Skip to content

fix(app-shell): diagnose in with a path on the right in metadata-admin predicates - #6652

Merged
os-sales merged 1 commit into
mainfrom
claude/issue-6617-in-path-right-diagnostic
Aug 28, 2026
Merged

fix(app-shell): diagnose in with a path on the right in metadata-admin predicates#6652
os-sales merged 1 commit into
mainfrom
claude/issue-6617-in-path-right-diagnostic

Conversation

@os-sales

Copy link
Copy Markdown
Collaborator

Fixes#6617

Direction 1 (diagnose only), as graded by triage. Zero verdict change — no expression that evaluates today reaches a different answer, and that is measured below rather than asserted.

The gap

evalExpr's in branch matches /^(.+?)\s+in\s+(\[.*\])$/: the right side must be a bracketed literal set. A membership test whose right side is a path therefore never reaches that branch. Carrying no == / != either, it falls all the way to the bare-truthy tail, where the whole text is handed to resolveValue as one operand:

predicaterouteverdict
'admin' in current_user.positionsquote-leading, so resolveValue's literal shortcut hands it to parseLiteral; the quoted-string branch declines it (starts with a quote, does not end with one) and the tail returns it verbatimTRUE for every user, whatever positions holds
data.roles in current_user.positionspath-shaped, so resolveValue splits on dots into data / roles in current_user / positions and walks off the draft at segment twoFALSE for every row

The first is ADR-0068's own headline example and the spelling SelectOptionSchema's docblock names as the canonical use of the key, and its failure direction is permissive: an option, field or section gated to admins renders for everyone.

Both were silent. objectstack#6936's warning hangs on resolveValue's path branch, which quote-leading text never enters; objectui#4049's PATH_SHAPED_LITERAL only matches text starting with an identifier character.

Premise re-verified on the current ref, not inherited

The feasibility note was measured on origin/main @ bac7ba43. I re-measured all of it on 9101be57 (this branch's base) with a throwaway probe before writing a line — 20 rows, direction predicted before each run, 20/20 confirmed, probe then deleted.

The PM's correction on PR #6618 holds, and I measured it directly. These four rows are identical — TRUE, zero warnings — in all four worlds:

'admin' in current_user.positions with…verdictwarnings
current_user.positions = ['admin']TRUE0
current_user.positions = ['viewer']TRUE0
current_user.positions = []TRUE0
current_usernot bound at allTRUE0

The root is never resolved, so binding or not binding current_user cannot change the outcome and PATH_SHAPED_LITERAL never fired for it either. This gap is not a regression from #6247; it is a property of the operator's grammar, not of which names the scope declares.

The change

The hook sits at the bare-truthy tail, after the in branch has already declined the text, and asks one question: does the text nonetheless carry a top-level in? The entire executable footprint is:

  • a fourth warn-once Set (+ its line in resetPredicateWarnings),
  • const IN_OPERATOR = ' in ',
  • a pure carriesTopLevelIn(expr),
  • a void warn function guarded by isDev() and the memo,
  • one statement in evalExpr: if (carriesTopLevelIn(expr)) warnInWithoutLiteralSet(expr, source);

Nothing new is resolved. No operand handling is added. git diff shows exactly one removed line in predicate.ts — the comment // Bare truthy check, replaced by a longer one — and no existing executable line changed. That is triage's distinguishing test for direction 2 answered structurally: the evaluator is not taught to resolve anything.

The trap: the detection is quote-aware by REUSE

A naive expr.includes(' in ') is wrong. 'plug in adapter' is a bare quoted literal — correct code, a truthy string — and accusing it would be a false statement about the author's code, the precise failure this file's diagnostics exist to prevent.

carriesTopLevelIn is splitTopLevel(expr, IN_OPERATOR).length > 1 — the file's existinginStr/depth walk, the same one the && / || splitters and findUnparseableSetElement already run. Inside a quoted run it never even tests the operator. No second scanner, which is also what keeps this a detection rather than a parser.

Why there is no other false positive: an expression reaching the bare-truthy tail that is correct is either a path (which cannot contain a space) or a literal — and the only literal that can contain ' in ' is a quoted string, which the inStr walk protects.

Two spellings are deliberately not detected and fail to silence (the status quo), never to a false claim: a tab-separated in, and one nested at depth > 0 inside parentheses. Both are pinned as silent.

The message

Names the offending text and the predicate that carried it, names the supported subset path in ['a','b'], names the fail-open direction, and states plainly that a path on the right of in cannot be written on this surface today — "not with different punctuation, not with a different spelling, not at all" — rather than implying some other spelling would work. The author's next question is "then how do I write it?", and the honest answer here is "you cannot".

No overlap with #4266, and neither can mask the other

Mutually exclusive by construction: #4266 fires from parseLiteral's array branch, reachable only for text that already matched an operator branch; this one fires at the bare-truthy tail, reachable only when every operator branch declined. Pinned four ways in §9.6 — a #4266 predicate fires #4266 only, a #4049 predicate fires #4049 only, a #6617 predicate fires #6617 only, and one predicate carrying two gaps reports both.

⚠️ Those assertions key on a phrase unique to each message, not on the bare card number: #6617's own text cites objectui#4049 as the rule that paths resolve only on the left of an operator, so toContain('objectui#4049') is true of #6617's message too. Written the naive way the exclusivity test passed for the wrong reason in one direction and failed spuriously in the other — it did, on first run, and that is why the constants exist.

Verification — union run at ac5a59c2

Every result below was produced at the final commit; each exit code was captured before any pipe, and each line quotes the gate's own verdict.

Suites — repo root, all vitest projects (the package-scoped form is a known false-green here). --project unit alone silently ran only 1 of the 3 files, since the two SchemaForm suites are .tsx and live in another project; re-run without it:

npx vitest run packages/app-shell/src/views/metadata-admin/predicate.test.ts \
packages/app-shell/src/views/metadata-admin/SchemaForm.optionVisibleWhen.test.tsx \
packages/app-shell/src/views/metadata-admin/SchemaForm.unresolvedPredicate.test.tsx
Test Files 3 passed (3)
Tests 165 passed (165)

That is the full blast radius: ./predicate has exactly three importers in the repo. The 94 pre-existing predicate.test.ts tests and both SchemaForm suites pass untouched — the test file diff is 306 insertions, 0 deletions.

Gates (each printed its own verdict line):

gateexitverdict
@object-ui/app-shelltype-check0> tsc --noEmit && tsc -p tsconfig.test.json
dependency-closure build (29 pkgs)0built before type-check, so no stale dist/*.d.ts
check:changeset-presence0✅ 2 source file(s) of 1 released package(s) changed, and this change declares 1 changeset(s)
check:changeset-no-major0✅ No changeset declares a major bump.
check:changeset-fixed0✅ All workspace packages are in the changeset fixed group.
check:changeset-overwrite0✅ No pre-existing changeset was modified or deleted.
check:control-bytes0✅ OK (scanned 5496 tracked text file(s))
check:vi-mock-specifiers0✅ OK
check:i18n-keys0
check:self-import0✅ No package names itself inside its own src/.
check:shell-escape-residue0✅ OK

The changeset gate ruled the bump: packages/app-shell/src/** is guarded, so a declaration is required, and it is an honest patch on @object-ui/app-shell. No gate refused anything.

type-check actually covers the edited test file — not assumed: tsc -p tsconfig.test.json --listFiles reports predicate.test.ts1 occurrence and predicate.ts1. (A package typecheck that excludes **/*.test.ts would have been a true statement about nothing.)

Lint — a declared narrowing, with its three measurements. Repo-wide pnpm lint stays CI's run. Locally: eslint's own file selection for packages/app-shell/src/views/metadata-admin/ chose 380 files, count read from --format json, 0 errors; the two changed files show 0 errors and 1 pre-existing no-explicit-any warning at predicate.ts:680 (let cur: any = ctx in resolveValue, untouched by this diff — confirmed absent from git diff). Invariance: this config enables no type-aware linting (no projectService, no project:, no typeChecked), so each file's verdict is a pure function of its own source plus the shared config — neither of which this diff changes for any file it does not contain.

