgmot9o2MLRq
@github-actions

Copy link
Copy Markdown
Contributor

changeset-claim-re-read

⚠️ 4 pending changeset(s) describe a file this change touches

Their bodies publish verbatim into the CHANGELOG at the next release, so this is a request to re-read them against your diff — addressed here because you are the one seat that can answer it without re-deriving anything.

⛔ Nothing here blocks, and nothing here is a verdict on your change. This gate exits 0, is not a required context, and judges name resolution, never meaning: it asked whether a pending body names a file you touched. "Is this sentence still true?" is the one question it will not answer, and the one you are being asked to answer.

.changeset/7125-dashboard-empty-state-keys-retired.md

  • names widgets.tsxpackages/app-shell/src/views/metadata-admin/widgets.tsx — edited by this change

    Not touched: table.noRows ('No rows to display') and engine.form.noRows (packages/app-shell/src/views/metadata-admin/i18n.ts, read at widgets.tsx) — two different, same-named keys in different namespaces. Nor the comments in WidgetEmptyState.tsx, DatasetWidget.tsx, ObjectDataTable.tsx and PivotTable.tsx that record WHY three widgets with three strings became one shared empty state; the packs' own comment keeps that rationale and now names the retirement instead of a row that is gone.

.changeset/8218-studio-property-panel-de-developerize.md

  • names widgets.tsxpackages/app-shell/src/views/metadata-admin/widgets.tsx — edited by this change

    SchemaForm + widgets.tsx were written for an administrator editing metadata. Studio's interface panel renders the very same form for someone who has never seen a JSON Schema, so four developer habits landed inside an otherwise fully Chinese surface. Same cause, one pass:

.changeset/9952-condition-placeholder-derives-from-offered-roots.md

  • names conditionScope.tspackages/app-shell/src/views/metadata-admin/conditionScope.ts — edited by this change

    The placeholder was a string literal — record.status != 'done' && user.isAdmin — handed to CelPredicateField at every mount, scope or no scope. The same component had already narrowed a record-scoped mount's autocomplete to RECORD_CONDITION_ROOTS (objectui#9645), which carries no user, and narrowed that mount's subject dropdown the same way (objectui#9855). At such a mount user is not merely unadvertised: conditionScope.ts states that a hook condition and a validation rule's guard are evaluated with { record, previous } and only those, fail-CLOSED at the validation host, and objectstack's wrapDeclarativeHook docblock says the condition formula is evaluated against two bindings, record and previous. So the one line an author reads before typing anything taught a root the evaluator never binds, and copying it cost the author the write.

.changeset/formfieldspec-dependson-5040.md

  • names widgets.tsxpackages/app-shell/src/views/metadata-admin/widgets.tsx — edited by this change

    FormFieldSpec — the authoring type for a metadata-admin form layout, the element type of FormSectionSpec.fields[] — did not declare dependsOn. widgets.tsx held a second, inline description of the same object as WidgetProps.fieldSpec, and that one did, because two registered widgets read it as their primary configuration: field-selector resolves dependsOn || reference || 'objectName' to decide whose field catalog to offer, and dynamic-config uses it to pick a sub-schema out of WidgetContext.dynamicSchemas. One value travelling down one channel, described twice, disagreeing on the one key that decides what those widgets show — so

Read the paragraph, not the line: both false halves of the objectui#8617 claim sat in one paragraph, and correcting either alone would have left it asserting the same wrong thing.

If a claim did go false, correct the body. That is precedented and prose-only, frontmatter untouched; check-changeset-overwrite.mjs will report the correction as its own case 2 ("correcting a declaration on purpose … legitimate"), which is the intended shape — one gate asks for the read, the other records the write.

Not covered, stated so nobody reads this as more: a born-false claim that spells no line address at all (objectui#9495 coordinated one by ORDINAL — "a grep finds that member first" — and deciding that means reading what the sentence means), a claim spelled as a symbol or a package rather than a backticked file name, and a file named ambiguously.

Compared the checked-out tree with 4dbab84d4 (merge-base with origin/main): 4 file(s) changed outside .changeset/, read against 1212 pending declaration(s) that publish a body (1771 pending in total). · run

@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

Metric Value Budget
Eager closure (gzip, 329 chunks) 3056.5 KB 3104.5 KB
Main entry chunk (gzip) 145.7 KB 350 KB
Entry file index-ClsxCmC3.js
Status PASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

