Skip to content

feat: gate detail/form edit & delete on the server's effective operation set (#3546) - #2832

Merged
os-zhuang merged 1 commit into
mainfrom
claude/detail-form-effective-ops-3546
Jul 27, 2026
Merged

feat: gate detail/form edit & delete on the server's effective operation set (#3546)#2832
os-zhuang merged 1 commit into
mainfrom
claude/detail-form-effective-ops-3546

Conversation

@os-zhuang

Copy link
Copy Markdown
Contributor

背景

框架 #3391 的独立 follow-up ③(前端,objectui 仓;对应 objectstack#3546)。

PR-4(objectui#2823)让列表/工具栏面(ObjectView Import、ListView/ObjectGrid Export)接入了服务端下发的 effective 操作集(/me/permissionsapiOperations,经 resolveCrudAffordances(obj, effectiveApiOperations?) 第二参交集)。detail / form 面的 edit/delete 此前仍只按 resolveCrudAffordances(obj)(bucket + userActions)判定,不与服务端 effective 集交集。本 PR 把同一交集扩展到 detail/form 面,使记录页及其表单永不提供服务端会 405 的 edit/delete/create

改动

  • coreisObjectInlineEditable(obj, effectiveApiOperations?) 获得与 resolveCrudAffordances 相同的可选第二参 —— inline-edit 现在额外与服务端 update 取交集。
  • app-shellRecordDetailView 把该对象的 effective 操作集传入 header 合成的 Edit/Delete 动作与记录体 inline-edit 门(canEdit);RelatedRecordActionsBridge 把每个子对象的 Create/Edit/Delete handler 与该子对象自身的 effective 集取交集。
  • plugin-detailrecord:details 的 inline-edit 与 effective update 取交集。
  • plugin-formObjectForm 的托管对象整表字段锁,在服务端拒绝 update(edit 模式)/ create(create 模式)时同样生效。

契约 / 兼容

向后兼容:effective 集缺失(全开对象、旧后端、或未挂 PermissionProvider)时,保持 bucket + userActions 的判定不变(即今天的行为)。叠加在既有的 per-object check('edit') / check('delete') 权限门之上(取交集,永不取并集)。

测试

  • coreisObjectInlineEditable 的 effective-ops 用例:含/不含 update、空集、undefined 回退、bucket 已禁则服务端授权也不再开启。
  • app-shell 新增 RelatedRecordActionsBridge 组件测试:在 full-CRUD / read-only / update-only / undefined 四种 effective 集下断言 Create/Edit/Delete 按钮的显隐。
  • 既有 record-details / ObjectForm.managedEdit / crudAffordances 套件回归通过;core / plugin-detail / plugin-form / app-shell 构建(tsc + dts)全绿。

关联

  • objectstack#3391(跟踪)/ objectstack#3546(本 follow-up)/ objectui#2823(PR-4,已铺路)。

🤖 Generated with Claude Code

https://claude.ai/code/session_012L8EfEa157Pe6C73qRnaJH


Generated by Claude Code

Extend the #3391 PR-4 effective-operation intersection from the list/toolbar
surface to the detail/form surfaces, so a record page and its forms never offer
an edit/delete/create operation the server would 405.
- core: isObjectInlineEditable(obj, effectiveApiOperations?) gains the same
optional 2nd arg as resolveCrudAffordances — inline-edit ANDs with server
`update`.
- app-shell RecordDetailView: thread effective ops into the synthesized
Edit/Delete header actions and the record-body inline-edit `canEdit` gate.
- app-shell RelatedRecordActionsBridge: intersect each child object's
Create/Edit/Delete handlers with that child's own effective set.
- plugin-detail record:details: AND inline-edit with effective `update`.
- plugin-form ObjectForm: blanket managed-object field lock also engages when
the server denies `update` (edit) / `create` (create).
Backward-compatible: missing effective set (unrestricted / old backend / no
PermissionProvider) leaves the bucket+userActions decision untouched. Layers on
top of the existing check('edit')/check('delete') gates (intersection).
Tests: core isObjectInlineEditable effective-ops cases; a RelatedRecordActions
Bridge component test asserting Create/Edit/Delete button visibility under
full-CRUD / read-only / update-only / undefined effective sets.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012L8EfEa157Pe6C73qRnaJH
@vercel

vercelBot commented Jul 27, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
objectuiIgnoredIgnoredJul 27, 2026 4:47am

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Main entry (gzip)28.0 KB350 KB
Entry fileindex-hHvj2HLp.js
StatusPASS