Proving zero-verdict-change instead of asserting it

In words. The single new statement is a void call placed on a path that already existed. It reads nothing from ctx, writes only its own memo Set, returns nothing, and splitTopLevel cannot throw on a string — so it cannot reach the catch in evaluatePredicate that would flip a verdict to fail-open. No operator branch was touched, no operand handling was added, resolveValue and parseLiteral are byte-identical. There is no channel by which an evaluated expression could reach a different answer.

Measured — ablation B. Removing the diagnostic call entirely (mutation proved on disk by grep counts on both the injected and the removed text; restored via git checkout HEAD -- PATH with an absolute PATH, and proved by git hash-object equalling the HEAD blob 22f014afandgit diff HEAD empty):

Tests 15 failed | 130 passed (145)
--- did ANY §9.3 verdict row fail? ---
none — every verdict row still passes with the diagnostic removed

15 diagnostic tests go red and zero verdict rows do. The §9.3 table is genuinely independent of the diagnostic. Together with the pre-change probe on 9101be57 (20/20 verdicts confirmed before the change), the verdicts are pinned identical on both sides of it.

Measured — ablation A, that the quote-aware reuse is load-bearing. Swapping splitTopLevel(...) for the naive expr.includes(IN_OPERATOR):

Tests 6 failed | 139 passed (145)
× a bare single-quoted literal containing the word does NOT warn — correct code is never accused
× the same, double-quoted does NOT warn — correct code is never accused
× a literal whose text is only the word does NOT warn — correct code is never accused
× a quoted literal carrying an apostrophe-free inner quote does NOT warn — correct code is never accused
× the negation of a quoted literal containing the word is silent too
× a parenthesised membership sits at depth > 0 and is not detected — silent, as before

Exactly the quote- and depth-protected controls, and nothing else. The trap pin discriminates: it would catch the naive implementation.

The both-directions pin

  • Warns:'admin' in current_user.positions (bound, unbound, empty and populated), 'x' in data.tags, data.roles in current_user.positions, inside ||, and with extra spaces around in.
  • Does NOT warn:'plug in adapter', "plug in adapter", ' in ', data.label == 'plug in adapter', data.label in ['plug in adapter','x'], "it in that", !'plug in adapter', and every supported literal-set form.

Warn-once memo keying is (sub-expression, predicate source) — the same ${text}::${source} scheme as the three existing sets, for the stated reason: keyed on the text alone, a form with fifteen gates spelling the same membership test would report one and hide the rest. No fourth scheme invented.

Out of scope, deliberately

Direction 3 (producer-side publish-time validation of predicate expressions) belongs to the objectstack#7010 family — another repo, another lane. No card opened from this surface, per the dispatch order; a note on whether it wants one is in my report.


Generated by Claude Code

…min predicates
The predicate evaluator matches membership as `path in ['a','b']` — the right
side must be a bracketed literal set. A membership test whose right side is a
PATH never matched that branch, carried no `==`/`!=` either, and fell to the
bare-truthy tail where the WHOLE text was evaluated as one operand.
`'admin' in current_user.positions` — ADR-0068's own headline example and the
spelling `SelectOptionSchema`'s docblock names as the canonical use of the key —
leads with a quote, so `parseLiteral`'s tail handed it back verbatim as a
non-empty string: TRUE for every user, whatever `positions` held. Fail-OPEN, so
a gate meant for admins rendered for everyone. `data.roles in
current_user.positions` walked off the draft mid-path and read FALSE for every
row instead. Both were silent: objectstack#6936's warning hangs on
`resolveValue`'s path branch, which quote-leading text never enters, and
objectui#4049's `PATH_SHAPED_LITERAL` only matches text starting with an
identifier character.
Diagnose only, zero semantic change — the third time this file takes the posture
#4049 and #4266 took. The hook sits at the bare-truthy tail, AFTER the `in`
branch has declined the text, and asks one question: does the text nonetheless
carry a top-level `in`? Nothing new is resolved and no operand handling is added.
The whole executable footprint is a fourth warn-once Set, a pure `carriesTopLevelIn`
predicate, a void warn function, and one `if` in `evalExpr`.
The detection reuses `splitTopLevel`'s existing quote-aware `inStr` walk rather
than a second scanner, so a predicate that is itself a quoted literal containing
the word (`'plug in adapter'` — correct code, a truthy string) is never accused;
a naive `includes(' in ')` would report it as broken, which is a worse defect
than the bug. Both directions pinned.
The message names the spelling, names the supported subset, and states plainly
that a path on the right of `in` cannot be written on this surface today, rather
than implying some other punctuation would work.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CRJge11jso9TpXRWFt1Z49
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 52 chunks)3237.8 KB3266.6 KB
Main entry chunk (gzip)157.3 KB350 KB
Entry fileindex-D2ACdgk0.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (consoleActionDispatch.js)0.20KB0.19KB
app-shell (index.js)11.89KB4.50KB
app-shell (runtime-config.js)20.61KB7.35KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (ActiveOrganizationStorage.js)25.05KB9.16KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)2.07KB1.00KB
auth (AuthProvider.js)40.18KB10.59KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)8.46KB3.43KB
auth (index.js)3.19KB1.44KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.30KB1.02KB
auth (useWorkspaceAdminStatus.js)5.13KB2.35KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)507.87KB115.07KB
core (index.js)5.30KB2.13KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)173.10KB47.96KB
fields (index.js)238.89KB60.02KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (fallbackInterpolation.js)6.25KB2.77KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)26.89KB9.04KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)5.60KB2.33KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)9.53KB3.38KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)4.64KB1.50KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)1.93KB0.88KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.85KB12.89KB
plugin-charts (index.js)64.66KB18.32KB
plugin-chatbot (index.js)190.33KB45.10KB
plugin-dashboard (index.js)133.41KB34.47KB
plugin-designer (index.js)212.80KB43.15KB
plugin-detail (index.js)245.29KB62.39KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)132.01KB32.23KB
plugin-gantt (index.js)165.16KB40.33KB
plugin-grid (index.js)201.66KB54.57KB
plugin-kanban (index.js)53.11KB14.62KB
plugin-list (index.js)112.86KB27.54KB
plugin-map (index.js)20.09KB6.62KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.51KB11.94KB
plugin-timeline (index.js)26.72KB7.71KB
plugin-tree (index.js)9.26KB3.13KB
plugin-view (index.js)85.87KB21.12KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)4.47KB1.63KB
react (SchemaRenderer.js)65.97KB21.98KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)2.44KB1.21KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (dashboard-widget-options.js)3.08KB1.30KB
sdui-parser (index.js)4.93KB2.24KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)12.13KB3.65KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.28KB0.23KB
sdui-parser (validate.js)9.30KB3.22KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)2.74KB1.41KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)3.75KB1.85KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.85KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (icon-key-migration.js)4.26KB1.63KB
types (index.js)4.72KB2.24KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (spec-ui-namespace.js)0.20KB0.19KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)6.28KB2.87KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-sales
os-sales marked this pull request as ready for review August 28, 2026 09:28
@os-sales
os-sales added this pull request to the merge queueAug 28, 2026
Merged via the queue into main with commit 813bf83Aug 28, 2026
30 checks passed
@os-sales
os-sales deleted the claude/issue-6617-in-path-right-diagnostic branch August 28, 2026 09:41
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

2 participants

@os-sales@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
fix(app-shell): diagnose `in` with a path on the right in metadata-admin predicates by os-sales · Pull Request #6652 · objectstack-ai/objectui · GitHub
Skip to content

fix(app-shell): diagnose in with a path on the right in metadata-admin predicates - #6652

Merged
os-sales merged 1 commit into
mainfrom
claude/issue-6617-in-path-right-diagnostic
Aug 28, 2026
Merged

fix(app-shell): diagnose in with a path on the right in metadata-admin predicates#6652
os-sales merged 1 commit into
mainfrom
claude/issue-6617-in-path-right-diagnostic

Conversation

@os-sales

Copy link
Copy Markdown
Collaborator

Fixes#6617

Direction 1 (diagnose only), as graded by triage. Zero verdict change — no expression that evaluates today reaches a different answer, and that is measured below rather than asserted.

