Skip to content

feat(fields,plugin-form,plugin-detail): Setup system_permissions → capability multi-select (ADR-0056 P2) - #2400

Closed
os-zhuang wants to merge 1 commit into
mainfrom
feat/perm-setup-capability-picker
Closed

feat(fields,plugin-form,plugin-detail): Setup system_permissions → capability multi-select (ADR-0056 P2)#2400
os-zhuang wants to merge 1 commit into
mainfrom
feat/perm-setup-capability-picker

Conversation

@os-zhuang

Copy link
Copy Markdown
Contributor

What

sys_permission_set.system_permissions in the Setup app is now a structured capability multi-select instead of a raw JSON textarea.

ADR-0056 P2 (#2399) — first step of the epic #2398 (consolidate permission-set editing into Studio).

How

  • New widgetCapabilityMultiSelectField → registered field:capability-multiselect (@object-ui/fields). Renders the live sys_capability registry (active only) as chips grouped by scope (Platform / Organization), labelled, with the capability description on hover.
  • Byte-equivalent round-trip: the field stores a JSON-string array of capability names (security-plugin.ts writes JSON.stringify, reads parseJson). The widget parses on load and emits JSON.stringify(names) on change — the on-disk shape never changes. Unknown/legacy names are preserved.
  • Single injection point: the widget hint is stamped onto the field in ObjectStackAdapter.getObjectSchema — the one method both the record form (ObjectForm) and the detail inline-edit (DetailView/DetailSection) read the schema through. The field's type (storage contract) is untouched. ObjectForm auto-gen now carries field.widget; DetailSection enriches + honors widget in its inline-edit switch.

Verified

  • UnitCapabilityMultiSelectField.test.tsx, 9/9: parse tolerance (JSON string / array / empty / comma-legacy), scope grouping, JSON-string emit on toggle on & off, legacy-name preservation, readonly badges.
  • Browser (live backend) — opened admin_full_access: system_permissions renders as the grouped picker (5 Platform chips selected + an Organization group). Toggled a capability and saved through the UI; confirmed the record persisted ["…","manage_org_users"] as a JSON string (byte-equal shape), then restored the original. row_level_security / tab_permissions correctly remain JSON (they are P3/P4).
  • Console tsc clean for the touched files.

Not in scope

admin_scope / row_level_security / tab_permissions structured editors are P3/P4 (tracked in #2398).

🤖 Generated with Claude Code

…pability multi-select (ADR-0056 P2)
Replace the raw JSON textarea for sys_permission_set.system_permissions with a
structured capability picker over the live sys_capability registry — scope-grouped,
labelled chips with the capability description on hover.
- New CapabilityMultiSelectField, registered field:capability-multiselect
(@object-ui/fields). Value round-trips BYTE-EQUIVALENT to the JSON-string-array
storage (parse on load, JSON.stringify(names) on save); unknown/legacy names
are preserved.
- Stamped onto the field at the single getObjectSchema choke point
(ObjectStackAdapter) so BOTH the record form (ObjectForm) and the detail-page
inline edit (DetailView/DetailSection) show the picker. Field storage type
unchanged. ObjectForm auto-gen now carries field.widget; DetailSection enriches
+ honors widget in its inline-edit switch.
ADR-0056 P2 / epic #2398. First step toward retiring Setup's permission JSON
textareas for structured Studio editors.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@vercel

vercelBot commented Jul 12, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
objectuiIgnoredIgnoredJul 12, 2026 12:54pm

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Main entry (gzip)60.4 KB350 KB
Entry fileindex-Cs50u1kM.js
StatusPASS

