Skip to content

fix(app-shell): PUT the object payload's fields as the spec's name-keyed map - #6491

Merged
os-support-ai merged 1 commit into
mainfrom
claude/issue-6240-object-payload-fields-map
Aug 26, 2026
Merged

fix(app-shell): PUT the object payload's fields as the spec's name-keyed map#6491
os-support-ai merged 1 commit into
mainfrom
claude/issue-6240-object-payload-fields-map

Conversation

@os-support-ai

@os-support-aios-support-ai commented Aug 26, 2026

Copy link
Copy Markdown
Collaborator

Fixes#6240

ObjectSchema.fields is a required record keyed by field name. Both of MetadataService's object writers emitted an array, and saveFields ran the conversion in the wrong direction outright: the server's own document arrives with fields as a map, and fields.map(toFieldPayload) replaced it with an array on every field save. Only the sibling writer MetadataFieldsPage agreed with the spec.

Step one — the card's unmeasured premise, measured

The card filed "whether the route is lenient about this today is unmeasured". It is not lenient, and there is no third outcome.

Against the installed @objectstack/spec 17.2.0 (ESM build, dist/data/index.mjs):

bodyverdict
fields: [{ name: 'n', type: 'text', label: 'N' }]invalid_type @ fields"expected record, received array"
fields: []invalid_type @ fields — the container's type, not its contents
fields: { n: { type: 'text', label: 'N' } }parses
fields: {}parses
key absentinvalid_type @ fields — it is required

And against the framework's own write door (objectstack @ f5a7f9c): metadata-protocol's saveMetaItem resolves metadata type object to that same ObjectSchema (spec/kernel/metadata-type-schemas.ts binds object: ObjectSchema; resolveOverlaySchema reads that registry), safeParses the whole item, and on failure throws 422 INVALID_METADATAbefore persisting. So the array was refused — not stripped (nothing strips it) and not stored (the throw precedes the write). The "stored verbatim" outcome objectui#6238 measured applies to types whose schema is tolerant or unregistered, and object is neither.

The user-visible claim, measured rather than argued: every designer object save and every designer field save that went through this service was a 422 that wrote nothing.

The three dispatch constraints

1 — the map key comes from a REQUIRED name, and a missing one fails loudly. Not a stylistic preference. Measured on 17.2.0:

ObjectSchema.safeParse({ …, fields: { undefined: { type: 'text', label: 'N' } } })
=> success = true

The spec accepts a { undefined: … } document. A conversion that keyed blindly would therefore have traded a loud, immediate, harmless 422 for a silently corrupt stored document. toFieldsMap throws instead, and the pins assert both the throw and that no request was issued — the half a toThrow() assertion cannot see.

Two more failure modes the conversion would otherwise have introduced, both refused:

  • Duplicate names. An array carries two entries called amount; a map cannot, so the later would silently swallow the earlier. That loss is created by this conversion, so this conversion refuses it.
  • __proto__.map['__proto__'] = field invokes the prototype setter rather than creating a key — and __proto__ is a spec-legal field name (the record's key schema is /^[a-z_][a-z0-9_]*$/, measured green). The map is built with Object.fromEntries, which defines an own property.

2 — saveFields' unknown-server-key preservation survives, and gains a pin....existingObject still carries every key of the fetched document this service does not model, asserted with a positive control in the same output proving fields really was replaced. It matters more now than before, not less: while the body was refused, nothing it preserved ever reached storage.

3 — the public signature is SEVERED, and this PR is additive-only at the public surface.saveObject(obj, existingFields?: FieldMetadataPayload[]) keeps its array parameter byte-for-byte; the conversion happens inside. Checked against the built entry rather than by grepping a source export keyword: dist/index.d.ts carries 0export * chains and names neither MetadataService nor the payload types, but it does export useMetadataService(): MetadataService | null, so the class's method signatures are reachable from the entry — and the diff touches none of them. The reshaped ObjectMetadataPayload.fields type is declared export in its source file but appears in no exported signature (grep on the built MetadataService.d.ts: declaration only) and has no importer anywhere in the repo, so its shape growth is not reachable from the entry. Nothing downstream is asked to change.

