Skip to content

feat(app-shell): CEL authoring safety for RLS policies — lint, field autocomplete, test-run - #2533

Merged
os-zhuang merged 1 commit into
mainfrom
claude/cel-rls-authoring-safety-29hqiy
Jul 15, 2026
Merged

feat(app-shell): CEL authoring safety for RLS policies — lint, field autocomplete, test-run#2533
os-zhuang merged 1 commit into
mainfrom
claude/cel-rls-authoring-safety-29hqiy

Conversation

@os-zhuang

Copy link
Copy Markdown
Contributor

Closes#2413.

Problem

The permission-set Studio RLS editor (PermissionAdvancedFacets) let admins author USING (read filter) / CHECK (write filter) predicates as bare textareas — no syntax validation, no field autocomplete, no way to test. RLS is the highest-risk authoring surface in the permission model: a typo silently mis-scopes rows, and some evaluation paths fail open, widening access with no visible error.

What this does

Three author-time safeties on the USING/CHECK editors, all delegated to the framework's canonical CEL engine (@objectstack/formula) so the GUI reaches the same verdict as the server rather than maintaining a second grammar (ADR-0032):

  • Inline lintvalidateExpression flags parse faults inline (and gates Save); unknown-field near-misses become non-blocking "did-you-mean" warnings; a non-pushdown-able USING filter gets a fail-open blast-radius advisory (isPushdownableCel) — directly targeting the "widens access" risk the issue calls out.
  • Field autocompleteintrospectScope offers the target object's fields plus scope vars (current_user, record, …) and stdlib functions as you type; member-access segments (current_user.) are deliberately not guessed.
  • Test-run — a per-policy dialog dry-runs a predicate against a sample record + current_user through ExpressionEngine.evaluate, showing allow / deny / non-boolean / error before shipping.

The engine loads lazily (dynamic import, feature-detected and error-swallowing, mirroring preview/capabilityLint.ts), so the CEL parser stays out of the main bundle and a missing/older engine degrades to "no assistance" rather than breaking the editor.

Acceptance criteria

  • Malformed CEL is flagged inline and blocks Save (parse errors only — never on warnings).
  • Autocomplete suggests valid field/scope identifiers for the policy's object.
  • An author can dry-run a USING/CHECK predicate against a sample record and see the result.
  • (Optional) Flags where a policy fails open — non-pushdown-able USING filters get a blast-radius advisory.

Files

  • Newmetadata-admin/celAuthoring.ts — the lazy, feature-detected bridge (lintCelPredicate / introspectCelScope / testRunCelPredicate + pure autocomplete helpers).
  • NewCelPredicateField.tsx — textarea + inline lint + as-you-type autocomplete.
  • NewCelTestRunDialog.tsx — the dry-run dialog.
  • WirePermissionAdvancedFacets.tsx (swap textareas → editor, per-policy Test button, aggregate lint errors), PermissionMatrixEditor.tsx (provide field loader, gate Save on CEL errors).
  • i18n perm.cel.* (en + zh-CN); adds @objectstack/formula dep; README + changeset.

Testing

  • pnpm --filter @object-ui/app-shell type-check — clean.
  • eslint on all changed files — 0 errors.
  • 37 new tests across 4 files, run against the real@objectstack/formula engine (no mocks for the happy path): lint (valid/malformed/typo/pushdown), autocomplete (token detection + insert + member-access suppression), test-run (allow/deny/non-boolean/error/invalid-JSON), facets Save-gating + dialog open, plus graceful-degradation when the engine is unavailable.
  • Full metadata-admin suite (77 files / 623 tests) green — no regressions.

Verification was done by driving the real components against the real CEL engine via RTL; full in-browser verification against a live backend was not run (no framework backend in this environment), but the lazy dynamic-import path follows the already-shipping capabilityLint.ts precedent.

🤖 Generated with Claude Code


Generated by Claude Code

…autocomplete, test-run (#2413)
The permission-set Studio RLS editor authored USING (read filter) / CHECK
(write filter) CEL predicates as bare textareas with no validation,
autocomplete, or way to test. RLS is security-critical: a typo silently
mis-scopes rows and some evaluation paths fail open, widening access with no
visible error.
Add three author-time safeties backed by the framework's canonical CEL engine
(@objectstack/formula), so the GUI reaches the same verdict as the server
rather than maintaining a second grammar:
- Inline lint (CelPredicateField): validateExpression flags parse faults inline
and gates Save; unknown-field near-misses become non-blocking did-you-mean
warnings; a non-pushdown-able USING filter gets a fail-open blast-radius
advisory (isPushdownableCel).
- Field autocomplete: introspectScope offers the object's fields plus scope
vars (current_user, record, …) and stdlib functions as you type.
- Test-run (CelTestRunDialog): dry-run a predicate against a sample record +
current_user via ExpressionEngine.evaluate, showing allow / deny /
non-boolean / error.
The engine loads lazily (dynamic import, feature-detected and error-swallowing
like preview/capabilityLint.ts), keeping the CEL parser out of the main bundle
and degrading to "no assistance" rather than breaking the editor.
New bridge metadata-admin/celAuthoring.ts; new perm.cel.* i18n keys (en +
zh-CN); adds @objectstack/formula dependency to app-shell. Docs + changeset
included.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ArGxyhL8ARrsxE87oNSdbj
@vercel

vercelBot commented Jul 15, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
objectuiIgnoredIgnoredJul 15, 2026 2:50pm

