Skip to content

feat(studio): render the runtime authoring gate's advisory findings after a save - #4236

Merged
yinlianghui merged 1 commit into
mainfrom
claude/issue-4133-advisory-findings
Aug 11, 2026
Merged

feat(studio): render the runtime authoring gate's advisory findings after a save#4236
yinlianghui merged 1 commit into
mainfrom
claude/issue-4133-advisory-findings

Conversation

@yinlianghui

Copy link
Copy Markdown
Collaborator

Fixes#4133

The gate's advisories ride a 200 — the save succeeded, the row persisted, the version bumped — and objectui discarded them one layer further out than the server used to: MetadataClient.save parsed the response body, returned it as an opaque T, and every call site awaited it for its side effect and dropped the value. objectstack#7435 (89d7b35a7) put them on the wire; this renders them.

Premise check

Verified against the installed rc.6 dist rather than assumed (a runtime safeParse, not a type read):

spec version: 17.0.0-rc.6
SaveMetaItemResponseSchema exported: true
RuntimeAuthoringIssueSchema exported: true
parse WITH advisories -> true
parse WITHOUT advisories -> true advisories key present: false
reverse probe: partial finding REJECTED -> true advisories.0.path | advisories.0.where | …

rulesRun is absent from the response and nothing here expects it.

The call-site map

Every app-shell write path takes its client from useMetadataClient, so that hook — not the ~20 client.save(...) call sites — is where this lifts. Measured, with the save mode each site uses:

call sitemodeadvisories today
ResourceEditPage.tsx:1100 — the main authoring editordraftnone (D1, below)
StudioDesignSurface.tsx — 8 sites, all pillarsdraftnone (D1)
ObjectHooksPanel.tsx, PackageOwdOverviewPanel.tsxdraftnone (D1)
views/runtime-metadata-persistence.tsdraftnone (D1)
EmbeddedItemEditor.tsx:102activerendered
datasource/DatasourceResourcePage.tsx:427activerendered
plugin-designer object / field / app pagesactiverendered (via MetadataClientConfig)

MetadataProvider's client is read-only and never receives one, so it is not wired.

Flow coverage — stated honestly, and pinned

A draft-then-publish flow surfaces nothing today, at both of its doors, for two different reasons — and the first is not the one the card assumed:

  • The save door. Drafts are never gated. The framework returns before running a single rule, at metadata-protocol/src/runtime-authoring-gate.ts:388:
    // D1 — drafts are never gated. Publishing one runs this same function.
    if (args.state !== 'active') return null;
    
    So a draft save produces no findings at all, rather than producing some that are withheld. The client is not what suppresses this; there is nothing to suppress.
  • The publish door. It does run the gate, but PublishMetaItemResponseSchema carries no advisories field until objectstack#7294.

Since Studio's designer saves as draft on every edit, that is the whole designer. a draft save carries no findings — the gate never ran (D1) is the control test asserting the publish path is unchanged.

Shape

Mirrors ObjectStackAdapter.onWriteWarning (#3431/#3455) — the repo's existing seam for exactly this problem: a successful write whose response carries something the author must be told, emitted as an event so the data layer never imports a toaster. Rendering mirrors writeWarningToast.ts (pure builder, caller-owned sink) and the 10s multi-finding toast of preview/usePublishAllDrafts.ts.

Warning tier, never error — the title says "Saved" first, because a successful save that reads as a failure is the defect this surface must not ship. Each finding renders rule + message + hint, with where as secondary context; path is a machine pointer and is omitted. message/hint are server prose, rendered verbatim — only the frame is translated (console.saveAdvisoryTitle, all ten packs). The finding type is re-exported from @objectstack/spec (RuntimeAuthoringIssue), not restated, so it cannot fork from the 422 issues[] it shares a declaration with.

Malformed findings are dropped rather than printed as blanks, and a throwing renderer cannot turn a committed save into an error.

Reverse verification

Direction predicted before running: removing the emit restores "parse and discard", so the pins asserting an event arrives go red and the absence-asserting ones cannot see it.

Measured, exactly as predicted — 5 red / 20 green:

× emits the findings a successful save returned
× carries rule, message and hint through verbatim — they are server prose
× labels the mode when a draft save does somehow advise
× survives the withEnvironment clone — console clients are all env-scoped
× survives the withPreviewDrafts clone
Tests 5 failed | 20 passed (25)

Worth recording: saveAdvisoryToast.test.ts stayed fully green through the revert. It exercises the pure builder, not the wiring — those tests alone would not catch this regression, which is what the data-layer emit pins carry. The clone pins are there because useMetadataClient routes every console client through withEnvironment; dropping the sink there would have disabled the channel silently.

Tests

packages/data-objectstack 28 files, 408 tests PASS
app-shell providers + metadata-admin + ratchet 147 files, 1488 tests PASS
i18n all-locales-key-parity 20 tests PASS
check:i18n-keys / check:i18n-drift / check:control-bytes PASS
eslint (7 touched files) 0 errors

Pre-existing reds, confirmed not mine

Both comparison-worktreed against clean origin/main (6314e87f2):

  • check:spec-symbols — identical failure set on clean main (5 symbols in @object-ui/types, incl. complex.zod.ts). My RuntimeAuthoringIssue re-export passes the gate.
  • data-objectstack type-check — spec-symbol-batch6.test.ts(208) reproduces with my changes fully reverted via git checkout origin/main --. Cause: rc.6 added a third DroppedFieldsEvent.reason member (primary_key) and the typetest pins two.
  • app-shell type-check — the resolveActionParams.test.ts reds. No error in any file this PR touches.

