Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .changeset/10061-filter-builder-incomplete-range.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@
fix(components): a half-typed `between` range in the filter builder shows itself as
incomplete instead of being dropped with no signal (objectui#10061)

Ruling batch #146 item 5 letter A (objectstack#18012) declares that while one bound of a
Ruling batch #146 item 5 letter A (objectstack `176b03582`) declares that while one bound of a
`between` pair is blank the condition is incomplete — **not emitted, and shown as
incomplete in the UI**. The first half has been true since objectui#5025: every write
path folds the row through the builder's own arity-aware `isFilterValueComplete`, so a
Expand Down
2 changes: 1 addition & 1 deletion .changeset/10062-dataset-filter-between-arm.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@
fix(app-shell): the Studio dataset-filter inspector stores a `between` range as the
spec's `$between`, with both bounds required (objectui#10062)

Executes ruling batch #146 item 5 letter A (objectstack#18012): the `between` arm of the
Executes ruling batch #146 item 5 letter A (objectstack `176b03582`): the `between` arm of the
dataset-filter bridge maps once a both-bounds completeness rule exists, and one does. Until
now a `Between` row in a dataset's or a measure's filter was dropped on every commit —
inertly since objectui#9372, but dropped — so a date range could be drawn in the inspector
Expand Down
23 changes: 23 additions & 0 deletions .changeset/10803-dead-citation-sweep-seventh-batch.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
---
---

Comment-only in `@object-ui/app-shell`, `@object-ui/components`, `@object-ui/core`,
`@object-ui/data-objectstack`, `@object-ui/i18n`, `@object-ui/permissions`,
`@object-ui/plugin-calendar`, `@object-ui/plugin-designer`, `@object-ui/plugin-detail`,
`@object-ui/plugin-form`, `@object-ui/plugin-grid`, `@object-ui/plugin-kanban`,
`@object-ui/plugin-list`, `@object-ui/plugin-tree`, `@object-ui/providers`,
`@object-ui/react` and `@object-ui/types` (two console warnings in `@object-ui/app-shell`
and `@object-ui/plugin-detail` are runtime text, declared separately below): docblocks and
code comments that cited an `objectstack` issue or pull request which answers 404 now cite
the commit in that repository that landed the change, written as objectstack and a
9-character sha (objectui#10803, the seventh batch). Where the sentence already names that
change's live pull request or commit, or dates the ruling it points at, the dead number is
dropped instead, and one sentence cites this repository's own landing commit, because the
fix it names landed here. Comments that named the apiMethods whitelist card as a bare
number now read `objectstack#3391`, and the two that paired it with a second bare number
read `objectstack#3546` for it: a bare number resolves to this repository, where both
numbers are unrelated cards. None of these comment edits moves a claim or changes a code or
type token. No published behaviour changes through them, so this declares no release.

The same repair in the pending changesets that carried these citations is prose-only, and
their frontmatter is byte-identical.
17 changes: 17 additions & 0 deletions .changeset/10803-seventh-batch-runtime-strings.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
---
'@object-ui/app-shell': patch
'@object-ui/plugin-detail': patch
---

fix(app-shell, plugin-detail): the unmapped activity type warnings no longer point at an objectstack issue that answers 404

`@object-ui/app-shell` warns on the console, once per value, when a `sys_activity` row's
`type` maps to no activity item type, and `@object-ui/plugin-detail`'s `[record:activity]`
block does the same when it maps to no feed item type. Both messages said `sys_activity.type` is
author-extensible with a pointer to an objectstack issue that answers 404 beside the
ruling's date. A reader of a console warning has no repository to resolve a commit
against, so the pointer is dropped rather than replaced: both now read "author-extensible
(ruled 2026-08-24)" (objectui#10803).

Nothing else in either message moves, and what renders, and when and how often each
warning fires, are unchanged.
4 changes: 2 additions & 2 deletions .changeset/17147-plugin-disclosure-not-enforced.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,8 +5,8 @@

The marketplace consent panel no longer promises confinement the runtime does not provide.

