Skip to content

test: pin the detail/form edit/delete gate to the server's effective operation set (#3546) - #2876

Merged
os-zhuang merged 1 commit into
mainfrom
claude/detail-form-edit-delete-backend-dqvxyu
Jul 27, 2026
Merged

test: pin the detail/form edit/delete gate to the server's effective operation set (#3546)#2876
os-zhuang merged 1 commit into
mainfrom
claude/detail-form-edit-delete-backend-dqvxyu

Conversation

@os-zhuang

Copy link
Copy Markdown
Contributor

背景

objectstack#3546 的实现已由 objectui#2832 合入 main —— detail/form 面的 edit/delete 确实已经与服务端 effective 操作集(/me/permissionsapiOperations)取交集。但该 issue 的第三条勾选项(「测试:effective 含/不含 update·delete 时按钮显隐」)只完成了一半:

  • 已有:@object-ui/coreisObjectInlineEditable 单测 + RelatedRecordActionsBridge 组件测试(子对象相关列表)。
  • 缺失:issue 标题点名的三个面本身—— detail header 的 Edit/Delete、记录体 inline-edit 门、form 的整表字段锁 —— 只靠「既有套件回归通过」兜底,没有任何测试真正钉住这三处的接线。

也就是说:在这三处任一处把 resolveCrudAffordances / isObjectInlineEditable 的第二参删掉,合入前的测试全绿。本 PR 补齐这部分覆盖,不改变任何行为。

改动

新增测试(25 例)

  • app-shellRecordDetailView.headerActionGates.test.tsx(11 例)—— 合成的 sys_edit / sys_delete 门,覆盖 full-CRUD / read-only / update-only / delete-only / 空集 / undefined / null 七种 effective 集。
  • plugin-detailrecord-details.effectiveOps.test.tsx(7 例)—— 交给 <DetailView>schema.inlineEdit,含作者 inlineEdit: false opt-out 优先级。
  • plugin-formObjectForm.effectiveOps.test.tsx(7 例)—— 渲染出的 input disabled 实际状态,含 create 模式按 create(而非 update)判定。

三个套件都额外钉住使其成为交集而非并集的两条性质:

  • 服务端授权永不重新打开 bucket 已关闭的 affordance(engine-owned system 即使 effective 全开仍锁);
  • userActions opt-in 永不盖过服务端拒绝(sys_user 开了 edit,但 effective 无 update 时仍锁)。

以及向后兼容:effective 缺失(全开对象 / 旧后端 / 未挂 PermissionProvider)保持 #3546 之前的行为。

生产代码(行为不变)

detail header 的门原本内联在 RecordDetailView 函数体里,而该组件深度耦合 routing / auth / presence / 数据拉取,无法在单测中渲染。故把这一处判定抽成导出的纯函数 resolveRecordHeaderActionGates(objectDef, effectiveApiOperations)——与 ObjectViewdefaultListColumnsFromObject 同一套路。

行为等价:返回的就是它所替换的那次 resolveCrudAffordances(objectDef, effectiveApiOperations)edit / delete 两位;两个调用点(header 合成 + InlineEditProvidercanEdit)原样改调。该函数加入包的 public export 列表,不构成公开 API 变化。

验证

  • 变异验证:在三个调用点分别删掉 effective 操作集实参后,新测试 14 例失败(三个文件全红)—— 证明这些用例钉的是接线本身,而不是在复述 core 的单测。恢复后全绿。
  • 触及包全量套件绿:212 文件 / 1953 用例
  • tsc 构建绿(app-shell / plugin-detail / plugin-form 及其依赖,29 个 task)。
  • eslint 0 error(仅既有 no-explicit-any warning)。

无 changeset

无行为变化、无公开 API 变化,按 AGENTS.md §9(feature 才需要 changeset)不写 changeset。CI 的 changeset-check 只校验 fixed group 配置,不要求每个 PR 带 changeset。

关联

objectstack#3546(本 issue,实现已由 objectui#2832 合入,本 PR 补其测试项)、objectstack#3391(跟踪)、objectui#2823(PR-4)。


