Skip to content

Retire the allowRestore / allowPurge columns from the metadata-admin permission matrix - #6607

Merged
os-sales merged 2 commits into
mainfrom
claude/issue-6595-retire-allowrestore-allowpurge-columns
Aug 27, 2026
Merged

Retire the allowRestore / allowPurge columns from the metadata-admin permission matrix#6607
os-sales merged 2 commits into
mainfrom
claude/issue-6595-retire-allowrestore-allowpurge-columns

Conversation

@os-sales

Copy link
Copy Markdown
Collaborator

Fixes#6595

Drops the two retired object-permission bits from the metadata-admin permission matrix: the authoring columns, the typed fields, the preview rows, and the now-unreachable "Purge (hard delete) granted without Delete" lint. allowTransfer is enforced upstream (objectstack#3004) and is untouched — it stays a column, and every pin below asserts that in the same render so the removals cannot pass for the wrong reason.

Both removed keys gated restore / purge ObjectQL operations that have never existed: a dispatched restore/purge is denied unconditionally by the evaluator's fail-closed destructive-operation backstop. Every tick of those checkboxes wrote a grant no runtime has ever read. @objectstack/spec retired both as retiredKey() tombstones (objectstack#12497; maintainer ruling 2026-08-26 accepting objectstack#1883 recommendation B, ADR-0049 enforce-or-remove).

The return path is named at every site the removal touchedpermission-slice.ts, PermissionMatrixEditor.tsx, previews/PermissionPreview.tsx, and both new pins: the keys come back with the M2 lifecycle initiative, whose restart is recorded upstream on objectstack#1883.

The one thing measured on the day: the installed spec's posture

The card's premise splits into a part that is true either way and a part that depends on a bump that has not arrived. Measured 2026-08-27 against the installed @objectstack/spec17.2.0, by running real ObjectPermissionSchema.safeParse calls with a control key:

allowRestore ACCEPTED
allowPurge ACCEPTED
allowTransfer ACCEPTED
bogusKey REFUSED unrecognized_keys: ["definitelyNotAKey"]

The control is what makes this falsifiable: the schema IS strict and DOES refuse unknown keys, and it still accepts both retired keys. permission.zod-Bwl7_K0U.d.ts agrees at the type level (allowRestore: z.ZodDefault(z.ZodBoolean)).

So the bump has not reached this repo, and this PR does what that implies:

  • The removal lands — valid in both worlds, since the gated operations have never existed.
  • The "publish refuses it" pin is NOT taken. It belongs to the bump PR. Nothing here blocks on the bump, and no pin is bumped as a rider.
  • A stored legacy value is carried through, not stripped. It is no longer modelled and no longer authorable; it rides through save untouched, exactly as any key this editor does not model does. Stripping today would delete stored data the schema still honours. Once the bump lands and a carried value becomes a body the schema refuses, strip-on-load becomes correct — objectui#4644's resolution for indexed. The pin recording today's posture says so in its own header, so the bump PR replaces it deliberately rather than deleting a red.

The card's line references were stale, and its site list was incomplete

Line numbers were re-derived by name rather than trusted. The three constructs the card named were all real (at 180-181, 27-28, 59-60/86 — unchanged). But a fourth site reads these keys and the card did not list it:

packages/app-shell/src/views/metadata-admin/i18n.ts carries the two column tooltips in both locale tables — perm.action.restore / perm.action.purge in ENGINE_STRINGS_EN and ENGINE_STRINGS_ZH. Removing the columns without them would have left four dead keys in a pack whose EN/ZH halves must stay in step. Removed in both locales; the pack is the engine.* carve-out, so no pack gate reaches it either way.

Three prose sites were also carrying the removed columns as fact and are corrected: the editor's header comment (lifecycle (Transfer / Restore / Purge)), the column-legend note (Tr/Re/Pu/VA/MA), the fixed-column count (object + 9 CRUD + bulk, now 7 — the min-w floor is deliberately unchanged, so the grid simply has more room), and the preview's capability list plus its two legend lines.

Tests

Two new pin files, PermissionMatrixEditor.retiredLifecycleKeys.test.tsx and previews/PermissionPreview.retiredLifecycleKeys.test.tsx, following the shape PermissionAdvancedFacets.retiredKeys.test.tsx set for the RLS priority tombstone: pin the key SET, not the absence of two keys, because a set assertion is what stops a retired key drifting back in beside a live one. They cover the column set, the checkbox surface, what reaches the wire (the "Grant all" seed, whose key set is the real product of this change), the dropped lint measured on a draft that still trips the lints that stayed, and the carry-through of a stored legacy value.

Reverse verification — direction predicted before running: RED. Restoring the two columns, the two preview rows and the lint on top of the committed fix turns all 7 new pins red (Test Files 2 failed (2) · Tests 7 failed (7)); every one of them fails, so none was passing for an unrelated reason. Mutation confirmed on disk by anchored grep counts (short: 'Re'=1, long: 'Purge'=1, purge-lint=1) plus blob hashes differing from the HEAD blobs — not a bare diffstat. Restore leg proven the same way: git hash-object reproduces both HEAD blobs byte-for-byte and git diff HEAD is empty. No rebuild leg applies — both pins import their subject by relative source path (./PermissionMatrixEditor, ./PermissionPreview), so no dist/ sits in the resolution path.

Union re-run after the final commit, at 005a792:

checkresult
19 permission test files (whole surface, not just the new pins)Test Files 19 passed (19) · Tests 90 passed (90)
@object-ui/app-shell type-checkgreen — tsc --noEmit and tsc -p tsconfig.test.json
check-changeset-presence✅ 6 source file(s) of 1 released package(s) changed, and this change declares 1 changeset(s)
check:control-bytes✅ check-control-bytes: OK (scanned 5455 tracked text file(s); skipped 85 binary)
check:i18n-keysgreen — every in-scope call-site key resolves against the en pack
check:i18n-driftNo en value changed in this range
check:i18n-dead-keysreport-only gate, exit 0

The type-check claim is measured, not assumed: tsc -p tsconfig.test.json --listFiles lists both new test files, so the green covers them rather than excluding them.

Lint was narrowed deliberately, and here is why the narrowing loses nothing.eslint --no-inline-config --format json over the 6 changed files reports errorCount 0 (27 warnings, all pre-existing patterns; --max-warnings is deliberately unset repo-wide, per lint.yml's own note). The population is read from eslint's own resolution — it returned exactly 6 result objects, so all 6 are in scope and none was ignored. And the invariance holds by construction: eslint.config.js enables no type-aware linting (no project / projectService / parserOptions.project), so a file's verdict depends only on its own contents and the config — this diff cannot move the verdict on any file it does not touch. CI runs the repo-wide pnpm lint regardless.

Out-of-scope findings, filed rather than fixed here

  • objectui#6605 — the matrix's four bulk buttons (R / CRUD / All / None) replace the object row instead of merging, silently deleting allowExport, readScope and writeScope, which the local ObjectPerm does not model. The sharpest shape: clicking All can widen effective read access by deleting a readScope: own narrowing. Different defect class from this card (those keys are live and enforced), so it is not touched here.
  • objectui#6606 — the permission authoring shapes are absent from PAYLOAD_SHAPES in check-designer-field-key-parity.mjs, so the very class this card instantiates is invisible to that gate on the permission surface. This card arrived as a hand-written upstream referral, not from CI.

Neither is addressed in this PR; both remain open.

Fence

Every edit is inside packages/app-shell/src/views/metadata-admin/ plus one .changeset/ file. Nothing under studio-design/ was read for edit or touched — the sibling round's region is untouched.


Generated by Claude Code

…sion columns
Both keys gated `restore` / `purge` ObjectQL operations that have never
existed — a dispatched restore/purge is denied unconditionally by the
evaluator's fail-closed destructive-operation backstop — so the two matrix
checkboxes were dead-end authoring surface: every tick wrote a grant no
runtime has ever read. `@objectstack/spec` retired both keys as
`retiredKey()` tombstones (objectstack#12497; maintainer ruling 2026-08-26
accepting objectstack#1883 recommendation B, ADR-0049 enforce-or-remove).
Removed: the two authoring columns, the two typed fields, the two preview
rows, the now-unreachable "Purge (hard delete) granted without Delete" lint,
and the two column tooltips in both locale tables. `allowTransfer` is
enforced upstream and is untouched.
A value stored by an older editor is not modelled and not authorable; it
rides through save untouched, as any key this editor does not model does.
The installed spec (17.2.0) still ACCEPTS both keys at permission parse, so
stripping stored values today would delete data the schema still honours —
strip-on-load belongs with the bump that lands the retirement.
The return path is named in every tombstone: both keys come back with the M2
lifecycle initiative, whose restart is recorded on objectstack#1883.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CRJge11jso9TpXRWFt1Z49
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 52 chunks)3235.4 KB3266.6 KB
Main entry chunk (gzip)157.0 KB350 KB
Entry fileindex-CTzDHwYr.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (consoleActionDispatch.js)0.20KB0.19KB
app-shell (index.js)11.89KB4.50KB
app-shell (runtime-config.js)20.61KB7.35KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (ActiveOrganizationStorage.js)25.05KB9.16KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)2.07KB1.00KB
auth (AuthProvider.js)40.18KB10.59KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)8.46KB3.43KB
auth (index.js)3.19KB1.44KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.30KB1.02KB
auth (useWorkspaceAdminStatus.js)5.13KB2.35KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)506.01KB114.64KB
core (index.js)5.30KB2.13KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)173.10KB47.96KB
fields (index.js)238.89KB60.02KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (fallbackInterpolation.js)6.25KB2.77KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)26.89KB9.04KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)5.60KB2.33KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)9.53KB3.38KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)4.64KB1.50KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)1.93KB0.88KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.85KB12.89KB
plugin-charts (index.js)64.66KB18.32KB
plugin-chatbot (index.js)188.60KB44.82KB
plugin-dashboard (index.js)133.48KB34.49KB
plugin-designer (index.js)212.80KB43.15KB
plugin-detail (index.js)245.29KB62.39KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)131.78KB32.19KB
plugin-gantt (index.js)165.16KB40.33KB
plugin-grid (index.js)201.66KB54.58KB
plugin-kanban (index.js)53.11KB14.62KB
plugin-list (index.js)112.86KB27.54KB
plugin-map (index.js)20.09KB6.62KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.51KB11.94KB
plugin-timeline (index.js)26.72KB7.71KB
plugin-tree (index.js)9.26KB3.13KB
plugin-view (index.js)85.87KB21.12KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)4.47KB1.63KB
react (SchemaRenderer.js)65.97KB21.98KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)2.44KB1.21KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (dashboard-widget-options.js)3.08KB1.30KB
sdui-parser (index.js)4.93KB2.24KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)12.13KB3.65KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.28KB0.23KB
sdui-parser (validate.js)7.54KB2.63KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)2.74KB1.41KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)3.75KB1.85KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.85KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (icon-key-migration.js)4.26KB1.63KB
types (index.js)4.72KB2.24KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (spec-ui-namespace.js)0.20KB0.19KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)6.28KB2.87KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-sales
os-sales marked this pull request as ready for review August 27, 2026 13:18
@os-sales
os-sales added this pull request to the merge queueAug 27, 2026
Merged via the queue into main with commit bac7ba4Aug 27, 2026
30 checks passed
@os-sales
os-sales deleted the claude/issue-6595-retire-allowrestore-allowpurge-columns branch August 27, 2026 13:30
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

metadata-admin permission matrix still authors the retired allowRestore / allowPurge bits — spec now rejects them at publish

2 participants

@os-sales@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Retire the `allowRestore` / `allowPurge` columns from the metadata-admin permission matrix by os-sales · Pull Request #6607 · objectstack-ai/objectui · GitHub
Skip to content

Retire the allowRestore / allowPurge columns from the metadata-admin permission matrix - #6607

Merged
os-sales merged 2 commits into
mainfrom
claude/issue-6595-retire-allowrestore-allowpurge-columns
Aug 27, 2026
Merged

Retire the allowRestore / allowPurge columns from the metadata-admin permission matrix#6607
os-sales merged 2 commits into
mainfrom
claude/issue-6595-retire-allowrestore-allowpurge-columns

Conversation

@os-sales

Copy link
Copy Markdown
Collaborator

Fixes#6595

Drops the two retired object-permission bits from the metadata-admin permission matrix: the authoring columns, the typed fields, the preview rows, and the now-unreachable "Purge (hard delete) granted without Delete" lint. allowTransfer is enforced upstream (objectstack#3004) and is untouched — it stays a column, and every pin below asserts that in the same render so the removals cannot pass for the wrong reason.

