Skip to content

fix(app-shell): Studio read-only packages stop advertising writability they do not have (#4036 B-half) - #4341

Merged
yinlianghui merged 1 commit into
mainfrom
claude/issue-4036-studio-readonly-affordances
Aug 11, 2026
Merged

fix(app-shell): Studio read-only packages stop advertising writability they do not have (#4036 B-half)#4341
yinlianghui merged 1 commit into
mainfrom
claude/issue-4036-studio-readonly-affordances

Conversation

@yinlianghui

Copy link
Copy Markdown
Collaborator

Part of #4036 — the B-half only. The card stays open: the A-half (whether the 15 overlay-allowed types become individually editable in Studio) is still pending upstream, and this PR leaves every gate exactly as policy-consistent as it found it.

The ruling this implements

objectstack-ai/objectstack#5768, maintainer half-ruling of 2026-08-06 — quoted verbatim and untranslated:

已放行(可拆 sub-issue 先行,不等 A):

  • B 半边:「可写」徽标与「含未保存改动」等误导 affordance 修正——策略、能力、显示三者对不上的显示侧先收敛到当前实际策略(一刀切只读)。

The policy the display is being made to cohere with, from the 裁决 comment in the same thread: Studio 维持包级只读.

So this is display-side only. No enable/disable gating, no save/publish path, and no part of the read-only policy is touched. The A-half review must find the surface exactly as it is today.

Two captions that contradicted the controls beside them

1. The access header badge advertised "writable" above 207 disabled checkboxes

/studio/:pkg/access rendered a permission set's title row as ... · Security · writable · ... while all 207 permission checkboxes and Save below it were disabled with the read-only-package tooltip. Both renderings answer the same question — can you write this? — from different inputs:

  • the controls read !!resolved.allowOrgOverride && !readOnly, i.e. the type registry AND the host package gate, which is the right answer;
  • the badge read entry.allowOrgOverride alone. permission is one of the overlay-allowed types, so that flag is true and the badge said "writable" in every package, read-only or not.

PageShell now accepts a readOnly host gate that dominates the type-level flag, and the Studio Access pillar passes the same value it already hands the matrix's own controls. The tooltip names the package as the reason by reusing the engine.studio.pkg.readonly* wording the Studio top bar and the identity strip already use for this gate, rather than inventing a second spelling for one screen. The badge slot became a single WritabilityBadge component because it was duplicated verbatim in the compact and hero headers — precisely the shape that lets a gate be honoured in one header and forgotten in the other.

2. The Data → Form layout caption claimed unsaved changes that could not exist

In a read-only package the form tab read Draft layout — your unsaved changes with Save draft disabled and no draggable element on the surface at all. The mechanism was not a stale diff: the caption was selected by formMode === 'layout' — a tab selector — so it asserted pending edits on every clean layout tab, read-only or not, while the component's real dirty flag sat a few lines below driving the preview warning. The claim now renders only for real local edits on a surface that can save them; a neutral Draft layout caption (engine.studio.data.form.layoutBadgeClean, added to both locale tables) covers every other case, so the caption still names what you are looking at.

Sweep for the same shape

Same-shape means "a display that answers a gate question from an input that is not the governing gate". On these screens there was nothing else:

  • the Access pillar chrome and the OWD overview panel already branch on readOnly for their own affordances;
  • the OWD panel's unsaved badge and the form tab's preview warning are already derived from real edit state (dirty / hasDraft), not from a tab selector;
  • the metadata directory and resource-list badges read the type registry alone, which is the whole truth in those screens — they are not package-scoped, so there is no host gate for them to disagree with. Different-shaped, correct as they stand.

Tests, and the reverse verification

Two new suites, 9 tests. Predicted directions were written down before the fix was removed, and the run matched exactly: 4 red, 5 green.

Reverting only the four source files to origin/main and keeping the tests:

× read-only package: the header does NOT claim the set is writable
AssertionError: expected [ 'writable', 'History' ] to not include 'writable'
× read-only package: the header reports read-only, naming the package as the reason
AssertionError: expected [ 'writable', 'History' ] to include 'read-only'
× read-only package: no unsaved-changes claim where nothing can be saved
× writable package, nothing edited yet: still no claim
Tests 4 failed | 5 passed (9)

The 5 that stay green are green on purpose, and one of them is an inverted case worth naming rather than dressing up as a red:

  • writable package with real unsaved edits: the claim renders passes before and after. Pre-fix the caption was a constant claim, so of course it renders once you really edit. It is not a red-first test — it is the anti-deletion pin: without it, "suppress the false claim" could be satisfied by deleting the claim outright, taking the caption from always-lying to never-telling.
  • three are control pins on the gating: a read-only package still disables every checkbox, still offers no Save, and still exposes no add-field affordance; a writable package keeps both. A red there would mean this PR had loosened the policy the B-half ruling explicitly preserves — so they must stay green, and they do.

Full ladder, all from the repo root:

  • pnpm exec vitest run --maxWorkers=2 packages/app-shell/src/views/metadata-admin/ packages/app-shell/src/views/studio-design/164 files / 1638 passed, 1 skipped. The PageShell refactor touches every metadata-admin page's chrome, so the sweep is the whole consumption radius of the changed component, not just the two new files.
  • build closure first (--filter '@object-ui/app-shell^...' build), then both tsc projects: tsc --noEmit → exit 0, tsc -p tsconfig.typetests.json → exit 0.
  • eslint on the six changed files → 0 errors, 38 warnings, all pre-existing and byte-identical on origin/main (react-hooks/* on untouched effects, plus one unused Button import in PageShell.tsx that origin/main carries at the same line — not introduced here, and out of scope for this PR).
  • gates: check-control-bytes OK, check-i18n-call-site-keys OK, check-i18n-en-drift (0 en values changed), check-changeset-presence / -fixed / -no-major OK.

