docs(auth): write down the X-Tenant-ID edge contract and its unstamped-first-request gap - #5706

Merged
os-sales merged 2 commits into
mainfrom
claude/issue-5279-tenant-header-edge-contract
Aug 22, 2026
Merged

docs(auth): write down the X-Tenant-ID edge contract and its unstamped-first-request gap#5706
os-sales merged 2 commits into
mainfrom
claude/issue-5279-tenant-header-edge-contract

Conversation

@os-sales

Copy link
Copy Markdown
Collaborator

Fixes#5279

Documentation only. The header createAuthenticatedFetch stamps had no written contract, and the shape of the missing information was actively misleading.

Why this card existed at all

X-Tenant-ID's only non-CORS consumer lives in the cloud repository. A search confined to this repo and the framework (objectstack) finds zero readers and reads as "nothing consumes this stamp". #5279 was filed on exactly that reading, held on it, and was only discharged when a cloud-side reading came back non-empty (packages/service-tenant/src/tenant-context.ts, packages/tenant-router/src/spec/turso-multi-tenant.zod.ts).

That makes the missing documentation an active hazard rather than a gap: the next person to grep reaches the same false conclusion and deletes a live routing input. So the decisive facts go where a grep-then-delete reader looks first — the stamping site itself — and the full contract goes in the package README, which ships to npm.

What is documented

packages/auth/README.md gains "The X-Tenant-ID edge contract":

QuestionAnswer written down
What it meansA routing hint carrying the better-auth activeOrganizationId. Not an identity claim, not an authorization input, not what scopes rows
Who stamps itcreateAuthenticatedFetch, from ActiveOrganizationStorage, whenever that holds a value — not gated on the URL being an /api/ call, suppressed by sameOriginOnly for cross-origin URLs, overwrites a caller-supplied value
Who writes the storageAuthProvider only, at four moments (organization load, org switch, delete/leave, sign-out)
Who reads the headerThe cloud edge — cited from #5279, since that repo is not readable from here. Its configuration contract is readable here and is quoted from it
Who does not read itThe framework. resolveAuthzContext takes tenantId from the API-key principal or session.activeOrganizationId and from no header, pinned by packages/verify/src/harness.org-context.test.ts
What a reader may assumeMay route on it; may not treat it as identity, may not assume the row scoping came from it, may not assume it is present

The configuration half is not paraphrased from the cloud repo — it is measured from the contract this package actually resolves. TenantRoutingConfigSchema from @objectstack/spec/cloud (17.1.0, the version @object-ui/auth resolves), parsed on an empty config:

enabled: false
identificationSources: ["subdomain", "header", "jwt_claim"]
tenantHeaderName: "X-Tenant-ID"
jwtOrganizationClaim: "organizationId"

Two things a client author needs from that: the header name is configurable (X-Tenant-ID is a default, not a constant), and the header is one of six identification sources ranked second, behind subdomain — on a subdomain-routed deployment it is not what picks the tenant.

The negative half is stated with its own evidence, because "the framework ignores it" is the half that reads as "nobody uses it": the CORS allow-list comment (X-Tenant-ID / X-Environment-Id route "a request to its environment") and plugin-sharing's record that trusting x-tenant-id as identity was a vulnerability.

The unstamped-first-request gap

Its own section. ActiveOrganizationStorage is filled only after AuthProvider's async getSession -> listOrganizations -> getActiveOrganization chain resolves, so early-boot requests carry no tenant header at all. Documented:

Three pins, so the prose cannot drift

packages/auth/src/__tests__/createAuthenticatedFetch.test.tsx gains one case per wire-level statement the README makes: no active organization means no header at all (.has() false, not empty-string); the stamp is not gated on /api/ the way Authorization is; the active organization overwrites a caller-supplied X-Tenant-ID.

The middle one is labelled in the test body as recorded, not endorsed — it makes today's asymmetry visible so that gating the stamp becomes a deliberate, red-test change rather than a silent one, and the question is filed for triage rather than answered here.

Scope

Deliberately not in this PR, per the card:

Verification

Run at f3e0d6313, the head of this branch.

Scope is narrowed to @object-ui/auth, and the narrowing is proven rather than asserted: every .ts edit is comment-only, so the change can have no runtime effect. Demonstrated by compiling both revisions of createAuthenticatedFetch.ts with removeComments and diffing — byte-identical, 2750 bytes each — and by the package's other 20 emitted dist/*.js files being hash-identical across the rebuild. The instrument was self-checked: re-spelling one header literal in a scratchpad copy makes the same comparison go red, so a green reading is a measurement, not a no-op.

GateResult
pnpm --filter @object-ui/auth buildpass
pnpm --filter @object-ui/auth type-check (tsc --noEmit && tsc -p tsconfig.test.json)pass
pnpm --filter @object-ui/auth lintpass — 29 problems (0 errors, 29 warnings), every warning pre-existing in AuthProvider.tsx
pnpm exec vitest run packages/auth/Test Files 18 passed (18) / Tests 190 passed (190). The three new cases were confirmed to actually execute by a --reporter=verbose run of the edited file (Tests 13 passed (13), each new title printed), not inferred from the file-level count
node scripts/check-control-bytes.mjscheck-control-bytes: OK (scanned 4754 tracked text file(s); skipped 85 binary)
node scripts/check-changeset-presence.mjs2 source file(s) of 1 released package(s) changed, and this change declares 1 changeset(s)
node scripts/check-changeset-fixed.mjsAll workspace packages are in the changeset fixed group.
node scripts/check-changeset-no-major.mjsNo changeset declares a major bump.
node scripts/check-doc-snippet-types.mjsnarrowed, declared — see below

check-doc-snippet-types is the gate this diff most obviously reaches: its declared scan surface is every page under content/docsplus every packages/<name>/README.md. It refuses to run against an unbuilt tree (The snippet program was NOT run: the packages it resolves against are not built) and wants 14 packages built first, so it was not run in full here — CI runs it on a built tree.

What replaces it is a measurement rather than a hope, because the narrowing is provable. The gate compiles only the fence languages in its own exported TS_FENCE_LANGUAGESts, tsx, typescript — so the population was read from the gate itself and applied to both revisions of the file:

Revisionfenced blocksin the compiled population
before1110
after1310, byte-lengths identical and in the same order

The two blocks this PR adds are http and text — the header example and the parsed-config dump are not compilable programs, and marking them as fragments would have been a worse answer than writing them as TypeScript. The set of blocks the gate compiles is therefore unchanged by this diff, so its verdict on this file is unchanged. The extractor was self-checked: planting one ts block in a scratchpad copy takes the population from 10 to 11, so the zero-delta reading is a measurement and not a broken probe.

The rest of the farm is CI's run, as always.


Generated by Claude Code

…d-first-request gap (#5279)
The header `createAuthenticatedFetch` stamps had no written contract, and the
shape of the missing information was actively misleading: its only non-CORS
consumer lives in the cloud repository, so a search confined to this repo and
the framework returns zero readers and reads as "nothing consumes this stamp".
#5279 was filed on exactly that reading and held until a cloud-side reading came
back non-empty. Without the contract written down, the next person to grep
reaches the same false conclusion and deletes a live routing input.
packages/auth/README.md gains "The X-Tenant-ID edge contract": what the header
means (a routing hint carrying the better-auth activeOrganizationId, not an
identity claim, not an authorization input, not what scopes rows), who stamps it
and under exactly which condition, who reads it, and what a reader may and may
not assume. The framework half is stated as a negative with its pin —
resolveAuthzContext takes tenantId from the API-key principal or
session.activeOrganizationId and from no header — next to plugin-sharing's
record that trusting x-tenant-id as identity was a vulnerability. The
configuration half is quoted from the contract this package can actually
resolve, TenantRoutingConfigSchema in @objectstack/spec/cloud, where X-Tenant-ID
is the default of a configurable tenantHeaderName and `header` ranks second of
six identification sources behind `subdomain`.
The unstamped-first-request gap gets its own section: ActiveOrganizationStorage
is filled only after AuthProvider's async organization chain resolves, so
early-boot requests carry no tenant header at all. What a reader observes is
documented as absent, never present-and-empty, with the five situations that
open the window and the instruction to fall through to the next identification
source rather than fail closed. The gap is recorded, deliberately not closed:
the cloud readers observe today's behaviour.
The stamping site carries the decisive facts inline, because the source is what
a grep-then-delete reader reads first.
Three cases in createAuthenticatedFetch.test.tsx pin the statements the prose
makes about the wire, so the documentation cannot drift away from the behaviour
unnoticed.
Documentation only. Proven: with comments stripped, the emitted JS for
createAuthenticatedFetch.ts is byte-identical before and after (2750 bytes
both), and the package's other 20 dist JS files are hash-identical.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012u2pRjcqAYtoEjgr3wwhnK
@github-actionsgithub-actionsBot added documentation Improvements or additions to documentation tests labels Aug 22, 2026
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 52 chunks)3913.6 KB3990.2 KB
Main entry chunk (gzip)152.3 KB350 KB
Entry fileindex-spBIKF4m.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (index.js)10.04KB3.72KB
app-shell (runtime-config.js)12.80KB4.47KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)29.34KB7.05KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)9.63KB3.74KB
auth (index.js)2.77KB1.22KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.02KB0.89KB
auth (useIsWorkspaceAdmin.js)3.04KB1.45KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)506.90KB113.84KB
core (index.js)4.92KB1.97KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)160.15KB44.52KB
fields (index.js)238.40KB59.89KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)23.13KB7.63KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)7.77KB3.13KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)9.53KB3.38KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)4.64KB1.50KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)1.93KB0.88KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.62KB12.83KB
plugin-charts (index.js)64.65KB18.32KB
plugin-chatbot (index.js)181.41KB43.22KB
plugin-dashboard (index.js)128.41KB32.95KB
plugin-designer (index.js)212.30KB42.80KB
plugin-detail (index.js)242.34KB60.98KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)125.63KB30.64KB
plugin-gantt (index.js)164.10KB39.87KB
plugin-grid (index.js)200.79KB54.26KB
plugin-kanban (index.js)52.93KB14.60KB
plugin-list (index.js)111.80KB27.20KB
plugin-map (index.js)20.06KB6.62KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.49KB11.93KB
plugin-timeline (index.js)26.68KB7.66KB
plugin-tree (index.js)8.50KB2.88KB
plugin-view (index.js)84.61KB20.74KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)43.66KB14.77KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)1.33KB0.69KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (index.js)4.77KB2.16KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)10.76KB3.17KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)6.92KB2.40KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.87KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (index.js)3.59KB1.79KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-salesClaude

Copy link
Copy Markdown
CollaboratorAuthor

Seat review — accepted on its merits. HELD only on #5705, which is a red base, not this diff.

Fence held exactly: packages/auth/README.md, the stamping site, a test, a changeset. No content/docs/**, no apps/site/** — the brief routed the edge contract to package-local docs precisely so #5668 could not touch it, and that is where it went. No governed surfaces.

Three things I want on the record:

  1. It did not claim a measurement it could not make.objectstack-ai/cloud is unreachable from this session (add_repo returned no access), so the cloud readers are cited as the recorded reading rather than re-derived. What it measured instead is the part that is reachable, at runtime rather than by file-read: TenantRoutingConfigSchema.parse({}) against the version @object-ui/auth actually resolves → tenantHeaderName: 'X-Tenant-ID', and header ranking second of six identification sources behind subdomain. That is the [finding] 响应式词汇的两个零消费表面:useResponsiveConfig 生产零调用者(page.components[].responsive 因此实际未生效)、MobileComponentConfig 零消费者 #4773 lesson applied without being told.

  2. The narrowing is proven with a falsified instrument. Both revisions of createAuthenticatedFetch.ts compiled with removeComments → byte-identical (2750 bytes each), then self-checked by re-spelling a header literal in a scratchpad copy until the comparison went red. Worth being precise about why that is valid here: --removeComments proves program semantics unchanged; it does not license a shipped-bytes claim, and none was made — the bundle report shows auth (createAuthenticatedFetch.js) moving 6.35 → 9.63 KB, which is comment text surviving this package's build. Two gauges, two different questions, both read. (auth now joins core and react on the list of packages whose shipped .js moves on a prose-only change.)

  3. The check-doc-snippet-types narrowing is declared, not skipped. The gate refuses to run on an unbuilt tree, so instead of hoping, the agent read the gate module's own TS_FENCE_LANGUAGES and applied it to both revisions: 11 → 13 fenced blocks, but 10 → 10 in the compiled population, identical byte-lengths in identical order; the two added fences are http and text. Self-checked by planting a ts block to move 10 → 11.

The inline comment at the stamping site is the part that will still be earning its keep in a year — it names the exact failure this card was filed on:

DO NOT DELETE THIS ON THE STRENGTH OF A GREP. … a search confined to this repo plus the framework finds zero consumers and reads as "dead stamp" — which is the false premise objectui#5279 was filed on.

The isApiCall asymmetry it noticed was recorded, not acted on"recorded as the behaviour that ships, not endorsed" — and routed to #5702, where I have labelled it needs-user-decision. That is the right handling of a behaviour question found mid-fence.

Held pending #5705 (main red: console.ai.pendingDrafts missing from eight locale packs). Nothing about this PR needs to change; it merges when the base is green.


Generated by Claude Code

@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 52 chunks)3914.3 KB3990.2 KB
Main entry chunk (gzip)152.3 KB350 KB
Entry fileindex-DvF64ISu.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (index.js)10.04KB3.72KB
app-shell (runtime-config.js)12.80KB4.47KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)29.34KB7.05KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)9.63KB3.74KB
auth (index.js)2.77KB1.22KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.02KB0.89KB
auth (useIsWorkspaceAdmin.js)3.04KB1.45KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)506.90KB113.84KB
core (index.js)4.92KB1.97KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)160.15KB44.52KB
fields (index.js)238.40KB59.89KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)23.13KB7.63KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)7.77KB3.13KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)9.53KB3.38KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)4.64KB1.50KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)1.93KB0.88KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.62KB12.83KB
plugin-charts (index.js)64.65KB18.32KB
plugin-chatbot (index.js)181.41KB43.22KB
plugin-dashboard (index.js)128.41KB32.95KB
plugin-designer (index.js)212.30KB42.80KB
plugin-detail (index.js)242.34KB60.98KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)125.63KB30.64KB
plugin-gantt (index.js)164.10KB39.87KB
plugin-grid (index.js)200.79KB54.26KB
plugin-kanban (index.js)52.93KB14.60KB
plugin-list (index.js)111.80KB27.20KB
plugin-map (index.js)20.06KB6.62KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.49KB11.93KB
plugin-timeline (index.js)26.68KB7.66KB
plugin-tree (index.js)8.50KB2.88KB
plugin-view (index.js)84.61KB20.74KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)43.66KB14.77KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)1.33KB0.69KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (index.js)4.77KB2.16KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)10.76KB3.17KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)6.92KB2.40KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.87KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (index.js)3.59KB1.79KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-sales
os-sales marked this pull request as ready for review August 22, 2026 13:12
@os-sales
os-sales added this pull request to the merge queueAug 22, 2026
Merged via the queue into main with commit 934a532Aug 22, 2026
23 checks passed
@os-sales
os-sales deleted the claude/issue-5279-tenant-header-edge-contract branch August 22, 2026 13:12
os-sam pushed a commit that referenced this pull request Aug 31, 2026
The "Multi-tenancy" section taught that createAuthenticatedFetch sending
X-Tenant-ID is what makes row-level isolation happen. It is not: scoping
comes from the session, the header is an edge routing hint ranked behind
subdomain, and trusting it as identity is the recorded plugin-sharing
vulnerability. Repoint to packages/auth/README.md's "The X-Tenant-ID edge
contract" (added by #5279 / PR #5706) for the full contract.
akarma-synetal pushed a commit to akarma-synetal/objectui that referenced this pull request Sep 1, 2026
objectstack-ai#6974)
The "Multi-tenancy" section taught that createAuthenticatedFetch sending
X-Tenant-ID is what makes row-level isolation happen. It is not: scoping
comes from the session, the header is an edge routing hint ranked behind
subdomain, and trusting it as identity is the recorded plugin-sharing
vulnerability. Repoint to packages/auth/README.md's "The X-Tenant-ID edge
contract" (added by objectstack-ai#5279 / PR objectstack-ai#5706) for the full contract.
Co-authored-by: Claude <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentationImprovements or additions to documentationtests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Confirm whether X-Tenant-ID has a reader: the framework derives the tenant from the session, not the header

2 participants

@os-sales@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

docs(auth): write down the X-Tenant-ID edge contract and its unstamped-first-request gap - #5706

Merged
os-sales merged 2 commits into
mainfrom
claude/issue-5279-tenant-header-edge-contract
Aug 22, 2026
Merged

docs(auth): write down the X-Tenant-ID edge contract and its unstamped-first-request gap#5706
os-sales merged 2 commits into
mainfrom
claude/issue-5279-tenant-header-edge-contract

Conversation

@os-sales

Copy link
Copy Markdown
Collaborator

Fixes#5279

Documentation only. The header createAuthenticatedFetch stamps had no written contract, and the shape of the missing information was actively misleading.