Which half each check covers

The parity gate here is declaration-only, so it cannot see this class at all.scripts/check-designer-field-key-parity.mjs compares key names against the spec's accept sets. fields is in ObjectSchema's accept set under either shape, so the gate was green for the entire time the array was on the wire — its own coverage note 4 says so. It is green before and after this change, and that is not evidence about the fix. The half it cannot see is covered by runtime assertions on the captured request bytes (JSON.parse of the PUT body), which is what every new pin reads.

Ablations — the right cells red, the controls green

Each mutation was verified on disk (injected/removed grep -c on the anchored text, both directions), restored by git checkout HEAD -- <path> under a trap … EXIT INT TERM with absolute paths, and every restore verified by blob-hash equality against the pinned base blob plus an empty git diff HEADRESTORE-CHECK OK blob=403bc0a95… after all four. No rebuild leg was needed or skipped: every test imports the subject relatively (from './MetadataService') and @object-ui/data-objectstack is aliased to packages/data-objectstack/src by the root vitest.config.mts, so no dist/ participates. The oracle @objectstack/spec/data is an installed package and was never mutated.

ablationredgreen (controls)
A — both writers emit an array again16 cells across 2 files, incl. the landed witnessall 5 the instrument schema cases; all 3 sibling pin files; saveAdvisories; retiredObjectEnabled
B — remove the missing-name guardexactly the 4 nameless-field cellsthe duplicate-name cell, the __proto__ cell, every shape cell
C — build the map by assignment instead of Object.fromEntriesexactly 1 cell: __proto__all 73 others
D — default to toFieldsMap(fields ?? []) (the wipe)exactly 1 cell: omits fields entirely … does NOT write {}all 73 others

C and D are what make those two cells non-degenerate: each sits precisely where the two readings disagree.

The landed witness, flipped

MetadataService.specKeyObjectPayload.test.ts pinned ['invalid_type @ fields'] so this could not silently change. It has now changed on purpose, so the pin is replaced rather than deleted — the claim it was really making ("judge the whole body, not just its key names") still holds and is stronger green than red, with a falsification asserting the body carries the field rather than having been emptied. Ablation A reds it.

Deliberately NOT done

Follow-ups filed (finding, unassigned, ungraded)

Verification

Run at c9a2d916f, the final commit, each verdict quoted from the gate itself.

Test Files 8 passed (8) # pnpm exec vitest run packages/app-shell/src/services/
Tests 74 passed (74) # baseline before this change: 7 files / 53 tests
> @object-ui/app-shell@17.6.0 type-check # tsc --noEmit && tsc -p tsconfig.test.json -> exit 0
designer-field-key-parity: OK
✅ check-control-bytes: OK (scanned 5363 tracked text file(s); skipped 85 binary).
✅ 6 source file(s) of 1 released package(s) changed, and this change declares 1 changeset(s)

type-check covers the edits rather than merely passing beside them: tsc -p tsconfig.test.json --listFiles reports all six edited/created files in the program (1 hit each), so "typecheck clean" is a statement about them.

Lint was not narrowed — the full repo-wide eslint . --no-inline-config --format json ran to completion: 3814 files judged by eslint's own config, 90 errors and 11244 warnings, every one of them pre-existing style noise in packages this diff does not touch. The nine services/ files contribute 0 errors; MetadataService.ts's single warning is the pre-existing const raw: any in saveFields, and the diff adds no : any line (git diff | grep '^+.*: any' is empty). Type-aware linting is not enabled (no project / projectService in eslint.config.js), so this diff cannot move any untouched file's verdict.

check:readme-exports fails locally with 61 findings, all of the single form "type entry ./dist/index.d.ts is not on disk — run pnpm build first", in six packages this diff does not touch. That is a prerequisite-not-met, not a measurement: building @object-ui/app-shell cleared all 8 of its own findings and left the other six packages' untouched. Recorded as NOT MEASURED locally rather than as a red; CI builds first.


