Skip to content

fix(components): a form field resolves a field widget or the default input — never a ui-namespace SDUI node renderer - #5326

Merged
os-support-ai merged 2 commits into
mainfrom
claude/issue-5254-form-field-crossnamespace-fallback
Aug 19, 2026
Merged

fix(components): a form field resolves a field widget or the default input — never a ui-namespace SDUI node renderer#5326
os-support-ai merged 2 commits into
mainfrom
claude/issue-5254-form-field-crossnamespace-fallback

Conversation

@os-support-ai

Copy link
Copy Markdown
Collaborator

Fixes#5254

Implements the maintainer ruling of 2026-08-19 (verbatim 「全部接受」), option B: form-field type resolution stops falling back to ui-namespace SDUI node renderers.

The located surface

The claim deliberately left the file surface unstated. Located by reading, it is one function in one file:

  • packages/components/src/renderers/form/form.tsxrenderFieldComponent, plus the default arm of its field switch.

That is the only site in the repo doing this resolution: a ComponentRegistry.get on a field:-prefixed key appears exactly twice across packages/**, both in this file (the other is resolvesToRegisteredFieldWidget, which only mirrors the rule and already spelled it the way the ruling prescribes). No overlap with the in-flight #5269 (packages/plugin-view), #5299 (packages/plugin-dashboard) or #5257 (packages/core).

Re-derived on current origin/main first

The fallback still existed and still had the shape the card recorded. Measured at 3fbbea1f3, built-in path (no registerAllFields()), field { name: 'contact', type: 'email', max_length: 50 }:

ComponentRegistry.get('email') = true ComponentRegistry.get('field:email') = false
attrs=["class","id","max_length","field","aria-describedby","aria-invalid","type","value","name"]
maxlength=null field="[object Object]"

Two things the card recorded, and a third it did not: because the ui node renderer draws its own label, the control got a second label element on top of the form's own — two labels naming one control.

I also measured how wide the fallback actually was. It answered 126 bare names on the built-in path (div, h1, card, button, form, alert, badge, the display text widget …), and 116 with the fields package registered too.

The change

A form field's type now resolves a field:-namespaced widget or takes the builtin default input branch. The || ComponentRegistry.get(type) tail is gone, and with it the whole "non-field component reached through the bare-name fallback" branch — so renderFieldComponent now dispatches to exactly one contract (FieldWidgetComponentProps). A colon-qualified type resolves only when it names the field namespace, closing the same hole for ui:email rather than only the bare spelling.

⚠️ Clause-② — this IS a behaviour change, stated plainly

A spelling that resolved yesterday stops resolving. A form field whose type names a non-field component renders the default input instead of that component. That is the substance of the ruling, not a side effect of it, and the changeset is minor for that reason (never major — objectui's major is pinned to @objectstack's).

Not softening it, but scoping it honestly: with registerAllFields() — the production configuration — every affected type already resolved its own field: widget, and object-derived forms go through mapFieldTypeToFormType, which has always emitted the field:-prefixed id. Rendering these components as top-level SDUI nodes is untouched; this rule governs field resolution only.

The verification the ruling put on the implementer

"Implementer must verify the default branch renders a usable input for these types."

Measured answer: on its own, it does not.inputType on that branch is whatever the author wrote, and a plain { name, type: 'password' } authors none — so the branch rendered type="text" and put a secret on screen in clear text. That is the "worse than the leak" outcome, and it is why this PR also adds NATIVE_INPUT_FIELD_TYPES to the default branch: email and password are declared field types in @object-ui/types (EmailFieldMetadata / PasswordFieldMetadata) and keep the native input they always rendered. An explicitly authored inputType still wins.

So the visible rendering of an email / password field is unchanged; what goes away is the leak, the duplicate label and the dead ceiling. After the fix, same field as above:

attrs=["class","maxlength","id","aria-describedby","aria-invalid","type","name"]
type=email maxlength=50 (no `field`, no `max_length`, one label)

The table is deliberately those two only. Other declared types with a native HTML equivalent (url, phone, number, color, date) already took this branch as type="text" and are untouched — widening it would change fields this card neither moved nor measured.

Reverse verification — predicted before running, both legs

Fix committed first, then reverted, so both legs ran from a known state.

