Skip to content

feat(studio-access): package-level OWD overview — audit & batch-edit sharingModel (#2505) - #2508

Merged
os-zhuang merged 2 commits into
mainfrom
claude/studio-access-package-owd-eic89v
Jul 15, 2026
Merged

feat(studio-access): package-level OWD overview — audit & batch-edit sharingModel (#2505)#2508
os-zhuang merged 2 commits into
mainfrom
claude/studio-access-package-owd-eic89v

Conversation

@os-zhuang

Copy link
Copy Markdown
Contributor

Closes#2505.

Problem

A package author can only inspect and edit an object's record-sharing baseline (OWD — sharingModel / externalSharingModel) one object at a time, via Data → object → Settings. A package with 20 objects requires opening 20 settings pages to audit its baseline posture, so in practice nobody does — and "which of my objects are org-wide writable?" can't be answered at a glance (ADR-0090 D1's silent-widening failure class is invisible object-by-object).

What this adds

A package-scoped "Record Sharing Baseline (OWD)" panel in the Studio Access pillar, as a sibling surface next to the permission-set rail (not inside the permission matrix):

  • Table of object × sharingModel × externalSharingModel covering every object the package owns (published ∪ pending drafts — the same merge the pillars do).
  • Inline selects using the canonical four values (private | public_read | public_read_write | controlled_by_parent), reusing the option labels / help copy from ObjectSettingsPanel.
  • controlled_by_parent rows show the master link (read-only) instead of an external dial, mirroring the per-object settings behavior.
  • Row-level external ≤ internal validation (ADR-0090 D11) surfaced inline; it blocks Save.
  • Save = per-object metadata drafts under the package scope — exactly what the per-object Settings tab writes, just N objects in one action. Publish then flows through the existing security-domain gate unchanged.
  • Deep-linkable via the existing ?surface= plumbing (owd:overview); the read-only OWD badge in PermissionMatrixEditor now links here, scrolled to the object.
  • Read-only packages render the table non-editable (badges only), following the pillar's courtesy gate.

This stays within one ownership boundary (every row's owner is the package author) — it is an aggregation of N per-object editing entry points, not a merge of OWD into the per-principal permission-set matrix.

Changes

  • views/studio-design/owd-sharing.ts (new) — shared OWD_MODELS, OWD_WIDTH axis, isExternalWider (D11), deriveMasterObject.
  • views/studio-design/PackageOwdOverviewPanel.tsx (new) — the overview surface.
  • views/studio-design/StudioDesignSurface.tsxAccessPillar hosts the panel via a pinned rail entry + ?surface=owd:overview deep-link; passes onOpenOwd to the matrix.
  • views/metadata-admin/PermissionMatrixEditor.tsx — optional onOpenOwd; the OWD badge becomes a link when provided (plain chip otherwise, so environment-scope / metadata-admin usage is unchanged).
  • views/metadata-admin/i18n.ts — EN + ZH strings.

Non-goals (per the issue)

  • No package-level default OWD with inheritance (would reintroduce the ambient "unset" state ADR-0090 D1 abolished).
  • Not merging OWD editing into the permission-set matrix (its badge stays read-only, now linkable).
  • No enable.* capability switches, and no changes to enforcement, lint, or the publish pipeline.

Verification

  • ADR-0054 testability proofs (PackageOwdOverviewPanel.test.tsx): list render, edit→per-object draft (with mode: 'draft' + packageId, unset drops the key), external > internal blocks Save inline, controlled_by_parent shows the master and no external dial, read-only badges only, deep-link highlight.
  • Unit tests for the shared helpers (owd-sharing.test.ts).
  • tsc --noEmit clean (turbo, 29/29). ESLint 0 errors. 16 new tests; full studio-design + PermissionMatrixEditor suites green (86 passed).