The gap

evalExpr's in branch matches /^(.+?)\s+in\s+(\[.*\])$/: the right side must be a bracketed literal set. A membership test whose right side is a path therefore never reaches that branch. Carrying no == / != either, it falls all the way to the bare-truthy tail, where the whole text is handed to resolveValue as one operand:

predicaterouteverdict
'admin' in current_user.positionsquote-leading, so resolveValue's literal shortcut hands it to parseLiteral; the quoted-string branch declines it (starts with a quote, does not end with one) and the tail returns it verbatimTRUE for every user, whatever positions holds
data.roles in current_user.positionspath-shaped, so resolveValue splits on dots into data / roles in current_user / positions and walks off the draft at segment twoFALSE for every row

The first is ADR-0068's own headline example and the spelling SelectOptionSchema's docblock names as the canonical use of the key, and its failure direction is permissive: an option, field or section gated to admins renders for everyone.

Both were silent. objectstack#6936's warning hangs on resolveValue's path branch, which quote-leading text never enters; objectui#4049's PATH_SHAPED_LITERAL only matches text starting with an identifier character.

Premise re-verified on the current ref, not inherited

The feasibility note was measured on origin/main @ bac7ba43. I re-measured all of it on 9101be57 (this branch's base) with a throwaway probe before writing a line — 20 rows, direction predicted before each run, 20/20 confirmed, probe then deleted.

The PM's correction on PR #6618 holds, and I measured it directly. These four rows are identical — TRUE, zero warnings — in all four worlds:

'admin' in current_user.positions with…verdictwarnings
current_user.positions = ['admin']TRUE0
current_user.positions = ['viewer']TRUE0
current_user.positions = []TRUE0
current_usernot bound at allTRUE0

The root is never resolved, so binding or not binding current_user cannot change the outcome and PATH_SHAPED_LITERAL never fired for it either. This gap is not a regression from #6247; it is a property of the operator's grammar, not of which names the scope declares.

The change

The hook sits at the bare-truthy tail, after the in branch has already declined the text, and asks one question: does the text nonetheless carry a top-level in? The entire executable footprint is:

  • a fourth warn-once Set (+ its line in resetPredicateWarnings),
  • const IN_OPERATOR = ' in ',
  • a pure carriesTopLevelIn(expr),
  • a void warn function guarded by isDev() and the memo,
  • one statement in evalExpr: if (carriesTopLevelIn(expr)) warnInWithoutLiteralSet(expr, source);

Nothing new is resolved. No operand handling is added. git diff shows exactly one removed line in predicate.ts — the comment // Bare truthy check, replaced by a longer one — and no existing executable line changed. That is triage's distinguishing test for direction 2 answered structurally: the evaluator is not taught to resolve anything.

The trap: the detection is quote-aware by REUSE

A naive expr.includes(' in ') is wrong. 'plug in adapter' is a bare quoted literal — correct code, a truthy string — and accusing it would be a false statement about the author's code, the precise failure this file's diagnostics exist to prevent.

carriesTopLevelIn is splitTopLevel(expr, IN_OPERATOR).length > 1 — the file's existinginStr/depth walk, the same one the && / || splitters and findUnparseableSetElement already run. Inside a quoted run it never even tests the operator. No second scanner, which is also what keeps this a detection rather than a parser.

Why there is no other false positive: an expression reaching the bare-truthy tail that is correct is either a path (which cannot contain a space) or a literal — and the only literal that can contain ' in ' is a quoted string, which the inStr walk protects.

Two spellings are deliberately not detected and fail to silence (the status quo), never to a false claim: a tab-separated in, and one nested at depth > 0 inside parentheses. Both are pinned as silent.

The message

Names the offending text and the predicate that carried it, names the supported subset path in ['a','b'], names the fail-open direction, and states plainly that a path on the right of in cannot be written on this surface today — "not with different punctuation, not with a different spelling, not at all" — rather than implying some other spelling would work. The author's next question is "then how do I write it?", and the honest answer here is "you cannot".

No overlap with #4266, and neither can mask the other

Mutually exclusive by construction: #4266 fires from parseLiteral's array branch, reachable only for text that already matched an operator branch; this one fires at the bare-truthy tail, reachable only when every operator branch declined. Pinned four ways in §9.6 — a #4266 predicate fires #4266 only, a #4049 predicate fires #4049 only, a #6617 predicate fires #6617 only, and one predicate carrying two gaps reports both.

⚠️ Those assertions key on a phrase unique to each message, not on the bare card number: #6617's own text cites objectui#4049 as the rule that paths resolve only on the left of an operator, so toContain('objectui#4049') is true of #6617's message too. Written the naive way the exclusivity test passed for the wrong reason in one direction and failed spuriously in the other — it did, on first run, and that is why the constants exist.

Verification — union run at ac5a59c2

Every result below was produced at the final commit; each exit code was captured before any pipe, and each line quotes the gate's own verdict.

Suites — repo root, all vitest projects (the package-scoped form is a known false-green here). --project unit alone silently ran only 1 of the 3 files, since the two SchemaForm suites are .tsx and live in another project; re-run without it:

npx vitest run packages/app-shell/src/views/metadata-admin/predicate.test.ts \
packages/app-shell/src/views/metadata-admin/SchemaForm.optionVisibleWhen.test.tsx \
packages/app-shell/src/views/metadata-admin/SchemaForm.unresolvedPredicate.test.tsx
Test Files 3 passed (3)
Tests 165 passed (165)

That is the full blast radius: ./predicate has exactly three importers in the repo. The 94 pre-existing predicate.test.ts tests and both SchemaForm suites pass untouched — the test file diff is 306 insertions, 0 deletions.

Gates (each printed its own verdict line):

gateexitverdict
@object-ui/app-shelltype-check0> tsc --noEmit && tsc -p tsconfig.test.json
dependency-closure build (29 pkgs)0built before type-check, so no stale dist/*.d.ts
check:changeset-presence0✅ 2 source file(s) of 1 released package(s) changed, and this change declares 1 changeset(s)
check:changeset-no-major0✅ No changeset declares a major bump.
check:changeset-fixed0✅ All workspace packages are in the changeset fixed group.
check:changeset-overwrite0✅ No pre-existing changeset was modified or deleted.
check:control-bytes0✅ OK (scanned 5496 tracked text file(s))
check:vi-mock-specifiers0✅ OK
check:i18n-keys0
check:self-import0✅ No package names itself inside its own src/.
check:shell-escape-residue0✅ OK

The changeset gate ruled the bump: packages/app-shell/src/** is guarded, so a declaration is required, and it is an honest patch on @object-ui/app-shell. No gate refused anything.

type-check actually covers the edited test file — not assumed: tsc -p tsconfig.test.json --listFiles reports predicate.test.ts1 occurrence and predicate.ts1. (A package typecheck that excludes **/*.test.ts would have been a true statement about nothing.)

Lint — a declared narrowing, with its three measurements. Repo-wide pnpm lint stays CI's run. Locally: eslint's own file selection for packages/app-shell/src/views/metadata-admin/ chose 380 files, count read from --format json, 0 errors; the two changed files show 0 errors and 1 pre-existing no-explicit-any warning at predicate.ts:680 (let cur: any = ctx in resolveValue, untouched by this diff — confirmed absent from git diff). Invariance: this config enables no type-aware linting (no projectService, no project:, no typeChecked), so each file's verdict is a pure function of its own source plus the shared config — neither of which this diff changes for any file it does not contain.

