Skip to content

fix(fls): wire real per-caller FLS into import targets and grid columns, drop dead field.permissions shape - #2866

Merged
os-zhuang merged 1 commit into
mainfrom
claude/metadata-field-level-permissions-sr37zy
Jul 27, 2026
Merged

fix(fls): wire real per-caller FLS into import targets and grid columns, drop dead field.permissions shape#2866
os-zhuang merged 1 commit into
mainfrom
claude/metadata-field-level-permissions-sr37zy

Conversation

@os-zhuang

Copy link
Copy Markdown
Contributor

Implements steps ① and ② of objectstack-ai/objectstack#3661 (metadata-plane FLS: dead field.permissions guards).

What changed

① Wire the real per-caller FLS channel (/auth/me/permissions via usePermissions().checkField) into the two surfaces that had none:

  • ImportWizard target fields (app-shell/ObjectView.tsx): the importable field set — and therefore the downloadable CSV template's columns — now drops fields the caller cannot edit (checkField(object, field, 'write')), instead of offering columns the server-side FLS write gate rejects with an explicit 403 (security-plugin.ts step 2.5). Permissive when no permission provider is mounted (!perms?.isLoaded), matching the ListView precedent.
  • ObjectGrid auto-derived columns (plugin-grid/ObjectGrid.tsx): columns the caller cannot read are dropped via checkField(object, field, 'read') — the same gate ListView already applies to its auto-derived columns (ListView.tsx:961).
  • ObjectForm (plugin-form/ObjectForm.tsx): the dead guard in field generation is deleted outright — its output already flows through the real applyFieldPerms gate (checkField read/write), so the dead check was redundant there rather than a gap.

② Remove the never-populated permissions?: { read?, write?, edit? } shape from @object-ui/types (BREAKING):

The shape was Phase 3.2.6 legacy: it exists in no @objectstack/spec schema, has zero producers in either repo, and every guard reading it permanently short-circuited to "allow" — declared ≠ enforced (ADR-0049 enforce-or-remove). Deleting the key makes any future guard written against it a compile error. Rides the major release currently being prepared (a major changeset for the fixed group is already pending).

What this is NOT

  • Not a write-path vulnerability fix — the server already 403s forbidden field writes (ObjectQL security middleware step 2.5). This closes the metadata-disclosure path (template column headers) and the UX trap (template offers columns the import then rejects).
  • Step ③ of the issue (per-caller masking of /meta object schemas) is intentionally not included: per the maintainer, target deployments have no untrusted authenticated callers, so the metadata plane stays unmasked with /auth/me/permissions as the authoritative per-caller channel (to be recorded in an ADR).

Verification

  • turbo run build for the 4 touched packages + dependents: 29/29 green.
  • vitest --project unit: 429 + 1010 tests green; --project dom --project dom-heavy for plugin-form / plugin-grid / app-shell / permissions: 1103 tests green.
  • changeset:check and turbo run lint for touched packages: green.
  • Grep sweep: zero remaining references to the removed shape in code, tests, or docs.

Closes nothing by itself — tracked by objectstack-ai/objectstack#3661 (steps ①②).

🤖 Generated with Claude Code

https://claude.ai/code/session_01AEb4XCVb7iLEBVe9HghjTt


Generated by Claude Code

…ns, drop dead field.permissions shape (objectstack#3661)
The `permissions?: { read?, write?, edit? }` key on field definitions was
declared-but-never-enforced: no producer ever populated it, so all three
guards reading it permanently short-circuited to "allow". Per ADR-0049
enforce-or-remove:
- ImportWizard target fields (ObjectView): filter by the server-resolved
/auth/me/permissions editable bit via usePermissions().checkField, so
the mapping step and the downloadable CSV template stop offering
columns the FLS write gate rejects with 403.
- ObjectGrid auto-derived columns: drop columns the caller cannot read
(same checkField gate ListView already applies).
- ObjectForm: delete the redundant dead guard in field generation — the
existing applyFieldPerms gate is the real enforcement point.
- @object-ui/types: remove the never-populated `permissions` field shape
(BREAKING) so future guards against it fail at compile time.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AEb4XCVb7iLEBVe9HghjTt
@vercel

vercelBot commented Jul 27, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
objectuiIgnoredIgnoredJul 27, 2026 1:46pm