Both removed keys gated restore / purge ObjectQL operations that have never existed: a dispatched restore/purge is denied unconditionally by the evaluator's fail-closed destructive-operation backstop. Every tick of those checkboxes wrote a grant no runtime has ever read. @objectstack/spec retired both as retiredKey() tombstones (objectstack#12497; maintainer ruling 2026-08-26 accepting objectstack#1883 recommendation B, ADR-0049 enforce-or-remove).

The return path is named at every site the removal touchedpermission-slice.ts, PermissionMatrixEditor.tsx, previews/PermissionPreview.tsx, and both new pins: the keys come back with the M2 lifecycle initiative, whose restart is recorded upstream on objectstack#1883.

The one thing measured on the day: the installed spec's posture

The card's premise splits into a part that is true either way and a part that depends on a bump that has not arrived. Measured 2026-08-27 against the installed @objectstack/spec17.2.0, by running real ObjectPermissionSchema.safeParse calls with a control key:

allowRestore ACCEPTED
allowPurge ACCEPTED
allowTransfer ACCEPTED
bogusKey REFUSED unrecognized_keys: ["definitelyNotAKey"]

The control is what makes this falsifiable: the schema IS strict and DOES refuse unknown keys, and it still accepts both retired keys. permission.zod-Bwl7_K0U.d.ts agrees at the type level (allowRestore: z.ZodDefault(z.ZodBoolean)).

So the bump has not reached this repo, and this PR does what that implies:

  • The removal lands — valid in both worlds, since the gated operations have never existed.
  • The "publish refuses it" pin is NOT taken. It belongs to the bump PR. Nothing here blocks on the bump, and no pin is bumped as a rider.
  • A stored legacy value is carried through, not stripped. It is no longer modelled and no longer authorable; it rides through save untouched, exactly as any key this editor does not model does. Stripping today would delete stored data the schema still honours. Once the bump lands and a carried value becomes a body the schema refuses, strip-on-load becomes correct — objectui#4644's resolution for indexed. The pin recording today's posture says so in its own header, so the bump PR replaces it deliberately rather than deleting a red.

The card's line references were stale, and its site list was incomplete

Line numbers were re-derived by name rather than trusted. The three constructs the card named were all real (at 180-181, 27-28, 59-60/86 — unchanged). But a fourth site reads these keys and the card did not list it:

packages/app-shell/src/views/metadata-admin/i18n.ts carries the two column tooltips in both locale tables — perm.action.restore / perm.action.purge in ENGINE_STRINGS_EN and ENGINE_STRINGS_ZH. Removing the columns without them would have left four dead keys in a pack whose EN/ZH halves must stay in step. Removed in both locales; the pack is the engine.* carve-out, so no pack gate reaches it either way.

Three prose sites were also carrying the removed columns as fact and are corrected: the editor's header comment (lifecycle (Transfer / Restore / Purge)), the column-legend note (Tr/Re/Pu/VA/MA), the fixed-column count (object + 9 CRUD + bulk, now 7 — the min-w floor is deliberately unchanged, so the grid simply has more room), and the preview's capability list plus its two legend lines.

Tests

Two new pin files, PermissionMatrixEditor.retiredLifecycleKeys.test.tsx and previews/PermissionPreview.retiredLifecycleKeys.test.tsx, following the shape PermissionAdvancedFacets.retiredKeys.test.tsx set for the RLS priority tombstone: pin the key SET, not the absence of two keys, because a set assertion is what stops a retired key drifting back in beside a live one. They cover the column set, the checkbox surface, what reaches the wire (the "Grant all" seed, whose key set is the real product of this change), the dropped lint measured on a draft that still trips the lints that stayed, and the carry-through of a stored legacy value.

Reverse verification — direction predicted before running: RED. Restoring the two columns, the two preview rows and the lint on top of the committed fix turns all 7 new pins red (Test Files 2 failed (2) · Tests 7 failed (7)); every one of them fails, so none was passing for an unrelated reason. Mutation confirmed on disk by anchored grep counts (short: 'Re'=1, long: 'Purge'=1, purge-lint=1) plus blob hashes differing from the HEAD blobs — not a bare diffstat. Restore leg proven the same way: git hash-object reproduces both HEAD blobs byte-for-byte and git diff HEAD is empty. No rebuild leg applies — both pins import their subject by relative source path (./PermissionMatrixEditor, ./PermissionPreview), so no dist/ sits in the resolution path.

Union re-run after the final commit, at 005a792:

checkresult
19 permission test files (whole surface, not just the new pins)Test Files 19 passed (19) · Tests 90 passed (90)
@object-ui/app-shell type-checkgreen — tsc --noEmit and tsc -p tsconfig.test.json
check-changeset-presence✅ 6 source file(s) of 1 released package(s) changed, and this change declares 1 changeset(s)
check:control-bytes✅ check-control-bytes: OK (scanned 5455 tracked text file(s); skipped 85 binary)
check:i18n-keysgreen — every in-scope call-site key resolves against the en pack
check:i18n-driftNo en value changed in this range
check:i18n-dead-keysreport-only gate, exit 0

The type-check claim is measured, not assumed: tsc -p tsconfig.test.json --listFiles lists both new test files, so the green covers them rather than excluding them.

Lint was narrowed deliberately, and here is why the narrowing loses nothing.eslint --no-inline-config --format json over the 6 changed files reports errorCount 0 (27 warnings, all pre-existing patterns; --max-warnings is deliberately unset repo-wide, per lint.yml's own note). The population is read from eslint's own resolution — it returned exactly 6 result objects, so all 6 are in scope and none was ignored. And the invariance holds by construction: eslint.config.js enables no type-aware linting (no project / projectService / parserOptions.project), so a file's verdict depends only on its own contents and the config — this diff cannot move the verdict on any file it does not touch. CI runs the repo-wide pnpm lint regardless.

Out-of-scope findings, filed rather than fixed here

  • objectui#6605 — the matrix's four bulk buttons (R / CRUD / All / None) replace the object row instead of merging, silently deleting allowExport, readScope and writeScope, which the local ObjectPerm does not model. The sharpest shape: clicking All can widen effective read access by deleting a readScope: own narrowing. Different defect class from this card (those keys are live and enforced), so it is not touched here.
  • objectui#6606 — the permission authoring shapes are absent from PAYLOAD_SHAPES in check-designer-field-key-parity.mjs, so the very class this card instantiates is invisible to that gate on the permission surface. This card arrived as a hand-written upstream referral, not from CI.

Neither is addressed in this PR; both remain open.

Fence

Every edit is inside packages/app-shell/src/views/metadata-admin/ plus one .changeset/ file. Nothing under studio-design/ was read for edit or touched — the sibling round's region is untouched.


Generated by Claude Code

…sion columns
Both keys gated `restore` / `purge` ObjectQL operations that have never
existed — a dispatched restore/purge is denied unconditionally by the
evaluator's fail-closed destructive-operation backstop — so the two matrix
checkboxes were dead-end authoring surface: every tick wrote a grant no
runtime has ever read. `@objectstack/spec` retired both keys as
`retiredKey()` tombstones (objectstack#12497; maintainer ruling 2026-08-26
accepting objectstack#1883 recommendation B, ADR-0049 enforce-or-remove).
Removed: the two authoring columns, the two typed fields, the two preview
rows, the now-unreachable "Purge (hard delete) granted without Delete" lint,
and the two column tooltips in both locale tables. `allowTransfer` is
enforced upstream and is untouched.
A value stored by an older editor is not modelled and not authorable; it
rides through save untouched, as any key this editor does not model does.
The installed spec (17.2.0) still ACCEPTS both keys at permission parse, so
stripping stored values today would delete data the schema still honours —
strip-on-load belongs with the bump that lands the retirement.
The return path is named in every tombstone: both keys come back with the M2
lifecycle initiative, whose restart is recorded on objectstack#1883.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CRJge11jso9TpXRWFt1Z49
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 52 chunks)3235.4 KB3266.6 KB
Main entry chunk (gzip)157.0 KB350 KB
Entry fileindex-CTzDHwYr.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (consoleActionDispatch.js)0.20KB0.19KB
app-shell (index.js)11.89KB4.50KB
app-shell (runtime-config.js)20.61KB7.35KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (ActiveOrganizationStorage.js)25.05KB9.16KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)2.07KB1.00KB
auth (AuthProvider.js)40.18KB10.59KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)8.46KB3.43KB
auth (index.js)3.19KB1.44KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.30KB1.02KB
auth (useWorkspaceAdminStatus.js)5.13KB2.35KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)506.01KB114.64KB
core (index.js)5.30KB2.13KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)173.10KB47.96KB
fields (index.js)238.89KB60.02KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (fallbackInterpolation.js)6.25KB2.77KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)26.89KB9.04KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)5.60KB2.33KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)9.53KB3.38KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)4.64KB1.50KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)1.93KB0.88KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.85KB12.89KB
plugin-charts (index.js)64.66KB18.32KB
plugin-chatbot (index.js)188.60KB44.82KB
plugin-dashboard (index.js)133.48KB34.49KB
plugin-designer (index.js)212.80KB43.15KB
plugin-detail (index.js)245.29KB62.39KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)131.78KB32.19KB
plugin-gantt (index.js)165.16KB40.33KB
plugin-grid (index.js)201.66KB54.58KB
plugin-kanban (index.js)53.11KB14.62KB
plugin-list (index.js)112.86KB27.54KB
plugin-map (index.js)20.09KB6.62KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.51KB11.94KB
plugin-timeline (index.js)26.72KB7.71KB
plugin-tree (index.js)9.26KB3.13KB
plugin-view (index.js)85.87KB21.12KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)4.47KB1.63KB
react (SchemaRenderer.js)65.97KB21.98KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)2.44KB1.21KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (dashboard-widget-options.js)3.08KB1.30KB
sdui-parser (index.js)4.93KB2.24KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)12.13KB3.65KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.28KB0.23KB
sdui-parser (validate.js)7.54KB2.63KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)2.74KB1.41KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)3.75KB1.85KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.85KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (icon-key-migration.js)4.26KB1.63KB
types (index.js)4.72KB2.24KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (spec-ui-namespace.js)0.20KB0.19KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)6.28KB2.87KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-sales
os-sales marked this pull request as ready for review August 27, 2026 13:18
@os-sales
os-sales added this pull request to the merge queueAug 27, 2026
Merged via the queue into main with commit bac7ba4Aug 27, 2026
30 checks passed
@os-sales
os-sales deleted the claude/issue-6595-retire-allowrestore-allowpurge-columns branch August 27, 2026 13:30
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

metadata-admin permission matrix still authors the retired allowRestore / allowPurge bits — spec now rejects them at publish

2 participants

@os-sales@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Retire the `allowRestore` / `allowPurge` columns from the metadata-admin permission matrix by os-sales · Pull Request #6607 · objectstack-ai/objectui · GitHub
Skip to content

Retire the allowRestore / allowPurge columns from the metadata-admin permission matrix - #6607

Merged
os-sales merged 2 commits into
mainfrom
claude/issue-6595-retire-allowrestore-allowpurge-columns
Aug 27, 2026
Merged

Retire the allowRestore / allowPurge columns from the metadata-admin permission matrix#6607
os-sales merged 2 commits into
mainfrom
claude/issue-6595-retire-allowrestore-allowpurge-columns

Conversation

@os-sales

Copy link
Copy Markdown
Collaborator

Fixes#6595

Drops the two retired object-permission bits from the metadata-admin permission matrix: the authoring columns, the typed fields, the preview rows, and the now-unreachable "Purge (hard delete) granted without Delete" lint. allowTransfer is enforced upstream (objectstack#3004) and is untouched — it stays a column, and every pin below asserts that in the same render so the removals cannot pass for the wrong reason.