Proving zero-verdict-change instead of asserting it

In words. The single new statement is a void call placed on a path that already existed. It reads nothing from ctx, writes only its own memo Set, returns nothing, and splitTopLevel cannot throw on a string — so it cannot reach the catch in evaluatePredicate that would flip a verdict to fail-open. No operator branch was touched, no operand handling was added, resolveValue and parseLiteral are byte-identical. There is no channel by which an evaluated expression could reach a different answer.

Measured — ablation B. Removing the diagnostic call entirely (mutation proved on disk by grep counts on both the injected and the removed text; restored via git checkout HEAD -- PATH with an absolute PATH, and proved by git hash-object equalling the HEAD blob 22f014afandgit diff HEAD empty):

Tests 15 failed | 130 passed (145)
--- did ANY §9.3 verdict row fail? ---
none — every verdict row still passes with the diagnostic removed

15 diagnostic tests go red and zero verdict rows do. The §9.3 table is genuinely independent of the diagnostic. Together with the pre-change probe on 9101be57 (20/20 verdicts confirmed before the change), the verdicts are pinned identical on both sides of it.

Measured — ablation A, that the quote-aware reuse is load-bearing. Swapping splitTopLevel(...) for the naive expr.includes(IN_OPERATOR):

Tests 6 failed | 139 passed (145)
× a bare single-quoted literal containing the word does NOT warn — correct code is never accused
× the same, double-quoted does NOT warn — correct code is never accused
× a literal whose text is only the word does NOT warn — correct code is never accused
× a quoted literal carrying an apostrophe-free inner quote does NOT warn — correct code is never accused
× the negation of a quoted literal containing the word is silent too
× a parenthesised membership sits at depth > 0 and is not detected — silent, as before

Exactly the quote- and depth-protected controls, and nothing else. The trap pin discriminates: it would catch the naive implementation.

The both-directions pin

  • Warns:'admin' in current_user.positions (bound, unbound, empty and populated), 'x' in data.tags, data.roles in current_user.positions, inside ||, and with extra spaces around in.
  • Does NOT warn:'plug in adapter', "plug in adapter", ' in ', data.label == 'plug in adapter', data.label in ['plug in adapter','x'], "it in that", !'plug in adapter', and every supported literal-set form.

Warn-once memo keying is (sub-expression, predicate source) — the same ${text}::${source} scheme as the three existing sets, for the stated reason: keyed on the text alone, a form with fifteen gates spelling the same membership test would report one and hide the rest. No fourth scheme invented.

Out of scope, deliberately

Direction 3 (producer-side publish-time validation of predicate expressions) belongs to the objectstack#7010 family — another repo, another lane. No card opened from this surface, per the dispatch order; a note on whether it wants one is in my report.


Generated by Claude Code

…min predicates
The predicate evaluator matches membership as `path in ['a','b']` — the right
side must be a bracketed literal set. A membership test whose right side is a
PATH never matched that branch, carried no `==`/`!=` either, and fell to the
bare-truthy tail where the WHOLE text was evaluated as one operand.
`'admin' in current_user.positions` — ADR-0068's own headline example and the
spelling `SelectOptionSchema`'s docblock names as the canonical use of the key —
leads with a quote, so `parseLiteral`'s tail handed it back verbatim as a
non-empty string: TRUE for every user, whatever `positions` held. Fail-OPEN, so
a gate meant for admins rendered for everyone. `data.roles in
current_user.positions` walked off the draft mid-path and read FALSE for every
row instead. Both were silent: objectstack#6936's warning hangs on
`resolveValue`'s path branch, which quote-leading text never enters, and
objectui#4049's `PATH_SHAPED_LITERAL` only matches text starting with an
identifier character.
Diagnose only, zero semantic change — the third time this file takes the posture
#4049 and #4266 took. The hook sits at the bare-truthy tail, AFTER the `in`
branch has declined the text, and asks one question: does the text nonetheless
carry a top-level `in`? Nothing new is resolved and no operand handling is added.
The whole executable footprint is a fourth warn-once Set, a pure `carriesTopLevelIn`
predicate, a void warn function, and one `if` in `evalExpr`.
The detection reuses `splitTopLevel`'s existing quote-aware `inStr` walk rather
than a second scanner, so a predicate that is itself a quoted literal containing
the word (`'plug in adapter'` — correct code, a truthy string) is never accused;
a naive `includes(' in ')` would report it as broken, which is a worse defect
than the bug. Both directions pinned.
The message names the spelling, names the supported subset, and states plainly
that a path on the right of `in` cannot be written on this surface today, rather
than implying some other punctuation would work.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CRJge11jso9TpXRWFt1Z49
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 52 chunks)3237.8 KB3266.6 KB
Main entry chunk (gzip)157.3 KB350 KB
Entry fileindex-D2ACdgk0.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (consoleActionDispatch.js)0.20KB0.19KB
app-shell (index.js)11.89KB4.50KB
app-shell (runtime-config.js)20.61KB7.35KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (ActiveOrganizationStorage.js)25.05KB9.16KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)2.07KB1.00KB
auth (AuthProvider.js)40.18KB10.59KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)8.46KB3.43KB
auth (index.js)3.19KB1.44KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.30KB1.02KB
auth (useWorkspaceAdminStatus.js)5.13KB2.35KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)507.87KB115.07KB
core (index.js)5.30KB2.13KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)173.10KB47.96KB
fields (index.js)238.89KB60.02KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (fallbackInterpolation.js)6.25KB2.77KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)26.89KB9.04KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)5.60KB2.33KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)9.53KB3.38KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)4.64KB1.50KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)1.93KB0.88KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.85KB12.89KB
plugin-charts (index.js)64.66KB18.32KB
plugin-chatbot (index.js)190.33KB45.10KB
plugin-dashboard (index.js)133.41KB34.47KB
plugin-designer (index.js)212.80KB43.15KB
plugin-detail (index.js)245.29KB62.39KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)132.01KB32.23KB
plugin-gantt (index.js)165.16KB40.33KB
plugin-grid (index.js)201.66KB54.57KB
plugin-kanban (index.js)53.11KB14.62KB
plugin-list (index.js)112.86KB27.54KB
plugin-map (index.js)20.09KB6.62KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.51KB11.94KB
plugin-timeline (index.js)26.72KB7.71KB
plugin-tree (index.js)9.26KB3.13KB
plugin-view (index.js)85.87KB21.12KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)4.47KB1.63KB
react (SchemaRenderer.js)65.97KB21.98KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)2.44KB1.21KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (dashboard-widget-options.js)3.08KB1.30KB
sdui-parser (index.js)4.93KB2.24KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)12.13KB3.65KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.28KB0.23KB
sdui-parser (validate.js)9.30KB3.22KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)2.74KB1.41KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)3.75KB1.85KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.85KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (icon-key-migration.js)4.26KB1.63KB
types (index.js)4.72KB2.24KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (spec-ui-namespace.js)0.20KB0.19KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)6.28KB2.87KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-sales
os-sales marked this pull request as ready for review August 28, 2026 09:28
@os-sales
os-sales added this pull request to the merge queueAug 28, 2026
Merged via the queue into main with commit 813bf83Aug 28, 2026
30 checks passed
@os-sales
os-sales deleted the claude/issue-6617-in-path-right-diagnostic branch August 28, 2026 09:41
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

2 participants

@os-sales@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(app-shell): diagnose `in` with a path on the right in metadata-admin predicates by os-sales · Pull Request #6652 · objectstack-ai/objectui · GitHub
Skip to content

fix(app-shell): diagnose in with a path on the right in metadata-admin predicates - #6652

Merged
os-sales merged 1 commit into
mainfrom
claude/issue-6617-in-path-right-diagnostic
Aug 28, 2026
Merged

fix(app-shell): diagnose in with a path on the right in metadata-admin predicates#6652
os-sales merged 1 commit into
mainfrom
claude/issue-6617-in-path-right-diagnostic

Conversation

@os-sales

Copy link
Copy Markdown
Collaborator

Fixes#6617

Direction 1 (diagnose only), as graded by triage. Zero verdict change — no expression that evaluates today reaches a different answer, and that is measured below rather than asserted.