Generated by Claude Code


Generated by Claude Code

…keyed map
`ObjectSchema.fields` is a REQUIRED record keyed by field name. Both of
`MetadataService`'s object writers emitted an array, and `saveFields` ran
the conversion in the wrong direction outright: the server's own document
arrives with `fields` as a map, and `fields.map(toFieldPayload)` replaced
it with an array on every field save.
Measured on the installed `@objectstack/spec` 17.2.0: an array — empty or
not — is refused `invalid_type @ fields`; a map (including `{}`) parses;
omitting the key is refused the same way. And the route is not lenient
about it. `metadata-protocol`'s `saveMetaItem` resolves metadata type
`object` to that same `ObjectSchema`, `safeParse`s the whole item and
throws `422 INVALID_METADATA` before persisting, so the array was
refused rather than stripped or stored.
The conversion refuses what it cannot key, because the spec will not:
`fields: { undefined: … }` PARSES GREEN, so a blind conversion would have
traded a loud, harmless 422 for a silently corrupt stored document. A
missing or blank `name` throws; so does a duplicate name, which is a loss
the array shape did not have. The map is built with `Object.fromEntries`
so a field literally named `__proto__` — a spec-legal name — becomes a
key instead of invoking the prototype setter.
`saveObject` with no `existingFields` still omits the key rather than
writing `{}`: a PUT is an upsert, so `{}` would delete every field of an
object on a save that only meant to rename it. `saveFields`' list IS
authoritative, so an empty one does write `{}`.
The public `existingFields` parameter keeps its `FieldMetadataPayload[]`
type — the array is converted inside — so no call site changes.
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 52 chunks)3234.5 KB3266.6 KB
Main entry chunk (gzip)157.4 KB350 KB
Entry fileindex-DxzC_ecq.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (consoleActionDispatch.js)0.20KB0.19KB
app-shell (index.js)11.30KB4.28KB
app-shell (runtime-config.js)18.10KB6.51KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (ActiveOrganizationStorage.js)25.05KB9.16KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)2.07KB1.00KB
auth (AuthProvider.js)40.18KB10.59KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)8.46KB3.43KB
auth (index.js)3.19KB1.44KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.30KB1.02KB
auth (useWorkspaceAdminStatus.js)5.13KB2.35KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)505.99KB114.64KB
core (index.js)5.30KB2.13KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)173.10KB47.96KB
fields (index.js)238.89KB60.02KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (fallbackInterpolation.js)6.25KB2.77KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)26.89KB9.04KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)5.60KB2.33KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)9.53KB3.38KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)4.64KB1.50KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)1.93KB0.88KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.91KB12.92KB
plugin-charts (index.js)64.66KB18.32KB
plugin-chatbot (index.js)188.60KB44.82KB
plugin-dashboard (index.js)133.48KB34.49KB
plugin-designer (index.js)211.90KB42.74KB
plugin-detail (index.js)245.29KB62.39KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)131.78KB32.19KB
plugin-gantt (index.js)164.14KB39.87KB
plugin-grid (index.js)201.66KB54.57KB
plugin-kanban (index.js)53.16KB14.65KB
plugin-list (index.js)112.74KB27.50KB
plugin-map (index.js)20.09KB6.62KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.51KB11.94KB
plugin-timeline (index.js)26.72KB7.71KB
plugin-tree (index.js)9.26KB3.13KB
plugin-view (index.js)84.85KB20.79KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)4.47KB1.63KB
react (SchemaRenderer.js)56.69KB19.03KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)2.05KB1.04KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (dashboard-widget-options.js)3.08KB1.30KB
sdui-parser (index.js)4.93KB2.24KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)12.13KB3.65KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.28KB0.23KB
sdui-parser (validate.js)7.54KB2.63KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)2.74KB1.41KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)3.75KB1.85KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.85KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (icon-key-migration.js)4.26KB1.63KB
types (index.js)4.72KB2.24KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (spec-ui-namespace.js)0.20KB0.19KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)6.28KB2.87KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-support-ai
os-support-ai marked this pull request as ready for review August 26, 2026 05:27
@os-support-ai
os-support-ai added this pull request to the merge queueAug 26, 2026
Merged via the queue into main with commit 9ea4cdeAug 26, 2026
30 checks passed
@os-support-ai
os-support-ai deleted the claude/issue-6240-object-payload-fields-map branch August 26, 2026 05:39
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

1 participant

@os-support-ai