Both removed keys gated restore / purge ObjectQL operations that have never existed: a dispatched restore/purge is denied unconditionally by the evaluator's fail-closed destructive-operation backstop. Every tick of those checkboxes wrote a grant no runtime has ever read. @objectstack/spec retired both as retiredKey() tombstones (objectstack#12497; maintainer ruling 2026-08-26 accepting objectstack#1883 recommendation B, ADR-0049 enforce-or-remove).

The return path is named at every site the removal touchedpermission-slice.ts, PermissionMatrixEditor.tsx, previews/PermissionPreview.tsx, and both new pins: the keys come back with the M2 lifecycle initiative, whose restart is recorded upstream on objectstack#1883.

The one thing measured on the day: the installed spec's posture

The card's premise splits into a part that is true either way and a part that depends on a bump that has not arrived. Measured 2026-08-27 against the installed @objectstack/spec17.2.0, by running real ObjectPermissionSchema.safeParse calls with a control key:

allowRestore ACCEPTED
allowPurge ACCEPTED
allowTransfer ACCEPTED
bogusKey REFUSED unrecognized_keys: ["definitelyNotAKey"]

The control is what makes this falsifiable: the schema IS strict and DOES refuse unknown keys, and it still accepts both retired keys. permission.zod-Bwl7_K0U.d.ts agrees at the type level (allowRestore: z.ZodDefault(z.ZodBoolean)).

So the bump has not reached this repo, and this PR does what that implies:

  • The removal lands — valid in both worlds, since the gated operations have never existed.
  • The "publish refuses it" pin is NOT taken. It belongs to the bump PR. Nothing here blocks on the bump, and no pin is bumped as a rider.
  • A stored legacy value is carried through, not stripped. It is no longer modelled and no longer authorable; it rides through save untouched, exactly as any key this editor does not model does. Stripping today would delete stored data the schema still honours. Once the bump lands and a carried value becomes a body the schema refuses, strip-on-load becomes correct — objectui#4644's resolution for indexed. The pin recording today's posture says so in its own header, so the bump PR replaces it deliberately rather than deleting a red.

The card's line references were stale, and its site list was incomplete

Line numbers were re-derived by name rather than trusted. The three constructs the card named were all real (at 180-181, 27-28, 59-60/86 — unchanged). But a fourth site reads these keys and the card did not list it:

packages/app-shell/src/views/metadata-admin/i18n.ts carries the two column tooltips in both locale tables — perm.action.restore / perm.action.purge in ENGINE_STRINGS_EN and ENGINE_STRINGS_ZH. Removing the columns without them would have left four dead keys in a pack whose EN/ZH halves must stay in step. Removed in both locales; the pack is the engine.* carve-out, so no pack gate reaches it either way.

Three prose sites were also carrying the removed columns as fact and are corrected: the editor's header comment (lifecycle (Transfer / Restore / Purge)), the column-legend note (Tr/Re/Pu/VA/MA), the fixed-column count (object + 9 CRUD + bulk, now 7 — the min-w floor is deliberately unchanged, so the grid simply has more room), and the preview's capability list plus its two legend lines.

Tests

Two new pin files, PermissionMatrixEditor.retiredLifecycleKeys.test.tsx and previews/PermissionPreview.retiredLifecycleKeys.test.tsx, following the shape PermissionAdvancedFacets.retiredKeys.test.tsx set for the RLS priority tombstone: pin the key SET, not the absence of two keys, because a set assertion is what stops a retired key drifting back in beside a live one. They cover the column set, the checkbox surface, what reaches the wire (the "Grant all" seed, whose key set is the real product of this change), the dropped lint measured on a draft that still trips the lints that stayed, and the carry-through of a stored legacy value.

Reverse verification — direction predicted before running: RED. Restoring the two columns, the two preview rows and the lint on top of the committed fix turns all 7 new pins red (Test Files 2 failed (2) · Tests 7 failed (7)); every one of them fails, so none was passing for an unrelated reason. Mutation confirmed on disk by anchored grep counts (short: 'Re'=1, long: 'Purge'=1, purge-lint=1) plus blob hashes differing from the HEAD blobs — not a bare diffstat. Restore leg proven the same way: git hash-object reproduces both HEAD blobs byte-for-byte and git diff HEAD is empty. No rebuild leg applies — both pins import their subject by relative source path (./PermissionMatrixEditor, ./PermissionPreview), so no dist/ sits in the resolution path.

Union re-run after the final commit, at 005a792:

checkresult
19 permission test files (whole surface, not just the new pins)Test Files 19 passed (19) · Tests 90 passed (90)
@object-ui/app-shell type-checkgreen — tsc --noEmit and tsc -p tsconfig.test.json
check-changeset-presence✅ 6 source file(s) of 1 released package(s) changed, and this change declares 1 changeset(s)
check:control-bytes✅ check-control-bytes: OK (scanned 5455 tracked text file(s); skipped 85 binary)
check:i18n-keysgreen — every in-scope call-site key resolves against the en pack
check:i18n-driftNo en value changed in this range
check:i18n-dead-keysreport-only gate, exit 0

The type-check claim is measured, not assumed: tsc -p tsconfig.test.json --listFiles lists both new test files, so the green covers them rather than excluding them.

Lint was narrowed deliberately, and here is why the narrowing loses nothing.eslint --no-inline-config --format json over the 6 changed files reports errorCount 0 (27 warnings, all pre-existing patterns; --max-warnings is deliberately unset repo-wide, per lint.yml's own note). The population is read from eslint's own resolution — it returned exactly 6 result objects, so all 6 are in scope and none was ignored. And the invariance holds by construction: eslint.config.js enables no type-aware linting (no project / projectService / parserOptions.project), so a file's verdict depends only on its own contents and the config — this diff cannot move the verdict on any file it does not touch. CI runs the repo-wide pnpm lint regardless.

Out-of-scope findings, filed rather than fixed here

  • objectui#6605 — the matrix's four bulk buttons (R / CRUD / All / None) replace the object row instead of merging, silently deleting allowExport, readScope and writeScope, which the local ObjectPerm does not model. The sharpest shape: clicking All can widen effective read access by deleting a readScope: own narrowing. Different defect class from this card (those keys are live and enforced), so it is not touched here.
  • objectui#6606 — the permission authoring shapes are absent from PAYLOAD_SHAPES in check-designer-field-key-parity.mjs, so the very class this card instantiates is invisible to that gate on the permission surface. This card arrived as a hand-written upstream referral, not from CI.

Neither is addressed in this PR; both remain open.

Fence

Every edit is inside packages/app-shell/src/views/metadata-admin/ plus one .changeset/ file. Nothing under studio-design/ was read for edit or touched — the sibling round's region is untouched.


Generated by Claude Code

…sion columns
Both keys gated `restore` / `purge` ObjectQL operations that have never
existed — a dispatched restore/purge is denied unconditionally by the
evaluator's fail-closed destructive-operation backstop — so the two matrix
checkboxes were dead-end authoring surface: every tick wrote a grant no
runtime has ever read. `@objectstack/spec` retired both keys as
`retiredKey()` tombstones (objectstack#12497; maintainer ruling 2026-08-26
accepting objectstack#1883 recommendation B, ADR-0049 enforce-or-remove).
Removed: the two authoring columns, the two typed fields, the two preview
rows, the now-unreachable "Purge (hard delete) granted without Delete" lint,
and the two column tooltips in both locale tables. `allowTransfer` is
enforced upstream and is untouched.
A value stored by an older editor is not modelled and not authorable; it
rides through save untouched, as any key this editor does not model does.
The installed spec (17.2.0) still ACCEPTS both keys at permission parse, so
stripping stored values today would delete data the schema still honours —
strip-on-load belongs with the bump that lands the retirement.
The return path is named in every tombstone: both keys come back with the M2
lifecycle initiative, whose restart is recorded on objectstack#1883.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CRJge11jso9TpXRWFt1Z49
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 52 chunks)3235.4 KB3266.6 KB
Main entry chunk (gzip)157.0 KB350 KB
Entry fileindex-CTzDHwYr.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (consoleActionDispatch.js)0.20KB0.19KB
app-shell (index.js)11.89KB4.50KB
app-shell (runtime-config.js)20.61KB7.35KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (ActiveOrganizationStorage.js)25.05KB9.16KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)2.07KB1.00KB
auth (AuthProvider.js)40.18KB10.59KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)8.46KB3.43KB
auth (index.js)3.19KB1.44KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.30KB1.02KB
auth (useWorkspaceAdminStatus.js)5.13KB2.35KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)506.01KB114.64KB
core (index.js)5.30KB2.13KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)173.10KB47.96KB
fields (index.js)238.89KB60.02KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (fallbackInterpolation.js)6.25KB2.77KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)26.89KB9.04KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)5.60KB2.33KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)9.53KB3.38KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)4.64KB1.50KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)1.93KB0.88KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.85KB12.89KB
plugin-charts (index.js)64.66KB18.32KB
plugin-chatbot (index.js)188.60KB44.82KB
plugin-dashboard (index.js)133.48KB34.49KB
plugin-designer (index.js)212.80KB43.15KB
plugin-detail (index.js)245.29KB62.39KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)131.78KB32.19KB
plugin-gantt (index.js)165.16KB40.33KB
plugin-grid (index.js)201.66KB54.58KB
plugin-kanban (index.js)53.11KB14.62KB
plugin-list (index.js)112.86KB27.54KB
plugin-map (index.js)20.09KB6.62KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.51KB11.94KB
plugin-timeline (index.js)26.72KB7.71KB
plugin-tree (index.js)9.26KB3.13KB
plugin-view (index.js)85.87KB21.12KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)4.47KB1.63KB
react (SchemaRenderer.js)65.97KB21.98KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)2.44KB1.21KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (dashboard-widget-options.js)3.08KB1.30KB
sdui-parser (index.js)4.93KB2.24KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)12.13KB3.65KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.28KB0.23KB
sdui-parser (validate.js)7.54KB2.63KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)2.74KB1.41KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)3.75KB1.85KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.85KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (icon-key-migration.js)4.26KB1.63KB
types (index.js)4.72KB2.24KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (spec-ui-namespace.js)0.20KB0.19KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)6.28KB2.87KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-sales
os-sales marked this pull request as ready for review August 27, 2026 13:18
@os-sales
os-sales added this pull request to the merge queueAug 27, 2026
Merged via the queue into main with commit bac7ba4Aug 27, 2026
30 checks passed
@os-sales
os-sales deleted the claude/issue-6595-retire-allowrestore-allowpurge-columns branch August 27, 2026 13:30
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

metadata-admin permission matrix still authors the retired allowRestore / allowPurge bits — spec now rejects them at publish

2 participants

@os-sales@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Retire the `allowRestore` / `allowPurge` columns from the metadata-admin permission matrix by os-sales · Pull Request #6607 · objectstack-ai/objectui · GitHub
Skip to content

Retire the allowRestore / allowPurge columns from the metadata-admin permission matrix - #6607

Merged
os-sales merged 2 commits into
mainfrom
claude/issue-6595-retire-allowrestore-allowpurge-columns
Aug 27, 2026
Merged

Retire the allowRestore / allowPurge columns from the metadata-admin permission matrix#6607
os-sales merged 2 commits into
mainfrom
claude/issue-6595-retire-allowrestore-allowpurge-columns

Conversation

@os-sales

Copy link
Copy Markdown
Collaborator

Fixes#6595

Drops the two retired object-permission bits from the metadata-admin permission matrix: the authoring columns, the typed fields, the preview rows, and the now-unreachable "Purge (hard delete) granted without Delete" lint. allowTransfer is enforced upstream (objectstack#3004) and is untouched — it stays a column, and every pin below asserts that in the same render so the removals cannot pass for the wrong reason.