Leg 1 — restore the bare-name fallback, keep all tests. Predicted 8 red, named in advance; observed exactly those 8, no others:

assertionpredictedobserved
never leaks the field metadata objectREDRED
never leaks max_length, ceiling capsREDRED
exactly ONE labelREDRED
stops routing a field into a non-field component (card)REDRED
authored inputType winsREDRED
carrier: no bare-name component in the field slotREDRED
carrier: renders the builtin default input insteadREDRED
host-group: bare-name gets no groupREDRED

Leg 2 — revert only NATIVE_INPUT_FIELD_TYPES. Predicted 2 red; observed exactly 2, with the failure text that is the ruling's answer in one line:

AssertionError: expected 'text' to be 'password'
AssertionError: expected 'text' to be 'email'

Assertions green on BOTH legs — pinning nothing on their own, said rather than counted: the registry-reading premise test, still resolves a field: widget, ui node renderers still reachable as NODES, builtin type on its own branch, and (leg 1 only) the three "usable input" assertions, since the old fallback also produced a native email/password input. They are counter-probes and routing guards, not evidence of the fix.

Every zero is counter-probed with a known-present neighbouring term — ComponentRegistry.get('form') / get('card') / get('barenameprobe') / get('plaindisplay') are asserted truthy next to each toBeUndefined() / toBeNull(), so no assertion can pass on an empty registry.

Build artifact between the edit and the thing under test

None for the tests. The root vitest.config.mts aliases every @object-ui/* specifier to that package's src/, so vitest reads the edited source directly; no dist/ sits in between. A build is required for type-check (it reads dependencies' .d.ts), and the first run in this fresh worktree failed with TS2307: Cannot find module '@object-ui/core' for that reason alone. After pnpm --filter '@object-ui/components^...' build it passes.

Fixture triage

Two existing tests pinned the removed branch and were rewritten rather than re-spelled, because their assertions passed precisely because the fallback existed:

Both keep a counter-probe showing the component is still registered and still resolvable — it is simply no longer reachable as a field.

Tests (all from repo root, canonical pnpm exec vitest run + the file path; no --)

Run on the final commit e20ea0d22:

scoperesult
packages/components/src/renderers/form + the two form-renderer suites50 files, 340 passed
packages/components (full)166 files, 1508 passed
packages/plugin-form + packages/plugin-detail143 files, 1398 passed
packages/plugin-viewplugin-listreactlayoutfields230 files, 3445 passed
packages/app-shell449 files, 4332 passed, 1 skipped
pnpm --filter @object-ui/components type-checkpass (after building the dep closure)
check:control-bytes / check:self-import / check:esm-specifierspass
eslint on the changed files0 errors (77 pre-existing warnings; any-count unchanged at 45)

Vitest was run from the repository root every time — packages/components owns a standalone vitest.config.ts and is one of the 11 packages objectui#5313 measured assertCanonicalVitestInvocation as NOT covering, so the guard was not relied on.

Filed separately, not fixed here

#5322 — a field:-prefixed password / email field (what mapFieldTypeToFormType emits) renders type="text" when its widget is not registered, showing a secret in clear text. Measured as pre-existing and unchanged by this PR on both sides of the change. Left to its own card exactly as the ruling directs, rather than widened into this one.


Generated by Claude Code

…amespace SDUI node renderers
A form field's `type` now resolves a `field:`-namespaced widget or takes the
builtin `default` input branch — it no longer falls back to whatever holds the
bare name in any namespace.
Maintainer ruling of 2026-08-19 on objectui#5254 (option B).
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RV6yuVCxymHYE16PL9vQkE
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Main entry (gzip)25.3 KB350 KB
Entry fileindex-CuENH-rI.js
StatusPASS

