Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
18 changes: 18 additions & 0 deletions .changeset/10803-dead-citation-sweep-eighth-batch.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
---
---

Comment-only in `@object-ui/app-shell`, `@object-ui/components`, `@object-ui/plugin-detail`,
`@object-ui/plugin-form` and `@object-ui/plugin-grid`: docblocks and code comments that cited
an `objectstack` issue or pull request by a bare number, which answers 404 in objectstack and
resolves to an unrelated issue or pull request in this repository, now cite the commit in
that repository that landed the change, written as objectstack and a 9-character sha
(objectui#10803, the eighth batch). One of them sits inside a quotation of an objectstack
source comment; there the commit stands in square brackets in place of the quoted number.
Comments that named objectstack's card for the effective operation set on detail and form
surfaces by its bare number, or qualified with this repository's name, now read
`objectstack#3546`: in this repository that number is an unrelated card. None of these
comment edits moves a claim or changes a code or type token. No published behaviour changes
through them, so this declares no release.

The same repair in the one pending changeset that carried such a citation is prose-only, and
its frontmatter is byte-identical.
2 changes: 1 addition & 1 deletion .changeset/7980-agent-key-envelope-read.md
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@ surface was `packages/app-shell/**` — not as a ruling that it should stay priv

**The console fix this unblocks.** The Integrations page's "Connect an AI agent" section
read `json?.error?.message` and stopped, so a refused key mint dropped two declared
things: the producer's marked `error.userMessage` (the #9934 channel, whose presence *is*
things: the producer's marked `error.userMessage` (the objectstack `79c46da90` channel, whose presence *is*
the marking) and `error.code`. The 5xx band is where that cost most — the producing door
substitutes the generic `Internal server error` into `message` while the mark rides
through untouched, so a marked 500/503 showed the developer the generic sentence and
Expand Down
4 changes: 2 additions & 2 deletions packages/app-shell/src/index.ts
Original file line number Diff line number Diff line change
Expand Up @@ -113,8 +113,8 @@ export type { DeclaredHomeApp } from './utils/index.js';
// consumer OUTSIDE this package inherits the pinned rule instead of writing a
// fourth reading of the same body. `apps/console`'s agent-key generator read
// `error.message` and stopped, so a producer-marked `error.userMessage` (the
// #9934 channel, which rides through the 5xx prose withhold untouched) and the
// declared `error.code` never reached the developer.
// objectstack `79c46da90` channel, which rides through the 5xx prose withhold
// untouched) and the declared `error.code` never reached the developer.
//
// The card behind `36fc74629` left this off the public entry as SCOPE RESTRAINT —
// that card's file surface was `packages/app-shell/**` — not as a ruling that the
Expand Down
5 changes: 3 additions & 2 deletions packages/app-shell/src/utils/apiErrorEnvelope.ts
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@
* `Internal server error` into it (see below), so it is the text that can be
* withheld.
* - `userMessage` — the text a producer marked, AT THROW TIME, as addressed to
* the END USER (#9934). Its presence IS the marking, and the envelope
* the END USER (objectstack `79c46da90`). Its presence IS the marking, and the envelope
* writer's own words are the rule this module implements: "a consumer that
* sees the field renders it verbatim and keeps its generic substitution
* (#3821) for everything unmarked".
Expand All @@ -39,7 +39,8 @@
* `...(thrown.userMessage !== undefined ? { userMessage: thrown.userMessage } : {})`
* - `errorFromThrown` (`@objectstack/runtime` `http-dispatcher.ts`), which that
* same door's note calls "byte for byte the dispatcher twin's expression …
* which serves this same path and has emitted the channel since #9934".
* which serves this same path and has emitted the channel since
* [objectstack `79c46da90`]".
*
* The framework pins the pair wire-side in `package-door-user-message.test.ts`.
*
Expand Down
4 changes: 2 additions & 2 deletions packages/app-shell/src/views/RecordDetailView.tsx
Original file line number Diff line number Diff line change
Expand Up @@ -213,7 +213,7 @@ function mergeFeedRows(prev: readonly FeedItem[], incoming: readonly FeedItem[])
* object — the primary `sys_edit` CTA (which also gates the record-body
* inline-edit session) and the `sys_delete` overflow item.