Both removed keys gated restore / purge ObjectQL operations that have never existed: a dispatched restore/purge is denied unconditionally by the evaluator's fail-closed destructive-operation backstop. Every tick of those checkboxes wrote a grant no runtime has ever read. @objectstack/spec retired both as retiredKey() tombstones (objectstack#12497; maintainer ruling 2026-08-26 accepting objectstack#1883 recommendation B, ADR-0049 enforce-or-remove).

The return path is named at every site the removal touchedpermission-slice.ts, PermissionMatrixEditor.tsx, previews/PermissionPreview.tsx, and both new pins: the keys come back with the M2 lifecycle initiative, whose restart is recorded upstream on objectstack#1883.

The one thing measured on the day: the installed spec's posture

The card's premise splits into a part that is true either way and a part that depends on a bump that has not arrived. Measured 2026-08-27 against the installed @objectstack/spec17.2.0, by running real ObjectPermissionSchema.safeParse calls with a control key:

allowRestore ACCEPTED
allowPurge ACCEPTED
allowTransfer ACCEPTED
bogusKey REFUSED unrecognized_keys: ["definitelyNotAKey"]

The control is what makes this falsifiable: the schema IS strict and DOES refuse unknown keys, and it still accepts both retired keys. permission.zod-Bwl7_K0U.d.ts agrees at the type level (allowRestore: z.ZodDefault(z.ZodBoolean)).

So the bump has not reached this repo, and this PR does what that implies:

  • The removal lands — valid in both worlds, since the gated operations have never existed.
  • The "publish refuses it" pin is NOT taken. It belongs to the bump PR. Nothing here blocks on the bump, and no pin is bumped as a rider.
  • A stored legacy value is carried through, not stripped. It is no longer modelled and no longer authorable; it rides through save untouched, exactly as any key this editor does not model does. Stripping today would delete stored data the schema still honours. Once the bump lands and a carried value becomes a body the schema refuses, strip-on-load becomes correct — objectui#4644's resolution for indexed. The pin recording today's posture says so in its own header, so the bump PR replaces it deliberately rather than deleting a red.

The card's line references were stale, and its site list was incomplete

Line numbers were re-derived by name rather than trusted. The three constructs the card named were all real (at 180-181, 27-28, 59-60/86 — unchanged). But a fourth site reads these keys and the card did not list it:

packages/app-shell/src/views/metadata-admin/i18n.ts carries the two column tooltips in both locale tables — perm.action.restore / perm.action.purge in ENGINE_STRINGS_EN and ENGINE_STRINGS_ZH. Removing the columns without them would have left four dead keys in a pack whose EN/ZH halves must stay in step. Removed in both locales; the pack is the engine.* carve-out, so no pack gate reaches it either way.

Three prose sites were also carrying the removed columns as fact and are corrected: the editor's header comment (lifecycle (Transfer / Restore / Purge)), the column-legend note (Tr/Re/Pu/VA/MA), the fixed-column count (object + 9 CRUD + bulk, now 7 — the min-w floor is deliberately unchanged, so the grid simply has more room), and the preview's capability list plus its two legend lines.

Tests

Two new pin files, PermissionMatrixEditor.retiredLifecycleKeys.test.tsx and previews/PermissionPreview.retiredLifecycleKeys.test.tsx, following the shape PermissionAdvancedFacets.retiredKeys.test.tsx set for the RLS priority tombstone: pin the key SET, not the absence of two keys, because a set assertion is what stops a retired key drifting back in beside a live one. They cover the column set, the checkbox surface, what reaches the wire (the "Grant all" seed, whose key set is the real product of this change), the dropped lint measured on a draft that still trips the lints that stayed, and the carry-through of a stored legacy value.

Reverse verification — direction predicted before running: RED. Restoring the two columns, the two preview rows and the lint on top of the committed fix turns all 7 new pins red (Test Files 2 failed (2) · Tests 7 failed (7)); every one of them fails, so none was passing for an unrelated reason. Mutation confirmed on disk by anchored grep counts (short: 'Re'=1, long: 'Purge'=1, purge-lint=1) plus blob hashes differing from the HEAD blobs — not a bare diffstat. Restore leg proven the same way: git hash-object reproduces both HEAD blobs byte-for-byte and git diff HEAD is empty. No rebuild leg applies — both pins import their subject by relative source path (./PermissionMatrixEditor, ./PermissionPreview), so no dist/ sits in the resolution path.

Union re-run after the final commit, at 005a792:

checkresult
19 permission test files (whole surface, not just the new pins)Test Files 19 passed (19) · Tests 90 passed (90)
@object-ui/app-shell type-checkgreen — tsc --noEmit and tsc -p tsconfig.test.json
check-changeset-presence✅ 6 source file(s) of 1 released package(s) changed, and this change declares 1 changeset(s)
check:control-bytes✅ check-control-bytes: OK (scanned 5455 tracked text file(s); skipped 85 binary)
check:i18n-keysgreen — every in-scope call-site key resolves against the en pack
check:i18n-driftNo en value changed in this range
check:i18n-dead-keysreport-only gate, exit 0

The type-check claim is measured, not assumed: tsc -p tsconfig.test.json --listFiles lists both new test files, so the green covers them rather than excluding them.

Lint was narrowed deliberately, and here is why the narrowing loses nothing.eslint --no-inline-config --format json over the 6 changed files reports errorCount 0 (27 warnings, all pre-existing patterns; --max-warnings is deliberately unset repo-wide, per lint.yml's own note). The population is read from eslint's own resolution — it returned exactly 6 result objects, so all 6 are in scope and none was ignored. And the invariance holds by construction: eslint.config.js enables no type-aware linting (no project / projectService / parserOptions.project), so a file's verdict depends only on its own contents and the config — this diff cannot move the verdict on any file it does not touch. CI runs the repo-wide pnpm lint regardless.

Out-of-scope findings, filed rather than fixed here

  • objectui#6605 — the matrix's four bulk buttons (R / CRUD / All / None) replace the object row instead of merging, silently deleting allowExport, readScope and writeScope, which the local ObjectPerm does not model. The sharpest shape: clicking All can widen effective read access by deleting a readScope: own narrowing. Different defect class from this card (those keys are live and enforced), so it is not touched here.
  • objectui#6606 — the permission authoring shapes are absent from PAYLOAD_SHAPES in check-designer-field-key-parity.mjs, so the very class this card instantiates is invisible to that gate on the permission surface. This card arrived as a hand-written upstream referral, not from CI.

Neither is addressed in this PR; both remain open.

Fence

Every edit is inside packages/app-shell/src/views/metadata-admin/ plus one .changeset/ file. Nothing under studio-design/ was read for edit or touched — the sibling round's region is untouched.


Generated by Claude Code

…sion columns
Both keys gated `restore` / `purge` ObjectQL operations that have never
existed — a dispatched restore/purge is denied unconditionally by the
evaluator's fail-closed destructive-operation backstop — so the two matrix
checkboxes were dead-end authoring surface: every tick wrote a grant no
runtime has ever read. `@objectstack/spec` retired both keys as
`retiredKey()` tombstones (objectstack#12497; maintainer ruling 2026-08-26
accepting objectstack#1883 recommendation B, ADR-0049 enforce-or-remove).
Removed: the two authoring columns, the two typed fields, the two preview
rows, the now-unreachable "Purge (hard delete) granted without Delete" lint,
and the two column tooltips in both locale tables. `allowTransfer` is
enforced upstream and is untouched.
A value stored by an older editor is not modelled and not authorable; it
rides through save untouched, as any key this editor does not model does.
The installed spec (17.2.0) still ACCEPTS both keys at permission parse, so
stripping stored values today would delete data the schema still honours —
strip-on-load belongs with the bump that lands the retirement.
The return path is named in every tombstone: both keys come back with the M2
lifecycle initiative, whose restart is recorded on objectstack#1883.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CRJge11jso9TpXRWFt1Z49
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 52 chunks)3235.4 KB3266.6 KB
Main entry chunk (gzip)157.0 KB350 KB
Entry fileindex-CTzDHwYr.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (consoleActionDispatch.js)0.20KB0.19KB
app-shell (index.js)11.89KB4.50KB
app-shell (runtime-config.js)20.61KB7.35KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (ActiveOrganizationStorage.js)25.05KB9.16KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)2.07KB1.00KB
auth (AuthProvider.js)40.18KB10.59KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)8.46KB3.43KB
auth (index.js)3.19KB1.44KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.30KB1.02KB
auth (useWorkspaceAdminStatus.js)5.13KB2.35KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)506.01KB114.64KB
core (index.js)5.30KB2.13KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)173.10KB47.96KB
fields (index.js)238.89KB60.02KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (fallbackInterpolation.js)6.25KB2.77KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)26.89KB9.04KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)5.60KB2.33KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)9.53KB3.38KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)4.64KB1.50KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)1.93KB0.88KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.85KB12.89KB
plugin-charts (index.js)64.66KB18.32KB
plugin-chatbot (index.js)188.60KB44.82KB
plugin-dashboard (index.js)133.48KB34.49KB
plugin-designer (index.js)212.80KB43.15KB
plugin-detail (index.js)245.29KB62.39KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)131.78KB32.19KB
plugin-gantt (index.js)165.16KB40.33KB
plugin-grid (index.js)201.66KB54.58KB
plugin-kanban (index.js)53.11KB14.62KB
plugin-list (index.js)112.86KB27.54KB
plugin-map (index.js)20.09KB6.62KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.51KB11.94KB
plugin-timeline (index.js)26.72KB7.71KB
plugin-tree (index.js)9.26KB3.13KB
plugin-view (index.js)85.87KB21.12KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)4.47KB1.63KB
react (SchemaRenderer.js)65.97KB21.98KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)2.44KB1.21KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (dashboard-widget-options.js)3.08KB1.30KB
sdui-parser (index.js)4.93KB2.24KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)12.13KB3.65KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.28KB0.23KB
sdui-parser (validate.js)7.54KB2.63KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)2.74KB1.41KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)3.75KB1.85KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.85KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (icon-key-migration.js)4.26KB1.63KB
types (index.js)4.72KB2.24KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (spec-ui-namespace.js)0.20KB0.19KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)6.28KB2.87KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-sales
os-sales marked this pull request as ready for review August 27, 2026 13:18
@os-sales
os-sales added this pull request to the merge queueAug 27, 2026
Merged via the queue into main with commit bac7ba4Aug 27, 2026
30 checks passed
@os-sales
os-sales deleted the claude/issue-6595-retire-allowrestore-allowpurge-columns branch August 27, 2026 13:30
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

metadata-admin permission matrix still authors the retired allowRestore / allowPurge bits — spec now rejects them at publish

2 participants

@os-sales@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' Retire the `allowRestore` / `allowPurge` columns from the metadata-admin permission matrix by os-sales · Pull Request #6607 · objectstack-ai/objectui · GitHub
Skip to content

Retire the allowRestore / allowPurge columns from the metadata-admin permission matrix - #6607

Merged
os-sales merged 2 commits into
mainfrom
claude/issue-6595-retire-allowrestore-allowpurge-columns
Aug 27, 2026
Merged

Retire the allowRestore / allowPurge columns from the metadata-admin permission matrix#6607
os-sales merged 2 commits into
mainfrom
claude/issue-6595-retire-allowrestore-allowpurge-columns

Conversation

@os-sales

Copy link
Copy Markdown
Collaborator

Fixes#6595

Drops the two retired object-permission bits from the metadata-admin permission matrix: the authoring columns, the typed fields, the preview rows, and the now-unreachable "Purge (hard delete) granted without Delete" lint. allowTransfer is enforced upstream (objectstack#3004) and is untouched — it stays a column, and every pin below asserts that in the same render so the removals cannot pass for the wrong reason.

