Skip to content

fix(app-shell): arm the create deep link on the create action, not on any toolbar action (#4123) - #4166

Merged
yinlianghui merged 1 commit into
mainfrom
claude/issue-4123-autorun-arm-predicate
Aug 10, 2026
Merged

fix(app-shell): arm the create deep link on the create action, not on any toolbar action (#4123)#4166
yinlianghui merged 1 commit into
mainfrom
claude/issue-4123-autorun-arm-predicate

Conversation

@yinlianghui

Copy link
Copy Markdown
Collaborator

Fixes#4123

Premise check

Still valid at origin/main (6b6721ccf). EnvironmentListToolbar.tsx armed on toolbarActions.length > 0 ? ctaKind : null, unchanged since #3803 closed, and #3803's verified consumption ordering (runner executes before the parent strips) is untouched by this PR and re-pinned by a test.

Phase 1 — the open reachability question, answered and measured

The card asked whether toolbarActions and the list action:bar actually renders can genuinely diverge, with the ADR-0066 D4 capability gate as the candidate path. They can, and the divergence is by construction:

  • the toolbar filtered placement only — a?.locations?.includes('list_toolbar');
  • action:bar additionally applies the D4 capability gate to what it renders (action-bar.tsx: actions.filter(a => mayInvoke(a?.requiredPermissions)), then actionRendersAt).

So a create action declaring requiredPermissions the caller lacks is counted by the toolbar and dropped by the bar. Measured with the real renderer + action:bar + action:button (the sibling test file stubs SchemaRenderer, which is precisely why this class was invisible to it):

capability-gated create: urlParam=null execute=0
no create action at all: urlParam=null execute=0

Both reproduce the card's exact measurement. Note this needs no change to cloud metadata to be wrong — the arming condition is simply keyed on the wrong thing, which is what the triage comment said when it promoted the card.

Phase 2 — the fix

One predicate over one list. The toolbar now builds its action list with both of the predicates the bar applies downstream — actionRendersAt plus useCapabilityGate — and arms on the create action's presence in that list:

const toolbarActions = (actions || []).filter(
(a: any) => actionRendersAt(a, 'list_toolbar') && mayInvoke(a?.requiredPermissions),
);
const hasCreateAction = toolbarActions.some((a: any) => a?.name === CREATE_ACTION);
const autoRunCreate = useAutoRunCreate(hasCreateAction ? ctaKind : null);

useCapabilityGate is the shared hook that exists exactly for surfaces filtering their own action lists instead of routing through ActionEngine.getActionsForLocation ("one hook so all three surfaces gate identically and can't drift apart"). This toolbar was a fourth such surface that bypassed it. The bar re-applies both predicates to the list it receives, which is idempotent on an already-filtered list — so arming and rendering cannot disagree by construction rather than by agreement of two copies.

The mechanism is NOT generic, so it was not generalized. The dispatch asked to measure before generalizing ?runAction=X to any action. runAction is read in exactly one place, hard-keyed to CREATE_ACTION; the only generic part is autoTrigger on the action schema, which is the transport, not the URL contract. Generalizing would be inventing a URL-to-action surface with no producer — declined per the startup-focus principle.

The chosen degradation, and why it is the honest one. When arming is unsatisfiable the URL is left alone. Consumption is the strip, so the alternative (strip anyway) destroys a one-shot user intent that nothing can recreate. Leaving it means the next mount that can act on it still does — a reload, or the action arriving with fresh metadata — which is pinned as its own test. The cost is a param that lingers when no create action ever appears; that is cosmetic and, unlike the current behaviour, recoverable.

Consequences of the one list. Two other affordances derive from it and previously disagreed with the bar in the same way:

  • the loading skeleton holds the create button's slot — a capability-gated create action never becomes that button, so holding its slot promised a button that could never arrive;
  • the plan-locked environment-add-upgrade CTA stands in for the create action so a free-plan click opens the upgrade prompt instead of POSTing into a 403. With no create action on the bar there is nothing to stand in for, and it used to render for a toolbar that had no create action at all.

Both now read hasCreateAction. This is deliberately in scope: leaving them on the old list would re-create the two-lists bug the fix exists to remove.

Tests

New file EnvironmentListToolbar.deepLinkArming.test.tsx — 10 cases over the realaction:bar + action:button + runner (handlers: { api } counts executions, a history.replaceState spy records the strip).

Pins, per the card:

  1. the card's measured failure — actions present, create absent → param not swallowed, execute=0, and a later mount with the create action still runs it (recoverability);
  2. the D4-gated case, plus its mirror (caller holds the capability → arms normally, proving the gate is the only thing stopping it);
  3. the happy path unchanged — create present → arms, triggers exactly once, strips;
  4. the finding(app-shell): useAutoRunCreate 在 render 阶段读 ref,?runAction=create_environment 的 autoTrigger 可能被无关 re-render 抹掉 #3803 ordering re-pinned — instrumented events equal ["runner:execute","parent:consumed+strip"];
  5. the skeleton and upgrade-CTA cases above.

