Skip to content

fix(data-objectstack,core): an object filter no longer depends on whether the query expands a lookup - #3084

Merged
os-zhuang merged 1 commit into
mainfrom
claude/object-filter-single-route
Jul 31, 2026
Merged

fix(data-objectstack,core): an object filter no longer depends on whether the query expands a lookup#3084
os-zhuang merged 1 commit into
mainfrom
claude/object-filter-single-route

Conversation

@os-zhuang

Copy link
Copy Markdown
Contributor

The last untouched half of the adapter's two find() routes. #3072 single-sourced the array branch; the object branch still had convertQueryParams converting a MongoDB-style filter to AST while translateFilterToAST returned it verbatim — so the same $filter went out in two formats, decided by whether the query happened to expand a lookup.

Sizing it before fixing it

I measured all 21 operator shapes through both routes, comparing the server-side predicate each ends at. Four diverged — and most of the gap was harmless, which was not obvious beforehand and is worth recording:

shapeverdict
{$and: […]} (dashboard scope filters, via mergeFilters)benign — survives the plain route as ['$and','=',[…]], which parseFilterAST reads back as a real $and. I expected this to be a third bug; it isn't.
$exists vs $nullbenign — the plain route inverts to $null, the server treats them identically
unknown operatorreal
$regexreal

The two that mattered

The unknown-operator guard only ran on one route.convertFiltersToAST throws on an unrecognised operator, with a comment stating it does so "to avoid silent failure". The expanded route never called it — so a typo'd operator threw on a plain read and shipped silently whenever a lookup was expanded. The guard was bypassed by exactly the condition it should have been indifferent to.

$regex was silently rewritten to contains. The existing test's own example makes the case better than prose could:

{name: {$regex: '^John'}}// "starts with John"// became['name','contains','^John']// looks for a literal caret — "John Smith" does NOT match

A different question, not a weaker version of the same one, and neither result looks wrong on screen. The rewrite sat behind a console.warn — not an error channel in a deployed app — and the function's own unknown-operator error message never listed $regex among the supported operators, so the code disagreed with itself. The spec has no $regex (FILTER_OPERATORS, data/filter.zod.ts), so there is nothing to translate it into. It is refused now, the same treatment the neighbouring unknown operator already got. Nothing in the repo depended on the conversion.

Bonus: the refusals stopped blaming the network

Both now throw FilterOperatorError with code: 'INVALID_FILTER' / httpStatus: 400. The pre-existing unknown-operator throw was a bare Error, which classifyLoadError classifies as a network fault — so a malformed filter told the user to check their connection (#3066). That was latent before this PR.

A test that asserted the old behaviour

filter-converter.test.ts pinned $regex → contains including the console.warn. Rewritten to assert the refusal, keeping the '^John' example — it documents the harm better than any comment.

Verification

9 new/changed tests. Reverting the two source files fails 9 of them. Both routes are driven for every case rather than the helper being called directly. Full suite 762 files / 8875 tests green; tsc clean; eslint 0 errors.

Refs #3072, #3081, #3066

🤖 Generated with Claude Code

…ther the query expands a lookup
#3072 single-sourced the ARRAY branch of the adapter's two `find()` routes. The
object branch was left as it was: `convertQueryParams` converted a MongoDB-style
filter to AST while `translateFilterToAST` returned it verbatim — so the same
`$filter` went out in two formats, decided by whether the query happened to
expand a lookup.
Measured across 21 operator shapes, four diverged. Most of the gap turned out to
be harmless, which is worth recording because it was not obvious: `{$and: […]}`
survives the plain route as a `['$and','=',[…]]` comparison that `parseFilterAST`
reads back as a real `$and`, and `$exists` vs `$null` is a difference the server
treats identically. Two were not harmless:
- THE UNKNOWN-OPERATOR GUARD ONLY RAN ON ONE ROUTE. `convertFiltersToAST` throws
on an unrecognised operator, with a comment saying it does so "to avoid silent
failure" — but the expanded route never called it, so a typo'd operator threw
on a plain read and shipped silently whenever a lookup was expanded.
- `$regex` WAS SILENTLY REWRITTEN TO `contains`. The existing test's own example
makes the case: `$regex: '^John'` means "starts with John", while
`contains '^John'` looks for a literal caret — so "John Smith" does not match.
A different question, not a weaker version of the same one, and neither result
looks wrong on screen. The rewrite sat behind a `console.warn`, which is not
an error channel in a deployed app, and the function's own unknown-operator
message never listed `$regex` among the supported set. The spec has no
`$regex` (`FILTER_OPERATORS`, data/filter.zod.ts), so there is nothing to
translate it into: it is refused now, the same treatment the neighbouring
unknown operator already got. Nothing in the repo depended on the conversion.
Both refusals throw `FilterOperatorError` carrying `code: 'INVALID_FILTER'` /
`httpStatus: 400`. The pre-existing unknown-operator throw was a bare `Error`,
which `classifyLoadError` reads as a network fault — so a malformed filter told
the user to check their connection (#3066), the one thing it was not.
`filter-converter.test.ts`'s `$regex` case asserted the old behaviour and is
rewritten to assert the refusal, keeping the `'^John'` example because it
demonstrates the harm better than any prose.
Verification: 9 new/changed tests; reverting the two source files fails 9 of
them. Full suite 762 files / 8875 tests green; tsc clean; eslint 0 errors.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@vercel