`PluginDisclosure` introduced a code-bearing package's structured permission set with "On install, this package will be granted:". A list of grants on a security panel is read as a confinement promise — the complement assumed denied — and on this platform it is not. The consented set is persisted (`sys_package_installation.granted_permissions`), re-confirmed on a widening upgrade, and registered on the runtime's `PluginPermissionEnforcer` at load; it is queried by nothing, because `SecurePluginContext` has zero production construction sites and the fs/network gates have no caller at all (measured on objectstack `9bd4344e4`; objectstack#17147).
`PluginDisclosure` introduced a code-bearing package's structured permission set with "On install, this package will be granted:". A list of grants on a security panel is read as a confinement promise — the complement assumed denied — and on this platform it is not. The consented set is persisted (`sys_package_installation.granted_permissions`), re-confirmed on a widening upgrade, and registered on the runtime's `PluginPermissionEnforcer` at load; it is queried by nothing, because `SecurePluginContext` has zero production construction sites and the fs/network gates have no caller at all (measured on objectstack `9bd4344e4`; recorded upstream in objectstack `aaacf1d5c`).

`marketplace.disclosure.grantsIntro` now states a REQUEST — "This package requests:" — and a new `marketplace.disclosure.notEnforced` line beside the list says the set is recorded at install, re-confirmed if a later version asks for more, and not yet a runtime restriction. Both land in all ten locale packs; the `ja` value stays predicate-final so that pack's halfwidth-colon rule still decides it.

The trust-tier badge is deliberately untouched: it is objectstack#11330's half of the same panel.
The trust-tier badge is deliberately untouched: it is the trust-tier half of the same panel, which objectstack `a9ee98992` settled separately.
2 changes: 1 addition & 1 deletion .changeset/3719-settings-valuedomain-combobox.md
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@ exists.
**Undeclared → the closed dropdown is untouched**, which is half the change rather than a
caveat. Those `options` are still exhaustive under objectstack#5131 (the sms/mail provider
selects), and `localization.locale` had its domain declaration deliberately **rejected** in
objectstack#6515 because its options *are* the shipped catalogs. Widening those to free
objectstack `2fdb36eb9` because its options *are* the shipped catalogs. Widening those to free
input would be a regression wearing this fix's clothes, so the two branches are pinned
against each other from the specifier data rather than from a list of key names — a key
that gains a domain server-side joins the right side of the pin with no edit here.
Expand Down
2 changes: 1 addition & 1 deletion .changeset/5896-feeditem-single-constructor.md
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ table (objectui#5878) and then built the `FeedItem` itself, ending in
situations: a type the table maps to `undefined` **on purpose** (`commented` /
`mentioned` / `login` / `logout`), and a type the table has never heard of. The
second is an **author-extended** value — `sys_activity.type` is
author-extensible (objectstack#11507 direction 4, ruled 2026-08-24), every
author-extensible (objectstack `88b9d749a`, direction 4, ruled 2026-08-24), every
column on that table is `readonly` so objectql never validates a write, and
ADR-0052 §5b.2 forwards an author's `activityMilestones[].type` into it
verbatim. So an activity that happened, was written and is queryable had no row
Expand Down
2 changes: 1 addition & 1 deletion .changeset/5987-permset-clone-to-customize.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ The permission matrix already locks a set a code package ships (the artifact
tier: `isArtifactBackedLayer`, the client mirror of the server's
`isArtifactBacked`), and its guidance offered only the pre-ruling remedies —
edit the source artifact and redeploy, a new runtime set, the
`OS_METADATA_WRITABLE` hatch. The ruled path (objectstack#11513, 「同意 第一步
`OS_METADATA_WRITABLE` hatch. The ruled path (objectstack `e170b0ae5`, 「同意 第一步
(创业阶段,Salesforce 式)」: lock the base, clone to customize) was never on the
screen, and the metadata-door refusal a Studio save receives names only the
pre-ruling remedies; the data door's refusal is the one that names the Clone
Expand Down
2 changes: 1 addition & 1 deletion .changeset/6654-retire-preview-mode-consumption.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ Retire the discovery-wire preview mode — the console no longer turns
authentication off because a server said `mode: 'preview'` (objectui#6654).