The gap

evalExpr's in branch matches /^(.+?)\s+in\s+(\[.*\])$/: the right side must be a bracketed literal set. A membership test whose right side is a path therefore never reaches that branch. Carrying no == / != either, it falls all the way to the bare-truthy tail, where the whole text is handed to resolveValue as one operand:

predicaterouteverdict
'admin' in current_user.positionsquote-leading, so resolveValue's literal shortcut hands it to parseLiteral; the quoted-string branch declines it (starts with a quote, does not end with one) and the tail returns it verbatimTRUE for every user, whatever positions holds
data.roles in current_user.positionspath-shaped, so resolveValue splits on dots into data / roles in current_user / positions and walks off the draft at segment twoFALSE for every row

The first is ADR-0068's own headline example and the spelling SelectOptionSchema's docblock names as the canonical use of the key, and its failure direction is permissive: an option, field or section gated to admins renders for everyone.

Both were silent. objectstack#6936's warning hangs on resolveValue's path branch, which quote-leading text never enters; objectui#4049's PATH_SHAPED_LITERAL only matches text starting with an identifier character.

Premise re-verified on the current ref, not inherited

The feasibility note was measured on origin/main @ bac7ba43. I re-measured all of it on 9101be57 (this branch's base) with a throwaway probe before writing a line — 20 rows, direction predicted before each run, 20/20 confirmed, probe then deleted.

The PM's correction on PR #6618 holds, and I measured it directly. These four rows are identical — TRUE, zero warnings — in all four worlds:

'admin' in current_user.positions with…verdictwarnings
current_user.positions = ['admin']TRUE0
current_user.positions = ['viewer']TRUE0
current_user.positions = []TRUE0
current_usernot bound at allTRUE0

The root is never resolved, so binding or not binding current_user cannot change the outcome and PATH_SHAPED_LITERAL never fired for it either. This gap is not a regression from #6247; it is a property of the operator's grammar, not of which names the scope declares.

The change

The hook sits at the bare-truthy tail, after the in branch has already declined the text, and asks one question: does the text nonetheless carry a top-level in? The entire executable footprint is:

  • a fourth warn-once Set (+ its line in resetPredicateWarnings),
  • const IN_OPERATOR = ' in ',
  • a pure carriesTopLevelIn(expr),
  • a void warn function guarded by isDev() and the memo,
  • one statement in evalExpr: if (carriesTopLevelIn(expr)) warnInWithoutLiteralSet(expr, source);

Nothing new is resolved. No operand handling is added. git diff shows exactly one removed line in predicate.ts — the comment // Bare truthy check, replaced by a longer one — and no existing executable line changed. That is triage's distinguishing test for direction 2 answered structurally: the evaluator is not taught to resolve anything.

The trap: the detection is quote-aware by REUSE

A naive expr.includes(' in ') is wrong. 'plug in adapter' is a bare quoted literal — correct code, a truthy string — and accusing it would be a false statement about the author's code, the precise failure this file's diagnostics exist to prevent.

carriesTopLevelIn is splitTopLevel(expr, IN_OPERATOR).length > 1 — the file's existinginStr/depth walk, the same one the && / || splitters and findUnparseableSetElement already run. Inside a quoted run it never even tests the operator. No second scanner, which is also what keeps this a detection rather than a parser.

Why there is no other false positive: an expression reaching the bare-truthy tail that is correct is either a path (which cannot contain a space) or a literal — and the only literal that can contain ' in ' is a quoted string, which the inStr walk protects.

Two spellings are deliberately not detected and fail to silence (the status quo), never to a false claim: a tab-separated in, and one nested at depth > 0 inside parentheses. Both are pinned as silent.

The message

Names the offending text and the predicate that carried it, names the supported subset path in ['a','b'], names the fail-open direction, and states plainly that a path on the right of in cannot be written on this surface today — "not with different punctuation, not with a different spelling, not at all" — rather than implying some other spelling would work. The author's next question is "then how do I write it?", and the honest answer here is "you cannot".

No overlap with #4266, and neither can mask the other

Mutually exclusive by construction: #4266 fires from parseLiteral's array branch, reachable only for text that already matched an operator branch; this one fires at the bare-truthy tail, reachable only when every operator branch declined. Pinned four ways in §9.6 — a #4266 predicate fires #4266 only, a #4049 predicate fires #4049 only, a #6617 predicate fires #6617 only, and one predicate carrying two gaps reports both.

⚠️ Those assertions key on a phrase unique to each message, not on the bare card number: #6617's own text cites objectui#4049 as the rule that paths resolve only on the left of an operator, so toContain('objectui#4049') is true of #6617's message too. Written the naive way the exclusivity test passed for the wrong reason in one direction and failed spuriously in the other — it did, on first run, and that is why the constants exist.

Verification — union run at ac5a59c2

Every result below was produced at the final commit; each exit code was captured before any pipe, and each line quotes the gate's own verdict.

Suites — repo root, all vitest projects (the package-scoped form is a known false-green here). --project unit alone silently ran only 1 of the 3 files, since the two SchemaForm suites are .tsx and live in another project; re-run without it:

npx vitest run packages/app-shell/src/views/metadata-admin/predicate.test.ts \
packages/app-shell/src/views/metadata-admin/SchemaForm.optionVisibleWhen.test.tsx \
packages/app-shell/src/views/metadata-admin/SchemaForm.unresolvedPredicate.test.tsx
Test Files 3 passed (3)
Tests 165 passed (165)

That is the full blast radius: ./predicate has exactly three importers in the repo. The 94 pre-existing predicate.test.ts tests and both SchemaForm suites pass untouched — the test file diff is 306 insertions, 0 deletions.

Gates (each printed its own verdict line):

gateexitverdict
@object-ui/app-shelltype-check0> tsc --noEmit && tsc -p tsconfig.test.json
dependency-closure build (29 pkgs)0built before type-check, so no stale dist/*.d.ts
check:changeset-presence0✅ 2 source file(s) of 1 released package(s) changed, and this change declares 1 changeset(s)
check:changeset-no-major0✅ No changeset declares a major bump.
check:changeset-fixed0✅ All workspace packages are in the changeset fixed group.
check:changeset-overwrite0✅ No pre-existing changeset was modified or deleted.
check:control-bytes0✅ OK (scanned 5496 tracked text file(s))
check:vi-mock-specifiers0✅ OK
check:i18n-keys0
check:self-import0✅ No package names itself inside its own src/.
check:shell-escape-residue0✅ OK

The changeset gate ruled the bump: packages/app-shell/src/** is guarded, so a declaration is required, and it is an honest patch on @object-ui/app-shell. No gate refused anything.

type-check actually covers the edited test file — not assumed: tsc -p tsconfig.test.json --listFiles reports predicate.test.ts1 occurrence and predicate.ts1. (A package typecheck that excludes **/*.test.ts would have been a true statement about nothing.)

Lint — a declared narrowing, with its three measurements. Repo-wide pnpm lint stays CI's run. Locally: eslint's own file selection for packages/app-shell/src/views/metadata-admin/ chose 380 files, count read from --format json, 0 errors; the two changed files show 0 errors and 1 pre-existing no-explicit-any warning at predicate.ts:680 (let cur: any = ctx in resolveValue, untouched by this diff — confirmed absent from git diff). Invariance: this config enables no type-aware linting (no projectService, no project:, no typeChecked), so each file's verdict is a pure function of its own source plus the shared config — neither of which this diff changes for any file it does not contain.