Both removed keys gated restore / purge ObjectQL operations that have never existed: a dispatched restore/purge is denied unconditionally by the evaluator's fail-closed destructive-operation backstop. Every tick of those checkboxes wrote a grant no runtime has ever read. @objectstack/spec retired both as retiredKey() tombstones (objectstack#12497; maintainer ruling 2026-08-26 accepting objectstack#1883 recommendation B, ADR-0049 enforce-or-remove).

The return path is named at every site the removal touchedpermission-slice.ts, PermissionMatrixEditor.tsx, previews/PermissionPreview.tsx, and both new pins: the keys come back with the M2 lifecycle initiative, whose restart is recorded upstream on objectstack#1883.

The one thing measured on the day: the installed spec's posture

The card's premise splits into a part that is true either way and a part that depends on a bump that has not arrived. Measured 2026-08-27 against the installed @objectstack/spec17.2.0, by running real ObjectPermissionSchema.safeParse calls with a control key:

allowRestore ACCEPTED
allowPurge ACCEPTED
allowTransfer ACCEPTED
bogusKey REFUSED unrecognized_keys: ["definitelyNotAKey"]

The control is what makes this falsifiable: the schema IS strict and DOES refuse unknown keys, and it still accepts both retired keys. permission.zod-Bwl7_K0U.d.ts agrees at the type level (allowRestore: z.ZodDefault(z.ZodBoolean)).

So the bump has not reached this repo, and this PR does what that implies:

  • The removal lands — valid in both worlds, since the gated operations have never existed.
  • The "publish refuses it" pin is NOT taken. It belongs to the bump PR. Nothing here blocks on the bump, and no pin is bumped as a rider.
  • A stored legacy value is carried through, not stripped. It is no longer modelled and no longer authorable; it rides through save untouched, exactly as any key this editor does not model does. Stripping today would delete stored data the schema still honours. Once the bump lands and a carried value becomes a body the schema refuses, strip-on-load becomes correct — objectui#4644's resolution for indexed. The pin recording today's posture says so in its own header, so the bump PR replaces it deliberately rather than deleting a red.

The card's line references were stale, and its site list was incomplete

Line numbers were re-derived by name rather than trusted. The three constructs the card named were all real (at 180-181, 27-28, 59-60/86 — unchanged). But a fourth site reads these keys and the card did not list it:

packages/app-shell/src/views/metadata-admin/i18n.ts carries the two column tooltips in both locale tables — perm.action.restore / perm.action.purge in ENGINE_STRINGS_EN and ENGINE_STRINGS_ZH. Removing the columns without them would have left four dead keys in a pack whose EN/ZH halves must stay in step. Removed in both locales; the pack is the engine.* carve-out, so no pack gate reaches it either way.

Three prose sites were also carrying the removed columns as fact and are corrected: the editor's header comment (lifecycle (Transfer / Restore / Purge)), the column-legend note (Tr/Re/Pu/VA/MA), the fixed-column count (object + 9 CRUD + bulk, now 7 — the min-w floor is deliberately unchanged, so the grid simply has more room), and the preview's capability list plus its two legend lines.

Tests

Two new pin files, PermissionMatrixEditor.retiredLifecycleKeys.test.tsx and previews/PermissionPreview.retiredLifecycleKeys.test.tsx, following the shape PermissionAdvancedFacets.retiredKeys.test.tsx set for the RLS priority tombstone: pin the key SET, not the absence of two keys, because a set assertion is what stops a retired key drifting back in beside a live one. They cover the column set, the checkbox surface, what reaches the wire (the "Grant all" seed, whose key set is the real product of this change), the dropped lint measured on a draft that still trips the lints that stayed, and the carry-through of a stored legacy value.

Reverse verification — direction predicted before running: RED. Restoring the two columns, the two preview rows and the lint on top of the committed fix turns all 7 new pins red (Test Files 2 failed (2) · Tests 7 failed (7)); every one of them fails, so none was passing for an unrelated reason. Mutation confirmed on disk by anchored grep counts (short: 'Re'=1, long: 'Purge'=1, purge-lint=1) plus blob hashes differing from the HEAD blobs — not a bare diffstat. Restore leg proven the same way: git hash-object reproduces both HEAD blobs byte-for-byte and git diff HEAD is empty. No rebuild leg applies — both pins import their subject by relative source path (./PermissionMatrixEditor, ./PermissionPreview), so no dist/ sits in the resolution path.

Union re-run after the final commit, at 005a792:

checkresult
19 permission test files (whole surface, not just the new pins)Test Files 19 passed (19) · Tests 90 passed (90)
@object-ui/app-shell type-checkgreen — tsc --noEmit and tsc -p tsconfig.test.json
check-changeset-presence✅ 6 source file(s) of 1 released package(s) changed, and this change declares 1 changeset(s)
check:control-bytes✅ check-control-bytes: OK (scanned 5455 tracked text file(s); skipped 85 binary)
check:i18n-keysgreen — every in-scope call-site key resolves against the en pack
check:i18n-driftNo en value changed in this range
check:i18n-dead-keysreport-only gate, exit 0

The type-check claim is measured, not assumed: tsc -p tsconfig.test.json --listFiles lists both new test files, so the green covers them rather than excluding them.

Lint was narrowed deliberately, and here is why the narrowing loses nothing.eslint --no-inline-config --format json over the 6 changed files reports errorCount 0 (27 warnings, all pre-existing patterns; --max-warnings is deliberately unset repo-wide, per lint.yml's own note). The population is read from eslint's own resolution — it returned exactly 6 result objects, so all 6 are in scope and none was ignored. And the invariance holds by construction: eslint.config.js enables no type-aware linting (no project / projectService / parserOptions.project), so a file's verdict depends only on its own contents and the config — this diff cannot move the verdict on any file it does not touch. CI runs the repo-wide pnpm lint regardless.

Out-of-scope findings, filed rather than fixed here

  • objectui#6605 — the matrix's four bulk buttons (R / CRUD / All / None) replace the object row instead of merging, silently deleting allowExport, readScope and writeScope, which the local ObjectPerm does not model. The sharpest shape: clicking All can widen effective read access by deleting a readScope: own narrowing. Different defect class from this card (those keys are live and enforced), so it is not touched here.
  • objectui#6606 — the permission authoring shapes are absent from PAYLOAD_SHAPES in check-designer-field-key-parity.mjs, so the very class this card instantiates is invisible to that gate on the permission surface. This card arrived as a hand-written upstream referral, not from CI.

Neither is addressed in this PR; both remain open.

Fence

Every edit is inside packages/app-shell/src/views/metadata-admin/ plus one .changeset/ file. Nothing under studio-design/ was read for edit or touched — the sibling round's region is untouched.


Generated by Claude Code

…sion columns
Both keys gated `restore` / `purge` ObjectQL operations that have never
existed — a dispatched restore/purge is denied unconditionally by the
evaluator's fail-closed destructive-operation backstop — so the two matrix
checkboxes were dead-end authoring surface: every tick wrote a grant no
runtime has ever read. `@objectstack/spec` retired both keys as
`retiredKey()` tombstones (objectstack#12497; maintainer ruling 2026-08-26
accepting objectstack#1883 recommendation B, ADR-0049 enforce-or-remove).
Removed: the two authoring columns, the two typed fields, the two preview
rows, the now-unreachable "Purge (hard delete) granted without Delete" lint,
and the two column tooltips in both locale tables. `allowTransfer` is
enforced upstream and is untouched.
A value stored by an older editor is not modelled and not authorable; it
rides through save untouched, as any key this editor does not model does.
The installed spec (17.2.0) still ACCEPTS both keys at permission parse, so
stripping stored values today would delete data the schema still honours —
strip-on-load belongs with the bump that lands the retirement.
The return path is named in every tombstone: both keys come back with the M2
lifecycle initiative, whose restart is recorded on objectstack#1883.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CRJge11jso9TpXRWFt1Z49
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 52 chunks)3235.4 KB3266.6 KB
Main entry chunk (gzip)157.0 KB350 KB
Entry fileindex-CTzDHwYr.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (consoleActionDispatch.js)0.20KB0.19KB
app-shell (index.js)11.89KB4.50KB
app-shell (runtime-config.js)20.61KB7.35KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (ActiveOrganizationStorage.js)25.05KB9.16KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)2.07KB1.00KB
auth (AuthProvider.js)40.18KB10.59KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)8.46KB3.43KB
auth (index.js)3.19KB1.44KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.30KB1.02KB
auth (useWorkspaceAdminStatus.js)5.13KB2.35KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)506.01KB114.64KB
core (index.js)5.30KB2.13KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)173.10KB47.96KB
fields (index.js)238.89KB60.02KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (fallbackInterpolation.js)6.25KB2.77KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)26.89KB9.04KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)5.60KB2.33KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)9.53KB3.38KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)4.64KB1.50KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)1.93KB0.88KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.85KB12.89KB
plugin-charts (index.js)64.66KB18.32KB
plugin-chatbot (index.js)188.60KB44.82KB
plugin-dashboard (index.js)133.48KB34.49KB
plugin-designer (index.js)212.80KB43.15KB
plugin-detail (index.js)245.29KB62.39KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)131.78KB32.19KB
plugin-gantt (index.js)165.16KB40.33KB
plugin-grid (index.js)201.66KB54.58KB
plugin-kanban (index.js)53.11KB14.62KB
plugin-list (index.js)112.86KB27.54KB
plugin-map (index.js)20.09KB6.62KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.51KB11.94KB
plugin-timeline (index.js)26.72KB7.71KB
plugin-tree (index.js)9.26KB3.13KB
plugin-view (index.js)85.87KB21.12KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)4.47KB1.63KB
react (SchemaRenderer.js)65.97KB21.98KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)2.44KB1.21KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (dashboard-widget-options.js)3.08KB1.30KB
sdui-parser (index.js)4.93KB2.24KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)12.13KB3.65KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.28KB0.23KB
sdui-parser (validate.js)7.54KB2.63KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)2.74KB1.41KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)3.75KB1.85KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.85KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (icon-key-migration.js)4.26KB1.63KB
types (index.js)4.72KB2.24KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (spec-ui-namespace.js)0.20KB0.19KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)6.28KB2.87KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-sales
os-sales marked this pull request as ready for review August 27, 2026 13:18
@os-sales
os-sales added this pull request to the merge queueAug 27, 2026
Merged via the queue into main with commit bac7ba4Aug 27, 2026
30 checks passed
@os-sales
os-sales deleted the claude/issue-6595-retire-allowrestore-allowpurge-columns branch August 27, 2026 13:30
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

metadata-admin permission matrix still authors the retired allowRestore / allowPurge bits — spec now rejects them at publish

2 participants

@os-sales@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Retire the `allowRestore` / `allowPurge` columns from the metadata-admin permission matrix by os-sales · Pull Request #6607 · objectstack-ai/objectui · GitHub
Skip to content

Retire the allowRestore / allowPurge columns from the metadata-admin permission matrix - #6607

Merged
os-sales merged 2 commits into
mainfrom
claude/issue-6595-retire-allowrestore-allowpurge-columns
Aug 27, 2026
Merged

Retire the allowRestore / allowPurge columns from the metadata-admin permission matrix#6607
os-sales merged 2 commits into
mainfrom
claude/issue-6595-retire-allowrestore-allowpurge-columns

Conversation

@os-sales

Copy link
Copy Markdown
Collaborator

Fixes#6595

Drops the two retired object-permission bits from the metadata-admin permission matrix: the authoring columns, the typed fields, the preview rows, and the now-unreachable "Purge (hard delete) granted without Delete" lint. allowTransfer is enforced upstream (objectstack#3004) and is untouched — it stays a column, and every pin below asserts that in the same render so the removals cannot pass for the wrong reason.