Package Size Gzipped
app-shell (consoleActionDispatch.js) 0.20KB 0.19KB
app-shell (index.js) 16.69KB 6.21KB
app-shell (runtime-config.js) 20.68KB 7.36KB
app-shell (types.js) 0.01KB 0.04KB
app-shell (urlParams.js) 10.06KB 3.86KB
auth (ActiveOrganizationStorage.js) 25.05KB 9.16KB
auth (AuthContext.js) 0.31KB 0.24KB
auth (AuthGuard.js) 2.07KB 1.00KB
auth (AuthProvider.js) 40.18KB 10.59KB
auth (AuthShell.js) 3.49KB 1.40KB
auth (ForgotPasswordForm.js) 12.21KB 3.45KB
auth (LoginForm.js) 18.15KB 5.39KB
auth (PreviewBanner.js) 0.90KB 0.50KB
auth (RegisterForm.js) 6.65KB 2.22KB
auth (SocialSignInButtons.js) 9.61KB 3.89KB
auth (UserMenu.js) 3.41KB 1.23KB
auth (auth-gate-events.js) 1.29KB 0.66KB
auth (authStyles.js) 5.04KB 1.72KB
auth (createAuthClient.js) 40.21KB 10.80KB
auth (createAuthenticatedFetch.js) 8.46KB 3.43KB
auth (index.js) 3.19KB 1.44KB
auth (invitation-status.js) 1.22KB 0.70KB
auth (org-roles.js) 6.66KB 2.78KB
auth (phone-identifier.js) 1.11KB 0.66KB
auth (types.js) 0.59KB 0.35KB
auth (useAuth.js) 5.30KB 1.02KB
auth (useWorkspaceAdminStatus.js) 11.08KB 4.58KB
collaboration (CommentThread.js) 26.08KB 7.56KB
collaboration (LiveCursors.js) 3.17KB 1.27KB
collaboration (PresenceAvatars.js) 6.49KB 2.64KB
collaboration (PresenceProvider.js) 2.79KB 1.13KB
collaboration (index.js) 1.68KB 0.73KB
collaboration (useCollaborationTranslation.js) 6.05KB 2.52KB
collaboration (useCommentSearch.js) 1.98KB 0.88KB
collaboration (useConflictResolution.js) 7.75KB 1.86KB
collaboration (useMentionNotifications.js) 1.81KB 0.68KB
collaboration (usePresence.js) 6.33KB 1.84KB
collaboration (useRealtimeSubscription.js) 7.91KB 2.01KB
components (index.js) 545.92KB 130.72KB
core (index.js) 8.94KB 3.59KB
create-plugin (index.js) 27.94KB 9.51KB
data-objectstack (index.js) 216.90KB 60.15KB
fields (index.js) 249.62KB 63.02KB
i18n (LocalizationContext.js) 1.76KB 0.96KB
i18n (builtinAggregateLabels.js) 0.86KB 0.49KB
i18n (currency.js) 1.22KB 0.64KB
i18n (fallbackInterpolation.js) 6.25KB 2.77KB
i18n (i18n.js) 8.87KB 3.64KB
i18n (index.js) 5.22KB 2.26KB
i18n (pickLocalized.js) 9.86KB 3.95KB
i18n (provider.js) 32.15KB 10.49KB
i18n (useDisplayLocale.js) 2.85KB 1.45KB
i18n (useObjectLabel.js) 34.34KB 9.17KB
i18n (useSafeTranslation.js) 5.60KB 2.33KB
layout (index.js) 38.83KB 10.95KB
mobile (MobileProvider.js) 0.92KB 0.49KB
mobile (ResponsiveContainer.js) 0.94KB 0.38KB
mobile (breakpoints.js) 1.51KB 0.70KB
mobile (createOfflineDataSource.js) 5.61KB 1.75KB
mobile (index.js) 1.99KB 0.87KB
mobile (offlineQueue.js) 3.91KB 1.35KB
mobile (pwa.js) 0.97KB 0.49KB
mobile (serviceWorker.js) 1.48KB 0.62KB
mobile (serviceWorkerSource.js) 3.41KB 1.48KB
mobile (useBreakpoint.js) 1.54KB 0.65KB
mobile (useGesture.js) 6.96KB 1.98KB
mobile (useOfflineSync.js) 1.99KB 0.72KB
mobile (usePullToRefresh.js) 2.53KB 0.85KB
mobile (useResponsive.js) 0.72KB 0.42KB
mobile (useSpecGesture.js) 5.52KB 2.10KB
mobile (useTouchTarget.js) 1.01KB 0.54KB
permissions (MePermissionsProvider.js) 13.52KB 4.88KB
permissions (PermissionContext.js) 0.31KB 0.25KB
permissions (PermissionGuard.js) 0.89KB 0.45KB
permissions (PermissionProvider.js) 6.24KB 2.16KB
permissions (discardProofCache.js) 1.04KB 0.55KB
permissions (evaluator.js) 8.39KB 3.10KB
permissions (index.js) 0.93KB 0.41KB
permissions (store.js) 0.91KB 0.42KB
permissions (useFieldPermissions.js) 1.28KB 0.53KB