Proving zero-verdict-change instead of asserting it

In words. The single new statement is a void call placed on a path that already existed. It reads nothing from ctx, writes only its own memo Set, returns nothing, and splitTopLevel cannot throw on a string — so it cannot reach the catch in evaluatePredicate that would flip a verdict to fail-open. No operator branch was touched, no operand handling was added, resolveValue and parseLiteral are byte-identical. There is no channel by which an evaluated expression could reach a different answer.

Measured — ablation B. Removing the diagnostic call entirely (mutation proved on disk by grep counts on both the injected and the removed text; restored via git checkout HEAD -- PATH with an absolute PATH, and proved by git hash-object equalling the HEAD blob 22f014afandgit diff HEAD empty):

Tests 15 failed | 130 passed (145)
--- did ANY §9.3 verdict row fail? ---
none — every verdict row still passes with the diagnostic removed

15 diagnostic tests go red and zero verdict rows do. The §9.3 table is genuinely independent of the diagnostic. Together with the pre-change probe on 9101be57 (20/20 verdicts confirmed before the change), the verdicts are pinned identical on both sides of it.

Measured — ablation A, that the quote-aware reuse is load-bearing. Swapping splitTopLevel(...) for the naive expr.includes(IN_OPERATOR):

Tests 6 failed | 139 passed (145)
× a bare single-quoted literal containing the word does NOT warn — correct code is never accused
× the same, double-quoted does NOT warn — correct code is never accused
× a literal whose text is only the word does NOT warn — correct code is never accused
× a quoted literal carrying an apostrophe-free inner quote does NOT warn — correct code is never accused
× the negation of a quoted literal containing the word is silent too
× a parenthesised membership sits at depth > 0 and is not detected — silent, as before

Exactly the quote- and depth-protected controls, and nothing else. The trap pin discriminates: it would catch the naive implementation.

The both-directions pin

  • Warns:'admin' in current_user.positions (bound, unbound, empty and populated), 'x' in data.tags, data.roles in current_user.positions, inside ||, and with extra spaces around in.
  • Does NOT warn:'plug in adapter', "plug in adapter", ' in ', data.label == 'plug in adapter', data.label in ['plug in adapter','x'], "it in that", !'plug in adapter', and every supported literal-set form.

Warn-once memo keying is (sub-expression, predicate source) — the same ${text}::${source} scheme as the three existing sets, for the stated reason: keyed on the text alone, a form with fifteen gates spelling the same membership test would report one and hide the rest. No fourth scheme invented.

Out of scope, deliberately

Direction 3 (producer-side publish-time validation of predicate expressions) belongs to the objectstack#7010 family — another repo, another lane. No card opened from this surface, per the dispatch order; a note on whether it wants one is in my report.


Generated by Claude Code

…min predicates
The predicate evaluator matches membership as `path in ['a','b']` — the right
side must be a bracketed literal set. A membership test whose right side is a
PATH never matched that branch, carried no `==`/`!=` either, and fell to the
bare-truthy tail where the WHOLE text was evaluated as one operand.
`'admin' in current_user.positions` — ADR-0068's own headline example and the
spelling `SelectOptionSchema`'s docblock names as the canonical use of the key —
leads with a quote, so `parseLiteral`'s tail handed it back verbatim as a
non-empty string: TRUE for every user, whatever `positions` held. Fail-OPEN, so
a gate meant for admins rendered for everyone. `data.roles in
current_user.positions` walked off the draft mid-path and read FALSE for every
row instead. Both were silent: objectstack#6936's warning hangs on
`resolveValue`'s path branch, which quote-leading text never enters, and
objectui#4049's `PATH_SHAPED_LITERAL` only matches text starting with an
identifier character.
Diagnose only, zero semantic change — the third time this file takes the posture
#4049 and #4266 took. The hook sits at the bare-truthy tail, AFTER the `in`
branch has declined the text, and asks one question: does the text nonetheless
carry a top-level `in`? Nothing new is resolved and no operand handling is added.
The whole executable footprint is a fourth warn-once Set, a pure `carriesTopLevelIn`
predicate, a void warn function, and one `if` in `evalExpr`.
The detection reuses `splitTopLevel`'s existing quote-aware `inStr` walk rather
than a second scanner, so a predicate that is itself a quoted literal containing
the word (`'plug in adapter'` — correct code, a truthy string) is never accused;
a naive `includes(' in ')` would report it as broken, which is a worse defect
than the bug. Both directions pinned.
The message names the spelling, names the supported subset, and states plainly
that a path on the right of `in` cannot be written on this surface today, rather
than implying some other punctuation would work.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CRJge11jso9TpXRWFt1Z49
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 52 chunks)3237.8 KB3266.6 KB
Main entry chunk (gzip)157.3 KB350 KB
Entry fileindex-D2ACdgk0.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (consoleActionDispatch.js)0.20KB0.19KB
app-shell (index.js)11.89KB4.50KB
app-shell (runtime-config.js)20.61KB7.35KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (ActiveOrganizationStorage.js)25.05KB9.16KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)2.07KB1.00KB
auth (AuthProvider.js)40.18KB10.59KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)8.46KB3.43KB
auth (index.js)3.19KB1.44KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.30KB1.02KB
auth (useWorkspaceAdminStatus.js)5.13KB2.35KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)507.87KB115.07KB
core (index.js)5.30KB2.13KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)173.10KB47.96KB
fields (index.js)238.89KB60.02KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (fallbackInterpolation.js)6.25KB2.77KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)26.89KB9.04KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)5.60KB2.33KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)9.53KB3.38KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)4.64KB1.50KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)1.93KB0.88KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.85KB12.89KB
plugin-charts (index.js)64.66KB18.32KB
plugin-chatbot (index.js)190.33KB45.10KB
plugin-dashboard (index.js)133.41KB34.47KB
plugin-designer (index.js)212.80KB43.15KB
plugin-detail (index.js)245.29KB62.39KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)132.01KB32.23KB
plugin-gantt (index.js)165.16KB40.33KB
plugin-grid (index.js)201.66KB54.57KB
plugin-kanban (index.js)53.11KB14.62KB
plugin-list (index.js)112.86KB27.54KB
plugin-map (index.js)20.09KB6.62KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.51KB11.94KB
plugin-timeline (index.js)26.72KB7.71KB
plugin-tree (index.js)9.26KB3.13KB
plugin-view (index.js)85.87KB21.12KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)4.47KB1.63KB
react (SchemaRenderer.js)65.97KB21.98KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)2.44KB1.21KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (dashboard-widget-options.js)3.08KB1.30KB
sdui-parser (index.js)4.93KB2.24KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)12.13KB3.65KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.28KB0.23KB
sdui-parser (validate.js)9.30KB3.22KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)2.74KB1.41KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)3.75KB1.85KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.85KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (icon-key-migration.js)4.26KB1.63KB
types (index.js)4.72KB2.24KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (spec-ui-namespace.js)0.20KB0.19KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)6.28KB2.87KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-sales
os-sales marked this pull request as ready for review August 28, 2026 09:28
@os-sales
os-sales added this pull request to the merge queueAug 28, 2026
Merged via the queue into main with commit 813bf83Aug 28, 2026
30 checks passed
@os-sales
os-sales deleted the claude/issue-6617-in-path-right-diagnostic branch August 28, 2026 09:41
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

2 participants

@os-sales@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(app-shell): diagnose `in` with a path on the right in metadata-admin predicates by os-sales · Pull Request #6652 · objectstack-ai/objectui · GitHub
Skip to content

fix(app-shell): diagnose in with a path on the right in metadata-admin predicates - #6652

Merged
os-sales merged 1 commit into
mainfrom
claude/issue-6617-in-path-right-diagnostic
Aug 28, 2026
Merged

fix(app-shell): diagnose in with a path on the right in metadata-admin predicates#6652
os-sales merged 1 commit into
mainfrom
claude/issue-6617-in-path-right-diagnostic

Conversation

@os-sales

Copy link
Copy Markdown
Collaborator

Fixes#6617

Direction 1 (diagnose only), as graded by triage. Zero verdict change — no expression that evaluates today reaches a different answer, and that is measured below rather than asserted.