All belong to the #4169 rc.6 train / PR #4208, not to this change.


Generated by Claude Code

…fter a save
The gate's advisories ride a 200 — the save succeeded, the row persisted — and
objectui discarded them client-side: `MetadataClient.save` parsed the response
body, returned it as an opaque `T`, and every call site awaited it for its side
effect and dropped the value. objectstack#7435 put them on the wire; this
renders them.
`MetadataClient` gains an `onSaveAdvisory` sink, invoked after a save whose
response carried a non-empty `advisories[]`. The console wires it in
`useMetadataClient` — the one hook every app-shell write path takes its client
from — so a single wiring covers ResourceEditPage, StudioDesignSurface,
EmbeddedItemEditor, DatasourceResourcePage and ObjectHooksPanel rather than a
toast copied into twenty call sites. The finding shape is re-exported from
`@objectstack/spec` (`RuntimeAuthoringIssue`) rather than restated, so it cannot
fork from the 422 `issues[]` it shares a declaration with.
The affordance is the warning tier and says "Saved" first: a successful save
that reads as a failure is the defect this surface must not ship. `message` and
`hint` are server prose and render verbatim; only the frame is translated.
Coverage is stated honestly and pinned: drafts are never gated (the framework
returns at its D1 early-return before running a rule), so Studio's designer —
which saves as draft on every edit — surfaces nothing today, and the publish
door returns no advisories until objectstack#7294.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017Qqyix2QcnpUC9XeYVDzx3
@vercel

vercelBot commented Aug 11, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
objectuiIgnoredIgnoredAug 11, 2026 5:27am

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Main entry (gzip)28.3 KB350 KB
Entry fileindex-Bhdq1r6j.js
StatusPASS

📦 Bundle Size Report

PackageSizeGzipped
app-shell (index.js)8.88KB3.25KB
app-shell (runtime-config.js)7.42KB2.32KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)7.57KB2.97KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)22.10KB4.37KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.13KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.64KB2.21KB
auth (SocialSignInButtons.js)9.60KB3.89KB
auth (UserMenu.js)3.40KB1.22KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)35.76KB9.11KB
auth (createAuthenticatedFetch.js)4.37KB1.69KB
auth (index.js)2.35KB1.07KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)4.91KB0.87KB
auth (useIsWorkspaceAdmin.js)1.61KB0.85KB
collaboration (CommentThread.js)26.07KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.65KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)488.60KB108.25KB
core (index.js)3.04KB1.15KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)145.46KB37.89KB
fields (index.js)228.33KB56.58KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.32KB1.77KB
i18n (index.js)2.65KB1.06KB
i18n (pickLocalized.js)1.70KB0.83KB
i18n (provider.js)9.48KB3.27KB
i18n (useObjectLabel.js)27.59KB6.63KB
i18n (useSafeTranslation.js)4.52KB1.96KB
layout (index.js)38.98KB10.85KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.74KB
mobile (index.js)1.50KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.71KB0.42KB
mobile (useResponsiveConfig.js)1.36KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)8.75KB3.06KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)3.67KB1.12KB
permissions (evaluator.js)4.41KB1.44KB
permissions (index.js)0.91KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.52KB
permissions (usePermissions.js)1.55KB0.71KB
plugin-ai (index.js)15.71KB3.79KB
plugin-calendar (index.js)45.23KB12.45KB
plugin-charts (index.js)61.52KB17.49KB
plugin-chatbot (index.js)180.33KB42.79KB
plugin-dashboard (index.js)118.58KB30.71KB
plugin-designer (index.js)210.85KB42.64KB
plugin-detail (index.js)238.21KB59.54KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)114.58KB27.68KB
plugin-gantt (index.js)164.14KB39.98KB
plugin-grid (index.js)187.97KB49.90KB
plugin-kanban (index.js)48.60KB13.41KB
plugin-list (index.js)110.31KB26.76KB
plugin-map (index.js)17.00KB5.32KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)40.58KB10.58KB
plugin-timeline (index.js)26.21KB7.52KB
plugin-tree (index.js)8.50KB2.88KB
plugin-view (index.js)84.03KB20.55KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.71KB3.53KB
providers (index.js)0.44KB0.22KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.67KB2.37KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)23.71KB7.96KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)1.23KB0.66KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)4.09KB1.74KB
sdui-parser (index.js)4.47KB2.03KB
sdui-parser (parse.js)10.04KB2.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)4.69KB1.48KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.87KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-retry.js)4.32KB2.02KB
types (index.js)2.71KB1.34KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@yinlianghui
yinlianghui marked this pull request as ready for review August 11, 2026 05:43
@yinlianghui
yinlianghui added this pull request to the merge queueAug 11, 2026
Merged via the queue into main with commit c0f9a4bAug 11, 2026
21 checks passed
@yinlianghui
yinlianghui deleted the claude/issue-4133-advisory-findings branch August 11, 2026 05:43
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Studio: render the runtime authoring gate's advisory findings returned by saveMetaItem

2 participants

@yinlianghui@claude