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Main entry (gzip)28.0 KB350 KB
Entry fileindex-CJrZitOs.js
StatusPASS

📦 Bundle Size Report

PackageSizeGzipped
app-shell (index.js)8.20KB2.97KB
app-shell (runtime-config.js)7.42KB2.32KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)7.57KB2.97KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)21.70KB4.21KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.12KB3.41KB
auth (LoginForm.js)17.86KB5.29KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.43KB2.09KB
auth (SocialSignInButtons.js)9.60KB3.89KB
auth (UserMenu.js)3.40KB1.22KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)33.74KB8.53KB
auth (createAuthenticatedFetch.js)4.37KB1.69KB
auth (index.js)1.83KB0.79KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)4.86KB0.85KB
auth (useIsWorkspaceAdmin.js)1.61KB0.85KB
collaboration (CommentThread.js)18.38KB4.49KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)3.65KB1.42KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.25KB0.53KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)450.90KB98.17KB
core (index.js)2.12KB0.77KB
create-plugin (index.js)9.28KB2.98KB
data-objectstack (index.js)127.29KB31.96KB
fields (index.js)218.35KB53.54KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.32KB1.77KB
i18n (index.js)2.46KB0.96KB
i18n (pickLocalized.js)1.70KB0.83KB
i18n (provider.js)5.37KB1.72KB
i18n (useObjectLabel.js)25.17KB5.80KB
i18n (useSafeTranslation.js)2.87KB1.28KB
layout (index.js)38.45KB10.67KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.74KB
mobile (index.js)1.50KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)4.42KB1.27KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.71KB0.42KB
mobile (useResponsiveConfig.js)1.36KB0.63KB
mobile (useSpecGesture.js)1.77KB0.77KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)6.84KB2.42KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)3.67KB1.12KB
permissions (evaluator.js)4.00KB1.23KB
permissions (index.js)0.91KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.52KB
permissions (usePermissions.js)1.55KB0.71KB
plugin-ai (index.js)15.71KB3.79KB
plugin-calendar (index.js)45.37KB12.48KB
plugin-charts (index.js)47.20KB13.35KB
plugin-chatbot (index.js)179.53KB42.79KB
plugin-dashboard (index.js)109.60KB28.33KB
plugin-designer (index.js)210.92KB42.69KB
plugin-detail (index.js)215.28KB52.50KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)103.44KB25.09KB
plugin-gantt (index.js)162.33KB39.53KB
plugin-grid (index.js)178.24KB46.72KB
plugin-kanban (index.js)47.82KB13.18KB
plugin-list (index.js)98.71KB23.32KB
plugin-map (index.js)16.80KB5.24KB
plugin-markdown (index.js)13.65KB4.67KB
plugin-report (index.js)37.07KB9.81KB
plugin-timeline (index.js)25.37KB7.20KB
plugin-tree (index.js)8.36KB2.81KB
plugin-view (index.js)85.70KB20.87KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.55KB0.67KB
providers (UploadProvider.js)11.71KB3.53KB
providers (index.js)0.44KB0.22KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)3.19KB1.38KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)18.70KB6.09KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)1.00KB0.55KB
sdui-parser (codegen.js)4.09KB1.74KB
sdui-parser (index.js)2.16KB0.94KB
sdui-parser (parse.js)10.04KB2.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)4.69KB1.48KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)0.77KB0.41KB
types (disclosure.js)0.20KB0.18KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (index.js)1.86KB0.91KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)0.20KB0.18KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.04KB1.93KB
types (system-fields.js)2.39KB1.17KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)0.75KB0.46KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@os-zhuang@claude