vercelBot commented Jul 31, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
objectuiIgnoredIgnoredJul 31, 2026 1:21am

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Main entry (gzip)27.9 KB350 KB
Entry fileindex-DVwDskhx.js
StatusPASS

📦 Bundle Size Report

PackageSizeGzipped
app-shell (index.js)8.26KB2.99KB
app-shell (runtime-config.js)7.42KB2.32KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)7.57KB2.97KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)22.10KB4.37KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.12KB3.41KB
auth (LoginForm.js)17.86KB5.29KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.43KB2.09KB
auth (SocialSignInButtons.js)9.60KB3.89KB
auth (UserMenu.js)3.40KB1.22KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)35.76KB9.11KB
auth (createAuthenticatedFetch.js)4.37KB1.69KB
auth (index.js)2.35KB1.07KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)4.91KB0.87KB
auth (useIsWorkspaceAdmin.js)1.61KB0.85KB
collaboration (CommentThread.js)18.38KB4.49KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)3.65KB1.42KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.25KB0.53KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)471.25KB102.82KB
core (index.js)2.16KB0.78KB
create-plugin (index.js)9.28KB2.98KB
data-objectstack (index.js)136.34KB34.64KB
fields (index.js)222.07KB54.35KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.32KB1.77KB
i18n (index.js)2.46KB0.96KB
i18n (pickLocalized.js)1.70KB0.83KB
i18n (provider.js)5.37KB1.72KB
i18n (useObjectLabel.js)25.17KB5.80KB
i18n (useSafeTranslation.js)3.26KB1.44KB
layout (index.js)38.45KB10.67KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.74KB
mobile (index.js)1.50KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.71KB0.42KB
mobile (useResponsiveConfig.js)1.36KB0.63KB
mobile (useSpecGesture.js)4.05KB1.53KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)8.76KB3.06KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)3.67KB1.12KB
permissions (evaluator.js)4.41KB1.44KB
permissions (index.js)0.91KB0.41KB
permissions (retry.js)3.48KB1.61KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.52KB
permissions (usePermissions.js)1.55KB0.71KB
plugin-ai (index.js)15.71KB3.79KB
plugin-calendar (index.js)44.90KB12.35KB
plugin-charts (index.js)60.52KB17.11KB
plugin-chatbot (index.js)180.09KB42.72KB
plugin-dashboard (index.js)111.59KB28.74KB
plugin-designer (index.js)210.51KB42.50KB
plugin-detail (index.js)221.81KB54.28KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)110.71KB26.67KB
plugin-gantt (index.js)162.26KB39.53KB
plugin-grid (index.js)182.21KB48.24KB
plugin-kanban (index.js)47.82KB13.18KB
plugin-list (index.js)103.85KB24.80KB
plugin-map (index.js)16.80KB5.24KB
plugin-markdown (index.js)13.65KB4.67KB
plugin-report (index.js)40.32KB10.53KB
plugin-timeline (index.js)25.75KB7.32KB
plugin-tree (index.js)8.36KB2.81KB
plugin-view (index.js)85.79KB20.99KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.71KB3.53KB
providers (index.js)0.44KB0.22KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.67KB2.37KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)19.28KB6.38KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)1.02KB0.55KB
sdui-parser (codegen.js)4.09KB1.74KB
sdui-parser (index.js)3.47KB1.54KB
sdui-parser (parse.js)10.04KB2.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)4.69KB1.48KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.87KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (index.js)2.07KB0.99KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)0.20KB0.18KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)1.08KB0.64KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-zhuang
os-zhuang merged commit ad0183a into mainJul 31, 2026
16 checks passed
@os-zhuang
os-zhuang deleted the claude/object-filter-single-route branch July 31, 2026 01:28
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@os-zhuang