Skip to content

test(app-shell): pin the built-in header Edit under a session-user relation predicate (objectstack#8499) - #4666

Merged
yinlianghui merged 2 commits into
mainfrom
claude/issue-8499-builtin-edit-visiblewhen
Aug 15, 2026
Merged

test(app-shell): pin the built-in header Edit under a session-user relation predicate (objectstack#8499)#4666
yinlianghui merged 2 commits into
mainfrom
claude/issue-8499-builtin-edit-visiblewhen

Conversation

@yinlianghui

Copy link
Copy Markdown
Collaborator

Fixesobjectstack-ai/objectstack#8499

Premise falsified — the behaviour already ships; the pin did not

The card was measured on @objectstack/*@17.0.0-rc.6. On current main (17.5.0) the console record header's built-in Edit already honors userActions.edit.visibleWhen: RecordDetailView.tsx evaluates it into editVisible and consumes it as a fourth conjunct of the sys_edit affordance gate. So this PR adds no behaviour change — it adds the regression pin for the card's exact repro shape, which no test covered.

Provenance — the wiring landed between rc.6 and 17.5.0, on both detail surfaces:

SurfaceFileLanded by
Console record pagepackages/app-shell/src/views/RecordDetailView.tsxPR #4524 (objectui#4213), merged 2026-08-13
DetailView headerpackages/plugin-detail/src/DetailView.tsxPR #4515 (objectui#4419), merged 2026-08-13

The mobile overflow twin (sys_edit_mobile, plugin-detail) is gated by the same schema.showEdit that carries editVisible, so it converges too.

The real gap: the card's predicate shape was untested on the built-in path

The card's declaration reads the session user against a relation field:

userActions: {edit: {visibleWhen: 'os.user.id != record.executor'},delete: {visibleWhen: 'os.user.id != record.executor'},}

Two existing pins bracket that shape without covering it, from opposite sides:

  • RecordDetailView.userActionPredicates.test.tsx (objectui#4213) drives the built-in path, but only with self-contained record.status string compares. It mounts no ExpressionProvider, so os.user is bound nowhere in it — a predicate reading the session user had never been evaluated on this path.
  • RecordDetailView.headerActionLookupPredicate.test.tsx (test(app-shell): pin relation-field header-action predicates on the console record page #4641 / objectstack#8500) drives os.user.id against a relation field, but only through declaredrecord_header actions — a different consumption seam, deliberately not the built-in one.

The card sits on the intersection, which is why it could be reported against a build that already carried the fix.

Why every case is a discriminating pair

visibleWhen fails CLOSED. An unbound os.user, a faulting compare, or a relation bound to the wrong side all hide the button — the same DOM as a correct evaluation, for the opposite reason. A pin asserting only absence would stay green if the predicate stopped being evaluated at all.

So each case pairs both directions on one declaration: the executor themself gets no Edit, any other session user keeps it. Only a genuinely-evaluated predicate produces both; the "present" half is what a fail-closed fault cannot fake. Both relation payload shapes (bare foreign key and $expanded) are asserted to reach the same verdict, plus an explicit assertion that no fault warning was emitted under the builtin:edit:visibleWhen label.

Reverse verification — direction predicted before running

Predicted: removing the editVisible conjunct (the rc.6 state) turns the five "Edit absent" assertions red and leaves the three "Edit present" controls green. Observed exactly that:

× hides the built-in Edit from the executor themself (BARE foreign key)
× hides it from the executor when the payload EXPANDED the relation
× reaches the SAME verdict whichever shape the relation arrived in
× evaluates without faulting — no warning under the built-in edit label
× hides BOTH from the executor in a single mount
Tests 5 failed | 3 passed (8)

Restored from the committed state (git checkout of the branch's own commit), tree clean.

Verification — all at head 3fcc3311f (the final commit)

GateResult
pnpm exec vitest run packages/app-shell/src/views243 files, 2311 passed, 1 skipped
pnpm --filter @object-ui/app-shell type-checkpass (tsc --noEmit + tsc -p tsconfig.test.json)
pnpm --filter '@object-ui/app-shell^...' buildpass (closure built before the suite)
scripts/check-changeset-presence.mjspass — see below
pnpm changeset:checkpass (fixed group, no major)
pnpm check:control-bytesOK (4192 tracked text files)

Tests-only, so the changeset is the gate's own prescribed exemption — an empty frontmatter. The gate's words:

Every one of them has an EMPTY frontmatter — declared as releasing nothing, which is the explicit exemption and a complete answer to this gate.