📦 Bundle Size Report

PackageSizeGzipped
app-shell (index.js)8.20KB2.97KB
app-shell (runtime-config.js)7.42KB2.32KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)7.57KB2.97KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)21.70KB4.21KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.12KB3.41KB
auth (LoginForm.js)17.86KB5.29KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.43KB2.09KB
auth (SocialSignInButtons.js)9.60KB3.89KB
auth (UserMenu.js)3.40KB1.22KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)33.74KB8.53KB
auth (createAuthenticatedFetch.js)4.37KB1.69KB
auth (index.js)1.83KB0.79KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)4.86KB0.85KB
auth (useIsWorkspaceAdmin.js)1.61KB0.85KB
collaboration (CommentThread.js)18.38KB4.49KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)3.65KB1.42KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.25KB0.53KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)450.70KB98.15KB
core (index.js)1.86KB0.63KB
create-plugin (index.js)9.28KB2.98KB
data-objectstack (index.js)127.29KB31.96KB
fields (index.js)214.60KB52.67KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.32KB1.77KB
i18n (index.js)2.46KB0.96KB
i18n (pickLocalized.js)1.70KB0.83KB
i18n (provider.js)5.37KB1.72KB
i18n (useObjectLabel.js)25.17KB5.80KB
i18n (useSafeTranslation.js)2.87KB1.28KB
layout (index.js)38.45KB10.67KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.74KB
mobile (index.js)1.50KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)4.42KB1.27KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.71KB0.42KB
mobile (useResponsiveConfig.js)1.36KB0.63KB
mobile (useSpecGesture.js)1.77KB0.77KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)6.84KB2.42KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)3.67KB1.12KB
permissions (evaluator.js)4.00KB1.23KB
permissions (index.js)0.91KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.52KB
permissions (usePermissions.js)1.55KB0.71KB
plugin-ai (index.js)15.71KB3.79KB
plugin-calendar (index.js)45.37KB12.48KB
plugin-charts (index.js)46.90KB13.26KB
plugin-chatbot (index.js)179.53KB42.79KB
plugin-dashboard (index.js)108.71KB28.00KB
plugin-designer (index.js)210.92KB42.69KB
plugin-detail (index.js)214.81KB52.43KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)103.53KB25.12KB
plugin-gantt (index.js)162.33KB39.53KB
plugin-grid (index.js)176.51KB46.38KB
plugin-kanban (index.js)47.82KB13.18KB
plugin-list (index.js)98.71KB23.32KB
plugin-map (index.js)16.80KB5.24KB
plugin-markdown (index.js)13.65KB4.67KB
plugin-report (index.js)37.07KB9.81KB
plugin-timeline (index.js)25.37KB7.20KB
plugin-tree (index.js)8.36KB2.81KB
plugin-view (index.js)85.70KB20.87KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.55KB0.67KB
providers (UploadProvider.js)11.71KB3.53KB
providers (index.js)0.44KB0.22KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)3.19KB1.38KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)18.70KB6.09KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)1.00KB0.55KB
sdui-parser (codegen.js)4.09KB1.74KB
sdui-parser (index.js)2.16KB0.94KB
sdui-parser (parse.js)10.04KB2.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)4.69KB1.48KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)0.77KB0.41KB
types (disclosure.js)0.20KB0.18KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (index.js)1.97KB0.93KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)0.20KB0.18KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.04KB1.93KB
types (system-fields.js)2.39KB1.17KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)0.75KB0.46KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-zhuang
os-zhuang marked this pull request as ready for review July 27, 2026 05:49
@os-zhuang
os-zhuang merged commit f9bbddb into mainJul 27, 2026
14 checks passed
@os-zhuang
os-zhuang deleted the claude/detail-form-effective-ops-3546 branch July 27, 2026 05:49
os-zhuang added a commit that referenced this pull request Jul 28, 2026
…e operation set (objectstack#3720) (#2889)
The fourth surface objectstack#3391 left open. The toolbar (#2823), detail/form
(#2832 + #2876) and related lists (#2832) all route through `resolveCrudAffordances`;
the main list's row CRUD has its own resolver and none of those rounds reached it.
Its gate was `operations ?? { update: !!onEdit, delete: !!onDelete }`, and ObjectView
wires onEdit/onDelete unconditionally while view JSON rarely declares `operations` —
so it was effectively always-on. A caller whose effective set carried neither `update`
nor `delete` still got the row kebab's Edit/Delete and the bulk delete.
- plugin-grid `resolveRowCrudAffordances` takes `managedBy` + `effectiveApiOperations`
and resolves the object verdict through the shared `resolveCrudAffordances` policy,
so the row gate is the same decision every other face makes. It also returns
`objectCanDelete` — bulk delete rides `onBulkDelete`, a different callback from the
row `onDelete`, so it must not be judged by whether the row handler happens to be wired.
- plugin-grid `ObjectGrid` threads its existing `effectiveApiOps` (until now fed only to
Export) into the row gate, and applies the delete verdict to bulk delete: the implicit
`['delete']`, a declared `bulkActions: ['delete']`, and any `bulkActionDefs` entry with
`operation: 'delete'`. Custom ids and non-delete operations pass through untouched.
- plugin-list `ListView`'s own bulk bar (the non-grid views) drops its built-in `delete`
under the same verdict.
Also closes the ADR-0103 gap on this chain: the bucket lock was documented as applied
upstream via the view's `operations.*`, but the all-open default meant it never was —
an engine-owned system / append-only / better-auth object leaked a generic row
Edit/Delete the engine rejects. A `userActions` opt-in still re-opens it.
Intersection, never union. A missing effective set preserves current behavior.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@os-zhuang@claude