Why this card existed at all

X-Tenant-ID's only non-CORS consumer lives in the cloud repository. A search confined to this repo and the framework (objectstack) finds zero readers and reads as "nothing consumes this stamp". #5279 was filed on exactly that reading, held on it, and was only discharged when a cloud-side reading came back non-empty (packages/service-tenant/src/tenant-context.ts, packages/tenant-router/src/spec/turso-multi-tenant.zod.ts).

That makes the missing documentation an active hazard rather than a gap: the next person to grep reaches the same false conclusion and deletes a live routing input. So the decisive facts go where a grep-then-delete reader looks first — the stamping site itself — and the full contract goes in the package README, which ships to npm.

What is documented

packages/auth/README.md gains "The X-Tenant-ID edge contract":

QuestionAnswer written down
What it meansA routing hint carrying the better-auth activeOrganizationId. Not an identity claim, not an authorization input, not what scopes rows
Who stamps itcreateAuthenticatedFetch, from ActiveOrganizationStorage, whenever that holds a value — not gated on the URL being an /api/ call, suppressed by sameOriginOnly for cross-origin URLs, overwrites a caller-supplied value
Who writes the storageAuthProvider only, at four moments (organization load, org switch, delete/leave, sign-out)
Who reads the headerThe cloud edge — cited from #5279, since that repo is not readable from here. Its configuration contract is readable here and is quoted from it
Who does not read itThe framework. resolveAuthzContext takes tenantId from the API-key principal or session.activeOrganizationId and from no header, pinned by packages/verify/src/harness.org-context.test.ts
What a reader may assumeMay route on it; may not treat it as identity, may not assume the row scoping came from it, may not assume it is present

The configuration half is not paraphrased from the cloud repo — it is measured from the contract this package actually resolves. TenantRoutingConfigSchema from @objectstack/spec/cloud (17.1.0, the version @object-ui/auth resolves), parsed on an empty config:

enabled: false
identificationSources: ["subdomain", "header", "jwt_claim"]
tenantHeaderName: "X-Tenant-ID"
jwtOrganizationClaim: "organizationId"

Two things a client author needs from that: the header name is configurable (X-Tenant-ID is a default, not a constant), and the header is one of six identification sources ranked second, behind subdomain — on a subdomain-routed deployment it is not what picks the tenant.

The negative half is stated with its own evidence, because "the framework ignores it" is the half that reads as "nobody uses it": the CORS allow-list comment (X-Tenant-ID / X-Environment-Id route "a request to its environment") and plugin-sharing's record that trusting x-tenant-id as identity was a vulnerability.

The unstamped-first-request gap

Its own section. ActiveOrganizationStorage is filled only after AuthProvider's async getSession -> listOrganizations -> getActiveOrganization chain resolves, so early-boot requests carry no tenant header at all. Documented:

Three pins, so the prose cannot drift

packages/auth/src/__tests__/createAuthenticatedFetch.test.tsx gains one case per wire-level statement the README makes: no active organization means no header at all (.has() false, not empty-string); the stamp is not gated on /api/ the way Authorization is; the active organization overwrites a caller-supplied X-Tenant-ID.

The middle one is labelled in the test body as recorded, not endorsed — it makes today's asymmetry visible so that gating the stamp becomes a deliberate, red-test change rather than a silent one, and the question is filed for triage rather than answered here.

Scope

Deliberately not in this PR, per the card:

Verification

Run at f3e0d6313, the head of this branch.

Scope is narrowed to @object-ui/auth, and the narrowing is proven rather than asserted: every .ts edit is comment-only, so the change can have no runtime effect. Demonstrated by compiling both revisions of createAuthenticatedFetch.ts with removeComments and diffing — byte-identical, 2750 bytes each — and by the package's other 20 emitted dist/*.js files being hash-identical across the rebuild. The instrument was self-checked: re-spelling one header literal in a scratchpad copy makes the same comparison go red, so a green reading is a measurement, not a no-op.

GateResult
pnpm --filter @object-ui/auth buildpass
pnpm --filter @object-ui/auth type-check (tsc --noEmit && tsc -p tsconfig.test.json)pass
pnpm --filter @object-ui/auth lintpass — 29 problems (0 errors, 29 warnings), every warning pre-existing in AuthProvider.tsx
pnpm exec vitest run packages/auth/Test Files 18 passed (18) / Tests 190 passed (190). The three new cases were confirmed to actually execute by a --reporter=verbose run of the edited file (Tests 13 passed (13), each new title printed), not inferred from the file-level count
node scripts/check-control-bytes.mjscheck-control-bytes: OK (scanned 4754 tracked text file(s); skipped 85 binary)
node scripts/check-changeset-presence.mjs2 source file(s) of 1 released package(s) changed, and this change declares 1 changeset(s)
node scripts/check-changeset-fixed.mjsAll workspace packages are in the changeset fixed group.
node scripts/check-changeset-no-major.mjsNo changeset declares a major bump.
node scripts/check-doc-snippet-types.mjsnarrowed, declared — see below

check-doc-snippet-types is the gate this diff most obviously reaches: its declared scan surface is every page under content/docsplus every packages/<name>/README.md. It refuses to run against an unbuilt tree (The snippet program was NOT run: the packages it resolves against are not built) and wants 14 packages built first, so it was not run in full here — CI runs it on a built tree.

What replaces it is a measurement rather than a hope, because the narrowing is provable. The gate compiles only the fence languages in its own exported TS_FENCE_LANGUAGESts, tsx, typescript — so the population was read from the gate itself and applied to both revisions of the file:

Revisionfenced blocksin the compiled population
before1110
after1310, byte-lengths identical and in the same order

The two blocks this PR adds are http and text — the header example and the parsed-config dump are not compilable programs, and marking them as fragments would have been a worse answer than writing them as TypeScript. The set of blocks the gate compiles is therefore unchanged by this diff, so its verdict on this file is unchanged. The extractor was self-checked: planting one ts block in a scratchpad copy takes the population from 10 to 11, so the zero-delta reading is a measurement and not a broken probe.

The rest of the farm is CI's run, as always.


Generated by Claude Code

…d-first-request gap (#5279)
The header `createAuthenticatedFetch` stamps had no written contract, and the
shape of the missing information was actively misleading: its only non-CORS
consumer lives in the cloud repository, so a search confined to this repo and
the framework returns zero readers and reads as "nothing consumes this stamp".
#5279 was filed on exactly that reading and held until a cloud-side reading came
back non-empty. Without the contract written down, the next person to grep
reaches the same false conclusion and deletes a live routing input.
packages/auth/README.md gains "The X-Tenant-ID edge contract": what the header
means (a routing hint carrying the better-auth activeOrganizationId, not an
identity claim, not an authorization input, not what scopes rows), who stamps it
and under exactly which condition, who reads it, and what a reader may and may
not assume. The framework half is stated as a negative with its pin —
resolveAuthzContext takes tenantId from the API-key principal or
session.activeOrganizationId and from no header — next to plugin-sharing's
record that trusting x-tenant-id as identity was a vulnerability. The
configuration half is quoted from the contract this package can actually
resolve, TenantRoutingConfigSchema in @objectstack/spec/cloud, where X-Tenant-ID
is the default of a configurable tenantHeaderName and `header` ranks second of
six identification sources behind `subdomain`.
The unstamped-first-request gap gets its own section: ActiveOrganizationStorage
is filled only after AuthProvider's async organization chain resolves, so
early-boot requests carry no tenant header at all. What a reader observes is
documented as absent, never present-and-empty, with the five situations that
open the window and the instruction to fall through to the next identification
source rather than fail closed. The gap is recorded, deliberately not closed:
the cloud readers observe today's behaviour.
The stamping site carries the decisive facts inline, because the source is what
a grep-then-delete reader reads first.
Three cases in createAuthenticatedFetch.test.tsx pin the statements the prose
makes about the wire, so the documentation cannot drift away from the behaviour
unnoticed.
Documentation only. Proven: with comments stripped, the emitted JS for
createAuthenticatedFetch.ts is byte-identical before and after (2750 bytes
both), and the package's other 20 dist JS files are hash-identical.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012u2pRjcqAYtoEjgr3wwhnK
@github-actionsgithub-actionsBot added documentation Improvements or additions to documentation tests labels Aug 22, 2026
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 52 chunks)3913.6 KB3990.2 KB
Main entry chunk (gzip)152.3 KB350 KB
Entry fileindex-spBIKF4m.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (index.js)10.04KB3.72KB
app-shell (runtime-config.js)12.80KB4.47KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)29.34KB7.05KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)9.63KB3.74KB
auth (index.js)2.77KB1.22KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.02KB0.89KB
auth (useIsWorkspaceAdmin.js)3.04KB1.45KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)506.90KB113.84KB
core (index.js)4.92KB1.97KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)160.15KB44.52KB
fields (index.js)238.40KB59.89KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)23.13KB7.63KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)7.77KB3.13KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)9.53KB3.38KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)4.64KB1.50KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)1.93KB0.88KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.62KB12.83KB
plugin-charts (index.js)64.65KB18.32KB
plugin-chatbot (index.js)181.41KB43.22KB
plugin-dashboard (index.js)128.41KB32.95KB
plugin-designer (index.js)212.30KB42.80KB
plugin-detail (index.js)242.34KB60.98KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)125.63KB30.64KB
plugin-gantt (index.js)164.10KB39.87KB
plugin-grid (index.js)200.79KB54.26KB
plugin-kanban (index.js)52.93KB14.60KB
plugin-list (index.js)111.80KB27.20KB
plugin-map (index.js)20.06KB6.62KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.49KB11.93KB
plugin-timeline (index.js)26.68KB7.66KB
plugin-tree (index.js)8.50KB2.88KB
plugin-view (index.js)84.61KB20.74KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)43.66KB14.77KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)1.33KB0.69KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (index.js)4.77KB2.16KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)10.76KB3.17KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)6.92KB2.40KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.87KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (index.js)3.59KB1.79KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-salesClaude

Copy link
Copy Markdown
CollaboratorAuthor

Seat review — accepted on its merits. HELD only on #5705, which is a red base, not this diff.

Fence held exactly: packages/auth/README.md, the stamping site, a test, a changeset. No content/docs/**, no apps/site/** — the brief routed the edge contract to package-local docs precisely so #5668 could not touch it, and that is where it went. No governed surfaces.

Three things I want on the record:

  1. It did not claim a measurement it could not make.objectstack-ai/cloud is unreachable from this session (add_repo returned no access), so the cloud readers are cited as the recorded reading rather than re-derived. What it measured instead is the part that is reachable, at runtime rather than by file-read: TenantRoutingConfigSchema.parse({}) against the version @object-ui/auth actually resolves → tenantHeaderName: 'X-Tenant-ID', and header ranking second of six identification sources behind subdomain. That is the [finding] 响应式词汇的两个零消费表面:useResponsiveConfig 生产零调用者(page.components[].responsive 因此实际未生效)、MobileComponentConfig 零消费者 #4773 lesson applied without being told.

  2. The narrowing is proven with a falsified instrument. Both revisions of createAuthenticatedFetch.ts compiled with removeComments → byte-identical (2750 bytes each), then self-checked by re-spelling a header literal in a scratchpad copy until the comparison went red. Worth being precise about why that is valid here: --removeComments proves program semantics unchanged; it does not license a shipped-bytes claim, and none was made — the bundle report shows auth (createAuthenticatedFetch.js) moving 6.35 → 9.63 KB, which is comment text surviving this package's build. Two gauges, two different questions, both read. (auth now joins core and react on the list of packages whose shipped .js moves on a prose-only change.)

  3. The check-doc-snippet-types narrowing is declared, not skipped. The gate refuses to run on an unbuilt tree, so instead of hoping, the agent read the gate module's own TS_FENCE_LANGUAGES and applied it to both revisions: 11 → 13 fenced blocks, but 10 → 10 in the compiled population, identical byte-lengths in identical order; the two added fences are http and text. Self-checked by planting a ts block to move 10 → 11.

The inline comment at the stamping site is the part that will still be earning its keep in a year — it names the exact failure this card was filed on:

DO NOT DELETE THIS ON THE STRENGTH OF A GREP. … a search confined to this repo plus the framework finds zero consumers and reads as "dead stamp" — which is the false premise objectui#5279 was filed on.

The isApiCall asymmetry it noticed was recorded, not acted on"recorded as the behaviour that ships, not endorsed" — and routed to #5702, where I have labelled it needs-user-decision. That is the right handling of a behaviour question found mid-fence.

Held pending #5705 (main red: console.ai.pendingDrafts missing from eight locale packs). Nothing about this PR needs to change; it merges when the base is green.


Generated by Claude Code

@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 52 chunks)3914.3 KB3990.2 KB
Main entry chunk (gzip)152.3 KB350 KB
Entry fileindex-DvF64ISu.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (index.js)10.04KB3.72KB
app-shell (runtime-config.js)12.80KB4.47KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)29.34KB7.05KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)9.63KB3.74KB
auth (index.js)2.77KB1.22KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.02KB0.89KB
auth (useIsWorkspaceAdmin.js)3.04KB1.45KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)506.90KB113.84KB
core (index.js)4.92KB1.97KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)160.15KB44.52KB
fields (index.js)238.40KB59.89KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)23.13KB7.63KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)7.77KB3.13KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)9.53KB3.38KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)4.64KB1.50KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)1.93KB0.88KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.62KB12.83KB
plugin-charts (index.js)64.65KB18.32KB
plugin-chatbot (index.js)181.41KB43.22KB
plugin-dashboard (index.js)128.41KB32.95KB
plugin-designer (index.js)212.30KB42.80KB
plugin-detail (index.js)242.34KB60.98KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)125.63KB30.64KB
plugin-gantt (index.js)164.10KB39.87KB
plugin-grid (index.js)200.79KB54.26KB
plugin-kanban (index.js)52.93KB14.60KB
plugin-list (index.js)111.80KB27.20KB
plugin-map (index.js)20.06KB6.62KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.49KB11.93KB
plugin-timeline (index.js)26.68KB7.66KB
plugin-tree (index.js)8.50KB2.88KB
plugin-view (index.js)84.61KB20.74KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)43.66KB14.77KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)1.33KB0.69KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (index.js)4.77KB2.16KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)10.76KB3.17KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)6.92KB2.40KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.87KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (index.js)3.59KB1.79KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-sales
os-sales marked this pull request as ready for review August 22, 2026 13:12
@os-sales
os-sales added this pull request to the merge queueAug 22, 2026
Merged via the queue into main with commit 934a532Aug 22, 2026
23 checks passed
@os-sales
os-sales deleted the claude/issue-5279-tenant-header-edge-contract branch August 22, 2026 13:12
os-sam pushed a commit that referenced this pull request Aug 31, 2026
The "Multi-tenancy" section taught that createAuthenticatedFetch sending
X-Tenant-ID is what makes row-level isolation happen. It is not: scoping
comes from the session, the header is an edge routing hint ranked behind
subdomain, and trusting it as identity is the recorded plugin-sharing
vulnerability. Repoint to packages/auth/README.md's "The X-Tenant-ID edge
contract" (added by #5279 / PR #5706) for the full contract.
akarma-synetal pushed a commit to akarma-synetal/objectui that referenced this pull request Sep 1, 2026
objectstack-ai#6974)
The "Multi-tenancy" section taught that createAuthenticatedFetch sending
X-Tenant-ID is what makes row-level isolation happen. It is not: scoping
comes from the session, the header is an edge routing hint ranked behind
subdomain, and trusting it as identity is the recorded plugin-sharing
vulnerability. Repoint to packages/auth/README.md's "The X-Tenant-ID edge
contract" (added by objectstack-ai#5279 / PR objectstack-ai#5706) for the full contract.
Co-authored-by: Claude <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentationImprovements or additions to documentationtests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Confirm whether X-Tenant-ID has a reader: the framework derives the tenant from the session, not the header

2 participants

@os-sales@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

docs(auth): write down the X-Tenant-ID edge contract and its unstamped-first-request gap - #5706

Merged
os-sales merged 2 commits into
mainfrom
claude/issue-5279-tenant-header-edge-contract
Aug 22, 2026
Merged

docs(auth): write down the X-Tenant-ID edge contract and its unstamped-first-request gap#5706
os-sales merged 2 commits into
mainfrom
claude/issue-5279-tenant-header-edge-contract

Conversation

@os-sales

Copy link
Copy Markdown
Collaborator

Fixes#5279

Documentation only. The header createAuthenticatedFetch stamps had no written contract, and the shape of the missing information was actively misleading.