`@objectstack/spec` retired the `RuntimeMode` value `'preview'` and the whole
`PreviewModeConfig` block (objectstack#11846). This console still read that
`PreviewModeConfig` block (objectstack `0c2334f6c`). This console still read that
surface back off the runtime discovery payload, which is a different layer from
the retired compile-time type — so the consumption could not simply be assumed
dead, and its removal was ruled deliberately (2026-08-29).
Expand Down
2 changes: 1 addition & 1 deletion .changeset/6730-shared-activity-type-bucket.md
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@ a `scheduled` meeting, a `login`, a nightly `system` rollup and an author's
its own icon, label and notification toggle. Following
`UNMAPPED_ACTIVITY_FEED_TYPE`'s precedent, an unrecognised value renders
through it and is named once on `console.warn` rather than being dropped —
`sys_activity.type` is author-extensible (objectstack#11507 direction 4), so
`sys_activity.type` is author-extensible (objectstack `88b9d749a`, direction 4), so
an unmapped value is real activity nobody has ruled on, not a mistake.
- The built-ins that had no honest presentation among the four existing kinds —
`system`, `completed`, `scheduled`, `login`, `logout` — now land in that
Expand Down
2 changes: 1 addition & 1 deletion .changeset/6748-preview-mode-provenance-ratchet.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ Test-only change in `@object-ui/auth`: `auth-spec-parity.test.ts` now watches
`PreviewModeConfig`, the `@objectstack/spec/kernel` symbol that
`packages/auth/README.md:328` claims the preview-mode prop aligns with. Upstream
retired that symbol in source and registered it as `kernel/PreviewModeConfig` in
`RETIRED_DEFS_BY_MAJOR[18]` (objectstack#11846, landed as PR objectstack#12718), so
`RETIRED_DEFS_BY_MAJOR[18]` (landed as PR objectstack#12718), so
it leaves the published set at spec major 18 — it is still exported by the 17.2.0 this
repo resolves, which is why the assertion ships green. It goes red at the spec-18 bump,
the exact moment the README sentence stops being true, which is the signal to correct
Expand Down
2 changes: 1 addition & 1 deletion .changeset/6757-global-search-notifications-renderers.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ Renderers for the `global:search` and `global:notifications` page blocks.
A page that declared either member drew the literal "Component
Placeholder" scaffold: both are first-class `PageComponentType` members that the
2026-08-26 maintainer ruling on objectstack#12183 kept declared once the
readiness read in objectstack#13117 evidenced both data sources shipped, and
readiness read in objectstack `225e7690f` evidenced both data sources shipped, and
the renderer was the remaining half.

Neither block adds a data layer — each is a new mount point on plumbing that was
Expand Down
2 changes: 1 addition & 1 deletion .changeset/7015-text-expression-content-channel.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ Docs only: the expression guides taught `"value": "${...}"` on `type: "text"`
nodes, which the renderer reads back but never evaluates, so the reader saw the
literal `${...}` on screen. All 29 authored occurrences now spell the carriage
`content`, the ruled sole evaluation channel for `text` (objectui#7015,
maintainer ruling 2026-08-31 on objectstack#13670, option 2).
maintainer ruling 2026-08-31, option 2, recorded in objectstack `8c6a7fc0b`).

No package source changed, so this ships nothing — `check-changeset-presence`
independently reports "no changeset is owed" for this diff. The declaration is
Expand Down
2 changes: 1 addition & 1 deletion .changeset/7979-package-form-dialog-envelope-reader.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ The create / edit / view package dialog POSTs and PATCHes `/api/v1/packages` thr
own `apiJson`, which held a fourth copy of the ADR-0112 failure-envelope ladder —
character for character the one `PackagesPage` had before `36fc74629`. It read the
diagnostic `error.message` and stopped, so two things a refusal carries never reached the
author: the producer's marked `error.userMessage` (present since objectstack#9934, emitted
author: the producer's marked `error.userMessage` (present since objectstack `79c46da90`, emitted
by both doors that serve these routes) and `error.code`.