Generated by Claude Code

…operation set (#3546)
objectui#2823 (PR-4) intersected the LIST/TOOLBAR affordances with the
server-resolved effective operation set, and objectui#2832 extended that
intersection to the detail/form surfaces. That PR's coverage stopped at
`@object-ui/core`'s `isObjectInlineEditable` plus a RelatedRecordActionsBridge
component test, leaving the three surfaces the issue actually names — the detail
header's Edit/Delete, the record-body inline-edit gate, and the form's blanket
field lock — pinned only by "existing suites still pass". This closes the
issue's last checklist item: button show/hide when the effective set does and
does not carry `update` / `delete`.
- app-shell `RecordDetailView.headerActionGates` (11 cases) — the synthesized
`sys_edit` / `sys_delete` gate across full-CRUD / read-only / update-only /
delete-only / empty / undefined / null effective sets.
- plugin-detail `record-details.effectiveOps` (7 cases) — the `inlineEdit` flag
handed to DetailView, incl. the author `inlineEdit: false` opt-out.
- plugin-form `ObjectForm.effectiveOps` (7 cases) — the rendered input's
`disabled` state, incl. create mode keying off `create` rather than `update`.
Each suite also pins the two properties that make this an INTERSECTION and not
a union: a server grant never re-opens an affordance the lifecycle bucket
closed, and a `userActions` opt-in never survives a server denial. The
`undefined` effective set (unrestricted object / old backend / no
PermissionProvider) is asserted to preserve the pre-#3546 behavior.
To make the header gate reachable from a unit test, its resolution is extracted
from the `RecordDetailView` body into an exported
`resolveRecordHeaderActionGates(objectDef, effectiveApiOperations)` — the same
pattern `ObjectView` uses for `defaultListColumnsFromObject`, since the record
page is wired into routing, auth, presence and data fetching too deeply to
render in a unit test. Behavior-preserving: it returns the `edit` / `delete`
bits of the identical `resolveCrudAffordances(objectDef, effectiveApiOperations)`
call it replaces, and it is not added to the package's public export list. No
changeset — no behavior or public API change.
Verified by mutation: dropping the effective-ops argument at each of the three
call sites fails 14 of the new tests, so they pin the wiring rather than
restating core's unit tests. Full suites for the touched packages green
(212 files / 1953 tests); tsc build green; eslint 0 errors.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YEcwUzbuzU8LM5dk4pYQQA
@vercel

vercelBot commented Jul 27, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
objectuiIgnoredIgnoredJul 27, 2026 3:43pm

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Main entry (gzip)28.0 KB350 KB
Entry fileindex-D5doqI4S.js
StatusPASS