Why this card existed at all

X-Tenant-ID's only non-CORS consumer lives in the cloud repository. A search confined to this repo and the framework (objectstack) finds zero readers and reads as "nothing consumes this stamp". #5279 was filed on exactly that reading, held on it, and was only discharged when a cloud-side reading came back non-empty (packages/service-tenant/src/tenant-context.ts, packages/tenant-router/src/spec/turso-multi-tenant.zod.ts).

That makes the missing documentation an active hazard rather than a gap: the next person to grep reaches the same false conclusion and deletes a live routing input. So the decisive facts go where a grep-then-delete reader looks first — the stamping site itself — and the full contract goes in the package README, which ships to npm.

What is documented

packages/auth/README.md gains "The X-Tenant-ID edge contract":

QuestionAnswer written down
What it meansA routing hint carrying the better-auth activeOrganizationId. Not an identity claim, not an authorization input, not what scopes rows
Who stamps itcreateAuthenticatedFetch, from ActiveOrganizationStorage, whenever that holds a value — not gated on the URL being an /api/ call, suppressed by sameOriginOnly for cross-origin URLs, overwrites a caller-supplied value
Who writes the storageAuthProvider only, at four moments (organization load, org switch, delete/leave, sign-out)
Who reads the headerThe cloud edge — cited from #5279, since that repo is not readable from here. Its configuration contract is readable here and is quoted from it
Who does not read itThe framework. resolveAuthzContext takes tenantId from the API-key principal or session.activeOrganizationId and from no header, pinned by packages/verify/src/harness.org-context.test.ts
What a reader may assumeMay route on it; may not treat it as identity, may not assume the row scoping came from it, may not assume it is present

The configuration half is not paraphrased from the cloud repo — it is measured from the contract this package actually resolves. TenantRoutingConfigSchema from @objectstack/spec/cloud (17.1.0, the version @object-ui/auth resolves), parsed on an empty config:

enabled: false
identificationSources: ["subdomain", "header", "jwt_claim"]
tenantHeaderName: "X-Tenant-ID"
jwtOrganizationClaim: "organizationId"

Two things a client author needs from that: the header name is configurable (X-Tenant-ID is a default, not a constant), and the header is one of six identification sources ranked second, behind subdomain — on a subdomain-routed deployment it is not what picks the tenant.

The negative half is stated with its own evidence, because "the framework ignores it" is the half that reads as "nobody uses it": the CORS allow-list comment (X-Tenant-ID / X-Environment-Id route "a request to its environment") and plugin-sharing's record that trusting x-tenant-id as identity was a vulnerability.

The unstamped-first-request gap

Its own section. ActiveOrganizationStorage is filled only after AuthProvider's async getSession -> listOrganizations -> getActiveOrganization chain resolves, so early-boot requests carry no tenant header at all. Documented:

Three pins, so the prose cannot drift

packages/auth/src/__tests__/createAuthenticatedFetch.test.tsx gains one case per wire-level statement the README makes: no active organization means no header at all (.has() false, not empty-string); the stamp is not gated on /api/ the way Authorization is; the active organization overwrites a caller-supplied X-Tenant-ID.

The middle one is labelled in the test body as recorded, not endorsed — it makes today's asymmetry visible so that gating the stamp becomes a deliberate, red-test change rather than a silent one, and the question is filed for triage rather than answered here.

Scope

Deliberately not in this PR, per the card:

Verification

Run at f3e0d6313, the head of this branch.

Scope is narrowed to @object-ui/auth, and the narrowing is proven rather than asserted: every .ts edit is comment-only, so the change can have no runtime effect. Demonstrated by compiling both revisions of createAuthenticatedFetch.ts with removeComments and diffing — byte-identical, 2750 bytes each — and by the package's other 20 emitted dist/*.js files being hash-identical across the rebuild. The instrument was self-checked: re-spelling one header literal in a scratchpad copy makes the same comparison go red, so a green reading is a measurement, not a no-op.

GateResult
pnpm --filter @object-ui/auth buildpass
pnpm --filter @object-ui/auth type-check (tsc --noEmit && tsc -p tsconfig.test.json)pass
pnpm --filter @object-ui/auth lintpass — 29 problems (0 errors, 29 warnings), every warning pre-existing in AuthProvider.tsx
pnpm exec vitest run packages/auth/Test Files 18 passed (18) / Tests 190 passed (190). The three new cases were confirmed to actually execute by a --reporter=verbose run of the edited file (Tests 13 passed (13), each new title printed), not inferred from the file-level count
node scripts/check-control-bytes.mjscheck-control-bytes: OK (scanned 4754 tracked text file(s); skipped 85 binary)
node scripts/check-changeset-presence.mjs2 source file(s) of 1 released package(s) changed, and this change declares 1 changeset(s)
node scripts/check-changeset-fixed.mjsAll workspace packages are in the changeset fixed group.
node scripts/check-changeset-no-major.mjsNo changeset declares a major bump.
node scripts/check-doc-snippet-types.mjsnarrowed, declared — see below

check-doc-snippet-types is the gate this diff most obviously reaches: its declared scan surface is every page under content/docsplus every packages/<name>/README.md. It refuses to run against an unbuilt tree (The snippet program was NOT run: the packages it resolves against are not built) and wants 14 packages built first, so it was not run in full here — CI runs it on a built tree.

What replaces it is a measurement rather than a hope, because the narrowing is provable. The gate compiles only the fence languages in its own exported TS_FENCE_LANGUAGESts, tsx, typescript — so the population was read from the gate itself and applied to both revisions of the file:

Revisionfenced blocksin the compiled population
before1110
after1310, byte-lengths identical and in the same order

The two blocks this PR adds are http and text — the header example and the parsed-config dump are not compilable programs, and marking them as fragments would have been a worse answer than writing them as TypeScript. The set of blocks the gate compiles is therefore unchanged by this diff, so its verdict on this file is unchanged. The extractor was self-checked: planting one ts block in a scratchpad copy takes the population from 10 to 11, so the zero-delta reading is a measurement and not a broken probe.

The rest of the farm is CI's run, as always.


Generated by Claude Code

…d-first-request gap (#5279)
The header `createAuthenticatedFetch` stamps had no written contract, and the
shape of the missing information was actively misleading: its only non-CORS
consumer lives in the cloud repository, so a search confined to this repo and
the framework returns zero readers and reads as "nothing consumes this stamp".
#5279 was filed on exactly that reading and held until a cloud-side reading came
back non-empty. Without the contract written down, the next person to grep
reaches the same false conclusion and deletes a live routing input.
packages/auth/README.md gains "The X-Tenant-ID edge contract": what the header
means (a routing hint carrying the better-auth activeOrganizationId, not an
identity claim, not an authorization input, not what scopes rows), who stamps it
and under exactly which condition, who reads it, and what a reader may and may
not assume. The framework half is stated as a negative with its pin —
resolveAuthzContext takes tenantId from the API-key principal or
session.activeOrganizationId and from no header — next to plugin-sharing's
record that trusting x-tenant-id as identity was a vulnerability. The
configuration half is quoted from the contract this package can actually
resolve, TenantRoutingConfigSchema in @objectstack/spec/cloud, where X-Tenant-ID
is the default of a configurable tenantHeaderName and `header` ranks second of
six identification sources behind `subdomain`.
The unstamped-first-request gap gets its own section: ActiveOrganizationStorage
is filled only after AuthProvider's async organization chain resolves, so
early-boot requests carry no tenant header at all. What a reader observes is
documented as absent, never present-and-empty, with the five situations that
open the window and the instruction to fall through to the next identification
source rather than fail closed. The gap is recorded, deliberately not closed:
the cloud readers observe today's behaviour.
The stamping site carries the decisive facts inline, because the source is what
a grep-then-delete reader reads first.
Three cases in createAuthenticatedFetch.test.tsx pin the statements the prose
makes about the wire, so the documentation cannot drift away from the behaviour
unnoticed.
Documentation only. Proven: with comments stripped, the emitted JS for
createAuthenticatedFetch.ts is byte-identical before and after (2750 bytes
both), and the package's other 20 dist JS files are hash-identical.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012u2pRjcqAYtoEjgr3wwhnK
@github-actionsgithub-actionsBot added documentation Improvements or additions to documentation tests labels Aug 22, 2026
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 52 chunks)3913.6 KB3990.2 KB
Main entry chunk (gzip)152.3 KB350 KB
Entry fileindex-spBIKF4m.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (index.js)10.04KB3.72KB
app-shell (runtime-config.js)12.80KB4.47KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)29.34KB7.05KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)9.63KB3.74KB
auth (index.js)2.77KB1.22KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.02KB0.89KB
auth (useIsWorkspaceAdmin.js)3.04KB1.45KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)506.90KB113.84KB
core (index.js)4.92KB1.97KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)160.15KB44.52KB
fields (index.js)238.40KB59.89KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)23.13KB7.63KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)7.77KB3.13KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)9.53KB3.38KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)4.64KB1.50KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)1.93KB0.88KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.62KB12.83KB
plugin-charts (index.js)64.65KB18.32KB
plugin-chatbot (index.js)181.41KB43.22KB
plugin-dashboard (index.js)128.41KB32.95KB
plugin-designer (index.js)212.30KB42.80KB
plugin-detail (index.js)242.34KB60.98KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)125.63KB30.64KB
plugin-gantt (index.js)164.10KB39.87KB
plugin-grid (index.js)200.79KB54.26KB
plugin-kanban (index.js)52.93KB14.60KB
plugin-list (index.js)111.80KB27.20KB
plugin-map (index.js)20.06KB6.62KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.49KB11.93KB
plugin-timeline (index.js)26.68KB7.66KB
plugin-tree (index.js)8.50KB2.88KB
plugin-view (index.js)84.61KB20.74KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)43.66KB14.77KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)1.33KB0.69KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (index.js)4.77KB2.16KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)10.76KB3.17KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)6.92KB2.40KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.87KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (index.js)3.59KB1.79KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-salesClaude

Copy link
Copy Markdown
CollaboratorAuthor

Seat review — accepted on its merits. HELD only on #5705, which is a red base, not this diff.

Fence held exactly: packages/auth/README.md, the stamping site, a test, a changeset. No content/docs/**, no apps/site/** — the brief routed the edge contract to package-local docs precisely so #5668 could not touch it, and that is where it went. No governed surfaces.

Three things I want on the record:

  1. It did not claim a measurement it could not make.objectstack-ai/cloud is unreachable from this session (add_repo returned no access), so the cloud readers are cited as the recorded reading rather than re-derived. What it measured instead is the part that is reachable, at runtime rather than by file-read: TenantRoutingConfigSchema.parse({}) against the version @object-ui/auth actually resolves → tenantHeaderName: 'X-Tenant-ID', and header ranking second of six identification sources behind subdomain. That is the [finding] 响应式词汇的两个零消费表面:useResponsiveConfig 生产零调用者(page.components[].responsive 因此实际未生效)、MobileComponentConfig 零消费者 #4773 lesson applied without being told.

  2. The narrowing is proven with a falsified instrument. Both revisions of createAuthenticatedFetch.ts compiled with removeComments → byte-identical (2750 bytes each), then self-checked by re-spelling a header literal in a scratchpad copy until the comparison went red. Worth being precise about why that is valid here: --removeComments proves program semantics unchanged; it does not license a shipped-bytes claim, and none was made — the bundle report shows auth (createAuthenticatedFetch.js) moving 6.35 → 9.63 KB, which is comment text surviving this package's build. Two gauges, two different questions, both read. (auth now joins core and react on the list of packages whose shipped .js moves on a prose-only change.)

  3. The check-doc-snippet-types narrowing is declared, not skipped. The gate refuses to run on an unbuilt tree, so instead of hoping, the agent read the gate module's own TS_FENCE_LANGUAGES and applied it to both revisions: 11 → 13 fenced blocks, but 10 → 10 in the compiled population, identical byte-lengths in identical order; the two added fences are http and text. Self-checked by planting a ts block to move 10 → 11.

The inline comment at the stamping site is the part that will still be earning its keep in a year — it names the exact failure this card was filed on:

DO NOT DELETE THIS ON THE STRENGTH OF A GREP. … a search confined to this repo plus the framework finds zero consumers and reads as "dead stamp" — which is the false premise objectui#5279 was filed on.

The isApiCall asymmetry it noticed was recorded, not acted on"recorded as the behaviour that ships, not endorsed" — and routed to #5702, where I have labelled it needs-user-decision. That is the right handling of a behaviour question found mid-fence.

Held pending #5705 (main red: console.ai.pendingDrafts missing from eight locale packs). Nothing about this PR needs to change; it merges when the base is green.


Generated by Claude Code

@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 52 chunks)3914.3 KB3990.2 KB
Main entry chunk (gzip)152.3 KB350 KB
Entry fileindex-DvF64ISu.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (index.js)10.04KB3.72KB
app-shell (runtime-config.js)12.80KB4.47KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)29.34KB7.05KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)9.63KB3.74KB
auth (index.js)2.77KB1.22KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.02KB0.89KB
auth (useIsWorkspaceAdmin.js)3.04KB1.45KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)506.90KB113.84KB
core (index.js)4.92KB1.97KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)160.15KB44.52KB
fields (index.js)238.40KB59.89KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)23.13KB7.63KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)7.77KB3.13KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)9.53KB3.38KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)4.64KB1.50KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)1.93KB0.88KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.62KB12.83KB
plugin-charts (index.js)64.65KB18.32KB
plugin-chatbot (index.js)181.41KB43.22KB
plugin-dashboard (index.js)128.41KB32.95KB
plugin-designer (index.js)212.30KB42.80KB
plugin-detail (index.js)242.34KB60.98KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)125.63KB30.64KB
plugin-gantt (index.js)164.10KB39.87KB
plugin-grid (index.js)200.79KB54.26KB
plugin-kanban (index.js)52.93KB14.60KB
plugin-list (index.js)111.80KB27.20KB
plugin-map (index.js)20.06KB6.62KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.49KB11.93KB
plugin-timeline (index.js)26.68KB7.66KB
plugin-tree (index.js)8.50KB2.88KB
plugin-view (index.js)84.61KB20.74KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)43.66KB14.77KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)1.33KB0.69KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (index.js)4.77KB2.16KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)10.76KB3.17KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)6.92KB2.40KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.87KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (index.js)3.59KB1.79KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-sales
os-sales marked this pull request as ready for review August 22, 2026 13:12
@os-sales
os-sales added this pull request to the merge queueAug 22, 2026
Merged via the queue into main with commit 934a532Aug 22, 2026
23 checks passed
@os-sales
os-sales deleted the claude/issue-5279-tenant-header-edge-contract branch August 22, 2026 13:12
os-sam pushed a commit that referenced this pull request Aug 31, 2026
The "Multi-tenancy" section taught that createAuthenticatedFetch sending
X-Tenant-ID is what makes row-level isolation happen. It is not: scoping
comes from the session, the header is an edge routing hint ranked behind
subdomain, and trusting it as identity is the recorded plugin-sharing
vulnerability. Repoint to packages/auth/README.md's "The X-Tenant-ID edge
contract" (added by #5279 / PR #5706) for the full contract.
akarma-synetal pushed a commit to akarma-synetal/objectui that referenced this pull request Sep 1, 2026
objectstack-ai#6974)
The "Multi-tenancy" section taught that createAuthenticatedFetch sending
X-Tenant-ID is what makes row-level isolation happen. It is not: scoping
comes from the session, the header is an edge routing hint ranked behind
subdomain, and trusting it as identity is the recorded plugin-sharing
vulnerability. Repoint to packages/auth/README.md's "The X-Tenant-ID edge
contract" (added by objectstack-ai#5279 / PR objectstack-ai#5706) for the full contract.
Co-authored-by: Claude <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentationImprovements or additions to documentationtests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Confirm whether X-Tenant-ID has a reader: the framework derives the tenant from the session, not the header

2 participants

@os-sales@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

docs(auth): write down the X-Tenant-ID edge contract and its unstamped-first-request gap - #5706

Merged
os-sales merged 2 commits into
mainfrom
claude/issue-5279-tenant-header-edge-contract
Aug 22, 2026
Merged

docs(auth): write down the X-Tenant-ID edge contract and its unstamped-first-request gap#5706
os-sales merged 2 commits into
mainfrom
claude/issue-5279-tenant-header-edge-contract

Conversation

@os-sales

Copy link
Copy Markdown
Collaborator

Fixes#5279

Documentation only. The header createAuthenticatedFetch stamps had no written contract, and the shape of the missing information was actively misleading.