The gap

evalExpr's in branch matches /^(.+?)\s+in\s+(\[.*\])$/: the right side must be a bracketed literal set. A membership test whose right side is a path therefore never reaches that branch. Carrying no == / != either, it falls all the way to the bare-truthy tail, where the whole text is handed to resolveValue as one operand:

predicaterouteverdict
'admin' in current_user.positionsquote-leading, so resolveValue's literal shortcut hands it to parseLiteral; the quoted-string branch declines it (starts with a quote, does not end with one) and the tail returns it verbatimTRUE for every user, whatever positions holds
data.roles in current_user.positionspath-shaped, so resolveValue splits on dots into data / roles in current_user / positions and walks off the draft at segment twoFALSE for every row

The first is ADR-0068's own headline example and the spelling SelectOptionSchema's docblock names as the canonical use of the key, and its failure direction is permissive: an option, field or section gated to admins renders for everyone.

Both were silent. objectstack#6936's warning hangs on resolveValue's path branch, which quote-leading text never enters; objectui#4049's PATH_SHAPED_LITERAL only matches text starting with an identifier character.

Premise re-verified on the current ref, not inherited

The feasibility note was measured on origin/main @ bac7ba43. I re-measured all of it on 9101be57 (this branch's base) with a throwaway probe before writing a line — 20 rows, direction predicted before each run, 20/20 confirmed, probe then deleted.

The PM's correction on PR #6618 holds, and I measured it directly. These four rows are identical — TRUE, zero warnings — in all four worlds:

'admin' in current_user.positions with…verdictwarnings
current_user.positions = ['admin']TRUE0
current_user.positions = ['viewer']TRUE0
current_user.positions = []TRUE0
current_usernot bound at allTRUE0

The root is never resolved, so binding or not binding current_user cannot change the outcome and PATH_SHAPED_LITERAL never fired for it either. This gap is not a regression from #6247; it is a property of the operator's grammar, not of which names the scope declares.

The change

The hook sits at the bare-truthy tail, after the in branch has already declined the text, and asks one question: does the text nonetheless carry a top-level in? The entire executable footprint is:

  • a fourth warn-once Set (+ its line in resetPredicateWarnings),
  • const IN_OPERATOR = ' in ',
  • a pure carriesTopLevelIn(expr),
  • a void warn function guarded by isDev() and the memo,
  • one statement in evalExpr: if (carriesTopLevelIn(expr)) warnInWithoutLiteralSet(expr, source);

Nothing new is resolved. No operand handling is added. git diff shows exactly one removed line in predicate.ts — the comment // Bare truthy check, replaced by a longer one — and no existing executable line changed. That is triage's distinguishing test for direction 2 answered structurally: the evaluator is not taught to resolve anything.

The trap: the detection is quote-aware by REUSE

A naive expr.includes(' in ') is wrong. 'plug in adapter' is a bare quoted literal — correct code, a truthy string — and accusing it would be a false statement about the author's code, the precise failure this file's diagnostics exist to prevent.

carriesTopLevelIn is splitTopLevel(expr, IN_OPERATOR).length > 1 — the file's existinginStr/depth walk, the same one the && / || splitters and findUnparseableSetElement already run. Inside a quoted run it never even tests the operator. No second scanner, which is also what keeps this a detection rather than a parser.

Why there is no other false positive: an expression reaching the bare-truthy tail that is correct is either a path (which cannot contain a space) or a literal — and the only literal that can contain ' in ' is a quoted string, which the inStr walk protects.

Two spellings are deliberately not detected and fail to silence (the status quo), never to a false claim: a tab-separated in, and one nested at depth > 0 inside parentheses. Both are pinned as silent.

The message

Names the offending text and the predicate that carried it, names the supported subset path in ['a','b'], names the fail-open direction, and states plainly that a path on the right of in cannot be written on this surface today — "not with different punctuation, not with a different spelling, not at all" — rather than implying some other spelling would work. The author's next question is "then how do I write it?", and the honest answer here is "you cannot".

No overlap with #4266, and neither can mask the other

Mutually exclusive by construction: #4266 fires from parseLiteral's array branch, reachable only for text that already matched an operator branch; this one fires at the bare-truthy tail, reachable only when every operator branch declined. Pinned four ways in §9.6 — a #4266 predicate fires #4266 only, a #4049 predicate fires #4049 only, a #6617 predicate fires #6617 only, and one predicate carrying two gaps reports both.

⚠️ Those assertions key on a phrase unique to each message, not on the bare card number: #6617's own text cites objectui#4049 as the rule that paths resolve only on the left of an operator, so toContain('objectui#4049') is true of #6617's message too. Written the naive way the exclusivity test passed for the wrong reason in one direction and failed spuriously in the other — it did, on first run, and that is why the constants exist.

Verification — union run at ac5a59c2

Every result below was produced at the final commit; each exit code was captured before any pipe, and each line quotes the gate's own verdict.

Suites — repo root, all vitest projects (the package-scoped form is a known false-green here). --project unit alone silently ran only 1 of the 3 files, since the two SchemaForm suites are .tsx and live in another project; re-run without it:

npx vitest run packages/app-shell/src/views/metadata-admin/predicate.test.ts \
packages/app-shell/src/views/metadata-admin/SchemaForm.optionVisibleWhen.test.tsx \
packages/app-shell/src/views/metadata-admin/SchemaForm.unresolvedPredicate.test.tsx
Test Files 3 passed (3)
Tests 165 passed (165)

That is the full blast radius: ./predicate has exactly three importers in the repo. The 94 pre-existing predicate.test.ts tests and both SchemaForm suites pass untouched — the test file diff is 306 insertions, 0 deletions.

Gates (each printed its own verdict line):

gateexitverdict
@object-ui/app-shelltype-check0> tsc --noEmit && tsc -p tsconfig.test.json
dependency-closure build (29 pkgs)0built before type-check, so no stale dist/*.d.ts
check:changeset-presence0✅ 2 source file(s) of 1 released package(s) changed, and this change declares 1 changeset(s)
check:changeset-no-major0✅ No changeset declares a major bump.
check:changeset-fixed0✅ All workspace packages are in the changeset fixed group.
check:changeset-overwrite0✅ No pre-existing changeset was modified or deleted.
check:control-bytes0✅ OK (scanned 5496 tracked text file(s))
check:vi-mock-specifiers0✅ OK
check:i18n-keys0
check:self-import0✅ No package names itself inside its own src/.
check:shell-escape-residue0✅ OK

The changeset gate ruled the bump: packages/app-shell/src/** is guarded, so a declaration is required, and it is an honest patch on @object-ui/app-shell. No gate refused anything.

type-check actually covers the edited test file — not assumed: tsc -p tsconfig.test.json --listFiles reports predicate.test.ts1 occurrence and predicate.ts1. (A package typecheck that excludes **/*.test.ts would have been a true statement about nothing.)

Lint — a declared narrowing, with its three measurements. Repo-wide pnpm lint stays CI's run. Locally: eslint's own file selection for packages/app-shell/src/views/metadata-admin/ chose 380 files, count read from --format json, 0 errors; the two changed files show 0 errors and 1 pre-existing no-explicit-any warning at predicate.ts:680 (let cur: any = ctx in resolveValue, untouched by this diff — confirmed absent from git diff). Invariance: this config enables no type-aware linting (no projectService, no project:, no typeChecked), so each file's verdict is a pure function of its own source plus the shared config — neither of which this diff changes for any file it does not contain.