📦 Bundle Size Report

PackageSizeGzipped
app-shell (index.js)8.20KB2.97KB
app-shell (runtime-config.js)7.42KB2.32KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)7.57KB2.97KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)22.10KB4.37KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.12KB3.41KB
auth (LoginForm.js)17.86KB5.29KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.43KB2.09KB
auth (SocialSignInButtons.js)9.60KB3.89KB
auth (UserMenu.js)3.40KB1.22KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)35.76KB9.11KB
auth (createAuthenticatedFetch.js)4.37KB1.69KB
auth (index.js)1.83KB0.79KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)4.91KB0.87KB
auth (useIsWorkspaceAdmin.js)1.61KB0.85KB
collaboration (CommentThread.js)18.38KB4.49KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)3.65KB1.42KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.25KB0.53KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)450.91KB98.17KB
core (index.js)2.12KB0.77KB
create-plugin (index.js)9.28KB2.98KB
data-objectstack (index.js)127.29KB31.96KB
fields (index.js)218.37KB53.54KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.32KB1.77KB
i18n (index.js)2.46KB0.96KB
i18n (pickLocalized.js)1.70KB0.83KB
i18n (provider.js)5.37KB1.72KB
i18n (useObjectLabel.js)25.17KB5.80KB
i18n (useSafeTranslation.js)2.87KB1.28KB
layout (index.js)38.45KB10.67KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.74KB
mobile (index.js)1.50KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)4.42KB1.27KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.71KB0.42KB
mobile (useResponsiveConfig.js)1.36KB0.63KB
mobile (useSpecGesture.js)1.77KB0.77KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)6.84KB2.42KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)3.67KB1.12KB
permissions (evaluator.js)4.00KB1.23KB
permissions (index.js)0.91KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.52KB
permissions (usePermissions.js)1.55KB0.71KB
plugin-ai (index.js)15.71KB3.79KB
plugin-calendar (index.js)45.37KB12.48KB
plugin-charts (index.js)47.20KB13.35KB
plugin-chatbot (index.js)179.53KB42.79KB
plugin-dashboard (index.js)109.60KB28.33KB
plugin-designer (index.js)210.92KB42.69KB
plugin-detail (index.js)215.28KB52.50KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)103.47KB25.10KB
plugin-gantt (index.js)162.33KB39.53KB
plugin-grid (index.js)178.24KB46.72KB
plugin-kanban (index.js)47.82KB13.18KB
plugin-list (index.js)98.71KB23.32KB
plugin-map (index.js)16.80KB5.24KB
plugin-markdown (index.js)13.65KB4.67KB
plugin-report (index.js)37.07KB9.81KB
plugin-timeline (index.js)25.37KB7.20KB
plugin-tree (index.js)8.36KB2.81KB
plugin-view (index.js)85.70KB20.87KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.55KB0.67KB
providers (UploadProvider.js)11.71KB3.53KB
providers (index.js)0.44KB0.22KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)3.19KB1.38KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)18.70KB6.09KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)1.00KB0.55KB
sdui-parser (codegen.js)4.09KB1.74KB
sdui-parser (index.js)2.16KB0.94KB
sdui-parser (parse.js)10.04KB2.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)4.69KB1.48KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)0.77KB0.41KB
types (disclosure.js)0.20KB0.18KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (index.js)1.86KB0.91KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)0.20KB0.18KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.04KB1.93KB
types (system-fields.js)2.39KB1.17KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)0.75KB0.46KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-zhuangos-zhuang changed the title test: 为 detail/form 面 edit/delete 的 effective 操作集交集补齐回归覆盖 (#3546)test: pin the detail/form edit/delete gate to the server's effective operation set (#3546)Jul 27, 2026
@os-zhuang
os-zhuang marked this pull request as ready for review July 27, 2026 15:48
@os-zhuang
os-zhuang merged commit 5141617 into mainJul 27, 2026
14 checks passed
@os-zhuang
os-zhuang deleted the claude/detail-form-edit-delete-backend-dqvxyu branch July 27, 2026 15:48
os-zhuang added a commit that referenced this pull request Jul 28, 2026
…e operation set (objectstack#3720) (#2889)
The fourth surface objectstack#3391 left open. The toolbar (#2823), detail/form
(#2832 + #2876) and related lists (#2832) all route through `resolveCrudAffordances`;
the main list's row CRUD has its own resolver and none of those rounds reached it.
Its gate was `operations ?? { update: !!onEdit, delete: !!onDelete }`, and ObjectView
wires onEdit/onDelete unconditionally while view JSON rarely declares `operations` —
so it was effectively always-on. A caller whose effective set carried neither `update`
nor `delete` still got the row kebab's Edit/Delete and the bulk delete.
- plugin-grid `resolveRowCrudAffordances` takes `managedBy` + `effectiveApiOperations`
and resolves the object verdict through the shared `resolveCrudAffordances` policy,
so the row gate is the same decision every other face makes. It also returns
`objectCanDelete` — bulk delete rides `onBulkDelete`, a different callback from the
row `onDelete`, so it must not be judged by whether the row handler happens to be wired.
- plugin-grid `ObjectGrid` threads its existing `effectiveApiOps` (until now fed only to
Export) into the row gate, and applies the delete verdict to bulk delete: the implicit
`['delete']`, a declared `bulkActions: ['delete']`, and any `bulkActionDefs` entry with
`operation: 'delete'`. Custom ids and non-delete operations pass through untouched.
- plugin-list `ListView`'s own bulk bar (the non-grid views) drops its built-in `delete`
under the same verdict.
Also closes the ADR-0103 gap on this chain: the bucket lock was documented as applied
upstream via the view's `operations.*`, but the all-open default meant it never was —
an engine-owned system / append-only / better-auth object leaked a generic row
Edit/Delete the engine rejects. A `userActions` opt-in still re-opens it.
Intersection, never union. A missing effective set preserves current behavior.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@os-zhuang@claude