Skip to content

fix(fields): the criteria builder stops calling an empty criteria "All records" (objectstack#3896) - #2962

Merged
os-zhuang merged 1 commit into
mainfrom
claude/sharing-rules-schema-bypass-h4c7xr
Jul 29, 2026
Merged

fix(fields): the criteria builder stops calling an empty criteria "All records" (objectstack#3896)#2962
os-zhuang merged 1 commit into
mainfrom
claude/sharing-rules-schema-bypass-h4c7xr

Conversation

@os-zhuang

Copy link
Copy Markdown
Contributor

Renderer half of objectstack#3896 / objectstack-ai/objectstack#3929.

The problem

FilterConditionField renders sys_sharing_rule.criteria_json. With no criteria it displayed "All records", and filterGroupToMongo carried a matching // empty = match all comment.

That was describing a bug as a feature. A sharing rule with no predicate was stored as criteria_json: null and evaluated as find(object, { filter: {} }) under the system context — every record of the object, granted to the recipient. SharingRuleSchema had always forbidden the shape ("never seeded as a permissive match-all", ADR-0049); the REST and data-API entries just never checked.

objectstack#3896 closes those entries: the server now refuses to save such a rule, and one already stored shares nothing. This is the renderer catching up — because a UI that advertises the failure mode is how an admin ends up choosing it deliberately.

Changes

  • The empty read-only state now says the rule shares nothing, in destructive styling. Key renamed fields.filterCondition.allRecordsfields.filterCondition.noCriteria and retranslated across all ten locales. Nothing else read the old key (the other allRecords keys live under list.* / console.objectView.* and are untouched).
  • New fields.filterCondition.criteriaRequired hint under the builder and the JSON editor while the criteria is empty. The server's rejection message is precise, but it only arrives as a toast after Save — the form does not map server fields[] onto per-field errors. This says it while the admin is still looking at the empty builder.
  • isMatchAllCriteria exported — a client-side mirror of the server predicate, covering {}, [] and the vacuous combinators ({ $and: [] }, { $or: [{}] }), conservative in the same direction. The server stays authoritative; this only decides whether the hint shows.
  • The stale // empty = match all comment is corrected.

Unparsable JSON keeps its own invalidJson message and does not also collect the empty-criteria hint.

Why the field is not marked required

Worth stating, since it is the obvious first instinct. sys_sharing_rule.criteria_json is nullable in every deployed tenant (rows predating the server gate), so required: true in the object metadata would translate into a destructiveNOT NULL migration that those very nulls block — objectstack's schema-drift.ts classifies it severity: error / category: destructive.

requiredWhen was the other candidate and was rejected too: objectstack evaluates it server-side against the merged record on update, so it would block editing or backfilling a legacy criteria-less row — including the fulledit access-level backfill — a wider blast radius than the bug. The invariant is enforced in objectstack's write guards (defineRule + a sys_sharing_rulebeforeInsert hook); this PR makes the UI stop contradicting it.

Verification

  • New FilterConditionField.matchAll.test.ts pins the client predicate against the shapes the server rejects, and against the ones it must let through.
  • packages/fields + packages/i18n: 51 files, 607 tests, all passing.type-check clean; eslint reports 0 errors on the changed files (remaining warnings are pre-existing, in untouched lines).

Merge order

Safe to merge independently — this PR only changes copy and adds a hint. It is most useful after objectstack#3929, since that is what makes "cannot be saved" true.


Generated by Claude Code

…l records"
`FilterConditionField` renders `sys_sharing_rule.criteria_json`. With no
criteria it displayed "All records", and `filterGroupToMongo` carried a
matching `// empty = match all` comment. That described a bug as a feature: a
sharing rule with no predicate was stored as `criteria_json: null` and
evaluated as `find(object, { filter: {} })` under the system context — every
record of the object, granted to the recipient. `SharingRuleSchema` had always
forbidden the shape ("never seeded as a permissive match-all", ADR-0049); the
REST and data-API entries just never checked.
objectstack#3896 closes those entries — the server now refuses to save such a
rule, and one already stored shares nothing. This is the renderer catching up,
because a UI that advertises the failure mode is how an admin ends up choosing
it on purpose.
- The empty read-only state says the rule shares nothing, in destructive
styling. Key renamed `fields.filterCondition.allRecords` →
`.noCriteria`, retranslated across all ten locales; nothing else read it.
- New `.criteriaRequired` hint under the builder and the JSON editor while the
criteria is empty. The server's rejection is precise but only arrives as a
toast after Save; this says it while the admin is still looking at the empty
builder.
- `isMatchAllCriteria` exported — a client mirror of the server predicate
covering `{}`, `[]`, and the vacuous combinators, conservative in the same
direction. The server stays authoritative; this only gates the hint.
Unparsable JSON keeps its own `invalidJson` message and does not also collect
the empty-criteria hint.
The field is deliberately NOT marked `required` in the object metadata:
`criteria_json` is nullable in deployed tenants, so `required: true` would only
produce a destructive NOT NULL migration those nulls block. The invariant lives
in the server's write guards; this stops the UI contradicting it.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QuViRSR1j6GJjf9qGbnqFX
@vercel

vercelBot commented Jul 29, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
objectuiIgnoredIgnoredJul 29, 2026 10:45am