📦 Bundle Size Report

PackageSizeGzipped
app-shell (index.js)7.84KB2.85KB
app-shell (runtime-config.js)7.42KB2.32KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)7.57KB2.97KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)21.08KB4.19KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.12KB3.41KB
auth (LoginForm.js)14.70KB4.38KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.63KB2.15KB
auth (SocialSignInButtons.js)8.89KB3.61KB
auth (UserMenu.js)3.40KB1.22KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)28.83KB7.01KB
auth (createAuthenticatedFetch.js)3.93KB1.55KB
auth (index.js)1.75KB0.76KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)4.74KB0.85KB
auth (useIsWorkspaceAdmin.js)1.61KB0.85KB
collaboration (CommentThread.js)18.38KB4.49KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)3.65KB1.42KB
collaboration (PresenceProvider.js)2.42KB0.96KB
collaboration (index.js)1.25KB0.53KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)441.51KB95.26KB
core (index.js)1.65KB0.59KB
create-plugin (index.js)9.28KB2.98KB
data-objectstack (index.js)111.81KB27.73KB
fields (index.js)190.04KB46.40KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.32KB1.77KB
i18n (index.js)2.46KB0.96KB
i18n (pickLocalized.js)1.31KB0.67KB
i18n (provider.js)5.37KB1.72KB
i18n (useObjectLabel.js)21.15KB4.68KB
i18n (useSafeTranslation.js)2.68KB0.98KB
layout (index.js)38.41KB10.65KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.74KB
mobile (index.js)1.50KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)4.42KB1.27KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.71KB0.42KB
mobile (useResponsiveConfig.js)1.36KB0.63KB
mobile (useSpecGesture.js)1.77KB0.77KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)5.09KB1.84KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)3.46KB1.03KB
permissions (evaluator.js)4.00KB1.23KB
permissions (index.js)0.91KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.52KB
permissions (usePermissions.js)1.50KB0.70KB
plugin-ai (index.js)15.71KB3.79KB
plugin-calendar (index.js)45.12KB12.34KB
plugin-charts (index.js)46.31KB13.06KB
plugin-chatbot (index.js)173.88KB41.49KB
plugin-dashboard (index.js)108.35KB26.87KB
plugin-designer (index.js)213.95KB43.04KB
plugin-detail (index.js)205.29KB49.54KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)104.27KB25.25KB
plugin-gantt (index.js)136.81KB33.91KB
plugin-grid (index.js)171.87KB45.39KB
plugin-kanban (index.js)48.16KB12.94KB
plugin-list (index.js)98.18KB23.16KB
plugin-map (index.js)16.80KB5.24KB
plugin-markdown (index.js)13.65KB4.67KB
plugin-report (index.js)37.83KB9.97KB
plugin-timeline (index.js)25.37KB7.20KB
plugin-tree (index.js)8.21KB2.76KB
plugin-view (index.js)85.47KB20.80KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.55KB0.67KB
providers (UploadProvider.js)11.71KB3.53KB
providers (index.js)0.44KB0.22KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)3.19KB1.38KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)18.23KB5.97KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)0.79KB0.43KB
sdui-parser (codegen.js)4.09KB1.74KB
sdui-parser (index.js)2.16KB0.94KB
sdui-parser (parse.js)10.04KB2.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)4.69KB1.48KB
tenant (TenantContext.js)0.31KB0.25KB
tenant (TenantGuard.js)1.04KB0.43KB
tenant (TenantProvider.js)2.76KB0.98KB
tenant (TenantScopedQuery.js)0.77KB0.44KB
tenant (index.js)0.75KB0.38KB
tenant (resolver.js)2.64KB0.76KB
tenant (useTenant.js)0.50KB0.32KB
tenant (useTenantBranding.js)0.62KB0.39KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)0.77KB0.41KB
types (disclosure.js)0.20KB0.18KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (index.js)1.54KB0.68KB
types (layout.js)0.20KB0.18KB
types (mobile.js)0.20KB0.18KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.26KB1.96KB
types (tenant.js)0.20KB0.18KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)0.75KB0.46KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-zhuang
os-zhuang marked this pull request as draft July 12, 2026 13:38
@os-zhuang

Copy link
Copy Markdown
ContributorAuthor

Re-scoped per design discussion (pure model: Studio designs, Setup assigns). Capabilities are part of permission design → they belong in the Studio access editor, not inline in Setup. So this PR's Setup-side capability-picker placement is superseded:

  • The CapabilityMultiSelectField component is kept and will be reused in the StudioPermissionMatrixEditor (a new System Capabilities section).
  • Setup's system_permissions will become a read-only summary + deep-link to Studio, like the other permission facets (no inline editing, no JSON).
  • Setup's permission-set page instead gains user assignment (admin's job).

Marking draft pending rework. Superseded by the reworked plan (ADR-0056 update incoming).

@os-zhuang

Copy link
Copy Markdown
ContributorAuthor

Parked — superseded in placement by the pure model (epic #2398, rewritten).

This PR put the capability multi-select in Setup. Under the reset design, Setup is read-only for every permission facet and system_permissions is designed in Studio like the others — so the picker belongs in Studio, not here.

The code is not wasted — the epic re-homes it:

  • CapabilityMultiSelectField (+ 9 passing tests) → Studio System Capabilities editor (epic P2).
  • getObjectSchema widget-override choke point + ObjectForm/DetailSection widget-honoring → reused by epic P1 to stamp the six Setup permission fields with a summary + Studio deep-link renderer (instead of an editable picker).

Keeping the branch (feat/perm-setup-capability-picker) for that re-home. Leaving this as draft; will close once P1/P2 land the re-homed versions.

@os-zhuang

Copy link
Copy Markdown
ContributorAuthor

Superseded by #2403 (pure model). The capability picker's placement (in Setup) was overruled — capabilities are now designed in Studio like every other facet. The reusable groundwork (CapabilityMultiSelectField + the getObjectSchema widget-override choke point) is carried forward in #2403 and re-homed: Studio for the capability picker, Setup for the read-only permission-facet-link summary. Closing to consolidate on #2403.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@os-zhuang