A changeset is included: the copy is user-visible.

Continuation note

The original agent on this card was killed by a host restart mid-implementation, leaving six uncommitted files in the worktree and nothing pushed. This PR inherits that work after judging each hunk against the ruling: all six were kept as correct, with the changeset added (it was missing) and the reverse verification and full ladder run here for the first time.


Generated by Claude Code

…y they do not have (#4036)
Two captions on the Studio package surfaces contradicted the controls beside
them. Both are display-side defects — the interaction gating was already
correct in each case, and this change does not touch it.
`/studio/<pkg>/access` rendered a permission set's title row as
`... · Security · writable · ...` while all 207 permission checkboxes and Save
below it were disabled with the read-only-package tooltip. The two renderings
answer the same question from different inputs: the controls read
`!!resolved.allowOrgOverride && !readOnly` (type registry AND host package
gate — the right answer), the badge read `entry.allowOrgOverride` alone, and
`permission` is one of the overlay-allowed types, so the badge said "writable"
in every package. PageShell now takes a `readOnly` host gate that dominates the
type-level flag; the Access pillar passes the same value it already gives the
matrix's controls, and the tooltip names the package as the reason by reusing
the `engine.studio.pkg.readonly*` wording the Studio top bar and identity strip
already use, rather than inventing a second spelling. The badge slot became one
`WritabilityBadge` because it was duplicated verbatim in the compact and hero
headers — the shape that lets a gate be honoured in one and forgotten in the
other.
The `Data -> Form` layout caption read `Draft layout — your unsaved changes`
in a read-only package, with `Save draft` disabled and no draggable element on
the surface. The mechanism was not a stale diff: the caption was selected by
`formMode === 'layout'`, a TAB selector, so it asserted pending edits on every
clean layout tab, read-only or not, while the component's real `dirty` flag sat
a few lines below driving the preview warning. The claim now renders only for
real local edits on a surface that can save them; a neutral `Draft layout`
caption covers every other case.
Nothing about the read-only policy changed. This is the B-half of the
objectstack#5768 split ruling — Studio keeps its blanket package-level
read-only while the A-half is under review — so both suites carry control
tests asserting a read-only package still disables every checkbox, still
offers no Save, and still exposes no add-field affordance.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017Qqyix2QcnpUC9XeYVDzx3
@vercel

vercelBot commented Aug 11, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
objectuiIgnoredIgnoredAug 11, 2026 5:47pm

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Main entry (gzip)29.5 KB350 KB
Entry fileindex-lBgfifzU.js
StatusPASS

📦 Bundle Size Report

PackageSizeGzipped
app-shell (index.js)9.56KB3.59KB
app-shell (runtime-config.js)7.42KB2.32KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)8.92KB3.41KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)22.10KB4.37KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.13KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.64KB2.21KB
auth (SocialSignInButtons.js)9.60KB3.89KB
auth (UserMenu.js)3.40KB1.22KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)35.76KB9.11KB
auth (createAuthenticatedFetch.js)4.37KB1.69KB
auth (index.js)2.35KB1.07KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)4.91KB0.87KB
auth (useIsWorkspaceAdmin.js)1.61KB0.85KB
collaboration (CommentThread.js)26.07KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.65KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)489.12KB108.41KB
core (index.js)3.04KB1.15KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)150.04KB39.79KB
fields (index.js)228.37KB56.62KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.32KB1.77KB
i18n (index.js)3.01KB1.22KB
i18n (pickLocalized.js)1.70KB0.83KB
i18n (provider.js)16.38KB5.47KB
i18n (useDisplayLocale.js)2.33KB1.20KB
i18n (useObjectLabel.js)27.59KB6.63KB
i18n (useSafeTranslation.js)4.52KB1.96KB
layout (index.js)38.98KB10.85KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.74KB
mobile (index.js)1.50KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.71KB0.42KB
mobile (useResponsiveConfig.js)1.36KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)8.75KB3.06KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)3.67KB1.12KB
permissions (evaluator.js)4.41KB1.44KB
permissions (index.js)0.91KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.52KB
permissions (usePermissions.js)1.55KB0.71KB
plugin-ai (index.js)15.71KB3.79KB
plugin-calendar (index.js)45.23KB12.45KB
plugin-charts (index.js)62.18KB17.67KB
plugin-chatbot (index.js)180.33KB42.79KB
plugin-dashboard (index.js)121.56KB31.56KB
plugin-designer (index.js)210.91KB42.67KB
plugin-detail (index.js)238.95KB59.76KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)114.58KB27.68KB
plugin-gantt (index.js)164.14KB39.98KB
plugin-grid (index.js)188.00KB49.94KB
plugin-kanban (index.js)48.60KB13.41KB
plugin-list (index.js)110.10KB26.74KB
plugin-map (index.js)18.05KB5.80KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)40.60KB10.58KB
plugin-timeline (index.js)26.21KB7.52KB
plugin-tree (index.js)8.50KB2.88KB
plugin-view (index.js)84.03KB20.55KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.71KB3.53KB
providers (index.js)0.44KB0.22KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.67KB2.37KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)23.71KB7.96KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)1.23KB0.66KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)4.09KB1.74KB
sdui-parser (index.js)4.47KB2.03KB
sdui-parser (parse.js)10.04KB2.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)4.69KB1.48KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.87KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-retry.js)4.32KB2.02KB
types (index.js)3.05KB1.52KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@yinlianghui@claude