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Main entry (gzip)27.9 KB350 KB
Entry fileindex-BFB7ivqK.js
StatusPASS

📦 Bundle Size Report

PackageSizeGzipped
app-shell (index.js)8.20KB2.97KB
app-shell (runtime-config.js)7.42KB2.32KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)7.57KB2.97KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)22.10KB4.37KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.12KB3.41KB
auth (LoginForm.js)17.86KB5.29KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.43KB2.09KB
auth (SocialSignInButtons.js)9.60KB3.89KB
auth (UserMenu.js)3.40KB1.22KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)35.76KB9.11KB
auth (createAuthenticatedFetch.js)4.37KB1.69KB
auth (index.js)2.25KB1.01KB
auth (org-roles.js)6.72KB2.85KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)4.91KB0.87KB
auth (useIsWorkspaceAdmin.js)1.61KB0.85KB
collaboration (CommentThread.js)18.38KB4.49KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)3.65KB1.42KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.25KB0.53KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)450.02KB97.88KB
core (index.js)2.16KB0.78KB
create-plugin (index.js)9.28KB2.98KB
data-objectstack (index.js)129.13KB32.55KB
fields (index.js)221.06KB54.17KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.32KB1.77KB
i18n (index.js)2.46KB0.96KB
i18n (pickLocalized.js)1.70KB0.83KB
i18n (provider.js)5.37KB1.72KB
i18n (useObjectLabel.js)25.17KB5.80KB
i18n (useSafeTranslation.js)3.26KB1.44KB
layout (index.js)38.45KB10.67KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.74KB
mobile (index.js)1.50KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)4.42KB1.27KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.71KB0.42KB
mobile (useResponsiveConfig.js)1.36KB0.63KB
mobile (useSpecGesture.js)1.77KB0.77KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)6.84KB2.42KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)3.67KB1.12KB
permissions (evaluator.js)4.41KB1.44KB
permissions (index.js)0.91KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.52KB
permissions (usePermissions.js)1.55KB0.71KB
plugin-ai (index.js)15.71KB3.79KB
plugin-calendar (index.js)44.90KB12.35KB
plugin-charts (index.js)57.26KB16.24KB
plugin-chatbot (index.js)179.93KB42.67KB
plugin-dashboard (index.js)109.60KB28.33KB
plugin-designer (index.js)210.56KB42.56KB
plugin-detail (index.js)216.93KB53.05KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)103.32KB25.08KB
plugin-gantt (index.js)162.26KB39.53KB
plugin-grid (index.js)179.35KB46.97KB
plugin-kanban (index.js)47.82KB13.18KB
plugin-list (index.js)98.19KB23.17KB
plugin-map (index.js)16.80KB5.24KB
plugin-markdown (index.js)13.65KB4.67KB
plugin-report (index.js)37.07KB9.81KB
plugin-timeline (index.js)25.03KB7.11KB
plugin-tree (index.js)8.36KB2.81KB
plugin-view (index.js)85.47KB20.82KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.55KB0.67KB
providers (UploadProvider.js)11.71KB3.53KB
providers (index.js)0.44KB0.22KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)3.19KB1.38KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)18.70KB6.09KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)1.00KB0.55KB
sdui-parser (codegen.js)4.09KB1.74KB
sdui-parser (index.js)2.16KB0.94KB
sdui-parser (parse.js)10.04KB2.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)4.69KB1.48KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)0.77KB0.41KB
types (disclosure.js)0.20KB0.18KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (index.js)1.86KB0.91KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)0.20KB0.18KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.04KB1.93KB
types (system-fields.js)2.39KB1.17KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)0.75KB0.46KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-zhuang
os-zhuang merged commit f8a95e5 into mainJul 29, 2026
16 checks passed
@os-zhuang
os-zhuang deleted the claude/sharing-rules-schema-bypass-h4c7xr branch July 29, 2026 11:05
os-zhuang added a commit that referenced this pull request Jul 29, 2026
#2966)
The server's VALIDATION_FAILED always carried fields[] — one entry per offending field with a human message — and every form dropped it, showing one undirected toast. On a long form the offending field is usually off-screen, so Save appeared to do nothing.
Three layers, each of which was dropping the detail: @object-ui/react gains extractFieldErrors(err), normalising the three shapes the error arrives in (typed ValidationError, the raw client error whose details falls back to the whole response body, and the hand-rolled duck-typed shape); @object-ui/data-objectstack maps a 400 VALIDATION_FAILED onto the ValidationError class that had been exported and never once constructed, and `create` now normalises at all (only `update` did); the form renderer applies entries via form.setError — but only when every rejected field has a visible input, falling through to the banner otherwise so the part the user cannot see inline is still said out loud.
The toast + scroll-and-focus of the first offender is shared with the client-side invalid handler (announceFieldErrors): to the person filling in the form these are the same event — only the referee differs.
Removes the reason for client-side predicate mirroring (#2962): a form no longer has to guess what the server will reject. Non-field failures (403, permission denials) take exactly the path they took before.
14 + 6 new tests; 107 files / 1073 tests green; tsc clean on all three changed packages.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@os-zhuang@claude