Why this card existed at all

X-Tenant-ID's only non-CORS consumer lives in the cloud repository. A search confined to this repo and the framework (objectstack) finds zero readers and reads as "nothing consumes this stamp". #5279 was filed on exactly that reading, held on it, and was only discharged when a cloud-side reading came back non-empty (packages/service-tenant/src/tenant-context.ts, packages/tenant-router/src/spec/turso-multi-tenant.zod.ts).

That makes the missing documentation an active hazard rather than a gap: the next person to grep reaches the same false conclusion and deletes a live routing input. So the decisive facts go where a grep-then-delete reader looks first — the stamping site itself — and the full contract goes in the package README, which ships to npm.

What is documented

packages/auth/README.md gains "The X-Tenant-ID edge contract":

QuestionAnswer written down
What it meansA routing hint carrying the better-auth activeOrganizationId. Not an identity claim, not an authorization input, not what scopes rows
Who stamps itcreateAuthenticatedFetch, from ActiveOrganizationStorage, whenever that holds a value — not gated on the URL being an /api/ call, suppressed by sameOriginOnly for cross-origin URLs, overwrites a caller-supplied value
Who writes the storageAuthProvider only, at four moments (organization load, org switch, delete/leave, sign-out)
Who reads the headerThe cloud edge — cited from #5279, since that repo is not readable from here. Its configuration contract is readable here and is quoted from it
Who does not read itThe framework. resolveAuthzContext takes tenantId from the API-key principal or session.activeOrganizationId and from no header, pinned by packages/verify/src/harness.org-context.test.ts
What a reader may assumeMay route on it; may not treat it as identity, may not assume the row scoping came from it, may not assume it is present

The configuration half is not paraphrased from the cloud repo — it is measured from the contract this package actually resolves. TenantRoutingConfigSchema from @objectstack/spec/cloud (17.1.0, the version @object-ui/auth resolves), parsed on an empty config:

enabled: false
identificationSources: ["subdomain", "header", "jwt_claim"]
tenantHeaderName: "X-Tenant-ID"
jwtOrganizationClaim: "organizationId"

Two things a client author needs from that: the header name is configurable (X-Tenant-ID is a default, not a constant), and the header is one of six identification sources ranked second, behind subdomain — on a subdomain-routed deployment it is not what picks the tenant.

The negative half is stated with its own evidence, because "the framework ignores it" is the half that reads as "nobody uses it": the CORS allow-list comment (X-Tenant-ID / X-Environment-Id route "a request to its environment") and plugin-sharing's record that trusting x-tenant-id as identity was a vulnerability.

The unstamped-first-request gap

Its own section. ActiveOrganizationStorage is filled only after AuthProvider's async getSession -> listOrganizations -> getActiveOrganization chain resolves, so early-boot requests carry no tenant header at all. Documented:

Three pins, so the prose cannot drift

packages/auth/src/__tests__/createAuthenticatedFetch.test.tsx gains one case per wire-level statement the README makes: no active organization means no header at all (.has() false, not empty-string); the stamp is not gated on /api/ the way Authorization is; the active organization overwrites a caller-supplied X-Tenant-ID.

The middle one is labelled in the test body as recorded, not endorsed — it makes today's asymmetry visible so that gating the stamp becomes a deliberate, red-test change rather than a silent one, and the question is filed for triage rather than answered here.

Scope

Deliberately not in this PR, per the card:

Verification

Run at f3e0d6313, the head of this branch.

Scope is narrowed to @object-ui/auth, and the narrowing is proven rather than asserted: every .ts edit is comment-only, so the change can have no runtime effect. Demonstrated by compiling both revisions of createAuthenticatedFetch.ts with removeComments and diffing — byte-identical, 2750 bytes each — and by the package's other 20 emitted dist/*.js files being hash-identical across the rebuild. The instrument was self-checked: re-spelling one header literal in a scratchpad copy makes the same comparison go red, so a green reading is a measurement, not a no-op.

GateResult
pnpm --filter @object-ui/auth buildpass
pnpm --filter @object-ui/auth type-check (tsc --noEmit && tsc -p tsconfig.test.json)pass
pnpm --filter @object-ui/auth lintpass — 29 problems (0 errors, 29 warnings), every warning pre-existing in AuthProvider.tsx
pnpm exec vitest run packages/auth/Test Files 18 passed (18) / Tests 190 passed (190). The three new cases were confirmed to actually execute by a --reporter=verbose run of the edited file (Tests 13 passed (13), each new title printed), not inferred from the file-level count
node scripts/check-control-bytes.mjscheck-control-bytes: OK (scanned 4754 tracked text file(s); skipped 85 binary)
node scripts/check-changeset-presence.mjs2 source file(s) of 1 released package(s) changed, and this change declares 1 changeset(s)
node scripts/check-changeset-fixed.mjsAll workspace packages are in the changeset fixed group.
node scripts/check-changeset-no-major.mjsNo changeset declares a major bump.
node scripts/check-doc-snippet-types.mjsnarrowed, declared — see below

check-doc-snippet-types is the gate this diff most obviously reaches: its declared scan surface is every page under content/docsplus every packages/<name>/README.md. It refuses to run against an unbuilt tree (The snippet program was NOT run: the packages it resolves against are not built) and wants 14 packages built first, so it was not run in full here — CI runs it on a built tree.

What replaces it is a measurement rather than a hope, because the narrowing is provable. The gate compiles only the fence languages in its own exported TS_FENCE_LANGUAGESts, tsx, typescript — so the population was read from the gate itself and applied to both revisions of the file:

Revisionfenced blocksin the compiled population
before1110
after1310, byte-lengths identical and in the same order

The two blocks this PR adds are http and text — the header example and the parsed-config dump are not compilable programs, and marking them as fragments would have been a worse answer than writing them as TypeScript. The set of blocks the gate compiles is therefore unchanged by this diff, so its verdict on this file is unchanged. The extractor was self-checked: planting one ts block in a scratchpad copy takes the population from 10 to 11, so the zero-delta reading is a measurement and not a broken probe.

The rest of the farm is CI's run, as always.


Generated by Claude Code

…d-first-request gap (#5279)
The header `createAuthenticatedFetch` stamps had no written contract, and the
shape of the missing information was actively misleading: its only non-CORS
consumer lives in the cloud repository, so a search confined to this repo and
the framework returns zero readers and reads as "nothing consumes this stamp".
#5279 was filed on exactly that reading and held until a cloud-side reading came
back non-empty. Without the contract written down, the next person to grep
reaches the same false conclusion and deletes a live routing input.
packages/auth/README.md gains "The X-Tenant-ID edge contract": what the header
means (a routing hint carrying the better-auth activeOrganizationId, not an
identity claim, not an authorization input, not what scopes rows), who stamps it
and under exactly which condition, who reads it, and what a reader may and may
not assume. The framework half is stated as a negative with its pin —
resolveAuthzContext takes tenantId from the API-key principal or
session.activeOrganizationId and from no header — next to plugin-sharing's
record that trusting x-tenant-id as identity was a vulnerability. The
configuration half is quoted from the contract this package can actually
resolve, TenantRoutingConfigSchema in @objectstack/spec/cloud, where X-Tenant-ID
is the default of a configurable tenantHeaderName and `header` ranks second of
six identification sources behind `subdomain`.
The unstamped-first-request gap gets its own section: ActiveOrganizationStorage
is filled only after AuthProvider's async organization chain resolves, so
early-boot requests carry no tenant header at all. What a reader observes is
documented as absent, never present-and-empty, with the five situations that
open the window and the instruction to fall through to the next identification
source rather than fail closed. The gap is recorded, deliberately not closed:
the cloud readers observe today's behaviour.
The stamping site carries the decisive facts inline, because the source is what
a grep-then-delete reader reads first.
Three cases in createAuthenticatedFetch.test.tsx pin the statements the prose
makes about the wire, so the documentation cannot drift away from the behaviour
unnoticed.
Documentation only. Proven: with comments stripped, the emitted JS for
createAuthenticatedFetch.ts is byte-identical before and after (2750 bytes
both), and the package's other 20 dist JS files are hash-identical.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012u2pRjcqAYtoEjgr3wwhnK
@github-actionsgithub-actionsBot added documentation Improvements or additions to documentation tests labels Aug 22, 2026
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 52 chunks)3913.6 KB3990.2 KB
Main entry chunk (gzip)152.3 KB350 KB
Entry fileindex-spBIKF4m.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (index.js)10.04KB3.72KB
app-shell (runtime-config.js)12.80KB4.47KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)29.34KB7.05KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)9.63KB3.74KB
auth (index.js)2.77KB1.22KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.02KB0.89KB
auth (useIsWorkspaceAdmin.js)3.04KB1.45KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)506.90KB113.84KB
core (index.js)4.92KB1.97KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)160.15KB44.52KB
fields (index.js)238.40KB59.89KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)23.13KB7.63KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)7.77KB3.13KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)9.53KB3.38KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)4.64KB1.50KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)1.93KB0.88KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.62KB12.83KB
plugin-charts (index.js)64.65KB18.32KB
plugin-chatbot (index.js)181.41KB43.22KB
plugin-dashboard (index.js)128.41KB32.95KB
plugin-designer (index.js)212.30KB42.80KB
plugin-detail (index.js)242.34KB60.98KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)125.63KB30.64KB
plugin-gantt (index.js)164.10KB39.87KB
plugin-grid (index.js)200.79KB54.26KB
plugin-kanban (index.js)52.93KB14.60KB
plugin-list (index.js)111.80KB27.20KB
plugin-map (index.js)20.06KB6.62KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.49KB11.93KB
plugin-timeline (index.js)26.68KB7.66KB
plugin-tree (index.js)8.50KB2.88KB
plugin-view (index.js)84.61KB20.74KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)43.66KB14.77KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)1.33KB0.69KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (index.js)4.77KB2.16KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)10.76KB3.17KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)6.92KB2.40KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.87KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (index.js)3.59KB1.79KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-salesClaude

Copy link
Copy Markdown
CollaboratorAuthor

Seat review — accepted on its merits. HELD only on #5705, which is a red base, not this diff.

Fence held exactly: packages/auth/README.md, the stamping site, a test, a changeset. No content/docs/**, no apps/site/** — the brief routed the edge contract to package-local docs precisely so #5668 could not touch it, and that is where it went. No governed surfaces.

Three things I want on the record:

  1. It did not claim a measurement it could not make.objectstack-ai/cloud is unreachable from this session (add_repo returned no access), so the cloud readers are cited as the recorded reading rather than re-derived. What it measured instead is the part that is reachable, at runtime rather than by file-read: TenantRoutingConfigSchema.parse({}) against the version @object-ui/auth actually resolves → tenantHeaderName: 'X-Tenant-ID', and header ranking second of six identification sources behind subdomain. That is the [finding] 响应式词汇的两个零消费表面:useResponsiveConfig 生产零调用者(page.components[].responsive 因此实际未生效)、MobileComponentConfig 零消费者 #4773 lesson applied without being told.

  2. The narrowing is proven with a falsified instrument. Both revisions of createAuthenticatedFetch.ts compiled with removeComments → byte-identical (2750 bytes each), then self-checked by re-spelling a header literal in a scratchpad copy until the comparison went red. Worth being precise about why that is valid here: --removeComments proves program semantics unchanged; it does not license a shipped-bytes claim, and none was made — the bundle report shows auth (createAuthenticatedFetch.js) moving 6.35 → 9.63 KB, which is comment text surviving this package's build. Two gauges, two different questions, both read. (auth now joins core and react on the list of packages whose shipped .js moves on a prose-only change.)

  3. The check-doc-snippet-types narrowing is declared, not skipped. The gate refuses to run on an unbuilt tree, so instead of hoping, the agent read the gate module's own TS_FENCE_LANGUAGES and applied it to both revisions: 11 → 13 fenced blocks, but 10 → 10 in the compiled population, identical byte-lengths in identical order; the two added fences are http and text. Self-checked by planting a ts block to move 10 → 11.

The inline comment at the stamping site is the part that will still be earning its keep in a year — it names the exact failure this card was filed on:

DO NOT DELETE THIS ON THE STRENGTH OF A GREP. … a search confined to this repo plus the framework finds zero consumers and reads as "dead stamp" — which is the false premise objectui#5279 was filed on.

The isApiCall asymmetry it noticed was recorded, not acted on"recorded as the behaviour that ships, not endorsed" — and routed to #5702, where I have labelled it needs-user-decision. That is the right handling of a behaviour question found mid-fence.

Held pending #5705 (main red: console.ai.pendingDrafts missing from eight locale packs). Nothing about this PR needs to change; it merges when the base is green.


Generated by Claude Code

@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 52 chunks)3914.3 KB3990.2 KB
Main entry chunk (gzip)152.3 KB350 KB
Entry fileindex-DvF64ISu.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (index.js)10.04KB3.72KB
app-shell (runtime-config.js)12.80KB4.47KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)29.34KB7.05KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)9.63KB3.74KB
auth (index.js)2.77KB1.22KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.02KB0.89KB
auth (useIsWorkspaceAdmin.js)3.04KB1.45KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)506.90KB113.84KB
core (index.js)4.92KB1.97KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)160.15KB44.52KB
fields (index.js)238.40KB59.89KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)23.13KB7.63KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)7.77KB3.13KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)9.53KB3.38KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)4.64KB1.50KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)1.93KB0.88KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.62KB12.83KB
plugin-charts (index.js)64.65KB18.32KB
plugin-chatbot (index.js)181.41KB43.22KB
plugin-dashboard (index.js)128.41KB32.95KB
plugin-designer (index.js)212.30KB42.80KB
plugin-detail (index.js)242.34KB60.98KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)125.63KB30.64KB
plugin-gantt (index.js)164.10KB39.87KB
plugin-grid (index.js)200.79KB54.26KB
plugin-kanban (index.js)52.93KB14.60KB
plugin-list (index.js)111.80KB27.20KB
plugin-map (index.js)20.06KB6.62KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.49KB11.93KB
plugin-timeline (index.js)26.68KB7.66KB
plugin-tree (index.js)8.50KB2.88KB
plugin-view (index.js)84.61KB20.74KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)43.66KB14.77KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)1.33KB0.69KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (index.js)4.77KB2.16KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)10.76KB3.17KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)6.92KB2.40KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.87KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (index.js)3.59KB1.79KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-sales
os-sales marked this pull request as ready for review August 22, 2026 13:12
@os-sales
os-sales added this pull request to the merge queueAug 22, 2026
Merged via the queue into main with commit 934a532Aug 22, 2026
23 checks passed
@os-sales
os-sales deleted the claude/issue-5279-tenant-header-edge-contract branch August 22, 2026 13:12
os-sam pushed a commit that referenced this pull request Aug 31, 2026
The "Multi-tenancy" section taught that createAuthenticatedFetch sending
X-Tenant-ID is what makes row-level isolation happen. It is not: scoping
comes from the session, the header is an edge routing hint ranked behind
subdomain, and trusting it as identity is the recorded plugin-sharing
vulnerability. Repoint to packages/auth/README.md's "The X-Tenant-ID edge
contract" (added by #5279 / PR #5706) for the full contract.
akarma-synetal pushed a commit to akarma-synetal/objectui that referenced this pull request Sep 1, 2026
objectstack-ai#6974)
The "Multi-tenancy" section taught that createAuthenticatedFetch sending
X-Tenant-ID is what makes row-level isolation happen. It is not: scoping
comes from the session, the header is an edge routing hint ranked behind
subdomain, and trusting it as identity is the recorded plugin-sharing
vulnerability. Repoint to packages/auth/README.md's "The X-Tenant-ID edge
contract" (added by objectstack-ai#5279 / PR objectstack-ai#5706) for the full contract.
Co-authored-by: Claude <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentationImprovements or additions to documentationtests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Confirm whether X-Tenant-ID has a reader: the framework derives the tenant from the session, not the header

2 participants

@os-sales@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

docs(auth): write down the X-Tenant-ID edge contract and its unstamped-first-request gap - #5706

Merged
os-sales merged 2 commits into
mainfrom
claude/issue-5279-tenant-header-edge-contract
Aug 22, 2026
Merged

docs(auth): write down the X-Tenant-ID edge contract and its unstamped-first-request gap#5706
os-sales merged 2 commits into
mainfrom
claude/issue-5279-tenant-header-edge-contract

Conversation

@os-sales

Copy link
Copy Markdown
Collaborator

Fixes#5279

Documentation only. The header createAuthenticatedFetch stamps had no written contract, and the shape of the missing information was actively misleading.