*
* [#3546] Each bit is the object's resolved CRUD affordance (lifecycle bucket +
* [objectstack#3546] Each bit is the object's resolved CRUD affordance (lifecycle bucket +
* `userActions`) INTERSECTED with the server-resolved effective API operation
* set (`/me/permissions` `apiOperations`) — never a union. So a server grant can
* never re-open an affordance the object's bucket closed, and a permissive
Expand Down Expand Up @@ -1190,7 +1190,7 @@ export function RecordDetailView({ dataSource, objects, onEdit, objectNameOverri
// standalone embed) the gate stays open — fail-open is safe because the
// server enforces data access regardless; this is purely a UI/DX filter.
const { can: canOnObject, isLoaded: permissionsLoaded, getObjectApiOperations, systemPermissions } = perms;
// [#3546] Server-resolved effective API operation set for this object
// [objectstack#3546] Server-resolved effective API operation set for this object
// (`/me/permissions` `apiOperations`). Threaded as the 2nd arg into
// `resolveRecordHeaderActionGates` for the detail header's Edit/Delete and
// the record-body inline-edit gate, so the detail surface never offers an
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -334,7 +334,7 @@ export function RelatedRecordActionsBridge({
resolve: ({ objectName, relationshipField, parentId }) => {
const childDef = objects.find((o: any) => o?.name === objectName);
if (!childDef || !base) return {} as RelatedRecordHandlers;
// [#3546] Intersect the child object's bucket affordances with the
// [objectstack#3546] Intersect the child object's bucket affordances with the
// server-resolved effective API operation set for THAT child
// (`/me/permissions` `apiOperations`), so a related list never offers
// Create/Edit/Delete on the child the server would 405. `undefined`
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -65,7 +65,7 @@ export interface PackageSaveResult {

/**
* Was this envelope's prose MARKED, i.e. did the producer address it to the end
* user (`error.userMessage`, #9934) rather than to whoever is debugging?
* user (`error.userMessage`, objectstack `79c46da90`) rather than to whoever is debugging?
*
* ⚠️ Why this is read separately instead of taken from
* {@link readEnvelopeFailureText}: that reader answers *what prose to show* and
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -408,9 +408,9 @@ function PackageSwitcher({
* ⭐ `userMessage` OUTRANKS `message`, and the order is the contract's,
* not a preference (objectui#7938).
*
* `error.userMessage` is the producer's #9934 channel, and the envelope
* writer's own words are the rule this line implements: "the text a
* producer marked, AT THROW TIME, as addressed to the END USER.
* `error.userMessage` is the producer's channel (objectstack `79c46da90`),
* and the envelope writer's own words are the rule this line implements:
* "the text a producer marked, AT THROW TIME, as addressed to the END USER.
* Presence IS the marking — a consumer that sees the field renders it
* verbatim and keeps its generic substitution for everything unmarked"
* (`sendError`, `@objectstack/types` `response-envelope.ts`). This
Expand Down
4 changes: 2 additions & 2 deletions packages/app-shell/src/views/studio-design/packages-io.ts
Original file line number Diff line number Diff line change
Expand Up @@ -223,8 +223,8 @@ export async function duplicatePackage(sourceId: string, targetId: string, targe
// Read by the SAME rule as `fetchPackages` above, and not by a second
// hand-rolled ladder: this arm read `error.message` alone, so a
// producer-marked `error.userMessage` — which the dispatcher door serving
// this very route has emitted since #9934 — had nowhere to appear, and
// `error.code` was dropped too. One definition of the rule, in
// this very route has emitted since objectstack `79c46da90` — had nowhere
// to appear, and `error.code` was dropped too. One definition of the rule, in
// {@link readEnvelopeFailureText}; leaving a copy of it a hundred lines
// below the import is exactly the drift this extraction exists to stop.
throw new Error(readEnvelopeFailureText(payload) ?? `HTTP ${res.status}`);
Expand Down
4 changes: 2 additions & 2 deletions packages/components/src/renderers/layout/containers.tsx
Original file line number Diff line number Diff line change
Expand Up @@ -1002,7 +1002,7 @@ const PageCardRenderer: React.FC<any> = ({ schema, className, ...props }) => {
// `children` is the authorable spelling; `body` is a READ-ONLY back-compat
// fallback for documents already stored with it (objectui#4027).