Both removed keys gated restore / purge ObjectQL operations that have never existed: a dispatched restore/purge is denied unconditionally by the evaluator's fail-closed destructive-operation backstop. Every tick of those checkboxes wrote a grant no runtime has ever read. @objectstack/spec retired both as retiredKey() tombstones (objectstack#12497; maintainer ruling 2026-08-26 accepting objectstack#1883 recommendation B, ADR-0049 enforce-or-remove).

The return path is named at every site the removal touchedpermission-slice.ts, PermissionMatrixEditor.tsx, previews/PermissionPreview.tsx, and both new pins: the keys come back with the M2 lifecycle initiative, whose restart is recorded upstream on objectstack#1883.

The one thing measured on the day: the installed spec's posture

The card's premise splits into a part that is true either way and a part that depends on a bump that has not arrived. Measured 2026-08-27 against the installed @objectstack/spec17.2.0, by running real ObjectPermissionSchema.safeParse calls with a control key:

allowRestore ACCEPTED
allowPurge ACCEPTED
allowTransfer ACCEPTED
bogusKey REFUSED unrecognized_keys: ["definitelyNotAKey"]

The control is what makes this falsifiable: the schema IS strict and DOES refuse unknown keys, and it still accepts both retired keys. permission.zod-Bwl7_K0U.d.ts agrees at the type level (allowRestore: z.ZodDefault(z.ZodBoolean)).

So the bump has not reached this repo, and this PR does what that implies:

  • The removal lands — valid in both worlds, since the gated operations have never existed.
  • The "publish refuses it" pin is NOT taken. It belongs to the bump PR. Nothing here blocks on the bump, and no pin is bumped as a rider.
  • A stored legacy value is carried through, not stripped. It is no longer modelled and no longer authorable; it rides through save untouched, exactly as any key this editor does not model does. Stripping today would delete stored data the schema still honours. Once the bump lands and a carried value becomes a body the schema refuses, strip-on-load becomes correct — objectui#4644's resolution for indexed. The pin recording today's posture says so in its own header, so the bump PR replaces it deliberately rather than deleting a red.

The card's line references were stale, and its site list was incomplete

Line numbers were re-derived by name rather than trusted. The three constructs the card named were all real (at 180-181, 27-28, 59-60/86 — unchanged). But a fourth site reads these keys and the card did not list it:

packages/app-shell/src/views/metadata-admin/i18n.ts carries the two column tooltips in both locale tables — perm.action.restore / perm.action.purge in ENGINE_STRINGS_EN and ENGINE_STRINGS_ZH. Removing the columns without them would have left four dead keys in a pack whose EN/ZH halves must stay in step. Removed in both locales; the pack is the engine.* carve-out, so no pack gate reaches it either way.

Three prose sites were also carrying the removed columns as fact and are corrected: the editor's header comment (lifecycle (Transfer / Restore / Purge)), the column-legend note (Tr/Re/Pu/VA/MA), the fixed-column count (object + 9 CRUD + bulk, now 7 — the min-w floor is deliberately unchanged, so the grid simply has more room), and the preview's capability list plus its two legend lines.

Tests

Two new pin files, PermissionMatrixEditor.retiredLifecycleKeys.test.tsx and previews/PermissionPreview.retiredLifecycleKeys.test.tsx, following the shape PermissionAdvancedFacets.retiredKeys.test.tsx set for the RLS priority tombstone: pin the key SET, not the absence of two keys, because a set assertion is what stops a retired key drifting back in beside a live one. They cover the column set, the checkbox surface, what reaches the wire (the "Grant all" seed, whose key set is the real product of this change), the dropped lint measured on a draft that still trips the lints that stayed, and the carry-through of a stored legacy value.

Reverse verification — direction predicted before running: RED. Restoring the two columns, the two preview rows and the lint on top of the committed fix turns all 7 new pins red (Test Files 2 failed (2) · Tests 7 failed (7)); every one of them fails, so none was passing for an unrelated reason. Mutation confirmed on disk by anchored grep counts (short: 'Re'=1, long: 'Purge'=1, purge-lint=1) plus blob hashes differing from the HEAD blobs — not a bare diffstat. Restore leg proven the same way: git hash-object reproduces both HEAD blobs byte-for-byte and git diff HEAD is empty. No rebuild leg applies — both pins import their subject by relative source path (./PermissionMatrixEditor, ./PermissionPreview), so no dist/ sits in the resolution path.

Union re-run after the final commit, at 005a792:

checkresult
19 permission test files (whole surface, not just the new pins)Test Files 19 passed (19) · Tests 90 passed (90)
@object-ui/app-shell type-checkgreen — tsc --noEmit and tsc -p tsconfig.test.json
check-changeset-presence✅ 6 source file(s) of 1 released package(s) changed, and this change declares 1 changeset(s)
check:control-bytes✅ check-control-bytes: OK (scanned 5455 tracked text file(s); skipped 85 binary)
check:i18n-keysgreen — every in-scope call-site key resolves against the en pack
check:i18n-driftNo en value changed in this range
check:i18n-dead-keysreport-only gate, exit 0

The type-check claim is measured, not assumed: tsc -p tsconfig.test.json --listFiles lists both new test files, so the green covers them rather than excluding them.

Lint was narrowed deliberately, and here is why the narrowing loses nothing.eslint --no-inline-config --format json over the 6 changed files reports errorCount 0 (27 warnings, all pre-existing patterns; --max-warnings is deliberately unset repo-wide, per lint.yml's own note). The population is read from eslint's own resolution — it returned exactly 6 result objects, so all 6 are in scope and none was ignored. And the invariance holds by construction: eslint.config.js enables no type-aware linting (no project / projectService / parserOptions.project), so a file's verdict depends only on its own contents and the config — this diff cannot move the verdict on any file it does not touch. CI runs the repo-wide pnpm lint regardless.

Out-of-scope findings, filed rather than fixed here

  • objectui#6605 — the matrix's four bulk buttons (R / CRUD / All / None) replace the object row instead of merging, silently deleting allowExport, readScope and writeScope, which the local ObjectPerm does not model. The sharpest shape: clicking All can widen effective read access by deleting a readScope: own narrowing. Different defect class from this card (those keys are live and enforced), so it is not touched here.
  • objectui#6606 — the permission authoring shapes are absent from PAYLOAD_SHAPES in check-designer-field-key-parity.mjs, so the very class this card instantiates is invisible to that gate on the permission surface. This card arrived as a hand-written upstream referral, not from CI.

Neither is addressed in this PR; both remain open.

Fence

Every edit is inside packages/app-shell/src/views/metadata-admin/ plus one .changeset/ file. Nothing under studio-design/ was read for edit or touched — the sibling round's region is untouched.


Generated by Claude Code

…sion columns
Both keys gated `restore` / `purge` ObjectQL operations that have never
existed — a dispatched restore/purge is denied unconditionally by the
evaluator's fail-closed destructive-operation backstop — so the two matrix
checkboxes were dead-end authoring surface: every tick wrote a grant no
runtime has ever read. `@objectstack/spec` retired both keys as
`retiredKey()` tombstones (objectstack#12497; maintainer ruling 2026-08-26
accepting objectstack#1883 recommendation B, ADR-0049 enforce-or-remove).
Removed: the two authoring columns, the two typed fields, the two preview
rows, the now-unreachable "Purge (hard delete) granted without Delete" lint,
and the two column tooltips in both locale tables. `allowTransfer` is
enforced upstream and is untouched.
A value stored by an older editor is not modelled and not authorable; it
rides through save untouched, as any key this editor does not model does.
The installed spec (17.2.0) still ACCEPTS both keys at permission parse, so
stripping stored values today would delete data the schema still honours —
strip-on-load belongs with the bump that lands the retirement.
The return path is named in every tombstone: both keys come back with the M2
lifecycle initiative, whose restart is recorded on objectstack#1883.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CRJge11jso9TpXRWFt1Z49
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 52 chunks)3235.4 KB3266.6 KB
Main entry chunk (gzip)157.0 KB350 KB
Entry fileindex-CTzDHwYr.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (consoleActionDispatch.js)0.20KB0.19KB
app-shell (index.js)11.89KB4.50KB
app-shell (runtime-config.js)20.61KB7.35KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (ActiveOrganizationStorage.js)25.05KB9.16KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)2.07KB1.00KB
auth (AuthProvider.js)40.18KB10.59KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)8.46KB3.43KB
auth (index.js)3.19KB1.44KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.30KB1.02KB
auth (useWorkspaceAdminStatus.js)5.13KB2.35KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)506.01KB114.64KB
core (index.js)5.30KB2.13KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)173.10KB47.96KB
fields (index.js)238.89KB60.02KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (fallbackInterpolation.js)6.25KB2.77KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)26.89KB9.04KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)5.60KB2.33KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)9.53KB3.38KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)4.64KB1.50KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)1.93KB0.88KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.85KB12.89KB
plugin-charts (index.js)64.66KB18.32KB
plugin-chatbot (index.js)188.60KB44.82KB
plugin-dashboard (index.js)133.48KB34.49KB
plugin-designer (index.js)212.80KB43.15KB
plugin-detail (index.js)245.29KB62.39KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)131.78KB32.19KB
plugin-gantt (index.js)165.16KB40.33KB
plugin-grid (index.js)201.66KB54.58KB
plugin-kanban (index.js)53.11KB14.62KB
plugin-list (index.js)112.86KB27.54KB
plugin-map (index.js)20.09KB6.62KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.51KB11.94KB
plugin-timeline (index.js)26.72KB7.71KB
plugin-tree (index.js)9.26KB3.13KB
plugin-view (index.js)85.87KB21.12KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)4.47KB1.63KB
react (SchemaRenderer.js)65.97KB21.98KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)2.44KB1.21KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (dashboard-widget-options.js)3.08KB1.30KB
sdui-parser (index.js)4.93KB2.24KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)12.13KB3.65KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.28KB0.23KB
sdui-parser (validate.js)7.54KB2.63KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)2.74KB1.41KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)3.75KB1.85KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.85KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (icon-key-migration.js)4.26KB1.63KB
types (index.js)4.72KB2.24KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (spec-ui-namespace.js)0.20KB0.19KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)6.28KB2.87KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-sales
os-sales marked this pull request as ready for review August 27, 2026 13:18
@os-sales
os-sales added this pull request to the merge queueAug 27, 2026
Merged via the queue into main with commit bac7ba4Aug 27, 2026
30 checks passed
@os-sales
os-sales deleted the claude/issue-6595-retire-allowrestore-allowpurge-columns branch August 27, 2026 13:30
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

metadata-admin permission matrix still authors the retired allowRestore / allowPurge bits — spec now rejects them at publish

2 participants

@os-sales@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Retire the `allowRestore` / `allowPurge` columns from the metadata-admin permission matrix by os-sales · Pull Request #6607 · objectstack-ai/objectui · GitHub
Skip to content

Retire the allowRestore / allowPurge columns from the metadata-admin permission matrix - #6607

Merged
os-sales merged 2 commits into
mainfrom
claude/issue-6595-retire-allowrestore-allowpurge-columns
Aug 27, 2026
Merged

Retire the allowRestore / allowPurge columns from the metadata-admin permission matrix#6607
os-sales merged 2 commits into
mainfrom
claude/issue-6595-retire-allowrestore-allowpurge-columns

Conversation

@os-sales

Copy link
Copy Markdown
Collaborator

Fixes#6595

Drops the two retired object-permission bits from the metadata-admin permission matrix: the authoring columns, the typed fields, the preview rows, and the now-unreachable "Purge (hard delete) granted without Delete" lint. allowTransfer is enforced upstream (objectstack#3004) and is untouched — it stays a column, and every pin below asserts that in the same render so the removals cannot pass for the wrong reason.