Why this card existed at all

X-Tenant-ID's only non-CORS consumer lives in the cloud repository. A search confined to this repo and the framework (objectstack) finds zero readers and reads as "nothing consumes this stamp". #5279 was filed on exactly that reading, held on it, and was only discharged when a cloud-side reading came back non-empty (packages/service-tenant/src/tenant-context.ts, packages/tenant-router/src/spec/turso-multi-tenant.zod.ts).

That makes the missing documentation an active hazard rather than a gap: the next person to grep reaches the same false conclusion and deletes a live routing input. So the decisive facts go where a grep-then-delete reader looks first — the stamping site itself — and the full contract goes in the package README, which ships to npm.

What is documented

packages/auth/README.md gains "The X-Tenant-ID edge contract":

QuestionAnswer written down
What it meansA routing hint carrying the better-auth activeOrganizationId. Not an identity claim, not an authorization input, not what scopes rows
Who stamps itcreateAuthenticatedFetch, from ActiveOrganizationStorage, whenever that holds a value — not gated on the URL being an /api/ call, suppressed by sameOriginOnly for cross-origin URLs, overwrites a caller-supplied value
Who writes the storageAuthProvider only, at four moments (organization load, org switch, delete/leave, sign-out)
Who reads the headerThe cloud edge — cited from #5279, since that repo is not readable from here. Its configuration contract is readable here and is quoted from it
Who does not read itThe framework. resolveAuthzContext takes tenantId from the API-key principal or session.activeOrganizationId and from no header, pinned by packages/verify/src/harness.org-context.test.ts
What a reader may assumeMay route on it; may not treat it as identity, may not assume the row scoping came from it, may not assume it is present

The configuration half is not paraphrased from the cloud repo — it is measured from the contract this package actually resolves. TenantRoutingConfigSchema from @objectstack/spec/cloud (17.1.0, the version @object-ui/auth resolves), parsed on an empty config:

enabled: false
identificationSources: ["subdomain", "header", "jwt_claim"]
tenantHeaderName: "X-Tenant-ID"
jwtOrganizationClaim: "organizationId"

Two things a client author needs from that: the header name is configurable (X-Tenant-ID is a default, not a constant), and the header is one of six identification sources ranked second, behind subdomain — on a subdomain-routed deployment it is not what picks the tenant.

The negative half is stated with its own evidence, because "the framework ignores it" is the half that reads as "nobody uses it": the CORS allow-list comment (X-Tenant-ID / X-Environment-Id route "a request to its environment") and plugin-sharing's record that trusting x-tenant-id as identity was a vulnerability.

The unstamped-first-request gap

Its own section. ActiveOrganizationStorage is filled only after AuthProvider's async getSession -> listOrganizations -> getActiveOrganization chain resolves, so early-boot requests carry no tenant header at all. Documented:

Three pins, so the prose cannot drift

packages/auth/src/__tests__/createAuthenticatedFetch.test.tsx gains one case per wire-level statement the README makes: no active organization means no header at all (.has() false, not empty-string); the stamp is not gated on /api/ the way Authorization is; the active organization overwrites a caller-supplied X-Tenant-ID.

The middle one is labelled in the test body as recorded, not endorsed — it makes today's asymmetry visible so that gating the stamp becomes a deliberate, red-test change rather than a silent one, and the question is filed for triage rather than answered here.

Scope

Deliberately not in this PR, per the card:

Verification

Run at f3e0d6313, the head of this branch.

Scope is narrowed to @object-ui/auth, and the narrowing is proven rather than asserted: every .ts edit is comment-only, so the change can have no runtime effect. Demonstrated by compiling both revisions of createAuthenticatedFetch.ts with removeComments and diffing — byte-identical, 2750 bytes each — and by the package's other 20 emitted dist/*.js files being hash-identical across the rebuild. The instrument was self-checked: re-spelling one header literal in a scratchpad copy makes the same comparison go red, so a green reading is a measurement, not a no-op.

GateResult
pnpm --filter @object-ui/auth buildpass
pnpm --filter @object-ui/auth type-check (tsc --noEmit && tsc -p tsconfig.test.json)pass
pnpm --filter @object-ui/auth lintpass — 29 problems (0 errors, 29 warnings), every warning pre-existing in AuthProvider.tsx
pnpm exec vitest run packages/auth/Test Files 18 passed (18) / Tests 190 passed (190). The three new cases were confirmed to actually execute by a --reporter=verbose run of the edited file (Tests 13 passed (13), each new title printed), not inferred from the file-level count
node scripts/check-control-bytes.mjscheck-control-bytes: OK (scanned 4754 tracked text file(s); skipped 85 binary)
node scripts/check-changeset-presence.mjs2 source file(s) of 1 released package(s) changed, and this change declares 1 changeset(s)
node scripts/check-changeset-fixed.mjsAll workspace packages are in the changeset fixed group.
node scripts/check-changeset-no-major.mjsNo changeset declares a major bump.
node scripts/check-doc-snippet-types.mjsnarrowed, declared — see below

check-doc-snippet-types is the gate this diff most obviously reaches: its declared scan surface is every page under content/docsplus every packages/<name>/README.md. It refuses to run against an unbuilt tree (The snippet program was NOT run: the packages it resolves against are not built) and wants 14 packages built first, so it was not run in full here — CI runs it on a built tree.

What replaces it is a measurement rather than a hope, because the narrowing is provable. The gate compiles only the fence languages in its own exported TS_FENCE_LANGUAGESts, tsx, typescript — so the population was read from the gate itself and applied to both revisions of the file:

Revisionfenced blocksin the compiled population
before1110
after1310, byte-lengths identical and in the same order

The two blocks this PR adds are http and text — the header example and the parsed-config dump are not compilable programs, and marking them as fragments would have been a worse answer than writing them as TypeScript. The set of blocks the gate compiles is therefore unchanged by this diff, so its verdict on this file is unchanged. The extractor was self-checked: planting one ts block in a scratchpad copy takes the population from 10 to 11, so the zero-delta reading is a measurement and not a broken probe.

The rest of the farm is CI's run, as always.


Generated by Claude Code

…d-first-request gap (#5279)
The header `createAuthenticatedFetch` stamps had no written contract, and the
shape of the missing information was actively misleading: its only non-CORS
consumer lives in the cloud repository, so a search confined to this repo and
the framework returns zero readers and reads as "nothing consumes this stamp".
#5279 was filed on exactly that reading and held until a cloud-side reading came
back non-empty. Without the contract written down, the next person to grep
reaches the same false conclusion and deletes a live routing input.
packages/auth/README.md gains "The X-Tenant-ID edge contract": what the header
means (a routing hint carrying the better-auth activeOrganizationId, not an
identity claim, not an authorization input, not what scopes rows), who stamps it
and under exactly which condition, who reads it, and what a reader may and may
not assume. The framework half is stated as a negative with its pin —
resolveAuthzContext takes tenantId from the API-key principal or
session.activeOrganizationId and from no header — next to plugin-sharing's
record that trusting x-tenant-id as identity was a vulnerability. The
configuration half is quoted from the contract this package can actually
resolve, TenantRoutingConfigSchema in @objectstack/spec/cloud, where X-Tenant-ID
is the default of a configurable tenantHeaderName and `header` ranks second of
six identification sources behind `subdomain`.
The unstamped-first-request gap gets its own section: ActiveOrganizationStorage
is filled only after AuthProvider's async organization chain resolves, so
early-boot requests carry no tenant header at all. What a reader observes is
documented as absent, never present-and-empty, with the five situations that
open the window and the instruction to fall through to the next identification
source rather than fail closed. The gap is recorded, deliberately not closed:
the cloud readers observe today's behaviour.
The stamping site carries the decisive facts inline, because the source is what
a grep-then-delete reader reads first.
Three cases in createAuthenticatedFetch.test.tsx pin the statements the prose
makes about the wire, so the documentation cannot drift away from the behaviour
unnoticed.
Documentation only. Proven: with comments stripped, the emitted JS for
createAuthenticatedFetch.ts is byte-identical before and after (2750 bytes
both), and the package's other 20 dist JS files are hash-identical.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012u2pRjcqAYtoEjgr3wwhnK
@github-actionsgithub-actionsBot added documentation Improvements or additions to documentation tests labels Aug 22, 2026
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 52 chunks)3913.6 KB3990.2 KB
Main entry chunk (gzip)152.3 KB350 KB
Entry fileindex-spBIKF4m.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (index.js)10.04KB3.72KB
app-shell (runtime-config.js)12.80KB4.47KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)29.34KB7.05KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)9.63KB3.74KB
auth (index.js)2.77KB1.22KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.02KB0.89KB
auth (useIsWorkspaceAdmin.js)3.04KB1.45KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)506.90KB113.84KB
core (index.js)4.92KB1.97KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)160.15KB44.52KB
fields (index.js)238.40KB59.89KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)23.13KB7.63KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)7.77KB3.13KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)9.53KB3.38KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)4.64KB1.50KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)1.93KB0.88KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.62KB12.83KB
plugin-charts (index.js)64.65KB18.32KB
plugin-chatbot (index.js)181.41KB43.22KB
plugin-dashboard (index.js)128.41KB32.95KB
plugin-designer (index.js)212.30KB42.80KB
plugin-detail (index.js)242.34KB60.98KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)125.63KB30.64KB
plugin-gantt (index.js)164.10KB39.87KB
plugin-grid (index.js)200.79KB54.26KB
plugin-kanban (index.js)52.93KB14.60KB
plugin-list (index.js)111.80KB27.20KB
plugin-map (index.js)20.06KB6.62KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.49KB11.93KB
plugin-timeline (index.js)26.68KB7.66KB
plugin-tree (index.js)8.50KB2.88KB
plugin-view (index.js)84.61KB20.74KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)43.66KB14.77KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)1.33KB0.69KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (index.js)4.77KB2.16KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)10.76KB3.17KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)6.92KB2.40KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.87KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (index.js)3.59KB1.79KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-salesClaude

Copy link
Copy Markdown
CollaboratorAuthor

Seat review — accepted on its merits. HELD only on #5705, which is a red base, not this diff.

Fence held exactly: packages/auth/README.md, the stamping site, a test, a changeset. No content/docs/**, no apps/site/** — the brief routed the edge contract to package-local docs precisely so #5668 could not touch it, and that is where it went. No governed surfaces.

Three things I want on the record:

  1. It did not claim a measurement it could not make.objectstack-ai/cloud is unreachable from this session (add_repo returned no access), so the cloud readers are cited as the recorded reading rather than re-derived. What it measured instead is the part that is reachable, at runtime rather than by file-read: TenantRoutingConfigSchema.parse({}) against the version @object-ui/auth actually resolves → tenantHeaderName: 'X-Tenant-ID', and header ranking second of six identification sources behind subdomain. That is the [finding] 响应式词汇的两个零消费表面:useResponsiveConfig 生产零调用者(page.components[].responsive 因此实际未生效)、MobileComponentConfig 零消费者 #4773 lesson applied without being told.

  2. The narrowing is proven with a falsified instrument. Both revisions of createAuthenticatedFetch.ts compiled with removeComments → byte-identical (2750 bytes each), then self-checked by re-spelling a header literal in a scratchpad copy until the comparison went red. Worth being precise about why that is valid here: --removeComments proves program semantics unchanged; it does not license a shipped-bytes claim, and none was made — the bundle report shows auth (createAuthenticatedFetch.js) moving 6.35 → 9.63 KB, which is comment text surviving this package's build. Two gauges, two different questions, both read. (auth now joins core and react on the list of packages whose shipped .js moves on a prose-only change.)

  3. The check-doc-snippet-types narrowing is declared, not skipped. The gate refuses to run on an unbuilt tree, so instead of hoping, the agent read the gate module's own TS_FENCE_LANGUAGES and applied it to both revisions: 11 → 13 fenced blocks, but 10 → 10 in the compiled population, identical byte-lengths in identical order; the two added fences are http and text. Self-checked by planting a ts block to move 10 → 11.

The inline comment at the stamping site is the part that will still be earning its keep in a year — it names the exact failure this card was filed on:

DO NOT DELETE THIS ON THE STRENGTH OF A GREP. … a search confined to this repo plus the framework finds zero consumers and reads as "dead stamp" — which is the false premise objectui#5279 was filed on.

The isApiCall asymmetry it noticed was recorded, not acted on"recorded as the behaviour that ships, not endorsed" — and routed to #5702, where I have labelled it needs-user-decision. That is the right handling of a behaviour question found mid-fence.

Held pending #5705 (main red: console.ai.pendingDrafts missing from eight locale packs). Nothing about this PR needs to change; it merges when the base is green.


Generated by Claude Code

@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 52 chunks)3914.3 KB3990.2 KB
Main entry chunk (gzip)152.3 KB350 KB
Entry fileindex-DvF64ISu.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (index.js)10.04KB3.72KB
app-shell (runtime-config.js)12.80KB4.47KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)29.34KB7.05KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)9.63KB3.74KB
auth (index.js)2.77KB1.22KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.02KB0.89KB
auth (useIsWorkspaceAdmin.js)3.04KB1.45KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)506.90KB113.84KB
core (index.js)4.92KB1.97KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)160.15KB44.52KB
fields (index.js)238.40KB59.89KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)23.13KB7.63KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)7.77KB3.13KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)9.53KB3.38KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)4.64KB1.50KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)1.93KB0.88KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.62KB12.83KB
plugin-charts (index.js)64.65KB18.32KB
plugin-chatbot (index.js)181.41KB43.22KB
plugin-dashboard (index.js)128.41KB32.95KB
plugin-designer (index.js)212.30KB42.80KB
plugin-detail (index.js)242.34KB60.98KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)125.63KB30.64KB
plugin-gantt (index.js)164.10KB39.87KB
plugin-grid (index.js)200.79KB54.26KB
plugin-kanban (index.js)52.93KB14.60KB
plugin-list (index.js)111.80KB27.20KB
plugin-map (index.js)20.06KB6.62KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.49KB11.93KB
plugin-timeline (index.js)26.68KB7.66KB
plugin-tree (index.js)8.50KB2.88KB
plugin-view (index.js)84.61KB20.74KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)43.66KB14.77KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)1.33KB0.69KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (index.js)4.77KB2.16KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)10.76KB3.17KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)6.92KB2.40KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.87KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (index.js)3.59KB1.79KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-sales
os-sales marked this pull request as ready for review August 22, 2026 13:12
@os-sales
os-sales added this pull request to the merge queueAug 22, 2026
Merged via the queue into main with commit 934a532Aug 22, 2026
23 checks passed
@os-sales
os-sales deleted the claude/issue-5279-tenant-header-edge-contract branch August 22, 2026 13:12
os-sam pushed a commit that referenced this pull request Aug 31, 2026
The "Multi-tenancy" section taught that createAuthenticatedFetch sending
X-Tenant-ID is what makes row-level isolation happen. It is not: scoping
comes from the session, the header is an edge routing hint ranked behind
subdomain, and trusting it as identity is the recorded plugin-sharing
vulnerability. Repoint to packages/auth/README.md's "The X-Tenant-ID edge
contract" (added by #5279 / PR #5706) for the full contract.
akarma-synetal pushed a commit to akarma-synetal/objectui that referenced this pull request Sep 1, 2026
objectstack-ai#6974)
The "Multi-tenancy" section taught that createAuthenticatedFetch sending
X-Tenant-ID is what makes row-level isolation happen. It is not: scoping
comes from the session, the header is an edge routing hint ranked behind
subdomain, and trusting it as identity is the recorded plugin-sharing
vulnerability. Repoint to packages/auth/README.md's "The X-Tenant-ID edge
contract" (added by objectstack-ai#5279 / PR objectstack-ai#5706) for the full contract.
Co-authored-by: Claude <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentationImprovements or additions to documentationtests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Confirm whether X-Tenant-ID has a reader: the framework derives the tenant from the session, not the header

2 participants

@os-sales@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

docs(auth): write down the X-Tenant-ID edge contract and its unstamped-first-request gap - #5706

Merged
os-sales merged 2 commits into
mainfrom
claude/issue-5279-tenant-header-edge-contract
Aug 22, 2026
Merged

docs(auth): write down the X-Tenant-ID edge contract and its unstamped-first-request gap#5706
os-sales merged 2 commits into
mainfrom
claude/issue-5279-tenant-header-edge-contract

Conversation

@os-sales

Copy link
Copy Markdown
Collaborator

Fixes#5279

Documentation only. The header createAuthenticatedFetch stamps had no written contract, and the shape of the missing information was actively misleading.