The read now comes from the one shared rule, `readEnvelopeFailureText`
Expand Down
4 changes: 2 additions & 2 deletions .changeset/8137-record-activity-calibration-repoint.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
Re-point the `record:activity.types` member calibration control in
`registry-inputs-spec-parity` from `'Account'` to `''`.
`@objectstack/spec` 17.3.0 made that vocabulary open —
`z.array(z.union([FeedItemType, z.string().min(1)]))`, objectstack#11658
executing the maintainer's 2026-08-24 ruling on objectstack#11507 — so the old
`z.array(z.union([FeedItemType, z.string().min(1)]))`, objectstack `1a6a19c31`
executing the maintainer's 2026-08-24 ruling — so the old
probe now accepts, while `''` is still refused for its CONTENT via `.min(1)`.
Test only; no package is released by this change.
2 changes: 1 addition & 1 deletion .changeset/console-form-marked-refusal-5210.md
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ returning 400 instead of 403 for permission failures, degrading the status
semantics logs, monitoring and API consumers depend on.

The maintainer ruling (2026-08-19) was a producer-side opt-in rather than a
chattier 403 branch, and the platform half shipped as objectstack#9934: a hook
chattier 403 branch, and the platform half shipped as objectstack `79c46da90`: a hook
marks its refusal text with `userMessage` at throw time. This is the consumer
half.

Expand Down
2 changes: 1 addition & 1 deletion .changeset/designer-publish-package-binding.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ The metadata designer states its package on the publish step, not only on the sa

Studio's designer save→publish loop bound the draft to a software package on the
save (`PUT ?mode=draft&package=<id>`) and then sealed it with a publish that named
no package at all. `objectstack#10354` (shipped in `@objectstack/rest` 17.2.0) taught
no package at all. objectstack `9e04c3e35` (shipped in `@objectstack/rest` 17.2.0) taught
`POST /meta/:type/:name/publish` to accept `?package=<id>`, so the second call can now
state the same binding the first one already states.

Expand Down
2 changes: 1 addition & 1 deletion .changeset/normalise-client-error-user-message-5901.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@

Preserve the producer's `userMessage` marking when `normaliseClientError` re-wraps a refusal.

`ApiErrorSchema.userMessage` (objectstack#9934) is the opt-in channel an application author
`ApiErrorSchema.userMessage` (objectstack `79c46da90`) is the opt-in channel an application author
sets at throw time to say "this text is for the end user", and the contract states it
status-agnostic — any refusal status may carry it. Both of the shapes this adapter re-wraps
into typed errors dropped the marking: a hook that refused a write with `VALIDATION_FAILED`
Expand Down
2 changes: 1 addition & 1 deletion .changeset/record-activity-open-vocabulary-fallback.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ queryable and invisible, with only a console warning to say so. It now renders
through a defined fallback presentation (`UNMAPPED_ACTIVITY_FEED_TYPE`, the
generic `system` feed type), still announced once per distinct type.

This follows the maintainer ruling of 2026-08-24 on objectstack#11507,
This follows the maintainer ruling of 2026-08-24 (objectstack `88b9d749a`),
direction 4: `sys_activity.type` is **author-extensible**. Every field on
`sys_activity` is `readonly: true` and objectql's `validateRecord` skips
readonly fields on both write branches, and ADR-0052 §5b.2 forwards an author's
Expand Down
4 changes: 2 additions & 2 deletions .changeset/retire-theme-component-schema-5489.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,8 +15,8 @@ and in neither `PROTOCOL_COMPONENTS` nor `PALETTE_PLACEHOLDER_BLOCKS`
(`packages/components/src/renderers/placeholders.tsx`), so it did not even
resolve to a placeholder — a page declaring one got the registry's "Unknown
component type" panel (OBJUI-001) instead of a theme manager. Declared-but-
unenforced, removed under the maintainer ruling of 2026-08-21 on
objectstack#10485 (option B).
unenforced, removed under the maintainer ruling of 2026-08-21
(option B, executed upstream by objectstack `35ad101bc`).

Removed from the published surface: the `ThemeComponentSchema` type
(`@object-ui/types`), the `ThemeComponentSchema` Zod object
Expand Down
2 changes: 1 addition & 1 deletion .changeset/retire-theme-switcher-preview-5647.md
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ pipeline: `tooltip` → 1), nor in `PROTOCOL_COMPONENTS` /
declares either kind (control: `"type": "form"` → 81) — so a page declaring
one got the registry's "Unknown component type" panel (OBJUI-001), never a
switcher or a preview. Declared-but-unenforced, removed under the 2026-08-21
maintainer ruling (option B) on objectstack#10485, extended to these siblings
maintainer ruling (option B, executed upstream by objectstack `35ad101bc`), extended to these siblings
by inheritance on identical evidence (objectui#5647).