//
// `body` was retired from the contract by objectstack#5775 (PR #6281, ADR-0087
// `body` was retired from the contract by objectstack#5775 (objectstack `85ec26d28`, ADR-0087
// D2): it was a second spelling of the slot every other container — grid, flex,
// section, tabs items — calls `children`, and the spec now declares `children`
// on `PageCardProps` and rejects `body` by name. The registration below stopped
Expand Down Expand Up @@ -1072,7 +1072,7 @@ ComponentRegistry.register('card', PageCardRenderer, {
{ name: 'title', type: ['string', 'object'], description: 'Accepts an inline translation map ({ en, "zh-CN", … })' },
{ name: 'bordered', type: 'boolean' },
// The card's content slot, respelled from `body` to `children`
// (objectui#4027). One slot, one spelling: objectstack#5775 (PR #6281)
// (objectui#4027). One slot, one spelling: objectstack#5775 (objectstack `85ec26d28`)
// retired `PageCardProps.body` and declared `children` in its place, so a
// designer that kept offering `body` was teaching a key the contract now
// rejects by name. The renderer still READS `body` for stored documents —
Expand Down
2 changes: 1 addition & 1 deletion packages/plugin-detail/src/index.tsx
Original file line number Diff line number Diff line change
Expand Up @@ -559,7 +559,7 @@ ComponentRegistry.register('details', RecordDetailsRenderer, {
// `inlineEdit` is documented as an opt-OUT because that is the only
// direction it can decide. The value is AND-ed with the object's own
// resolved editability (`isObjectInlineEditable`, ADR-0103) and with the
// server's effective API operation set (objectui#3546), so `true` cannot
// server's effective API operation set (objectstack#3546), so `true` cannot
// open editing the platform refuses; only `false` is unconditional. Saying
// "enables inline editing" would advertise an authority this key does not
// have.
Expand Down
2 changes: 1 addition & 1 deletion packages/plugin-detail/src/renderers/record-details.tsx
Original file line number Diff line number Diff line change
Expand Up @@ -800,7 +800,7 @@ export const RecordDetailsRenderer: React.FC<RecordDetailsRendererProps> = ({
// source of truth — formerly a hand-mirrored `NON_EDITABLE_BUCKETS` set kept
// in lockstep by hand because plugin-detail can't depend on app-shell.
// Authors can still force-disable with `inlineEdit: false`.
// [#3546] Also AND inline-editability with the server's effective API
// [objectstack#3546] Also AND inline-editability with the server's effective API
// operation set for this object (`/me/permissions` `apiOperations`) — the
// record body must not offer double-click/pencil editing the server would
// 405. `undefined` (unrestricted / old backend) leaves the bucket affordance
Expand Down
2 changes: 1 addition & 1 deletion packages/plugin-form/src/fieldWriteGate.ts
Original file line number Diff line number Diff line change
Expand Up @@ -190,7 +190,7 @@ export interface GateFormFieldsOptions extends ApplyFieldPermissionsOptions {
* open; the engine-owned buckets (`engine-owned`, `append-only`,
* `better-auth`) resolve closed unless the object OPENED per-record writing via
* `userActions.{edit,create}` (e.g. sys_user opens `edit` for its profile
* fields). #3546 intersects that with the server's effective API operation set
* fields). objectstack#3546 intersects that with the server's effective API operation set
* for the object, so the lock also engages when the server denies `update`
* (edit) or `create` (create) — the intersection the detail header and the
* list toolbar apply.
Expand Down
2 changes: 1 addition & 1 deletion packages/plugin-grid/src/hooks/useRecordCrudVerdicts.ts
Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,7 @@
* The singular probe the detail header uses answers ONE record. Folding it into
* a list row-by-row would cost 2N round trips (a 50-row page = 100 POSTs), and
* that cost is why this card sat blocked: the batch form
* (`recordIds: string[]`, objectstack#8326, shipped in objectstack PR #8452) is
* (`recordIds: string[]`, objectstack#8326, shipped in objectstack `27358d517`) is
* what makes a page-level fold affordable. `records[i]` answers `recordIds[i]`;
* each entry is the verdict the singular form returns for that id, so the list
* and the detail header read the same number by construction rather than by
Expand Down
Loading