Why this card existed at all

X-Tenant-ID's only non-CORS consumer lives in the cloud repository. A search confined to this repo and the framework (objectstack) finds zero readers and reads as "nothing consumes this stamp". #5279 was filed on exactly that reading, held on it, and was only discharged when a cloud-side reading came back non-empty (packages/service-tenant/src/tenant-context.ts, packages/tenant-router/src/spec/turso-multi-tenant.zod.ts).

That makes the missing documentation an active hazard rather than a gap: the next person to grep reaches the same false conclusion and deletes a live routing input. So the decisive facts go where a grep-then-delete reader looks first — the stamping site itself — and the full contract goes in the package README, which ships to npm.

What is documented

packages/auth/README.md gains "The X-Tenant-ID edge contract":

QuestionAnswer written down
What it meansA routing hint carrying the better-auth activeOrganizationId. Not an identity claim, not an authorization input, not what scopes rows
Who stamps itcreateAuthenticatedFetch, from ActiveOrganizationStorage, whenever that holds a value — not gated on the URL being an /api/ call, suppressed by sameOriginOnly for cross-origin URLs, overwrites a caller-supplied value
Who writes the storageAuthProvider only, at four moments (organization load, org switch, delete/leave, sign-out)
Who reads the headerThe cloud edge — cited from #5279, since that repo is not readable from here. Its configuration contract is readable here and is quoted from it
Who does not read itThe framework. resolveAuthzContext takes tenantId from the API-key principal or session.activeOrganizationId and from no header, pinned by packages/verify/src/harness.org-context.test.ts
What a reader may assumeMay route on it; may not treat it as identity, may not assume the row scoping came from it, may not assume it is present

The configuration half is not paraphrased from the cloud repo — it is measured from the contract this package actually resolves. TenantRoutingConfigSchema from @objectstack/spec/cloud (17.1.0, the version @object-ui/auth resolves), parsed on an empty config:

enabled: false
identificationSources: ["subdomain", "header", "jwt_claim"]
tenantHeaderName: "X-Tenant-ID"
jwtOrganizationClaim: "organizationId"

Two things a client author needs from that: the header name is configurable (X-Tenant-ID is a default, not a constant), and the header is one of six identification sources ranked second, behind subdomain — on a subdomain-routed deployment it is not what picks the tenant.

The negative half is stated with its own evidence, because "the framework ignores it" is the half that reads as "nobody uses it": the CORS allow-list comment (X-Tenant-ID / X-Environment-Id route "a request to its environment") and plugin-sharing's record that trusting x-tenant-id as identity was a vulnerability.

The unstamped-first-request gap

Its own section. ActiveOrganizationStorage is filled only after AuthProvider's async getSession -> listOrganizations -> getActiveOrganization chain resolves, so early-boot requests carry no tenant header at all. Documented:

Three pins, so the prose cannot drift

packages/auth/src/__tests__/createAuthenticatedFetch.test.tsx gains one case per wire-level statement the README makes: no active organization means no header at all (.has() false, not empty-string); the stamp is not gated on /api/ the way Authorization is; the active organization overwrites a caller-supplied X-Tenant-ID.

The middle one is labelled in the test body as recorded, not endorsed — it makes today's asymmetry visible so that gating the stamp becomes a deliberate, red-test change rather than a silent one, and the question is filed for triage rather than answered here.

Scope

Deliberately not in this PR, per the card:

Verification

Run at f3e0d6313, the head of this branch.

Scope is narrowed to @object-ui/auth, and the narrowing is proven rather than asserted: every .ts edit is comment-only, so the change can have no runtime effect. Demonstrated by compiling both revisions of createAuthenticatedFetch.ts with removeComments and diffing — byte-identical, 2750 bytes each — and by the package's other 20 emitted dist/*.js files being hash-identical across the rebuild. The instrument was self-checked: re-spelling one header literal in a scratchpad copy makes the same comparison go red, so a green reading is a measurement, not a no-op.

GateResult
pnpm --filter @object-ui/auth buildpass
pnpm --filter @object-ui/auth type-check (tsc --noEmit && tsc -p tsconfig.test.json)pass
pnpm --filter @object-ui/auth lintpass — 29 problems (0 errors, 29 warnings), every warning pre-existing in AuthProvider.tsx
pnpm exec vitest run packages/auth/Test Files 18 passed (18) / Tests 190 passed (190). The three new cases were confirmed to actually execute by a --reporter=verbose run of the edited file (Tests 13 passed (13), each new title printed), not inferred from the file-level count
node scripts/check-control-bytes.mjscheck-control-bytes: OK (scanned 4754 tracked text file(s); skipped 85 binary)
node scripts/check-changeset-presence.mjs2 source file(s) of 1 released package(s) changed, and this change declares 1 changeset(s)
node scripts/check-changeset-fixed.mjsAll workspace packages are in the changeset fixed group.
node scripts/check-changeset-no-major.mjsNo changeset declares a major bump.
node scripts/check-doc-snippet-types.mjsnarrowed, declared — see below

check-doc-snippet-types is the gate this diff most obviously reaches: its declared scan surface is every page under content/docsplus every packages/<name>/README.md. It refuses to run against an unbuilt tree (The snippet program was NOT run: the packages it resolves against are not built) and wants 14 packages built first, so it was not run in full here — CI runs it on a built tree.

What replaces it is a measurement rather than a hope, because the narrowing is provable. The gate compiles only the fence languages in its own exported TS_FENCE_LANGUAGESts, tsx, typescript — so the population was read from the gate itself and applied to both revisions of the file:

Revisionfenced blocksin the compiled population
before1110
after1310, byte-lengths identical and in the same order

The two blocks this PR adds are http and text — the header example and the parsed-config dump are not compilable programs, and marking them as fragments would have been a worse answer than writing them as TypeScript. The set of blocks the gate compiles is therefore unchanged by this diff, so its verdict on this file is unchanged. The extractor was self-checked: planting one ts block in a scratchpad copy takes the population from 10 to 11, so the zero-delta reading is a measurement and not a broken probe.

The rest of the farm is CI's run, as always.


Generated by Claude Code

…d-first-request gap (#5279)
The header `createAuthenticatedFetch` stamps had no written contract, and the
shape of the missing information was actively misleading: its only non-CORS
consumer lives in the cloud repository, so a search confined to this repo and
the framework returns zero readers and reads as "nothing consumes this stamp".
#5279 was filed on exactly that reading and held until a cloud-side reading came
back non-empty. Without the contract written down, the next person to grep
reaches the same false conclusion and deletes a live routing input.
packages/auth/README.md gains "The X-Tenant-ID edge contract": what the header
means (a routing hint carrying the better-auth activeOrganizationId, not an
identity claim, not an authorization input, not what scopes rows), who stamps it
and under exactly which condition, who reads it, and what a reader may and may
not assume. The framework half is stated as a negative with its pin —
resolveAuthzContext takes tenantId from the API-key principal or
session.activeOrganizationId and from no header — next to plugin-sharing's
record that trusting x-tenant-id as identity was a vulnerability. The
configuration half is quoted from the contract this package can actually
resolve, TenantRoutingConfigSchema in @objectstack/spec/cloud, where X-Tenant-ID
is the default of a configurable tenantHeaderName and `header` ranks second of
six identification sources behind `subdomain`.
The unstamped-first-request gap gets its own section: ActiveOrganizationStorage
is filled only after AuthProvider's async organization chain resolves, so
early-boot requests carry no tenant header at all. What a reader observes is
documented as absent, never present-and-empty, with the five situations that
open the window and the instruction to fall through to the next identification
source rather than fail closed. The gap is recorded, deliberately not closed:
the cloud readers observe today's behaviour.
The stamping site carries the decisive facts inline, because the source is what
a grep-then-delete reader reads first.
Three cases in createAuthenticatedFetch.test.tsx pin the statements the prose
makes about the wire, so the documentation cannot drift away from the behaviour
unnoticed.
Documentation only. Proven: with comments stripped, the emitted JS for
createAuthenticatedFetch.ts is byte-identical before and after (2750 bytes
both), and the package's other 20 dist JS files are hash-identical.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012u2pRjcqAYtoEjgr3wwhnK
@github-actionsgithub-actionsBot added documentation Improvements or additions to documentation tests labels Aug 22, 2026
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 52 chunks)3913.6 KB3990.2 KB
Main entry chunk (gzip)152.3 KB350 KB
Entry fileindex-spBIKF4m.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (index.js)10.04KB3.72KB
app-shell (runtime-config.js)12.80KB4.47KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)29.34KB7.05KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)9.63KB3.74KB
auth (index.js)2.77KB1.22KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.02KB0.89KB
auth (useIsWorkspaceAdmin.js)3.04KB1.45KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)506.90KB113.84KB
core (index.js)4.92KB1.97KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)160.15KB44.52KB
fields (index.js)238.40KB59.89KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)23.13KB7.63KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)7.77KB3.13KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)9.53KB3.38KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)4.64KB1.50KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)1.93KB0.88KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.62KB12.83KB
plugin-charts (index.js)64.65KB18.32KB
plugin-chatbot (index.js)181.41KB43.22KB
plugin-dashboard (index.js)128.41KB32.95KB
plugin-designer (index.js)212.30KB42.80KB
plugin-detail (index.js)242.34KB60.98KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)125.63KB30.64KB
plugin-gantt (index.js)164.10KB39.87KB
plugin-grid (index.js)200.79KB54.26KB
plugin-kanban (index.js)52.93KB14.60KB
plugin-list (index.js)111.80KB27.20KB
plugin-map (index.js)20.06KB6.62KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.49KB11.93KB
plugin-timeline (index.js)26.68KB7.66KB
plugin-tree (index.js)8.50KB2.88KB
plugin-view (index.js)84.61KB20.74KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)43.66KB14.77KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)1.33KB0.69KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (index.js)4.77KB2.16KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)10.76KB3.17KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)6.92KB2.40KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.87KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (index.js)3.59KB1.79KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-salesClaude

Copy link
Copy Markdown
CollaboratorAuthor

Seat review — accepted on its merits. HELD only on #5705, which is a red base, not this diff.

Fence held exactly: packages/auth/README.md, the stamping site, a test, a changeset. No content/docs/**, no apps/site/** — the brief routed the edge contract to package-local docs precisely so #5668 could not touch it, and that is where it went. No governed surfaces.

Three things I want on the record:

  1. It did not claim a measurement it could not make.objectstack-ai/cloud is unreachable from this session (add_repo returned no access), so the cloud readers are cited as the recorded reading rather than re-derived. What it measured instead is the part that is reachable, at runtime rather than by file-read: TenantRoutingConfigSchema.parse({}) against the version @object-ui/auth actually resolves → tenantHeaderName: 'X-Tenant-ID', and header ranking second of six identification sources behind subdomain. That is the [finding] 响应式词汇的两个零消费表面:useResponsiveConfig 生产零调用者(page.components[].responsive 因此实际未生效)、MobileComponentConfig 零消费者 #4773 lesson applied without being told.

  2. The narrowing is proven with a falsified instrument. Both revisions of createAuthenticatedFetch.ts compiled with removeComments → byte-identical (2750 bytes each), then self-checked by re-spelling a header literal in a scratchpad copy until the comparison went red. Worth being precise about why that is valid here: --removeComments proves program semantics unchanged; it does not license a shipped-bytes claim, and none was made — the bundle report shows auth (createAuthenticatedFetch.js) moving 6.35 → 9.63 KB, which is comment text surviving this package's build. Two gauges, two different questions, both read. (auth now joins core and react on the list of packages whose shipped .js moves on a prose-only change.)

  3. The check-doc-snippet-types narrowing is declared, not skipped. The gate refuses to run on an unbuilt tree, so instead of hoping, the agent read the gate module's own TS_FENCE_LANGUAGES and applied it to both revisions: 11 → 13 fenced blocks, but 10 → 10 in the compiled population, identical byte-lengths in identical order; the two added fences are http and text. Self-checked by planting a ts block to move 10 → 11.

The inline comment at the stamping site is the part that will still be earning its keep in a year — it names the exact failure this card was filed on:

DO NOT DELETE THIS ON THE STRENGTH OF A GREP. … a search confined to this repo plus the framework finds zero consumers and reads as "dead stamp" — which is the false premise objectui#5279 was filed on.

The isApiCall asymmetry it noticed was recorded, not acted on"recorded as the behaviour that ships, not endorsed" — and routed to #5702, where I have labelled it needs-user-decision. That is the right handling of a behaviour question found mid-fence.

Held pending #5705 (main red: console.ai.pendingDrafts missing from eight locale packs). Nothing about this PR needs to change; it merges when the base is green.


Generated by Claude Code

@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 52 chunks)3914.3 KB3990.2 KB
Main entry chunk (gzip)152.3 KB350 KB
Entry fileindex-DvF64ISu.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (index.js)10.04KB3.72KB
app-shell (runtime-config.js)12.80KB4.47KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)29.34KB7.05KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)9.63KB3.74KB
auth (index.js)2.77KB1.22KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.02KB0.89KB
auth (useIsWorkspaceAdmin.js)3.04KB1.45KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)506.90KB113.84KB
core (index.js)4.92KB1.97KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)160.15KB44.52KB
fields (index.js)238.40KB59.89KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)23.13KB7.63KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)7.77KB3.13KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)9.53KB3.38KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)4.64KB1.50KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)1.93KB0.88KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.62KB12.83KB
plugin-charts (index.js)64.65KB18.32KB
plugin-chatbot (index.js)181.41KB43.22KB
plugin-dashboard (index.js)128.41KB32.95KB
plugin-designer (index.js)212.30KB42.80KB
plugin-detail (index.js)242.34KB60.98KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)125.63KB30.64KB
plugin-gantt (index.js)164.10KB39.87KB
plugin-grid (index.js)200.79KB54.26KB
plugin-kanban (index.js)52.93KB14.60KB
plugin-list (index.js)111.80KB27.20KB
plugin-map (index.js)20.06KB6.62KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.49KB11.93KB
plugin-timeline (index.js)26.68KB7.66KB
plugin-tree (index.js)8.50KB2.88KB
plugin-view (index.js)84.61KB20.74KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)43.66KB14.77KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)1.33KB0.69KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (index.js)4.77KB2.16KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)10.76KB3.17KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)6.92KB2.40KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.87KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (index.js)3.59KB1.79KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-sales
os-sales marked this pull request as ready for review August 22, 2026 13:12
@os-sales
os-sales added this pull request to the merge queueAug 22, 2026
Merged via the queue into main with commit 934a532Aug 22, 2026
23 checks passed
@os-sales
os-sales deleted the claude/issue-5279-tenant-header-edge-contract branch August 22, 2026 13:12
os-sam pushed a commit that referenced this pull request Aug 31, 2026
The "Multi-tenancy" section taught that createAuthenticatedFetch sending
X-Tenant-ID is what makes row-level isolation happen. It is not: scoping
comes from the session, the header is an edge routing hint ranked behind
subdomain, and trusting it as identity is the recorded plugin-sharing
vulnerability. Repoint to packages/auth/README.md's "The X-Tenant-ID edge
contract" (added by #5279 / PR #5706) for the full contract.
akarma-synetal pushed a commit to akarma-synetal/objectui that referenced this pull request Sep 1, 2026
objectstack-ai#6974)
The "Multi-tenancy" section taught that createAuthenticatedFetch sending
X-Tenant-ID is what makes row-level isolation happen. It is not: scoping
comes from the session, the header is an edge routing hint ranked behind
subdomain, and trusting it as identity is the recorded plugin-sharing
vulnerability. Repoint to packages/auth/README.md's "The X-Tenant-ID edge
contract" (added by objectstack-ai#5279 / PR objectstack-ai#5706) for the full contract.
Co-authored-by: Claude <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentationImprovements or additions to documentationtests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Confirm whether X-Tenant-ID has a reader: the framework derives the tenant from the session, not the header

2 participants

@os-sales@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

docs(auth): write down the X-Tenant-ID edge contract and its unstamped-first-request gap - #5706

Merged
os-sales merged 2 commits into
mainfrom
claude/issue-5279-tenant-header-edge-contract
Aug 22, 2026
Merged

docs(auth): write down the X-Tenant-ID edge contract and its unstamped-first-request gap#5706
os-sales merged 2 commits into
mainfrom
claude/issue-5279-tenant-header-edge-contract

Conversation

@os-sales

Copy link
Copy Markdown
Collaborator

Fixes#5279

Documentation only. The header createAuthenticatedFetch stamps had no written contract, and the shape of the missing information was actively misleading.