References

🤖 Generated with Claude Code

https://claude.ai/code/session_014wYveoZSpRweBkvXMY5Gg6


Generated by Claude Code

…sharingModel (#2505)
Add a package-scoped "Record Sharing Baseline (OWD)" panel to the Studio
Access pillar, a sibling surface next to the permission-set rail. It lists
every object the package owns (published ∪ pending drafts) with its internal
`sharingModel` and external `externalSharingModel`, so an author can audit
the package's record baseline at a glance instead of visiting each object's
Settings page one at a time.
- New `PackageOwdOverviewPanel`: object × internal × external table with
inline selects reusing the canonical four OWD values and the option
labels/help copy from ObjectSettingsPanel. Save writes one package-scoped
metadata draft per changed object (identical to the per-object Settings
write, N at once); publish flows through the unchanged security-domain gate.
- `controlled_by_parent` rows show the master link (read-only) instead of an
external dial; row-level `external ≤ internal` validation (ADR-0090 D11) is
surfaced inline and blocks Save.
- New shared `owd-sharing.ts`: canonical `OWD_MODELS`, the `OWD_WIDTH` axis,
`isExternalWider` (D11 comparison), and `deriveMasterObject`.
- Access pillar hosts it via a pinned rail entry + the existing `?surface=`
deep-link plumbing (`owd:overview`); the read-only OWD badge in the
permission matrix now deep-links here, scrolled to the object.
- Read-only packages render the table non-editable (badges only).
- EN/ZH i18n; ADR-0054 testability proofs (list render, edit→draft,
validation block, controlled_by_parent, read-only, deep-link) + unit tests
for the shared helpers. 16 new tests; full studio-design + permission-matrix
suites green (86).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014wYveoZSpRweBkvXMY5Gg6
@vercel

vercelBot commented Jul 15, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
objectuiIgnoredIgnoredJul 15, 2026 5:46am

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

❌ Console Performance Budget

MetricValueBudget
Main entry (gzip)** KB**KB
Entry file``
StatusFAIL

📦 Bundle Size Report

PackageSizeGzipped
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)21.70KB4.21KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.12KB3.41KB
auth (LoginForm.js)17.12KB5.00KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.63KB2.15KB
auth (SocialSignInButtons.js)9.60KB3.89KB
auth (UserMenu.js)3.40KB1.22KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)30.17KB7.28KB
auth (createAuthenticatedFetch.js)3.93KB1.55KB
auth (index.js)1.83KB0.79KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)4.86KB0.85KB
auth (useIsWorkspaceAdmin.js)1.61KB0.85KB
collaboration (CommentThread.js)18.38KB4.49KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)3.65KB1.42KB
collaboration (PresenceProvider.js)2.42KB0.96KB
collaboration (index.js)1.25KB0.53KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
core (index.js)1.69KB0.60KB
create-plugin (index.js)9.28KB2.98KB
data-objectstack (index.js)113.70KB28.15KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.32KB1.77KB
i18n (index.js)2.46KB0.96KB
i18n (pickLocalized.js)1.70KB0.83KB
i18n (provider.js)5.37KB1.72KB
i18n (useObjectLabel.js)21.22KB4.69KB
i18n (useSafeTranslation.js)2.68KB0.98KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.74KB
mobile (index.js)1.50KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)4.42KB1.27KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.71KB0.42KB
mobile (useResponsiveConfig.js)1.36KB0.63KB
mobile (useSpecGesture.js)1.77KB0.77KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)5.09KB1.84KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)3.46KB1.03KB
permissions (evaluator.js)4.00KB1.23KB
permissions (index.js)0.91KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.52KB
permissions (usePermissions.js)1.50KB0.70KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.55KB0.67KB
providers (UploadProvider.js)11.71KB3.53KB
providers (index.js)0.44KB0.22KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)3.19KB1.38KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)18.70KB6.09KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)0.79KB0.43KB
sdui-parser (codegen.js)4.09KB1.74KB
sdui-parser (index.js)2.16KB0.94KB
sdui-parser (parse.js)10.04KB2.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)4.69KB1.48KB
tenant (TenantContext.js)0.31KB0.25KB
tenant (TenantGuard.js)1.04KB0.43KB
tenant (TenantProvider.js)2.76KB0.98KB
tenant (TenantScopedQuery.js)0.77KB0.44KB
tenant (index.js)0.75KB0.38KB
tenant (resolver.js)2.64KB0.76KB
tenant (useTenant.js)0.50KB0.32KB
tenant (useTenantBranding.js)0.62KB0.39KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)0.77KB0.41KB
types (disclosure.js)0.20KB0.18KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (index.js)1.54KB0.68KB
types (layout.js)0.20KB0.18KB
types (mobile.js)0.20KB0.18KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.26KB1.96KB
types (tenant.js)0.20KB0.18KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)0.75KB0.46KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Main entry (gzip)27.5 KB350 KB
Entry fileindex-BJ7MgtxY.js
StatusPASS