Removed from the published surface: the `ThemeSwitcherSchema` /
Expand Down
2 changes: 1 addition & 1 deletion .changeset/spec-refresh-17-2-0-5668.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,4 +6,4 @@ Refreshes the lockfile so every `@objectstack/*` package resolves at `17.2.0`

**The docs-site and console builds stop pulling a Postgres connection-string parser toward the browser bundle.** `@objectstack/spec@17.1.0` imported `pg-connection-string` at the top level of `dist/index.mjs` with no `browser` export condition, so `apps/site`'s production build failed with `Module not found: Can't resolve 'fs'` on every route that reaches `@object-ui/components` from a client component — red on `main` since 2026-08-22 (objectui#5668). `17.2.0` ships the objectstack#11072 fix: `.`, `./data`, `./system`, `./kernel` and `./cloud` now carry `browser` conditions pointing at schema-free `dist/browser/**` bundles, and the site build is back to `Tasks: 29 successful, 29 total`.

The refresh is lockfile-only — every manifest already declared `^17.0.0`, which admits `17.2.0`, so no dependency range changed. No shipped source moves: the two in-repo adaptations are a drift-guard test and a CI gate, both forced by `17.2.0` retiring the spec's theme module (objectstack#10485) exactly as the objectui#5716 localization predicted — its `Theme`/`ThemeMode`/`ColorPalette` ALLOW entries in `check:spec-symbols` went stale and were deleted, and the parity test now pins the vacancy (the spec re-publishing a theme name is a loud collision) instead of a spec leg that no longer exists.
The refresh is lockfile-only — every manifest already declared `^17.0.0`, which admits `17.2.0`, so no dependency range changed. No shipped source moves: the two in-repo adaptations are a drift-guard test and a CI gate, both forced by `17.2.0` retiring the spec's theme module (objectstack `35ad101bc`) exactly as the objectui#5716 localization predicted — its `Theme`/`ThemeMode`/`ColorPalette` ALLOW entries in `check:spec-symbols` went stale and were deleted, and the parity test now pins the vacancy (the spec re-publishing a theme name is a loud collision) instead of a spec leg that no longer exists.
2 changes: 1 addition & 1 deletion .changeset/theme-clientvalidation-dead-entry-5715.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@

Removed the dead `theme:` entry from `clientValidation.ts`'s `LOADERS` table, which
read `ThemeSchema` off `@objectstack/spec/ui` — a symbol the spec retired upstream
(objectstack#10485 / PR objectstack#10695, which deleted the whole `ui/theme.zod.ts`
(objectstack `35ad101bc`, which deleted the whole `ui/theme.zod.ts`
module). `theme` was never a registered metadata type, so metadata-admin never asked
for it (objectui#5715).

Expand Down
2 changes: 1 addition & 1 deletion .changeset/theme-types-localized-5716.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@
'@object-ui/providers': minor
---

Localize the theme document types: `@object-ui/types` now owns `Theme`, `ThemeMode` and `ColorPalette` (objectui#5716 ruling, 2026-08-23). The spec retired its theme module (objectstack#10485) while ObjectUI retained the theme system, so the types are hand-written from the last-published `@objectstack/spec` 17.1.0 shapes instead of re-exported — a spec dependency refresh past the retirement no longer breaks these packages.
Localize the theme document types: `@object-ui/types` now owns `Theme`, `ThemeMode` and `ColorPalette` (objectui#5716 ruling, 2026-08-23). The spec retired its theme module (objectstack `35ad101bc`) while ObjectUI retained the theme system, so the types are hand-written from the last-published `@objectstack/spec` 17.1.0 shapes instead of re-exported — a spec dependency refresh past the retirement no longer breaks these packages.

Published-name REMOVALS from `@object-ui/types` (zero in-repo readers, deleted under the same ruling's rider):

Expand Down
Loading
Loading