Why this card existed at all

X-Tenant-ID's only non-CORS consumer lives in the cloud repository. A search confined to this repo and the framework (objectstack) finds zero readers and reads as "nothing consumes this stamp". #5279 was filed on exactly that reading, held on it, and was only discharged when a cloud-side reading came back non-empty (packages/service-tenant/src/tenant-context.ts, packages/tenant-router/src/spec/turso-multi-tenant.zod.ts).

That makes the missing documentation an active hazard rather than a gap: the next person to grep reaches the same false conclusion and deletes a live routing input. So the decisive facts go where a grep-then-delete reader looks first — the stamping site itself — and the full contract goes in the package README, which ships to npm.

What is documented

packages/auth/README.md gains "The X-Tenant-ID edge contract":

QuestionAnswer written down
What it meansA routing hint carrying the better-auth activeOrganizationId. Not an identity claim, not an authorization input, not what scopes rows
Who stamps itcreateAuthenticatedFetch, from ActiveOrganizationStorage, whenever that holds a value — not gated on the URL being an /api/ call, suppressed by sameOriginOnly for cross-origin URLs, overwrites a caller-supplied value
Who writes the storageAuthProvider only, at four moments (organization load, org switch, delete/leave, sign-out)
Who reads the headerThe cloud edge — cited from #5279, since that repo is not readable from here. Its configuration contract is readable here and is quoted from it
Who does not read itThe framework. resolveAuthzContext takes tenantId from the API-key principal or session.activeOrganizationId and from no header, pinned by packages/verify/src/harness.org-context.test.ts
What a reader may assumeMay route on it; may not treat it as identity, may not assume the row scoping came from it, may not assume it is present

The configuration half is not paraphrased from the cloud repo — it is measured from the contract this package actually resolves. TenantRoutingConfigSchema from @objectstack/spec/cloud (17.1.0, the version @object-ui/auth resolves), parsed on an empty config:

enabled: false
identificationSources: ["subdomain", "header", "jwt_claim"]
tenantHeaderName: "X-Tenant-ID"
jwtOrganizationClaim: "organizationId"

Two things a client author needs from that: the header name is configurable (X-Tenant-ID is a default, not a constant), and the header is one of six identification sources ranked second, behind subdomain — on a subdomain-routed deployment it is not what picks the tenant.

The negative half is stated with its own evidence, because "the framework ignores it" is the half that reads as "nobody uses it": the CORS allow-list comment (X-Tenant-ID / X-Environment-Id route "a request to its environment") and plugin-sharing's record that trusting x-tenant-id as identity was a vulnerability.

The unstamped-first-request gap

Its own section. ActiveOrganizationStorage is filled only after AuthProvider's async getSession -> listOrganizations -> getActiveOrganization chain resolves, so early-boot requests carry no tenant header at all. Documented:

Three pins, so the prose cannot drift

packages/auth/src/__tests__/createAuthenticatedFetch.test.tsx gains one case per wire-level statement the README makes: no active organization means no header at all (.has() false, not empty-string); the stamp is not gated on /api/ the way Authorization is; the active organization overwrites a caller-supplied X-Tenant-ID.

The middle one is labelled in the test body as recorded, not endorsed — it makes today's asymmetry visible so that gating the stamp becomes a deliberate, red-test change rather than a silent one, and the question is filed for triage rather than answered here.

Scope

Deliberately not in this PR, per the card:

Verification

Run at f3e0d6313, the head of this branch.

Scope is narrowed to @object-ui/auth, and the narrowing is proven rather than asserted: every .ts edit is comment-only, so the change can have no runtime effect. Demonstrated by compiling both revisions of createAuthenticatedFetch.ts with removeComments and diffing — byte-identical, 2750 bytes each — and by the package's other 20 emitted dist/*.js files being hash-identical across the rebuild. The instrument was self-checked: re-spelling one header literal in a scratchpad copy makes the same comparison go red, so a green reading is a measurement, not a no-op.

GateResult
pnpm --filter @object-ui/auth buildpass
pnpm --filter @object-ui/auth type-check (tsc --noEmit && tsc -p tsconfig.test.json)pass
pnpm --filter @object-ui/auth lintpass — 29 problems (0 errors, 29 warnings), every warning pre-existing in AuthProvider.tsx
pnpm exec vitest run packages/auth/Test Files 18 passed (18) / Tests 190 passed (190). The three new cases were confirmed to actually execute by a --reporter=verbose run of the edited file (Tests 13 passed (13), each new title printed), not inferred from the file-level count
node scripts/check-control-bytes.mjscheck-control-bytes: OK (scanned 4754 tracked text file(s); skipped 85 binary)
node scripts/check-changeset-presence.mjs2 source file(s) of 1 released package(s) changed, and this change declares 1 changeset(s)
node scripts/check-changeset-fixed.mjsAll workspace packages are in the changeset fixed group.
node scripts/check-changeset-no-major.mjsNo changeset declares a major bump.
node scripts/check-doc-snippet-types.mjsnarrowed, declared — see below

check-doc-snippet-types is the gate this diff most obviously reaches: its declared scan surface is every page under content/docsplus every packages/<name>/README.md. It refuses to run against an unbuilt tree (The snippet program was NOT run: the packages it resolves against are not built) and wants 14 packages built first, so it was not run in full here — CI runs it on a built tree.

What replaces it is a measurement rather than a hope, because the narrowing is provable. The gate compiles only the fence languages in its own exported TS_FENCE_LANGUAGESts, tsx, typescript — so the population was read from the gate itself and applied to both revisions of the file:

Revisionfenced blocksin the compiled population
before1110
after1310, byte-lengths identical and in the same order

The two blocks this PR adds are http and text — the header example and the parsed-config dump are not compilable programs, and marking them as fragments would have been a worse answer than writing them as TypeScript. The set of blocks the gate compiles is therefore unchanged by this diff, so its verdict on this file is unchanged. The extractor was self-checked: planting one ts block in a scratchpad copy takes the population from 10 to 11, so the zero-delta reading is a measurement and not a broken probe.

The rest of the farm is CI's run, as always.


Generated by Claude Code

…d-first-request gap (#5279)
The header `createAuthenticatedFetch` stamps had no written contract, and the
shape of the missing information was actively misleading: its only non-CORS
consumer lives in the cloud repository, so a search confined to this repo and
the framework returns zero readers and reads as "nothing consumes this stamp".
#5279 was filed on exactly that reading and held until a cloud-side reading came
back non-empty. Without the contract written down, the next person to grep
reaches the same false conclusion and deletes a live routing input.
packages/auth/README.md gains "The X-Tenant-ID edge contract": what the header
means (a routing hint carrying the better-auth activeOrganizationId, not an
identity claim, not an authorization input, not what scopes rows), who stamps it
and under exactly which condition, who reads it, and what a reader may and may
not assume. The framework half is stated as a negative with its pin —
resolveAuthzContext takes tenantId from the API-key principal or
session.activeOrganizationId and from no header — next to plugin-sharing's
record that trusting x-tenant-id as identity was a vulnerability. The
configuration half is quoted from the contract this package can actually
resolve, TenantRoutingConfigSchema in @objectstack/spec/cloud, where X-Tenant-ID
is the default of a configurable tenantHeaderName and `header` ranks second of
six identification sources behind `subdomain`.
The unstamped-first-request gap gets its own section: ActiveOrganizationStorage
is filled only after AuthProvider's async organization chain resolves, so
early-boot requests carry no tenant header at all. What a reader observes is
documented as absent, never present-and-empty, with the five situations that
open the window and the instruction to fall through to the next identification
source rather than fail closed. The gap is recorded, deliberately not closed:
the cloud readers observe today's behaviour.
The stamping site carries the decisive facts inline, because the source is what
a grep-then-delete reader reads first.
Three cases in createAuthenticatedFetch.test.tsx pin the statements the prose
makes about the wire, so the documentation cannot drift away from the behaviour
unnoticed.
Documentation only. Proven: with comments stripped, the emitted JS for
createAuthenticatedFetch.ts is byte-identical before and after (2750 bytes
both), and the package's other 20 dist JS files are hash-identical.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012u2pRjcqAYtoEjgr3wwhnK
@github-actionsgithub-actionsBot added documentation Improvements or additions to documentation tests labels Aug 22, 2026
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 52 chunks)3913.6 KB3990.2 KB
Main entry chunk (gzip)152.3 KB350 KB
Entry fileindex-spBIKF4m.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (index.js)10.04KB3.72KB
app-shell (runtime-config.js)12.80KB4.47KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)29.34KB7.05KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)9.63KB3.74KB
auth (index.js)2.77KB1.22KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.02KB0.89KB
auth (useIsWorkspaceAdmin.js)3.04KB1.45KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)506.90KB113.84KB
core (index.js)4.92KB1.97KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)160.15KB44.52KB
fields (index.js)238.40KB59.89KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)23.13KB7.63KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)7.77KB3.13KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)9.53KB3.38KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)4.64KB1.50KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)1.93KB0.88KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.62KB12.83KB
plugin-charts (index.js)64.65KB18.32KB
plugin-chatbot (index.js)181.41KB43.22KB
plugin-dashboard (index.js)128.41KB32.95KB
plugin-designer (index.js)212.30KB42.80KB
plugin-detail (index.js)242.34KB60.98KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)125.63KB30.64KB
plugin-gantt (index.js)164.10KB39.87KB
plugin-grid (index.js)200.79KB54.26KB
plugin-kanban (index.js)52.93KB14.60KB
plugin-list (index.js)111.80KB27.20KB
plugin-map (index.js)20.06KB6.62KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.49KB11.93KB
plugin-timeline (index.js)26.68KB7.66KB
plugin-tree (index.js)8.50KB2.88KB
plugin-view (index.js)84.61KB20.74KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)43.66KB14.77KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)1.33KB0.69KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (index.js)4.77KB2.16KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)10.76KB3.17KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)6.92KB2.40KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.87KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (index.js)3.59KB1.79KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-salesClaude

Copy link
Copy Markdown
CollaboratorAuthor

Seat review — accepted on its merits. HELD only on #5705, which is a red base, not this diff.

Fence held exactly: packages/auth/README.md, the stamping site, a test, a changeset. No content/docs/**, no apps/site/** — the brief routed the edge contract to package-local docs precisely so #5668 could not touch it, and that is where it went. No governed surfaces.

Three things I want on the record:

  1. It did not claim a measurement it could not make.objectstack-ai/cloud is unreachable from this session (add_repo returned no access), so the cloud readers are cited as the recorded reading rather than re-derived. What it measured instead is the part that is reachable, at runtime rather than by file-read: TenantRoutingConfigSchema.parse({}) against the version @object-ui/auth actually resolves → tenantHeaderName: 'X-Tenant-ID', and header ranking second of six identification sources behind subdomain. That is the [finding] 响应式词汇的两个零消费表面:useResponsiveConfig 生产零调用者(page.components[].responsive 因此实际未生效)、MobileComponentConfig 零消费者 #4773 lesson applied without being told.

  2. The narrowing is proven with a falsified instrument. Both revisions of createAuthenticatedFetch.ts compiled with removeComments → byte-identical (2750 bytes each), then self-checked by re-spelling a header literal in a scratchpad copy until the comparison went red. Worth being precise about why that is valid here: --removeComments proves program semantics unchanged; it does not license a shipped-bytes claim, and none was made — the bundle report shows auth (createAuthenticatedFetch.js) moving 6.35 → 9.63 KB, which is comment text surviving this package's build. Two gauges, two different questions, both read. (auth now joins core and react on the list of packages whose shipped .js moves on a prose-only change.)

  3. The check-doc-snippet-types narrowing is declared, not skipped. The gate refuses to run on an unbuilt tree, so instead of hoping, the agent read the gate module's own TS_FENCE_LANGUAGES and applied it to both revisions: 11 → 13 fenced blocks, but 10 → 10 in the compiled population, identical byte-lengths in identical order; the two added fences are http and text. Self-checked by planting a ts block to move 10 → 11.

The inline comment at the stamping site is the part that will still be earning its keep in a year — it names the exact failure this card was filed on:

DO NOT DELETE THIS ON THE STRENGTH OF A GREP. … a search confined to this repo plus the framework finds zero consumers and reads as "dead stamp" — which is the false premise objectui#5279 was filed on.

The isApiCall asymmetry it noticed was recorded, not acted on"recorded as the behaviour that ships, not endorsed" — and routed to #5702, where I have labelled it needs-user-decision. That is the right handling of a behaviour question found mid-fence.

Held pending #5705 (main red: console.ai.pendingDrafts missing from eight locale packs). Nothing about this PR needs to change; it merges when the base is green.


Generated by Claude Code

@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 52 chunks)3914.3 KB3990.2 KB
Main entry chunk (gzip)152.3 KB350 KB
Entry fileindex-DvF64ISu.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (index.js)10.04KB3.72KB
app-shell (runtime-config.js)12.80KB4.47KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)29.34KB7.05KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)9.63KB3.74KB
auth (index.js)2.77KB1.22KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.02KB0.89KB
auth (useIsWorkspaceAdmin.js)3.04KB1.45KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)506.90KB113.84KB
core (index.js)4.92KB1.97KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)160.15KB44.52KB
fields (index.js)238.40KB59.89KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)23.13KB7.63KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)7.77KB3.13KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)9.53KB3.38KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)4.64KB1.50KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)1.93KB0.88KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.62KB12.83KB
plugin-charts (index.js)64.65KB18.32KB
plugin-chatbot (index.js)181.41KB43.22KB
plugin-dashboard (index.js)128.41KB32.95KB
plugin-designer (index.js)212.30KB42.80KB
plugin-detail (index.js)242.34KB60.98KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)125.63KB30.64KB
plugin-gantt (index.js)164.10KB39.87KB
plugin-grid (index.js)200.79KB54.26KB
plugin-kanban (index.js)52.93KB14.60KB
plugin-list (index.js)111.80KB27.20KB
plugin-map (index.js)20.06KB6.62KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.49KB11.93KB
plugin-timeline (index.js)26.68KB7.66KB
plugin-tree (index.js)8.50KB2.88KB
plugin-view (index.js)84.61KB20.74KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)43.66KB14.77KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)1.33KB0.69KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (index.js)4.77KB2.16KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)10.76KB3.17KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)6.92KB2.40KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.87KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (index.js)3.59KB1.79KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-sales
os-sales marked this pull request as ready for review August 22, 2026 13:12
@os-sales
os-sales added this pull request to the merge queueAug 22, 2026
Merged via the queue into main with commit 934a532Aug 22, 2026
23 checks passed
@os-sales
os-sales deleted the claude/issue-5279-tenant-header-edge-contract branch August 22, 2026 13:12
os-sam pushed a commit that referenced this pull request Aug 31, 2026
The "Multi-tenancy" section taught that createAuthenticatedFetch sending
X-Tenant-ID is what makes row-level isolation happen. It is not: scoping
comes from the session, the header is an edge routing hint ranked behind
subdomain, and trusting it as identity is the recorded plugin-sharing
vulnerability. Repoint to packages/auth/README.md's "The X-Tenant-ID edge
contract" (added by #5279 / PR #5706) for the full contract.
akarma-synetal pushed a commit to akarma-synetal/objectui that referenced this pull request Sep 1, 2026
objectstack-ai#6974)
The "Multi-tenancy" section taught that createAuthenticatedFetch sending
X-Tenant-ID is what makes row-level isolation happen. It is not: scoping
comes from the session, the header is an edge routing hint ranked behind
subdomain, and trusting it as identity is the recorded plugin-sharing
vulnerability. Repoint to packages/auth/README.md's "The X-Tenant-ID edge
contract" (added by objectstack-ai#5279 / PR objectstack-ai#5706) for the full contract.
Co-authored-by: Claude <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentationImprovements or additions to documentationtests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Confirm whether X-Tenant-ID has a reader: the framework derives the tenant from the session, not the header

2 participants

@os-sales@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

docs(auth): write down the X-Tenant-ID edge contract and its unstamped-first-request gap - #5706

Merged
os-sales merged 2 commits into
mainfrom
claude/issue-5279-tenant-header-edge-contract
Aug 22, 2026
Merged

docs(auth): write down the X-Tenant-ID edge contract and its unstamped-first-request gap#5706
os-sales merged 2 commits into
mainfrom
claude/issue-5279-tenant-header-edge-contract

Conversation

@os-sales

Copy link
Copy Markdown
Collaborator

Fixes#5279

Documentation only. The header createAuthenticatedFetch stamps had no written contract, and the shape of the missing information was actively misleading.