permissions (usePermissions.js) 4.83KB 2.27KB
plugin-ai (index.js) 14.81KB 3.63KB
plugin-calendar (index.js) 49.92KB 14.22KB
plugin-charts (index.js) 71.73KB 20.08KB
plugin-chatbot (index.js) 198.20KB 47.14KB
plugin-dashboard (index.js) 132.96KB 35.17KB
plugin-designer (index.js) 215.94KB 44.33KB
plugin-detail (index.js) 255.18KB 66.49KB
plugin-editor (index.js) 2.23KB 1.05KB
plugin-form (index.js) 139.56KB 35.40KB
plugin-gantt (index.js) 167.62KB 41.26KB
plugin-grid (index.js) 213.44KB 58.21KB
plugin-kanban (index.js) 48.71KB 15.17KB
plugin-list (index.js) 113.55KB 27.99KB
plugin-map (index.js) 21.48KB 6.99KB
plugin-markdown (index.js) 13.88KB 4.80KB
plugin-report (index.js) 43.41KB 11.93KB
plugin-timeline (index.js) 30.68KB 8.95KB
plugin-tree (index.js) 10.58KB 3.72KB
plugin-view (index.js) 85.18KB 21.05KB
providers (DataSourceProvider.js) 0.75KB 0.39KB
providers (MetadataProvider.js) 1.37KB 0.59KB
providers (ThemeProvider.js) 1.90KB 0.85KB
providers (UploadProvider.js) 11.66KB 3.50KB
providers (index.js) 0.45KB 0.23KB
providers (types.js) 0.01KB 0.04KB
react-runtime (index.js) 5.62KB 2.34KB
react (LazyPluginLoader.js) 4.47KB 1.63KB
react (SchemaRenderer.js) 109.04KB 36.08KB
react (data-invalidation.js) 5.05KB 2.08KB
react (index.js) 4.63KB 2.18KB
react (schema-input.js) 4.25KB 2.04KB
react (spec-input.js) 0.20KB 0.18KB
sdui-parser (body-dialect.js) 4.38KB 1.98KB
sdui-parser (codegen.js) 6.58KB 2.74KB
sdui-parser (dashboard-widget-options.js) 3.08KB 1.30KB
sdui-parser (index.js) 5.74KB 2.54KB
sdui-parser (input-type.js) 2.84KB 1.40KB
sdui-parser (kanban-quick-add.js) 3.89KB 1.87KB
sdui-parser (parse.js) 25.28KB 7.80KB
sdui-parser (provenance.js) 3.66KB 1.82KB
sdui-parser (types.js) 0.28KB 0.23KB
sdui-parser (validate.js) 15.71KB 5.30KB
types (ai.js) 4.11KB 2.06KB
types (api-types.js) 0.20KB 0.18KB
types (app.js) 2.87KB 1.00KB
types (base.js) 0.20KB 0.18KB
types (blocks.js) 0.20KB 0.18KB
types (complex.js) 2.93KB 1.49KB
types (crud.js) 0.20KB 0.18KB
types (dashboard-filter-alias.js) 6.23KB 2.74KB
types (data-display.js) 3.75KB 1.85KB
types (data-protocol.js) 0.20KB 0.19KB
types (data.js) 0.20KB 0.18KB
types (designer.js) 1.85KB 0.85KB
types (disclosure.js) 0.20KB 0.18KB
types (error-code.js) 1.54KB 0.88KB
types (expression.js) 0.20KB 0.18KB
types (feedback.js) 0.20KB 0.18KB
types (field-types.js) 0.20KB 0.18KB
types (form.js) 0.20KB 0.18KB
types (http-inflight.js) 8.87KB 3.73KB
types (http-retry.js) 4.32KB 2.02KB
types (icon-key-migration.js) 4.26KB 1.63KB
types (index.js) 4.74KB 2.25KB
types (layout.js) 0.20KB 0.18KB
types (managed-by.js) 0.19KB 0.18KB
types (mobile.js) 4.73KB 2.28KB
types (navigation.js) 0.20KB 0.18KB
types (objectql.js) 0.20KB 0.18KB
types (overlay.js) 0.20KB 0.18KB
types (permissions.js) 0.20KB 0.18KB
types (plugin-scope.js) 0.20KB 0.18KB
types (record-components.js) 0.20KB 0.19KB
types (record-semantics.js) 1.28KB 0.67KB
types (registry.js) 0.20KB 0.18KB
types (reports.js) 0.20KB 0.18KB
types (select-option.js) 0.20KB 0.19KB
types (spec-report.js) 5.05KB 1.93KB
types (spec-ui-namespace.js) 0.20KB 0.19KB
types (strict-authoring-face.js) 14.04KB 5.36KB
types (system-fields.js) 3.33KB 1.54KB
types (theme.js) 6.28KB 2.87KB
types (ui-action.js) 8.11KB 3.32KB
types (views.js) 0.20KB 0.18KB
types (widget.js) 0.20KB 0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

2 participants