Reverse verification, direction predicted before running: reverting only the arming predicate (keeping the gated list) turns exactly 3 pins red, each reproducing the card's signature — ['parent:consumed+strip'] logged with execute never called, and runActionParam() back to null. The other 3 stay green because they are held by the list, not the predicate; that split is the attribution working correctly.

before fix: Tests 6 failed | 4 passed (10)
after fix: Test Files 5 passed (5) | Tests 52 passed (52) # whole environment suite
predicate reverted: Tests 3 failed | 7 passed (10)

Gates (repo root, per AGENTS.md §怎么跑测试):

pnpm exec vitest run packages/app-shell/src/environment/ packages/app-shell/src/console/home/
→ Test Files 9 passed (9) | Tests 68 passed (68)
pnpm exec vitest run packages/app-shell/src/views/ # ObjectView is the caller
→ Test Files 197 passed (197) | Tests 1926 passed | 1 skipped (1927)
pnpm --filter @object-ui/app-shell type-check → clean
pnpm exec eslint (both changed files) → 0 errors
node scripts/check-changeset-presence.mjs → 1 changeset declared
node scripts/check-changeset-no-major.mjs → no major

The residual react-hooks/refs warning at return shouldRun; is pre-existing and left untouched, as #3803's closing note ruled (render-purity smell with no constructible divergence).

Out of scope

Filed #4162 (observation-class, measured): autoTrigger is consumed only by action:button, so an auto-triggered action that spills past action:bar's maxVisible is rendered by action:menu, which ignores the flag — urlParam=null execute=0 again, one layer deeper, and not closed by this PR (the create action is in the post-gate list there, so arming is correct by this predicate; the bar then hands it to a renderer that drops it). The right shape is a design question with at least three candidate answers, so it is filed rather than patched here.


Generated by Claude Code

… any toolbar action (#4123)
`EnvironmentListToolbar` armed `useAutoRunCreate` from `toolbarActions.length > 0`.
Consumption of `?runAction=create_environment` is modelled as stripping the param,
so arming is destructive: a toolbar with any other action stripped the deep link
and triggered nothing (measured with the real action:bar + action:button runner:
urlParam=null execute=0), leaving the intent unrecoverable on reload.
Arming now keys on the create action's presence, and that presence is read from a
list built with BOTH predicates action:bar applies to what it renders --
`actionRendersAt` plus the ADR-0066 D4 capability gate (`useCapabilityGate`). The
toolbar previously filtered placement only, so a create action the caller may not
invoke was counted here and dropped there; one list means arming and rendering
cannot disagree by construction. The loading skeleton and the plan-locked upgrade
CTA, both stand-ins for the create button, follow the same list.
The #3803-verified consumption ordering is untouched and re-pinned: the runner
consumes autoTrigger before the parent strips the param.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017Qqyix2QcnpUC9XeYVDzx3
@vercel

vercelBot commented Aug 10, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
objectuiIgnoredIgnoredAug 10, 2026 3:13pm

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Main entry (gzip)28.3 KB350 KB
Entry fileindex-DUlgZO4u.js
StatusPASS

📦 Bundle Size Report

PackageSizeGzipped
app-shell (index.js)8.66KB3.13KB
app-shell (runtime-config.js)7.42KB2.32KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)7.57KB2.97KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)22.10KB4.37KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.13KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.64KB2.21KB
auth (SocialSignInButtons.js)9.60KB3.89KB
auth (UserMenu.js)3.40KB1.22KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)35.76KB9.11KB
auth (createAuthenticatedFetch.js)4.37KB1.69KB
auth (index.js)2.35KB1.07KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)4.91KB0.87KB
auth (useIsWorkspaceAdmin.js)1.61KB0.85KB
collaboration (CommentThread.js)26.07KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.65KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)485.06KB107.21KB
core (index.js)3.04KB1.15KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)140.66KB36.25KB
fields (index.js)229.40KB56.93KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.32KB1.77KB
i18n (index.js)2.65KB1.06KB
i18n (pickLocalized.js)1.70KB0.83KB
i18n (provider.js)9.48KB3.27KB
i18n (useObjectLabel.js)27.59KB6.63KB
i18n (useSafeTranslation.js)4.52KB1.96KB
layout (index.js)38.87KB10.80KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.74KB
mobile (index.js)1.50KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.71KB0.42KB
mobile (useResponsiveConfig.js)1.36KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)8.75KB3.06KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)3.67KB1.12KB
permissions (evaluator.js)4.41KB1.44KB
permissions (index.js)0.91KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.52KB
permissions (usePermissions.js)1.55KB0.71KB
plugin-ai (index.js)15.71KB3.79KB
plugin-calendar (index.js)45.23KB12.45KB
plugin-charts (index.js)61.52KB17.49KB
plugin-chatbot (index.js)180.33KB42.79KB
plugin-dashboard (index.js)118.52KB30.68KB
plugin-designer (index.js)210.51KB42.51KB
plugin-detail (index.js)237.80KB59.48KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)114.58KB27.68KB
plugin-gantt (index.js)162.81KB39.67KB
plugin-grid (index.js)188.04KB49.91KB
plugin-kanban (index.js)48.60KB13.41KB
plugin-list (index.js)110.04KB26.67KB
plugin-map (index.js)17.00KB5.32KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)40.58KB10.58KB
plugin-timeline (index.js)26.21KB7.52KB
plugin-tree (index.js)8.50KB2.88KB
plugin-view (index.js)84.03KB20.55KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.71KB3.53KB
providers (index.js)0.44KB0.22KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.67KB2.37KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)23.71KB7.95KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)1.23KB0.66KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)4.09KB1.74KB
sdui-parser (index.js)4.47KB2.03KB
sdui-parser (parse.js)10.04KB2.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)4.69KB1.48KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.87KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-retry.js)4.32KB2.02KB
types (index.js)2.71KB1.34KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

2 participants

@yinlianghui@claude