Request Review

@github-actionsgithub-actionsBot added documentation Improvements or additions to documentation dependencies tests labels Jul 15, 2026
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Main entry (gzip)27.5 KB350 KB
Entry fileindex-Dx8Oqof3.js
StatusPASS

📦 Bundle Size Report

PackageSizeGzipped
app-shell (index.js)8.17KB2.95KB
app-shell (runtime-config.js)7.42KB2.32KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)7.57KB2.97KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)21.70KB4.21KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.12KB3.41KB
auth (LoginForm.js)17.12KB5.00KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.63KB2.15KB
auth (SocialSignInButtons.js)9.60KB3.89KB
auth (UserMenu.js)3.40KB1.22KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)30.17KB7.28KB
auth (createAuthenticatedFetch.js)3.93KB1.55KB
auth (index.js)1.83KB0.79KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)4.86KB0.85KB
auth (useIsWorkspaceAdmin.js)1.61KB0.85KB
collaboration (CommentThread.js)18.38KB4.49KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)3.65KB1.42KB
collaboration (PresenceProvider.js)2.42KB0.96KB
collaboration (index.js)1.25KB0.53KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)442.41KB95.47KB
core (index.js)1.69KB0.60KB
create-plugin (index.js)9.28KB2.98KB
data-objectstack (index.js)113.70KB28.15KB
fields (index.js)202.54KB49.50KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.32KB1.77KB
i18n (index.js)2.46KB0.96KB
i18n (pickLocalized.js)1.70KB0.83KB
i18n (provider.js)5.37KB1.72KB
i18n (useObjectLabel.js)21.22KB4.69KB
i18n (useSafeTranslation.js)2.68KB0.98KB
layout (index.js)38.45KB10.67KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.74KB
mobile (index.js)1.50KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)4.42KB1.27KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.71KB0.42KB
mobile (useResponsiveConfig.js)1.36KB0.63KB
mobile (useSpecGesture.js)1.77KB0.77KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)5.09KB1.84KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)3.46KB1.03KB
permissions (evaluator.js)4.00KB1.23KB
permissions (index.js)0.91KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.52KB
permissions (usePermissions.js)1.50KB0.70KB
plugin-ai (index.js)15.71KB3.79KB
plugin-calendar (index.js)45.12KB12.34KB
plugin-charts (index.js)46.31KB13.06KB
plugin-chatbot (index.js)176.76KB42.28KB
plugin-dashboard (index.js)108.35KB26.87KB
plugin-designer (index.js)213.94KB43.03KB
plugin-detail (index.js)210.51KB50.88KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)104.26KB25.24KB
plugin-gantt (index.js)149.17KB37.17KB
plugin-grid (index.js)172.52KB45.58KB
plugin-kanban (index.js)48.16KB12.94KB
plugin-list (index.js)99.07KB23.46KB
plugin-map (index.js)16.80KB5.24KB
plugin-markdown (index.js)13.65KB4.67KB
plugin-report (index.js)37.82KB9.96KB
plugin-timeline (index.js)25.37KB7.20KB
plugin-tree (index.js)8.36KB2.81KB
plugin-view (index.js)85.54KB20.82KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.55KB0.67KB
providers (UploadProvider.js)11.71KB3.53KB
providers (index.js)0.44KB0.22KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)3.19KB1.38KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)18.70KB6.09KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)0.79KB0.43KB
sdui-parser (codegen.js)4.09KB1.74KB
sdui-parser (index.js)2.16KB0.94KB
sdui-parser (parse.js)10.04KB2.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)4.69KB1.48KB
tenant (TenantContext.js)0.31KB0.25KB
tenant (TenantGuard.js)1.04KB0.43KB
tenant (TenantProvider.js)2.76KB0.98KB
tenant (TenantScopedQuery.js)0.77KB0.44KB
tenant (index.js)0.75KB0.38KB
tenant (resolver.js)2.64KB0.76KB
tenant (useTenant.js)0.50KB0.32KB
tenant (useTenantBranding.js)0.62KB0.39KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)0.77KB0.41KB
types (disclosure.js)0.20KB0.18KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (index.js)1.54KB0.68KB
types (layout.js)0.20KB0.18KB
types (mobile.js)0.20KB0.18KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.26KB1.96KB
types (tenant.js)0.20KB0.18KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)0.75KB0.46KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-zhuang
os-zhuang marked this pull request as ready for review July 15, 2026 15:15
@os-zhuang
os-zhuang merged commit cee5d6e into mainJul 15, 2026
10 checks passed
@os-zhuang
os-zhuang deleted the claude/cel-rls-authoring-safety-29hqiy branch July 15, 2026 15:16
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesdocumentationImprovements or additions to documentationtests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat(app-shell): CEL authoring safety for RLS policies — lint, field autocomplete, test-run

2 participants

@os-zhuang@claude