From 4398baaa0054415d41b6618c1d2d39d48d4e8242 Mon Sep 17 00:00:00 2001 From: Jack Zhuang <50353452+hotlong@users.noreply.github.com> Date: Wed, 2 Sep 2026 09:03:47 +0800 Subject: [PATCH 1/4] chore: bump objectui to 67dadd602a3a fix(plugin-grid,plugin-list): FLS-gate the `$expand` projection at both sites (#7229) objectui@67dadd602a3a891666ea1513c5de677140784b6a --- .changeset/console-67dadd602a3a.md | 30 ++++++++++++++++++++++++++++++ .objectui-sha | 2 +- 2 files changed, 31 insertions(+), 1 deletion(-) create mode 100644 .changeset/console-67dadd602a3a.md diff --git a/.changeset/console-67dadd602a3a.md b/.changeset/console-67dadd602a3a.md new file mode 100644 index 0000000000..731ae9d3e1 --- /dev/null +++ b/.changeset/console-67dadd602a3a.md @@ -0,0 +1,30 @@ +--- +"@objectstack/console": minor +--- + +Console (objectui) refreshed to `67dadd602a3a`. Frontend changes in this range: + +Derived from the changesets objectui declared over the range — 16 releasing of 24 changesets added across 24 non-merge commits; omitted: 8 release-nothing changesets (they ship no package code). + +- **minor** — A grouped grid now says, where the group counts are, that it grouped a **page** (objectui#7189). (objectui `8952395b4`) +- **minor** — **Breaking for authored metadata:** `DataTableSchema.toolbar` is RETIRED (objectui#6881, maintainer ruling 2026-08-31). A `data-table` node that authors `toolbar` no longer valida… (objectui `3561bd2ca`) +- **minor** — Retire `ChartDataSeries.data`, and correct `ChartSchema.categories`' prose to the read it has always had (objectui#6896, ADR-0049 enforce-or-remove; maintainer ruling 2026-08-31). (objectui `b0d308da9`) +- **minor** — **BREAKING** — Retire the form-view section `className` / `gridClassName` reads (objectstack#13626, maintainer ruling 2026-09-01, director decision batch C). (objectui `9c7490268`) +- **minor** — `page:header` resolves its `actions` as declared ACTION IDS (objectui#6252, implementing the objectstack#11592 ruling — maintainer, 2026-08-25, on recommendation B). (objectui `8ec11e14f`) +- **patch** — FLS-gate the `$expand` projection at both build sites (objectui#7215). (objectui `67dadd602`) +- **patch** — Gantt toolbar: the period label names the visible window, and the prev/next buttons step it (objectui#7203). (objectui `231d1b93c`) +- **patch** — fix(app-shell,plugin-list): a list view's own `description` now reaches the screen (objectui `f626808d4`) +- **patch** — A gantt list view no longer shows the record-count bar, because the bar describes a request that view does not draw (objectui#7210, half 1). (objectui `5015fcf52`) +- **patch** — Fix: a grid grouped by a field it does not also show as a column no longer collapses every row into one `(empty)` group (objectui#7179). (objectui `a6d8b8d44`) +- **patch** — Stop shipping `dist/__tests__/numberInputBrowserReadings.d.ts` in the published tarball (objectui#6943). `packages/fields/tsconfig.json` now excludes the tooling DIRECTORIES (`__t… (objectui `39d69ad53`) +- **patch** — Scatter now says when it cannot place a row, instead of drawing an empty axis. (objectui `93bbc2055`) +- **patch** — Fix: a `dependsOn` lookup column is no longer permanently uneditable in an editable `ObjectGrid`. (objectui `84ffdbcbb`) +- **patch** — `ObjectGrid` no longer copies `descriptionField`, `lookupColumns` or `lookupFilters` onto a relational column's `fieldMeta` (objectui#7166). No behaviour change — all three still… (objectui `a276480b7`) +- **patch** — `RecordComments` and `PointInTimeRestore` resolve their copy from the locale packs instead of hardcoded English (objectui#7163). (objectui `866cd1d3f`) +- **patch** — Pie, donut, funnel and treemap now say when rows carry no magnitude they can draw. (objectui `5eddeeb68`) + +⚠️ 2 of these carry a breaking change: 2 by the author's own breaking annotation in the changeset body — objectui declares no `major` inside a launch window (`scripts/check-changeset-no-major.mjs`). Each is marked **BREAKING** in the list above — read them before compiling the release record. + + + +objectui range: `d8ec8d6d4f01...67dadd602a3a` diff --git a/.objectui-sha b/.objectui-sha index a261c4262a..0d080b5c2a 100644 --- a/.objectui-sha +++ b/.objectui-sha @@ -1 +1 @@ -d8ec8d6d4f011b11c8eb1e6dbd364ef206711391 +67dadd602a3a891666ea1513c5de677140784b6a From 05ebb93d7aa231889b230b13de512431d38b20e4 Mon Sep 17 00:00:00 2001 From: Jack Zhuang <50353452+hotlong@users.noreply.github.com> Date: Wed, 2 Sep 2026 09:41:10 +0800 Subject: [PATCH 2/4] chore(spec): re-measure the eight objectui pin citations at 67dadd602 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit check:objectui-pin-citations refuses a pin bump whose asserting citations still name the old pin, and refuses a sha-only rewrite. Every record was re-read at objectui@67dadd602 instead: - ObjectGrid.tsx changed (7 commits, 461 lines): the bulk-selection block moved 3187-3202 → 3436-3451, byte-identical, shifted by insertions above. hooks/useBulkExecutor.ts is unchanged; 284-289 re-read. - containers.tsx changed (164 lines) from :995 on, below every cited anchor: 729-735 / 788 (tabs) and 918-924 / 965 (accordion) unmoved. - button.tsx, resolve-icon.ts, lazy-icon.tsx, plugin-dashboard index.tsx, ObjectMetricWidget.tsx, MetricWidget.tsx, MetricCard.tsx are byte-identical at both pins; every anchor re-read, none moved. Co-Authored-By: Claude Fable 5.1 --- .../api-methods-batch-conformance.test.ts | 17 ++++--- packages/spec/src/ui/component.test.ts | 41 +++++++++------- packages/spec/src/ui/component.zod.ts | 49 ++++++++++--------- 3 files changed, 57 insertions(+), 50 deletions(-) diff --git a/packages/spec/src/data/api-methods-batch-conformance.test.ts b/packages/spec/src/data/api-methods-batch-conformance.test.ts index a51a7f0419..4b7621de7f 100644 --- a/packages/spec/src/data/api-methods-batch-conformance.test.ts +++ b/packages/spec/src/data/api-methods-batch-conformance.test.ts @@ -61,16 +61,17 @@ const SINGLE_RECORD_WRITE_ONLY: Record = { // `revoked` on ONE key. The multi-select surface this rule protects does not // exist for API keys, and the shape a future one would take does not need // `bulk` either — both read off the console build this release pins - // (`.objectui-sha` = `d8ec8d6d4`, `packages/plugin-grid`; re-measured at - // that pin, 2026-09-01 — previously measured at `9602dc820`, before that at - // `190fbd01d`, `9a3daf8d3`, originally at `6314e87f2`. `ObjectGrid.tsx` DID - // change across the move off `9602dc820`, so both claims below were - // re-derived rather than carried over: `ObjectGrid.tsx:3187-3202`, whose - // block is byte-identical to the one cited at `9602dc820:2586-2601` and - // shifted only by insertions above it, and + // (`.objectui-sha` = `67dadd602`, `packages/plugin-grid`; re-measured at + // that pin, 2026-09-02 — previously measured at `d8ec8d6d4`, before that at + // `9602dc820`, `190fbd01d`, `9a3daf8d3`, originally at `6314e87f2`. + // `ObjectGrid.tsx` DID change across the move off `d8ec8d6d4` (seven + // commits, 461 lines), so both claims below were re-derived rather than + // carried over: `ObjectGrid.tsx:3436-3451`, whose block is byte-identical + // to the one cited at `d8ec8d6d4:3187-3202` and shifted only by insertions + // above it, and // `hooks/useBulkExecutor.ts:284-289`, in a file byte-identical at both pins // and re-READ there rather than carried on that identity — it still ends on - // `label = 'bulk delete'`, the line the `284-288` span cited two pins ago + // `label = 'bulk delete'`, the line the `284-288` span cited three pins ago // stopped short of, truncating the second of the two branches it names (the // #10274 class of anchor error, found by re-reading rather than by the file // changing, which is why byte-identity is never taken as proof an anchor is diff --git a/packages/spec/src/ui/component.test.ts b/packages/spec/src/ui/component.test.ts index e54b73bdb7..9435120aac 100644 --- a/packages/spec/src/ui/component.test.ts +++ b/packages/spec/src/ui/component.test.ts @@ -278,13 +278,15 @@ describe('PageAccordionProps variant (#6776)', () => { // same file's `ComponentRegistry.register('accordion', …)` publishes the key to // the Studio block designer at `:965` (the `items` input, documented as // `[{ label, icon?, collapsed?, children }]`). Measured at the pin this repo -// builds against — `.objectui-sha` = `d8ec8d6d4`. Re-derived at that pin -// 2026-09-01: `containers.tsx` DID change across the move off `9602dc820`, so -// both anchors above were re-derived rather than carried over — the icon block -// moved `851-857` → `918-924` and the registration input `898` → `965`, both -// shifted by insertions above them, with the cited text itself unchanged. Every -// anchor was re-READ at the new pin, never inferred, because identity preserves -// a wrong anchor as faithfully as a right one (#10274). +// builds against — `.objectui-sha` = `67dadd602`. Re-derived at that pin +// 2026-09-02: `containers.tsx` DID change across the move off `d8ec8d6d4` +// (164 lines), but that change lands from `:995` on, below both anchors (its +// only edit above them rewrites one import line in place), so neither moved — +// the icon block is still `918-924` and the registration input still `965`, +// each re-READ there with the cited text unchanged. The earlier hop off +// `9602dc820` is the one that moved them, `851-857` → `918-924` and `898` → +// `965`. Every anchor was re-READ at the new pin, never inferred, because +// identity preserves a wrong anchor as faithfully as a right one (#10274). // // #9397 spent a full dispatch cycle re-deriving that read point from scratch // after the sweep proposed retiring the key. This block plus the `.describe()` @@ -367,12 +369,14 @@ describe('PageTabsProps items[].value / items[].count (#5775)', () => { // same file's `ComponentRegistry.register('tabs', …)` publishes the key to the // Studio block designer at `:788` (the `items` input, documented as // `[{ label, value?, icon?, count?, visibleWhen?, children }]`). Measured at -// the pin this repo builds against — `.objectui-sha` = `d8ec8d6d4`. Re-derived -// at that pin 2026-09-01: `containers.tsx` DID change across the move off -// `9602dc820`, so both anchors above were re-derived rather than carried over — -// the icon block moved `662-668` → `729-735` and the registration input -// `721` → `788`, both shifted by insertions above them, with the cited text -// itself unchanged. Both were re-READ at the new pin, never inferred (#10274). +// the pin this repo builds against — `.objectui-sha` = `67dadd602`. Re-derived +// at that pin 2026-09-02: `containers.tsx` DID change across the move off +// `d8ec8d6d4` (164 lines), but that change lands from `:995` on, below both +// anchors, so neither moved — the icon block is still `729-735` and the +// registration input still `788`, each re-READ there with the cited text +// unchanged. The earlier hop off `9602dc820` is the one that moved them, +// `662-668` → `729-735` and `721` → `788`. Both were re-READ at the new pin, +// never inferred (#10274). // // #9397 spent a full dispatch cycle re-deriving the accordion's read point // after the sweep proposed retiring it. This block plus the `.describe()` it @@ -2441,11 +2445,12 @@ describe('#7751 — object-* block props schemas', () => { // #9881 and #9972 recorded the accordion and tab items; these two close the set. // // The button record re-measured at the pin this repo builds against — -// `.objectui-sha` = `d8ec8d6d4`, re-derived there 2026-09-01: `button.tsx` and -// `resolve-icon.ts` are both byte-identical to the ones at `9602dc820`, and -// every anchor below was still re-READ at the new pin rather than carried on -// that identity (#10274). The move off `9602dc820` changed neither the read -// point nor a single line number here. +// `.objectui-sha` = `67dadd602`, re-derived there 2026-09-02: `button.tsx` and +// `resolve-icon.ts` are both byte-identical to the ones at `d8ec8d6d4` (and at +// `9602dc820` before it), and every anchor below was still re-READ at the new +// pin rather than carried on that identity (#10274). Neither the move off +// `d8ec8d6d4` nor the one off `9602dc820` changed the read point or a single +// line number here. // The one move that changed the button READ POINT and not merely its line // numbers was the one onto `9602dc820`: objectui#5993 deleted `button.tsx`'s // file-local `toPascalCase` + `iconNameMap` + `icons` index and routed the diff --git a/packages/spec/src/ui/component.zod.ts b/packages/spec/src/ui/component.zod.ts index 82e973e081..746fba9849 100644 --- a/packages/spec/src/ui/component.zod.ts +++ b/packages/spec/src/ui/component.zod.ts @@ -642,12 +642,13 @@ export const PageTabsProps = strictObject({ * false candidate a component over). * * The key is LIVE at the objectui pin this repo builds against - * (`.objectui-sha` = `d8ec8d6d4`; re-derived at that pin 2026-09-01 — - * `containers.tsx` DID change across the move off `9602dc820`, so both - * anchors below were re-derived rather than carried over, the icon block - * moving `662-668` → `729-735` and the registration input `721` → `788`, - * both shifted by insertions above them with the cited text unchanged; - * both were re-READ there, never inferred): `containers.tsx:729-735` + * (`.objectui-sha` = `67dadd602`; re-derived at that pin 2026-09-02 — + * `containers.tsx` DID change across the move off `d8ec8d6d4`, but that + * change lands from `:995` on, below both anchors, so neither moved: the + * icon block is still `729-735` and the registration input still `788`, + * each re-READ there with the cited text unchanged, never inferred; the + * earlier hop off `9602dc820` is the one that moved them, `662-668` → + * `729-735` and `721` → `788`): `containers.tsx:729-735` * renders * `{item.icon && }` inside the * `TabsTrigger`, left of the label span (`mr-1.5 h-3.5 w-3.5 shrink-0 @@ -1701,12 +1702,13 @@ export const PageAccordionProps = strictObject({ * re-derive the same false candidate). * * The key is LIVE at the objectui pin this repo builds against - * (`.objectui-sha` = `d8ec8d6d4`; re-derived at that pin 2026-09-01 — - * `containers.tsx` DID change across the move off `9602dc820`, so both - * anchors below were re-derived rather than carried over, the icon block - * moving `851-857` → `918-924` and the registration input `898` → `965`, - * both shifted by insertions above them with the cited text unchanged; - * both were re-READ there, never inferred): `containers.tsx:918-924` + * (`.objectui-sha` = `67dadd602`; re-derived at that pin 2026-09-02 — + * `containers.tsx` DID change across the move off `d8ec8d6d4`, but that + * change lands from `:995` on, below both anchors, so neither moved: the + * icon block is still `918-924` and the registration input still `965`, + * each re-READ there with the cited text unchanged, never inferred; the + * earlier hop off `9602dc820` is the one that moved them, `851-857` → + * `918-924` and `898` → `965`): `containers.tsx:918-924` * renders * `{item.icon && }` inside the * `AccordionTrigger`, grouped with the label in the trigger's one wrapping @@ -1881,10 +1883,11 @@ export const ElementButtonPropsSchema = lazySchema(() => strictObject({ * the button. * * The key is LIVE at the objectui pin this repo builds against - * (`.objectui-sha` = `d8ec8d6d4`; re-derived at that pin 2026-09-01 — + * (`.objectui-sha` = `67dadd602`; re-derived at that pin 2026-09-02 — * `button.tsx` and `resolve-icon.ts` are both byte-identical to the ones at - * `9602dc820` and every anchor below is unmoved, each one re-READ at the new - * pin rather than carried on that identity (#10274). The read point MOVED + * `d8ec8d6d4` (and at `9602dc820` before it) and every anchor below is + * unmoved, each one re-READ at the new pin rather than carried on that + * identity (#10274). The read point MOVED * rather than died on the earlier hop onto `9602dc820`, which is why the * anchors below span a second file): `components/src/renderers/form/ * button.tsx:36` resolves `schema.icon` through the shared `resolveIcon`, @@ -2465,15 +2468,13 @@ export const ObjectMetricPropsSchema = lazySchema(() => strictObject({ * same record for the metric tile. * * The key is LIVE at the objectui pin this repo builds against - * (`.objectui-sha` = `d8ec8d6d4`; re-derived at that pin 2026-09-01 — of the - * files in the chain below, `index.tsx` DID change across the move off - * `9602dc820` while `ObjectMetricWidget.tsx`, `MetricWidget.tsx`, - * `MetricCard.tsx` and `lazy-icon.tsx` are byte-identical to the ones at - * `9602dc820`; this time NO anchor moved, `index.tsx`'s included — its - * `object-metric` registration begins at `:194` and the icon input still - * lands on `:204`, the change to that file sitting elsewhere in it. Every - * anchor below was re-READ at the new pin rather than inferred from either - * that identity or that unchanged number), and the chain runs + * (`.objectui-sha` = `67dadd602`; re-derived at that pin 2026-09-02 — all + * five files in the chain below, `index.tsx`, `ObjectMetricWidget.tsx`, + * `MetricWidget.tsx`, `MetricCard.tsx` and `lazy-icon.tsx`, are + * byte-identical to the ones at `d8ec8d6d4`, so NO anchor moved — the + * `object-metric` registration still begins at `:194` and the icon input + * still lands on `:204`. Every anchor below was re-READ at the new pin + * rather than inferred from that identity), and the chain runs * three files: * `plugin-dashboard/src/index.tsx:204` publishes it as a designer input * (`Icon (Lucide name)`) on the registered `object-metric` block; From 1b93fd1745e766ece7a72fdad2ec0b91656c92b8 Mon Sep 17 00:00:00 2001 From: Jack Zhuang <50353452+hotlong@users.noreply.github.com> Date: Wed, 2 Sep 2026 11:09:34 +0800 Subject: [PATCH 3/4] chore(sdui-parser): re-record the objectui lockstep at 67dadd602 check:sdui-lockstep refuses a pin move whose parity record still names the old pin. Re-recorded with --update against the objectui tree checked out at the pinned SHA: 214 grammar lines byte-identical, 24 diagnostic codes agree, no port owed. Co-Authored-By: Claude Fable 5.1 --- packages/sdui-parser/objectui-lockstep.json | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/packages/sdui-parser/objectui-lockstep.json b/packages/sdui-parser/objectui-lockstep.json index 91346738d0..5a7fe8b69f 100644 --- a/packages/sdui-parser/objectui-lockstep.json +++ b/packages/sdui-parser/objectui-lockstep.json @@ -6,8 +6,8 @@ ], "objectui": { "repo": "https://github.com/objectstack-ai/objectui.git", - "rev": "d8ec8d6d4f011b11c8eb1e6dbd364ef206711391", - "revDate": "2026-09-01T08:23:58+00:00", + "rev": "67dadd602a3a891666ea1513c5de677140784b6a", + "revDate": "2026-09-01T16:00:05Z", "source": "packages/sdui-parser/src", "files": [ "packages/sdui-parser/src/codegen.ts", @@ -20,7 +20,7 @@ "packages/sdui-parser/src/validate.ts" ] }, - "recordedAgainstPin": "d8ec8d6d4f011b11c8eb1e6dbd364ef206711391", + "recordedAgainstPin": "67dadd602a3a891666ea1513c5de677140784b6a", "grammarRegion": { "file": "packages/sdui-parser/src/parse.ts", "delimiter": "/* ---------------------- the JS literal subset (#6614) ---------------------- */", From ec0c8c1284271b29424e21d75a94c74573178f1a Mon Sep 17 00:00:00 2001 From: Jack Zhuang <50353452+hotlong@users.noreply.github.com> Date: Wed, 2 Sep 2026 17:29:03 +0800 Subject: [PATCH 4/4] chore(sdui): re-record sdui.manifest.json's provenance at objectui 67dadd602 check-sdui-manifest refuses a pin move whose manifest record names the old pin. Regenerated with gen-sdui-manifest-node against @object-ui 17.6.0 (the version the new pin ships): 57 components, content unchanged, record moved to 67dadd602a3a. Co-Authored-By: Claude Fable 5.1 --- scripts/sdui-manifest.record.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/scripts/sdui-manifest.record.json b/scripts/sdui-manifest.record.json index 5cd4dad238..f5fe4d79b9 100644 --- a/scripts/sdui-manifest.record.json +++ b/scripts/sdui-manifest.record.json @@ -9,10 +9,10 @@ "a pin bump without regeneration goes RED there — that is the anti-rot half of the freshness gate.", "Regenerate + re-record: node scripts/gen-sdui-manifest-node.mjs (see its header for the offline mode)." ], - "objectuiSha": "d8ec8d6d4f011b11c8eb1e6dbd364ef206711391", + "objectuiSha": "67dadd602a3a891666ea1513c5de677140784b6a", "objectuiPackagesVersion": "17.6.0", "generator": "scripts/gen-sdui-manifest-node.mjs", - "generatedAt": "2026-09-01", + "generatedAt": "2026-09-02", "sha256": "49211fee7792cf51174930dc2c1be2169d5175f77a83491f68f90b3f0c19e69d", "components": 57 }