Both removed keys gated restore / purge ObjectQL operations that have never existed: a dispatched restore/purge is denied unconditionally by the evaluator's fail-closed destructive-operation backstop. Every tick of those checkboxes wrote a grant no runtime has ever read. @objectstack/spec retired both as retiredKey() tombstones (objectstack#12497; maintainer ruling 2026-08-26 accepting objectstack#1883 recommendation B, ADR-0049 enforce-or-remove).

The return path is named at every site the removal touchedpermission-slice.ts, PermissionMatrixEditor.tsx, previews/PermissionPreview.tsx, and both new pins: the keys come back with the M2 lifecycle initiative, whose restart is recorded upstream on objectstack#1883.

The one thing measured on the day: the installed spec's posture

The card's premise splits into a part that is true either way and a part that depends on a bump that has not arrived. Measured 2026-08-27 against the installed @objectstack/spec17.2.0, by running real ObjectPermissionSchema.safeParse calls with a control key:

allowRestore ACCEPTED
allowPurge ACCEPTED
allowTransfer ACCEPTED
bogusKey REFUSED unrecognized_keys: ["definitelyNotAKey"]

The control is what makes this falsifiable: the schema IS strict and DOES refuse unknown keys, and it still accepts both retired keys. permission.zod-Bwl7_K0U.d.ts agrees at the type level (allowRestore: z.ZodDefault(z.ZodBoolean)).

So the bump has not reached this repo, and this PR does what that implies:

  • The removal lands — valid in both worlds, since the gated operations have never existed.
  • The "publish refuses it" pin is NOT taken. It belongs to the bump PR. Nothing here blocks on the bump, and no pin is bumped as a rider.
  • A stored legacy value is carried through, not stripped. It is no longer modelled and no longer authorable; it rides through save untouched, exactly as any key this editor does not model does. Stripping today would delete stored data the schema still honours. Once the bump lands and a carried value becomes a body the schema refuses, strip-on-load becomes correct — objectui#4644's resolution for indexed. The pin recording today's posture says so in its own header, so the bump PR replaces it deliberately rather than deleting a red.

The card's line references were stale, and its site list was incomplete

Line numbers were re-derived by name rather than trusted. The three constructs the card named were all real (at 180-181, 27-28, 59-60/86 — unchanged). But a fourth site reads these keys and the card did not list it:

packages/app-shell/src/views/metadata-admin/i18n.ts carries the two column tooltips in both locale tables — perm.action.restore / perm.action.purge in ENGINE_STRINGS_EN and ENGINE_STRINGS_ZH. Removing the columns without them would have left four dead keys in a pack whose EN/ZH halves must stay in step. Removed in both locales; the pack is the engine.* carve-out, so no pack gate reaches it either way.

Three prose sites were also carrying the removed columns as fact and are corrected: the editor's header comment (lifecycle (Transfer / Restore / Purge)), the column-legend note (Tr/Re/Pu/VA/MA), the fixed-column count (object + 9 CRUD + bulk, now 7 — the min-w floor is deliberately unchanged, so the grid simply has more room), and the preview's capability list plus its two legend lines.

Tests

Two new pin files, PermissionMatrixEditor.retiredLifecycleKeys.test.tsx and previews/PermissionPreview.retiredLifecycleKeys.test.tsx, following the shape PermissionAdvancedFacets.retiredKeys.test.tsx set for the RLS priority tombstone: pin the key SET, not the absence of two keys, because a set assertion is what stops a retired key drifting back in beside a live one. They cover the column set, the checkbox surface, what reaches the wire (the "Grant all" seed, whose key set is the real product of this change), the dropped lint measured on a draft that still trips the lints that stayed, and the carry-through of a stored legacy value.

Reverse verification — direction predicted before running: RED. Restoring the two columns, the two preview rows and the lint on top of the committed fix turns all 7 new pins red (Test Files 2 failed (2) · Tests 7 failed (7)); every one of them fails, so none was passing for an unrelated reason. Mutation confirmed on disk by anchored grep counts (short: 'Re'=1, long: 'Purge'=1, purge-lint=1) plus blob hashes differing from the HEAD blobs — not a bare diffstat. Restore leg proven the same way: git hash-object reproduces both HEAD blobs byte-for-byte and git diff HEAD is empty. No rebuild leg applies — both pins import their subject by relative source path (./PermissionMatrixEditor, ./PermissionPreview), so no dist/ sits in the resolution path.

Union re-run after the final commit, at 005a792:

checkresult
19 permission test files (whole surface, not just the new pins)Test Files 19 passed (19) · Tests 90 passed (90)
@object-ui/app-shell type-checkgreen — tsc --noEmit and tsc -p tsconfig.test.json
check-changeset-presence✅ 6 source file(s) of 1 released package(s) changed, and this change declares 1 changeset(s)
check:control-bytes✅ check-control-bytes: OK (scanned 5455 tracked text file(s); skipped 85 binary)
check:i18n-keysgreen — every in-scope call-site key resolves against the en pack
check:i18n-driftNo en value changed in this range
check:i18n-dead-keysreport-only gate, exit 0

The type-check claim is measured, not assumed: tsc -p tsconfig.test.json --listFiles lists both new test files, so the green covers them rather than excluding them.

Lint was narrowed deliberately, and here is why the narrowing loses nothing.eslint --no-inline-config --format json over the 6 changed files reports errorCount 0 (27 warnings, all pre-existing patterns; --max-warnings is deliberately unset repo-wide, per lint.yml's own note). The population is read from eslint's own resolution — it returned exactly 6 result objects, so all 6 are in scope and none was ignored. And the invariance holds by construction: eslint.config.js enables no type-aware linting (no project / projectService / parserOptions.project), so a file's verdict depends only on its own contents and the config — this diff cannot move the verdict on any file it does not touch. CI runs the repo-wide pnpm lint regardless.

Out-of-scope findings, filed rather than fixed here

  • objectui#6605 — the matrix's four bulk buttons (R / CRUD / All / None) replace the object row instead of merging, silently deleting allowExport, readScope and writeScope, which the local ObjectPerm does not model. The sharpest shape: clicking All can widen effective read access by deleting a readScope: own narrowing. Different defect class from this card (those keys are live and enforced), so it is not touched here.
  • objectui#6606 — the permission authoring shapes are absent from PAYLOAD_SHAPES in check-designer-field-key-parity.mjs, so the very class this card instantiates is invisible to that gate on the permission surface. This card arrived as a hand-written upstream referral, not from CI.

Neither is addressed in this PR; both remain open.

Fence

Every edit is inside packages/app-shell/src/views/metadata-admin/ plus one .changeset/ file. Nothing under studio-design/ was read for edit or touched — the sibling round's region is untouched.


Generated by Claude Code

…sion columns
Both keys gated `restore` / `purge` ObjectQL operations that have never
existed — a dispatched restore/purge is denied unconditionally by the
evaluator's fail-closed destructive-operation backstop — so the two matrix
checkboxes were dead-end authoring surface: every tick wrote a grant no
runtime has ever read. `@objectstack/spec` retired both keys as
`retiredKey()` tombstones (objectstack#12497; maintainer ruling 2026-08-26
accepting objectstack#1883 recommendation B, ADR-0049 enforce-or-remove).
Removed: the two authoring columns, the two typed fields, the two preview
rows, the now-unreachable "Purge (hard delete) granted without Delete" lint,
and the two column tooltips in both locale tables. `allowTransfer` is
enforced upstream and is untouched.
A value stored by an older editor is not modelled and not authorable; it
rides through save untouched, as any key this editor does not model does.
The installed spec (17.2.0) still ACCEPTS both keys at permission parse, so
stripping stored values today would delete data the schema still honours —
strip-on-load belongs with the bump that lands the retirement.
The return path is named in every tombstone: both keys come back with the M2
lifecycle initiative, whose restart is recorded on objectstack#1883.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CRJge11jso9TpXRWFt1Z49
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 52 chunks)3235.4 KB3266.6 KB
Main entry chunk (gzip)157.0 KB350 KB
Entry fileindex-CTzDHwYr.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (consoleActionDispatch.js)0.20KB0.19KB
app-shell (index.js)11.89KB4.50KB
app-shell (runtime-config.js)20.61KB7.35KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (ActiveOrganizationStorage.js)25.05KB9.16KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)2.07KB1.00KB
auth (AuthProvider.js)40.18KB10.59KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)8.46KB3.43KB
auth (index.js)3.19KB1.44KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.30KB1.02KB
auth (useWorkspaceAdminStatus.js)5.13KB2.35KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)506.01KB114.64KB
core (index.js)5.30KB2.13KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)173.10KB47.96KB
fields (index.js)238.89KB60.02KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (fallbackInterpolation.js)6.25KB2.77KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)26.89KB9.04KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)5.60KB2.33KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)9.53KB3.38KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)4.64KB1.50KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)1.93KB0.88KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.85KB12.89KB
plugin-charts (index.js)64.66KB18.32KB
plugin-chatbot (index.js)188.60KB44.82KB
plugin-dashboard (index.js)133.48KB34.49KB
plugin-designer (index.js)212.80KB43.15KB
plugin-detail (index.js)245.29KB62.39KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)131.78KB32.19KB
plugin-gantt (index.js)165.16KB40.33KB
plugin-grid (index.js)201.66KB54.58KB
plugin-kanban (index.js)53.11KB14.62KB
plugin-list (index.js)112.86KB27.54KB
plugin-map (index.js)20.09KB6.62KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.51KB11.94KB
plugin-timeline (index.js)26.72KB7.71KB
plugin-tree (index.js)9.26KB3.13KB
plugin-view (index.js)85.87KB21.12KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)4.47KB1.63KB
react (SchemaRenderer.js)65.97KB21.98KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)2.44KB1.21KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (dashboard-widget-options.js)3.08KB1.30KB
sdui-parser (index.js)4.93KB2.24KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)12.13KB3.65KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.28KB0.23KB
sdui-parser (validate.js)7.54KB2.63KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)2.74KB1.41KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)3.75KB1.85KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.85KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (icon-key-migration.js)4.26KB1.63KB
types (index.js)4.72KB2.24KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (spec-ui-namespace.js)0.20KB0.19KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)6.28KB2.87KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-sales
os-sales marked this pull request as ready for review August 27, 2026 13:18
@os-sales
os-sales added this pull request to the merge queueAug 27, 2026
Merged via the queue into main with commit bac7ba4Aug 27, 2026
30 checks passed
@os-sales
os-sales deleted the claude/issue-6595-retire-allowrestore-allowpurge-columns branch August 27, 2026 13:30
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

metadata-admin permission matrix still authors the retired allowRestore / allowPurge bits — spec now rejects them at publish

2 participants

@os-sales@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); Retire the `allowRestore` / `allowPurge` columns from the metadata-admin permission matrix by os-sales · Pull Request #6607 · objectstack-ai/objectui · GitHub
Skip to content

Retire the allowRestore / allowPurge columns from the metadata-admin permission matrix - #6607

Merged
os-sales merged 2 commits into
mainfrom
claude/issue-6595-retire-allowrestore-allowpurge-columns
Aug 27, 2026
Merged

Retire the allowRestore / allowPurge columns from the metadata-admin permission matrix#6607
os-sales merged 2 commits into
mainfrom
claude/issue-6595-retire-allowrestore-allowpurge-columns

Conversation

@os-sales

Copy link
Copy Markdown
Collaborator

Fixes#6595

Drops the two retired object-permission bits from the metadata-admin permission matrix: the authoring columns, the typed fields, the preview rows, and the now-unreachable "Purge (hard delete) granted without Delete" lint. allowTransfer is enforced upstream (objectstack#3004) and is untouched — it stays a column, and every pin below asserts that in the same render so the removals cannot pass for the wrong reason.