📦 Bundle Size Report

PackageSizeGzipped
app-shell (index.js)9.83KB3.70KB
app-shell (runtime-config.js)7.42KB2.32KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)8.92KB3.41KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)29.33KB7.05KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.13KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.64KB2.21KB
auth (SocialSignInButtons.js)9.60KB3.89KB
auth (UserMenu.js)3.40KB1.22KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.79KB
auth (createAuthenticatedFetch.js)6.34KB2.43KB
auth (index.js)2.71KB1.22KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.02KB0.88KB
auth (useIsWorkspaceAdmin.js)1.61KB0.85KB
collaboration (CommentThread.js)26.07KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.65KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)506.75KB113.40KB
core (index.js)4.11KB1.62KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)159.80KB44.34KB
fields (index.js)237.07KB59.46KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.42KB1.39KB
i18n (pickLocalized.js)3.69KB1.73KB
i18n (provider.js)23.13KB7.63KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)29.43KB7.15KB
i18n (useSafeTranslation.js)7.77KB3.13KB
layout (index.js)39.16KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.74KB
mobile (index.js)1.50KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.71KB0.42KB
mobile (useResponsiveConfig.js)1.36KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)9.35KB3.31KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)4.42KB1.42KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.91KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.52KB
permissions (usePermissions.js)1.81KB0.83KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.62KB12.83KB
plugin-charts (index.js)64.75KB18.37KB
plugin-chatbot (index.js)181.21KB43.14KB
plugin-dashboard (index.js)127.92KB32.80KB
plugin-designer (index.js)212.39KB42.83KB
plugin-detail (index.js)241.46KB60.56KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)124.19KB30.20KB
plugin-gantt (index.js)164.10KB39.87KB
plugin-grid (index.js)198.22KB53.28KB
plugin-kanban (index.js)52.93KB14.60KB
plugin-list (index.js)111.66KB27.13KB
plugin-map (index.js)20.08KB6.62KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.49KB11.93KB
plugin-timeline (index.js)26.68KB7.66KB
plugin-tree (index.js)8.50KB2.88KB
plugin-view (index.js)84.55KB20.67KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.44KB0.22KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)36.10KB12.26KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)1.33KB0.69KB
react (schema-input.js)1.45KB0.83KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (index.js)4.77KB2.16KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)10.76KB3.17KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)6.92KB2.40KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.87KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-retry.js)4.32KB2.02KB
types (index.js)3.08KB1.53KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-support-ai
os-support-ai marked this pull request as ready for review August 19, 2026 15:03
@os-support-aiClaude

Copy link
Copy Markdown
CollaboratorAuthor

ACCEPT — PM review, round 16.

  • Path surface (git diff --name-only origin/main... @ e20ea0d, base 8477be5): 5 files — packages/components/src/renderers/form/form.tsx, three sibling tests, one changeset. Entirely inside the declared surface; zero governed-surface hits (docs/adr/**, .claude/**, skills/**, AGENTS.md, CLAUDE.md, content/docs/releases/).
  • Gates: every gate job completed: success on e20ea0d — Lint, Type Check, Test shards 1–4, Build & E2E, Build Docs, Doc Snippet / Doc Component Type Check, Changeset Declaration / Bump Policy / Fixed Group, Bundle Analysis, Control Byte Scan, Internal Docs Link Check, Skill Guide Path Check. No cancelled, no in_progress. (Test (coverage) and dependabot are ordinary skips.)
  • Bump: minor on @object-ui/components, breaking semantics spelled out in the changeset body — correct under the pinned-major policy. ⛔ not major.
  • The ruling's required verification came back negative, and that is why this PR is right. Option B removed the bare-name fallback; the dev then measured the default branch and found it derives <input type> from inputType, which a plain { name, type: 'password' } never authors — the field would have rendered type="text" and shown a secret in clear text. The deliberately two-entry NATIVE_INPUT_FIELD_TYPES table (keyed on EmailFieldMetadata / PasswordFieldMetadata) closes exactly that hole and nothing wider; an explicitly authored inputType still wins. Reporting the negative instead of asserting the ruling held is the behaviour the dispatch asked for.

Merging.


Generated by Claude Code

@os-support-ai
os-support-ai added this pull request to the merge queueAug 19, 2026
Merged via the queue into main with commit 232f61aAug 19, 2026
22 checks passed
@os-support-ai
os-support-ai deleted the claude/issue-5254-form-field-crossnamespace-fallback branch August 19, 2026 15:04
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

form 字段 type: 'email' 经 bare-name 回退落进 SDUI 节点渲染器,field(对象)与 max_length 一起泄漏到 DOM

2 participants

@os-support-ai@claude