📦 Bundle Size Report

PackageSizeGzipped
app-shell (index.js)7.84KB2.85KB
app-shell (runtime-config.js)7.42KB2.32KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)7.57KB2.97KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)21.70KB4.21KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.12KB3.41KB
auth (LoginForm.js)17.12KB5.00KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.63KB2.15KB
auth (SocialSignInButtons.js)9.60KB3.89KB
auth (UserMenu.js)3.40KB1.22KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)30.17KB7.28KB
auth (createAuthenticatedFetch.js)3.93KB1.55KB
auth (index.js)1.83KB0.79KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)4.86KB0.85KB
auth (useIsWorkspaceAdmin.js)1.61KB0.85KB
collaboration (CommentThread.js)18.38KB4.49KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)3.65KB1.42KB
collaboration (PresenceProvider.js)2.42KB0.96KB
collaboration (index.js)1.25KB0.53KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)441.87KB95.38KB
core (index.js)1.69KB0.60KB
create-plugin (index.js)9.28KB2.98KB
data-objectstack (index.js)113.70KB28.15KB
fields (index.js)202.54KB49.50KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.32KB1.77KB
i18n (index.js)2.46KB0.96KB
i18n (pickLocalized.js)1.70KB0.83KB
i18n (provider.js)5.37KB1.72KB
i18n (useObjectLabel.js)21.22KB4.69KB
i18n (useSafeTranslation.js)2.68KB0.98KB
layout (index.js)38.45KB10.67KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.74KB
mobile (index.js)1.50KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)4.42KB1.27KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.71KB0.42KB
mobile (useResponsiveConfig.js)1.36KB0.63KB
mobile (useSpecGesture.js)1.77KB0.77KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)5.09KB1.84KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)3.46KB1.03KB
permissions (evaluator.js)4.00KB1.23KB
permissions (index.js)0.91KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.52KB
permissions (usePermissions.js)1.50KB0.70KB
plugin-ai (index.js)15.71KB3.79KB
plugin-calendar (index.js)45.12KB12.34KB
plugin-charts (index.js)46.31KB13.06KB
plugin-chatbot (index.js)176.76KB42.28KB
plugin-dashboard (index.js)108.35KB26.87KB
plugin-designer (index.js)213.94KB43.03KB
plugin-detail (index.js)210.51KB50.88KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)104.26KB25.24KB
plugin-gantt (index.js)149.17KB37.17KB
plugin-grid (index.js)172.52KB45.58KB
plugin-kanban (index.js)48.16KB12.94KB
plugin-list (index.js)98.99KB23.43KB
plugin-map (index.js)16.80KB5.24KB
plugin-markdown (index.js)13.65KB4.67KB
plugin-report (index.js)37.82KB9.96KB
plugin-timeline (index.js)25.37KB7.20KB
plugin-tree (index.js)8.36KB2.81KB
plugin-view (index.js)85.54KB20.82KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.55KB0.67KB
providers (UploadProvider.js)11.71KB3.53KB
providers (index.js)0.44KB0.22KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)3.19KB1.38KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)18.70KB6.09KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)0.79KB0.43KB
sdui-parser (codegen.js)4.09KB1.74KB
sdui-parser (index.js)2.16KB0.94KB
sdui-parser (parse.js)10.04KB2.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)4.69KB1.48KB
tenant (TenantContext.js)0.31KB0.25KB
tenant (TenantGuard.js)1.04KB0.43KB
tenant (TenantProvider.js)2.76KB0.98KB
tenant (TenantScopedQuery.js)0.77KB0.44KB
tenant (index.js)0.75KB0.38KB
tenant (resolver.js)2.64KB0.76KB
tenant (useTenant.js)0.50KB0.32KB
tenant (useTenantBranding.js)0.62KB0.39KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)0.77KB0.41KB
types (disclosure.js)0.20KB0.18KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (index.js)1.54KB0.68KB
types (layout.js)0.20KB0.18KB
types (mobile.js)0.20KB0.18KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.26KB1.96KB
types (tenant.js)0.20KB0.18KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)0.75KB0.46KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-zhuang
os-zhuang marked this pull request as ready for review July 15, 2026 08:56
@os-zhuang
os-zhuang merged commit 466a5c6 into mainJul 15, 2026
10 checks passed
@os-zhuang
os-zhuang deleted the claude/studio-access-package-owd-eic89v branch July 15, 2026 08:56
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Studio Access pillar: package-level OWD overview — audit & batch-edit sharingModel across all objects in a package

2 participants

@os-zhuang@claude