Scope

One new test file plus that changeset. RecordDetailView.tsx is byte-unchanged — the ablation above was reverted.


Generated by Claude Code

@vercel

vercelBot commented Aug 15, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
objectuiIgnoredIgnoredAug 15, 2026 6:01am

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Main entry (gzip)24.7 KB350 KB
Entry fileindex-BYT0mfw7.js
StatusPASS

📦 Bundle Size Report

PackageSizeGzipped
app-shell (index.js)9.56KB3.59KB
app-shell (runtime-config.js)7.42KB2.32KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)8.92KB3.41KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)25.13KB5.40KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.13KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.64KB2.21KB
auth (SocialSignInButtons.js)9.60KB3.89KB
auth (UserMenu.js)3.40KB1.22KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)38.46KB10.17KB
auth (createAuthenticatedFetch.js)6.34KB2.43KB
auth (index.js)2.35KB1.07KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.02KB0.88KB
auth (useIsWorkspaceAdmin.js)1.61KB0.85KB
collaboration (CommentThread.js)26.07KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.65KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)489.91KB108.67KB
core (index.js)3.79KB1.52KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)163.56KB44.83KB
fields (index.js)230.37KB57.17KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.32KB1.77KB
i18n (index.js)3.35KB1.38KB
i18n (pickLocalized.js)3.69KB1.73KB
i18n (provider.js)23.12KB7.62KB
i18n (useDisplayLocale.js)2.84KB1.45KB
i18n (useObjectLabel.js)27.59KB6.63KB
i18n (useSafeTranslation.js)7.77KB3.13KB
layout (index.js)38.98KB10.85KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.74KB
mobile (index.js)1.50KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.71KB0.42KB
mobile (useResponsiveConfig.js)1.36KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)8.75KB3.06KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)3.67KB1.12KB
permissions (evaluator.js)4.41KB1.44KB
permissions (index.js)0.91KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.52KB
permissions (usePermissions.js)1.55KB0.71KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.86KB12.91KB
plugin-charts (index.js)62.10KB17.67KB
plugin-chatbot (index.js)181.21KB43.14KB
plugin-dashboard (index.js)121.84KB31.74KB
plugin-designer (index.js)212.58KB42.83KB
plugin-detail (index.js)239.93KB60.01KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)114.72KB27.70KB
plugin-gantt (index.js)164.30KB40.02KB
plugin-grid (index.js)190.02KB50.48KB
plugin-kanban (index.js)52.74KB14.53KB
plugin-list (index.js)111.82KB27.23KB
plugin-map (index.js)18.16KB5.81KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)41.38KB11.09KB
plugin-timeline (index.js)26.68KB7.66KB
plugin-tree (index.js)8.50KB2.88KB
plugin-view (index.js)83.81KB20.49KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.71KB3.53KB
providers (index.js)0.44KB0.22KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.67KB2.37KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)27.64KB9.44KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)1.26KB0.67KB
react (schema-input.js)1.45KB0.83KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)4.09KB1.74KB
sdui-parser (index.js)4.47KB2.03KB
sdui-parser (parse.js)10.04KB2.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)4.69KB1.48KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.87KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-retry.js)4.32KB2.02KB
types (index.js)3.05KB1.52KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@yinlianghui
yinlianghui marked this pull request as ready for review August 15, 2026 06:18
@yinlianghui
yinlianghui added this pull request to the merge queueAug 15, 2026
Merged via the queue into main with commit fb31248Aug 15, 2026
21 checks passed
@yinlianghui
yinlianghui deleted the claude/issue-8499-builtin-edit-visiblewhen branch August 15, 2026 06:18
yinlianghui pushed a commit that referenced this pull request Aug 15, 2026
The empty-frontmatter changeset is this repo's explicit exemption for a diff
that touches released packages' src/ without changing published behaviour —
the same answer PRs #4641 and #4666 gave the same gate. Two of the four touched
test files live under plugin-form / plugin-detail src/, which the gate counts.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RnQd8iMMUwXQEV1crFmQiQ
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

userActions.edit.visibleWhen 对详情页页头内建【编辑】不生效 —— 同一份声明里 delete 生效、edit 不生效(17.0.0-rc.6)

2 participants

@yinlianghui@claude