Both removed keys gated restore / purge ObjectQL operations that have never existed: a dispatched restore/purge is denied unconditionally by the evaluator's fail-closed destructive-operation backstop. Every tick of those checkboxes wrote a grant no runtime has ever read. @objectstack/spec retired both as retiredKey() tombstones (objectstack#12497; maintainer ruling 2026-08-26 accepting objectstack#1883 recommendation B, ADR-0049 enforce-or-remove).

The return path is named at every site the removal touchedpermission-slice.ts, PermissionMatrixEditor.tsx, previews/PermissionPreview.tsx, and both new pins: the keys come back with the M2 lifecycle initiative, whose restart is recorded upstream on objectstack#1883.

The one thing measured on the day: the installed spec's posture

The card's premise splits into a part that is true either way and a part that depends on a bump that has not arrived. Measured 2026-08-27 against the installed @objectstack/spec17.2.0, by running real ObjectPermissionSchema.safeParse calls with a control key:

allowRestore ACCEPTED
allowPurge ACCEPTED
allowTransfer ACCEPTED
bogusKey REFUSED unrecognized_keys: ["definitelyNotAKey"]

The control is what makes this falsifiable: the schema IS strict and DOES refuse unknown keys, and it still accepts both retired keys. permission.zod-Bwl7_K0U.d.ts agrees at the type level (allowRestore: z.ZodDefault(z.ZodBoolean)).

So the bump has not reached this repo, and this PR does what that implies:

  • The removal lands — valid in both worlds, since the gated operations have never existed.
  • The "publish refuses it" pin is NOT taken. It belongs to the bump PR. Nothing here blocks on the bump, and no pin is bumped as a rider.
  • A stored legacy value is carried through, not stripped. It is no longer modelled and no longer authorable; it rides through save untouched, exactly as any key this editor does not model does. Stripping today would delete stored data the schema still honours. Once the bump lands and a carried value becomes a body the schema refuses, strip-on-load becomes correct — objectui#4644's resolution for indexed. The pin recording today's posture says so in its own header, so the bump PR replaces it deliberately rather than deleting a red.

The card's line references were stale, and its site list was incomplete

Line numbers were re-derived by name rather than trusted. The three constructs the card named were all real (at 180-181, 27-28, 59-60/86 — unchanged). But a fourth site reads these keys and the card did not list it:

packages/app-shell/src/views/metadata-admin/i18n.ts carries the two column tooltips in both locale tables — perm.action.restore / perm.action.purge in ENGINE_STRINGS_EN and ENGINE_STRINGS_ZH. Removing the columns without them would have left four dead keys in a pack whose EN/ZH halves must stay in step. Removed in both locales; the pack is the engine.* carve-out, so no pack gate reaches it either way.

Three prose sites were also carrying the removed columns as fact and are corrected: the editor's header comment (lifecycle (Transfer / Restore / Purge)), the column-legend note (Tr/Re/Pu/VA/MA), the fixed-column count (object + 9 CRUD + bulk, now 7 — the min-w floor is deliberately unchanged, so the grid simply has more room), and the preview's capability list plus its two legend lines.

Tests

Two new pin files, PermissionMatrixEditor.retiredLifecycleKeys.test.tsx and previews/PermissionPreview.retiredLifecycleKeys.test.tsx, following the shape PermissionAdvancedFacets.retiredKeys.test.tsx set for the RLS priority tombstone: pin the key SET, not the absence of two keys, because a set assertion is what stops a retired key drifting back in beside a live one. They cover the column set, the checkbox surface, what reaches the wire (the "Grant all" seed, whose key set is the real product of this change), the dropped lint measured on a draft that still trips the lints that stayed, and the carry-through of a stored legacy value.

Reverse verification — direction predicted before running: RED. Restoring the two columns, the two preview rows and the lint on top of the committed fix turns all 7 new pins red (Test Files 2 failed (2) · Tests 7 failed (7)); every one of them fails, so none was passing for an unrelated reason. Mutation confirmed on disk by anchored grep counts (short: 'Re'=1, long: 'Purge'=1, purge-lint=1) plus blob hashes differing from the HEAD blobs — not a bare diffstat. Restore leg proven the same way: git hash-object reproduces both HEAD blobs byte-for-byte and git diff HEAD is empty. No rebuild leg applies — both pins import their subject by relative source path (./PermissionMatrixEditor, ./PermissionPreview), so no dist/ sits in the resolution path.

Union re-run after the final commit, at 005a792:

checkresult
19 permission test files (whole surface, not just the new pins)Test Files 19 passed (19) · Tests 90 passed (90)
@object-ui/app-shell type-checkgreen — tsc --noEmit and tsc -p tsconfig.test.json
check-changeset-presence✅ 6 source file(s) of 1 released package(s) changed, and this change declares 1 changeset(s)
check:control-bytes✅ check-control-bytes: OK (scanned 5455 tracked text file(s); skipped 85 binary)
check:i18n-keysgreen — every in-scope call-site key resolves against the en pack
check:i18n-driftNo en value changed in this range
check:i18n-dead-keysreport-only gate, exit 0

The type-check claim is measured, not assumed: tsc -p tsconfig.test.json --listFiles lists both new test files, so the green covers them rather than excluding them.

Lint was narrowed deliberately, and here is why the narrowing loses nothing.eslint --no-inline-config --format json over the 6 changed files reports errorCount 0 (27 warnings, all pre-existing patterns; --max-warnings is deliberately unset repo-wide, per lint.yml's own note). The population is read from eslint's own resolution — it returned exactly 6 result objects, so all 6 are in scope and none was ignored. And the invariance holds by construction: eslint.config.js enables no type-aware linting (no project / projectService / parserOptions.project), so a file's verdict depends only on its own contents and the config — this diff cannot move the verdict on any file it does not touch. CI runs the repo-wide pnpm lint regardless.

Out-of-scope findings, filed rather than fixed here

  • objectui#6605 — the matrix's four bulk buttons (R / CRUD / All / None) replace the object row instead of merging, silently deleting allowExport, readScope and writeScope, which the local ObjectPerm does not model. The sharpest shape: clicking All can widen effective read access by deleting a readScope: own narrowing. Different defect class from this card (those keys are live and enforced), so it is not touched here.
  • objectui#6606 — the permission authoring shapes are absent from PAYLOAD_SHAPES in check-designer-field-key-parity.mjs, so the very class this card instantiates is invisible to that gate on the permission surface. This card arrived as a hand-written upstream referral, not from CI.

Neither is addressed in this PR; both remain open.

Fence

Every edit is inside packages/app-shell/src/views/metadata-admin/ plus one .changeset/ file. Nothing under studio-design/ was read for edit or touched — the sibling round's region is untouched.


Generated by Claude Code

…sion columns
Both keys gated `restore` / `purge` ObjectQL operations that have never
existed — a dispatched restore/purge is denied unconditionally by the
evaluator's fail-closed destructive-operation backstop — so the two matrix
checkboxes were dead-end authoring surface: every tick wrote a grant no
runtime has ever read. `@objectstack/spec` retired both keys as
`retiredKey()` tombstones (objectstack#12497; maintainer ruling 2026-08-26
accepting objectstack#1883 recommendation B, ADR-0049 enforce-or-remove).
Removed: the two authoring columns, the two typed fields, the two preview
rows, the now-unreachable "Purge (hard delete) granted without Delete" lint,
and the two column tooltips in both locale tables. `allowTransfer` is
enforced upstream and is untouched.
A value stored by an older editor is not modelled and not authorable; it
rides through save untouched, as any key this editor does not model does.
The installed spec (17.2.0) still ACCEPTS both keys at permission parse, so
stripping stored values today would delete data the schema still honours —
strip-on-load belongs with the bump that lands the retirement.
The return path is named in every tombstone: both keys come back with the M2
lifecycle initiative, whose restart is recorded on objectstack#1883.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CRJge11jso9TpXRWFt1Z49
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 52 chunks)3235.4 KB3266.6 KB
Main entry chunk (gzip)157.0 KB350 KB
Entry fileindex-CTzDHwYr.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (consoleActionDispatch.js)0.20KB0.19KB
app-shell (index.js)11.89KB4.50KB
app-shell (runtime-config.js)20.61KB7.35KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (ActiveOrganizationStorage.js)25.05KB9.16KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)2.07KB1.00KB
auth (AuthProvider.js)40.18KB10.59KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)8.46KB3.43KB
auth (index.js)3.19KB1.44KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.30KB1.02KB
auth (useWorkspaceAdminStatus.js)5.13KB2.35KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)506.01KB114.64KB
core (index.js)5.30KB2.13KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)173.10KB47.96KB
fields (index.js)238.89KB60.02KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (fallbackInterpolation.js)6.25KB2.77KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)26.89KB9.04KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)5.60KB2.33KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)9.53KB3.38KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)4.64KB1.50KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)1.93KB0.88KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.85KB12.89KB
plugin-charts (index.js)64.66KB18.32KB
plugin-chatbot (index.js)188.60KB44.82KB
plugin-dashboard (index.js)133.48KB34.49KB
plugin-designer (index.js)212.80KB43.15KB
plugin-detail (index.js)245.29KB62.39KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)131.78KB32.19KB
plugin-gantt (index.js)165.16KB40.33KB
plugin-grid (index.js)201.66KB54.58KB
plugin-kanban (index.js)53.11KB14.62KB
plugin-list (index.js)112.86KB27.54KB
plugin-map (index.js)20.09KB6.62KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.51KB11.94KB
plugin-timeline (index.js)26.72KB7.71KB
plugin-tree (index.js)9.26KB3.13KB
plugin-view (index.js)85.87KB21.12KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)4.47KB1.63KB
react (SchemaRenderer.js)65.97KB21.98KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)2.44KB1.21KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (dashboard-widget-options.js)3.08KB1.30KB
sdui-parser (index.js)4.93KB2.24KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)12.13KB3.65KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.28KB0.23KB
sdui-parser (validate.js)7.54KB2.63KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)2.74KB1.41KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)3.75KB1.85KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.85KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (icon-key-migration.js)4.26KB1.63KB
types (index.js)4.72KB2.24KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (spec-ui-namespace.js)0.20KB0.19KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)6.28KB2.87KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-sales
os-sales marked this pull request as ready for review August 27, 2026 13:18
@os-sales
os-sales added this pull request to the merge queueAug 27, 2026
Merged via the queue into main with commit bac7ba4Aug 27, 2026
30 checks passed
@os-sales
os-sales deleted the claude/issue-6595-retire-allowrestore-allowpurge-columns branch August 27, 2026 13:30
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

metadata-admin permission matrix still authors the retired allowRestore / allowPurge bits — spec now rejects them at publish

2 participants

@os-sales@claude