Why this card existed at all

X-Tenant-ID's only non-CORS consumer lives in the cloud repository. A search confined to this repo and the framework (objectstack) finds zero readers and reads as "nothing consumes this stamp". #5279 was filed on exactly that reading, held on it, and was only discharged when a cloud-side reading came back non-empty (packages/service-tenant/src/tenant-context.ts, packages/tenant-router/src/spec/turso-multi-tenant.zod.ts).

That makes the missing documentation an active hazard rather than a gap: the next person to grep reaches the same false conclusion and deletes a live routing input. So the decisive facts go where a grep-then-delete reader looks first — the stamping site itself — and the full contract goes in the package README, which ships to npm.

What is documented

packages/auth/README.md gains "The X-Tenant-ID edge contract":

QuestionAnswer written down
What it meansA routing hint carrying the better-auth activeOrganizationId. Not an identity claim, not an authorization input, not what scopes rows
Who stamps itcreateAuthenticatedFetch, from ActiveOrganizationStorage, whenever that holds a value — not gated on the URL being an /api/ call, suppressed by sameOriginOnly for cross-origin URLs, overwrites a caller-supplied value
Who writes the storageAuthProvider only, at four moments (organization load, org switch, delete/leave, sign-out)
Who reads the headerThe cloud edge — cited from #5279, since that repo is not readable from here. Its configuration contract is readable here and is quoted from it
Who does not read itThe framework. resolveAuthzContext takes tenantId from the API-key principal or session.activeOrganizationId and from no header, pinned by packages/verify/src/harness.org-context.test.ts
What a reader may assumeMay route on it; may not treat it as identity, may not assume the row scoping came from it, may not assume it is present

The configuration half is not paraphrased from the cloud repo — it is measured from the contract this package actually resolves. TenantRoutingConfigSchema from @objectstack/spec/cloud (17.1.0, the version @object-ui/auth resolves), parsed on an empty config:

enabled: false
identificationSources: ["subdomain", "header", "jwt_claim"]
tenantHeaderName: "X-Tenant-ID"
jwtOrganizationClaim: "organizationId"

Two things a client author needs from that: the header name is configurable (X-Tenant-ID is a default, not a constant), and the header is one of six identification sources ranked second, behind subdomain — on a subdomain-routed deployment it is not what picks the tenant.

The negative half is stated with its own evidence, because "the framework ignores it" is the half that reads as "nobody uses it": the CORS allow-list comment (X-Tenant-ID / X-Environment-Id route "a request to its environment") and plugin-sharing's record that trusting x-tenant-id as identity was a vulnerability.

The unstamped-first-request gap

Its own section. ActiveOrganizationStorage is filled only after AuthProvider's async getSession -> listOrganizations -> getActiveOrganization chain resolves, so early-boot requests carry no tenant header at all. Documented:

Three pins, so the prose cannot drift

packages/auth/src/__tests__/createAuthenticatedFetch.test.tsx gains one case per wire-level statement the README makes: no active organization means no header at all (.has() false, not empty-string); the stamp is not gated on /api/ the way Authorization is; the active organization overwrites a caller-supplied X-Tenant-ID.

The middle one is labelled in the test body as recorded, not endorsed — it makes today's asymmetry visible so that gating the stamp becomes a deliberate, red-test change rather than a silent one, and the question is filed for triage rather than answered here.

Scope

Deliberately not in this PR, per the card:

Verification

Run at f3e0d6313, the head of this branch.

Scope is narrowed to @object-ui/auth, and the narrowing is proven rather than asserted: every .ts edit is comment-only, so the change can have no runtime effect. Demonstrated by compiling both revisions of createAuthenticatedFetch.ts with removeComments and diffing — byte-identical, 2750 bytes each — and by the package's other 20 emitted dist/*.js files being hash-identical across the rebuild. The instrument was self-checked: re-spelling one header literal in a scratchpad copy makes the same comparison go red, so a green reading is a measurement, not a no-op.

GateResult
pnpm --filter @object-ui/auth buildpass
pnpm --filter @object-ui/auth type-check (tsc --noEmit && tsc -p tsconfig.test.json)pass
pnpm --filter @object-ui/auth lintpass — 29 problems (0 errors, 29 warnings), every warning pre-existing in AuthProvider.tsx
pnpm exec vitest run packages/auth/Test Files 18 passed (18) / Tests 190 passed (190). The three new cases were confirmed to actually execute by a --reporter=verbose run of the edited file (Tests 13 passed (13), each new title printed), not inferred from the file-level count
node scripts/check-control-bytes.mjscheck-control-bytes: OK (scanned 4754 tracked text file(s); skipped 85 binary)
node scripts/check-changeset-presence.mjs2 source file(s) of 1 released package(s) changed, and this change declares 1 changeset(s)
node scripts/check-changeset-fixed.mjsAll workspace packages are in the changeset fixed group.
node scripts/check-changeset-no-major.mjsNo changeset declares a major bump.
node scripts/check-doc-snippet-types.mjsnarrowed, declared — see below

check-doc-snippet-types is the gate this diff most obviously reaches: its declared scan surface is every page under content/docsplus every packages/<name>/README.md. It refuses to run against an unbuilt tree (The snippet program was NOT run: the packages it resolves against are not built) and wants 14 packages built first, so it was not run in full here — CI runs it on a built tree.

What replaces it is a measurement rather than a hope, because the narrowing is provable. The gate compiles only the fence languages in its own exported TS_FENCE_LANGUAGESts, tsx, typescript — so the population was read from the gate itself and applied to both revisions of the file:

Revisionfenced blocksin the compiled population
before1110
after1310, byte-lengths identical and in the same order

The two blocks this PR adds are http and text — the header example and the parsed-config dump are not compilable programs, and marking them as fragments would have been a worse answer than writing them as TypeScript. The set of blocks the gate compiles is therefore unchanged by this diff, so its verdict on this file is unchanged. The extractor was self-checked: planting one ts block in a scratchpad copy takes the population from 10 to 11, so the zero-delta reading is a measurement and not a broken probe.

The rest of the farm is CI's run, as always.


Generated by Claude Code

…d-first-request gap (#5279)
The header `createAuthenticatedFetch` stamps had no written contract, and the
shape of the missing information was actively misleading: its only non-CORS
consumer lives in the cloud repository, so a search confined to this repo and
the framework returns zero readers and reads as "nothing consumes this stamp".
#5279 was filed on exactly that reading and held until a cloud-side reading came
back non-empty. Without the contract written down, the next person to grep
reaches the same false conclusion and deletes a live routing input.
packages/auth/README.md gains "The X-Tenant-ID edge contract": what the header
means (a routing hint carrying the better-auth activeOrganizationId, not an
identity claim, not an authorization input, not what scopes rows), who stamps it
and under exactly which condition, who reads it, and what a reader may and may
not assume. The framework half is stated as a negative with its pin —
resolveAuthzContext takes tenantId from the API-key principal or
session.activeOrganizationId and from no header — next to plugin-sharing's
record that trusting x-tenant-id as identity was a vulnerability. The
configuration half is quoted from the contract this package can actually
resolve, TenantRoutingConfigSchema in @objectstack/spec/cloud, where X-Tenant-ID
is the default of a configurable tenantHeaderName and `header` ranks second of
six identification sources behind `subdomain`.
The unstamped-first-request gap gets its own section: ActiveOrganizationStorage
is filled only after AuthProvider's async organization chain resolves, so
early-boot requests carry no tenant header at all. What a reader observes is
documented as absent, never present-and-empty, with the five situations that
open the window and the instruction to fall through to the next identification
source rather than fail closed. The gap is recorded, deliberately not closed:
the cloud readers observe today's behaviour.
The stamping site carries the decisive facts inline, because the source is what
a grep-then-delete reader reads first.
Three cases in createAuthenticatedFetch.test.tsx pin the statements the prose
makes about the wire, so the documentation cannot drift away from the behaviour
unnoticed.
Documentation only. Proven: with comments stripped, the emitted JS for
createAuthenticatedFetch.ts is byte-identical before and after (2750 bytes
both), and the package's other 20 dist JS files are hash-identical.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012u2pRjcqAYtoEjgr3wwhnK
@github-actionsgithub-actionsBot added documentation Improvements or additions to documentation tests labels Aug 22, 2026
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 52 chunks)3913.6 KB3990.2 KB
Main entry chunk (gzip)152.3 KB350 KB
Entry fileindex-spBIKF4m.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (index.js)10.04KB3.72KB
app-shell (runtime-config.js)12.80KB4.47KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)29.34KB7.05KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)9.63KB3.74KB
auth (index.js)2.77KB1.22KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.02KB0.89KB
auth (useIsWorkspaceAdmin.js)3.04KB1.45KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)506.90KB113.84KB
core (index.js)4.92KB1.97KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)160.15KB44.52KB
fields (index.js)238.40KB59.89KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)23.13KB7.63KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)7.77KB3.13KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)9.53KB3.38KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)4.64KB1.50KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)1.93KB0.88KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.62KB12.83KB
plugin-charts (index.js)64.65KB18.32KB
plugin-chatbot (index.js)181.41KB43.22KB
plugin-dashboard (index.js)128.41KB32.95KB
plugin-designer (index.js)212.30KB42.80KB
plugin-detail (index.js)242.34KB60.98KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)125.63KB30.64KB
plugin-gantt (index.js)164.10KB39.87KB
plugin-grid (index.js)200.79KB54.26KB
plugin-kanban (index.js)52.93KB14.60KB
plugin-list (index.js)111.80KB27.20KB
plugin-map (index.js)20.06KB6.62KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.49KB11.93KB
plugin-timeline (index.js)26.68KB7.66KB
plugin-tree (index.js)8.50KB2.88KB
plugin-view (index.js)84.61KB20.74KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)43.66KB14.77KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)1.33KB0.69KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (index.js)4.77KB2.16KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)10.76KB3.17KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)6.92KB2.40KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.87KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (index.js)3.59KB1.79KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-salesClaude

Copy link
Copy Markdown
CollaboratorAuthor

Seat review — accepted on its merits. HELD only on #5705, which is a red base, not this diff.

Fence held exactly: packages/auth/README.md, the stamping site, a test, a changeset. No content/docs/**, no apps/site/** — the brief routed the edge contract to package-local docs precisely so #5668 could not touch it, and that is where it went. No governed surfaces.

Three things I want on the record:

  1. It did not claim a measurement it could not make.objectstack-ai/cloud is unreachable from this session (add_repo returned no access), so the cloud readers are cited as the recorded reading rather than re-derived. What it measured instead is the part that is reachable, at runtime rather than by file-read: TenantRoutingConfigSchema.parse({}) against the version @object-ui/auth actually resolves → tenantHeaderName: 'X-Tenant-ID', and header ranking second of six identification sources behind subdomain. That is the [finding] 响应式词汇的两个零消费表面:useResponsiveConfig 生产零调用者(page.components[].responsive 因此实际未生效)、MobileComponentConfig 零消费者 #4773 lesson applied without being told.

  2. The narrowing is proven with a falsified instrument. Both revisions of createAuthenticatedFetch.ts compiled with removeComments → byte-identical (2750 bytes each), then self-checked by re-spelling a header literal in a scratchpad copy until the comparison went red. Worth being precise about why that is valid here: --removeComments proves program semantics unchanged; it does not license a shipped-bytes claim, and none was made — the bundle report shows auth (createAuthenticatedFetch.js) moving 6.35 → 9.63 KB, which is comment text surviving this package's build. Two gauges, two different questions, both read. (auth now joins core and react on the list of packages whose shipped .js moves on a prose-only change.)

  3. The check-doc-snippet-types narrowing is declared, not skipped. The gate refuses to run on an unbuilt tree, so instead of hoping, the agent read the gate module's own TS_FENCE_LANGUAGES and applied it to both revisions: 11 → 13 fenced blocks, but 10 → 10 in the compiled population, identical byte-lengths in identical order; the two added fences are http and text. Self-checked by planting a ts block to move 10 → 11.

The inline comment at the stamping site is the part that will still be earning its keep in a year — it names the exact failure this card was filed on:

DO NOT DELETE THIS ON THE STRENGTH OF A GREP. … a search confined to this repo plus the framework finds zero consumers and reads as "dead stamp" — which is the false premise objectui#5279 was filed on.

The isApiCall asymmetry it noticed was recorded, not acted on"recorded as the behaviour that ships, not endorsed" — and routed to #5702, where I have labelled it needs-user-decision. That is the right handling of a behaviour question found mid-fence.

Held pending #5705 (main red: console.ai.pendingDrafts missing from eight locale packs). Nothing about this PR needs to change; it merges when the base is green.


Generated by Claude Code

@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 52 chunks)3914.3 KB3990.2 KB
Main entry chunk (gzip)152.3 KB350 KB
Entry fileindex-DvF64ISu.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (index.js)10.04KB3.72KB
app-shell (runtime-config.js)12.80KB4.47KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)29.34KB7.05KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)9.63KB3.74KB
auth (index.js)2.77KB1.22KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.02KB0.89KB
auth (useIsWorkspaceAdmin.js)3.04KB1.45KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)506.90KB113.84KB
core (index.js)4.92KB1.97KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)160.15KB44.52KB
fields (index.js)238.40KB59.89KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)23.13KB7.63KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)7.77KB3.13KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)9.53KB3.38KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)4.64KB1.50KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)1.93KB0.88KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.62KB12.83KB
plugin-charts (index.js)64.65KB18.32KB
plugin-chatbot (index.js)181.41KB43.22KB
plugin-dashboard (index.js)128.41KB32.95KB
plugin-designer (index.js)212.30KB42.80KB
plugin-detail (index.js)242.34KB60.98KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)125.63KB30.64KB
plugin-gantt (index.js)164.10KB39.87KB
plugin-grid (index.js)200.79KB54.26KB
plugin-kanban (index.js)52.93KB14.60KB
plugin-list (index.js)111.80KB27.20KB
plugin-map (index.js)20.06KB6.62KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.49KB11.93KB
plugin-timeline (index.js)26.68KB7.66KB
plugin-tree (index.js)8.50KB2.88KB
plugin-view (index.js)84.61KB20.74KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)43.66KB14.77KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)1.33KB0.69KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (index.js)4.77KB2.16KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)10.76KB3.17KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)6.92KB2.40KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.87KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (index.js)3.59KB1.79KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-sales
os-sales marked this pull request as ready for review August 22, 2026 13:12
@os-sales
os-sales added this pull request to the merge queueAug 22, 2026
Merged via the queue into main with commit 934a532Aug 22, 2026
23 checks passed
@os-sales
os-sales deleted the claude/issue-5279-tenant-header-edge-contract branch August 22, 2026 13:12
os-sam pushed a commit that referenced this pull request Aug 31, 2026
The "Multi-tenancy" section taught that createAuthenticatedFetch sending
X-Tenant-ID is what makes row-level isolation happen. It is not: scoping
comes from the session, the header is an edge routing hint ranked behind
subdomain, and trusting it as identity is the recorded plugin-sharing
vulnerability. Repoint to packages/auth/README.md's "The X-Tenant-ID edge
contract" (added by #5279 / PR #5706) for the full contract.
akarma-synetal pushed a commit to akarma-synetal/objectui that referenced this pull request Sep 1, 2026
objectstack-ai#6974)
The "Multi-tenancy" section taught that createAuthenticatedFetch sending
X-Tenant-ID is what makes row-level isolation happen. It is not: scoping
comes from the session, the header is an edge routing hint ranked behind
subdomain, and trusting it as identity is the recorded plugin-sharing
vulnerability. Repoint to packages/auth/README.md's "The X-Tenant-ID edge
contract" (added by objectstack-ai#5279 / PR objectstack-ai#5706) for the full contract.
Co-authored-by: Claude <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentationImprovements or additions to documentationtests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Confirm whether X-Tenant-ID has a reader: the framework derives the tenant from the session, not the header

2 participants

@os-sales@claude