Proving zero-verdict-change instead of asserting it

In words. The single new statement is a void call placed on a path that already existed. It reads nothing from ctx, writes only its own memo Set, returns nothing, and splitTopLevel cannot throw on a string — so it cannot reach the catch in evaluatePredicate that would flip a verdict to fail-open. No operator branch was touched, no operand handling was added, resolveValue and parseLiteral are byte-identical. There is no channel by which an evaluated expression could reach a different answer.

Measured — ablation B. Removing the diagnostic call entirely (mutation proved on disk by grep counts on both the injected and the removed text; restored via git checkout HEAD -- PATH with an absolute PATH, and proved by git hash-object equalling the HEAD blob 22f014afandgit diff HEAD empty):

Tests 15 failed | 130 passed (145)
--- did ANY §9.3 verdict row fail? ---
none — every verdict row still passes with the diagnostic removed

15 diagnostic tests go red and zero verdict rows do. The §9.3 table is genuinely independent of the diagnostic. Together with the pre-change probe on 9101be57 (20/20 verdicts confirmed before the change), the verdicts are pinned identical on both sides of it.

Measured — ablation A, that the quote-aware reuse is load-bearing. Swapping splitTopLevel(...) for the naive expr.includes(IN_OPERATOR):

Tests 6 failed | 139 passed (145)
× a bare single-quoted literal containing the word does NOT warn — correct code is never accused
× the same, double-quoted does NOT warn — correct code is never accused
× a literal whose text is only the word does NOT warn — correct code is never accused
× a quoted literal carrying an apostrophe-free inner quote does NOT warn — correct code is never accused
× the negation of a quoted literal containing the word is silent too
× a parenthesised membership sits at depth > 0 and is not detected — silent, as before

Exactly the quote- and depth-protected controls, and nothing else. The trap pin discriminates: it would catch the naive implementation.

The both-directions pin

  • Warns:'admin' in current_user.positions (bound, unbound, empty and populated), 'x' in data.tags, data.roles in current_user.positions, inside ||, and with extra spaces around in.
  • Does NOT warn:'plug in adapter', "plug in adapter", ' in ', data.label == 'plug in adapter', data.label in ['plug in adapter','x'], "it in that", !'plug in adapter', and every supported literal-set form.

Warn-once memo keying is (sub-expression, predicate source) — the same ${text}::${source} scheme as the three existing sets, for the stated reason: keyed on the text alone, a form with fifteen gates spelling the same membership test would report one and hide the rest. No fourth scheme invented.

Out of scope, deliberately

Direction 3 (producer-side publish-time validation of predicate expressions) belongs to the objectstack#7010 family — another repo, another lane. No card opened from this surface, per the dispatch order; a note on whether it wants one is in my report.


Generated by Claude Code

…min predicates
The predicate evaluator matches membership as `path in ['a','b']` — the right
side must be a bracketed literal set. A membership test whose right side is a
PATH never matched that branch, carried no `==`/`!=` either, and fell to the
bare-truthy tail where the WHOLE text was evaluated as one operand.
`'admin' in current_user.positions` — ADR-0068's own headline example and the
spelling `SelectOptionSchema`'s docblock names as the canonical use of the key —
leads with a quote, so `parseLiteral`'s tail handed it back verbatim as a
non-empty string: TRUE for every user, whatever `positions` held. Fail-OPEN, so
a gate meant for admins rendered for everyone. `data.roles in
current_user.positions` walked off the draft mid-path and read FALSE for every
row instead. Both were silent: objectstack#6936's warning hangs on
`resolveValue`'s path branch, which quote-leading text never enters, and
objectui#4049's `PATH_SHAPED_LITERAL` only matches text starting with an
identifier character.
Diagnose only, zero semantic change — the third time this file takes the posture
#4049 and #4266 took. The hook sits at the bare-truthy tail, AFTER the `in`
branch has declined the text, and asks one question: does the text nonetheless
carry a top-level `in`? Nothing new is resolved and no operand handling is added.
The whole executable footprint is a fourth warn-once Set, a pure `carriesTopLevelIn`
predicate, a void warn function, and one `if` in `evalExpr`.
The detection reuses `splitTopLevel`'s existing quote-aware `inStr` walk rather
than a second scanner, so a predicate that is itself a quoted literal containing
the word (`'plug in adapter'` — correct code, a truthy string) is never accused;
a naive `includes(' in ')` would report it as broken, which is a worse defect
than the bug. Both directions pinned.
The message names the spelling, names the supported subset, and states plainly
that a path on the right of `in` cannot be written on this surface today, rather
than implying some other punctuation would work.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CRJge11jso9TpXRWFt1Z49
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 52 chunks)3237.8 KB3266.6 KB
Main entry chunk (gzip)157.3 KB350 KB
Entry fileindex-D2ACdgk0.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (consoleActionDispatch.js)0.20KB0.19KB
app-shell (index.js)11.89KB4.50KB
app-shell (runtime-config.js)20.61KB7.35KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (ActiveOrganizationStorage.js)25.05KB9.16KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)2.07KB1.00KB
auth (AuthProvider.js)40.18KB10.59KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)8.46KB3.43KB
auth (index.js)3.19KB1.44KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.30KB1.02KB
auth (useWorkspaceAdminStatus.js)5.13KB2.35KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)507.87KB115.07KB
core (index.js)5.30KB2.13KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)173.10KB47.96KB
fields (index.js)238.89KB60.02KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (fallbackInterpolation.js)6.25KB2.77KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)26.89KB9.04KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)5.60KB2.33KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)9.53KB3.38KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)4.64KB1.50KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)1.93KB0.88KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.85KB12.89KB
plugin-charts (index.js)64.66KB18.32KB
plugin-chatbot (index.js)190.33KB45.10KB
plugin-dashboard (index.js)133.41KB34.47KB
plugin-designer (index.js)212.80KB43.15KB
plugin-detail (index.js)245.29KB62.39KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)132.01KB32.23KB
plugin-gantt (index.js)165.16KB40.33KB
plugin-grid (index.js)201.66KB54.57KB
plugin-kanban (index.js)53.11KB14.62KB
plugin-list (index.js)112.86KB27.54KB
plugin-map (index.js)20.09KB6.62KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.51KB11.94KB
plugin-timeline (index.js)26.72KB7.71KB
plugin-tree (index.js)9.26KB3.13KB
plugin-view (index.js)85.87KB21.12KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)4.47KB1.63KB
react (SchemaRenderer.js)65.97KB21.98KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)2.44KB1.21KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (dashboard-widget-options.js)3.08KB1.30KB
sdui-parser (index.js)4.93KB2.24KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)12.13KB3.65KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.28KB0.23KB
sdui-parser (validate.js)9.30KB3.22KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)2.74KB1.41KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)3.75KB1.85KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.85KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (icon-key-migration.js)4.26KB1.63KB
types (index.js)4.72KB2.24KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (spec-ui-namespace.js)0.20KB0.19KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)6.28KB2.87KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-sales
os-sales marked this pull request as ready for review August 28, 2026 09:28
@os-sales
os-sales added this pull request to the merge queueAug 28, 2026
Merged via the queue into main with commit 813bf83Aug 28, 2026
30 checks passed
@os-sales
os-sales deleted the claude/issue-6617-in-path-right-diagnostic branch August 28, 2026 09:41
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

2 participants

@os-sales@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' fix(app-shell): diagnose `in` with a path on the right in metadata-admin predicates by os-sales · Pull Request #6652 · objectstack-ai/objectui · GitHub
Skip to content

fix(app-shell): diagnose in with a path on the right in metadata-admin predicates - #6652

Merged
os-sales merged 1 commit into
mainfrom
claude/issue-6617-in-path-right-diagnostic
Aug 28, 2026
Merged

fix(app-shell): diagnose in with a path on the right in metadata-admin predicates#6652
os-sales merged 1 commit into
mainfrom
claude/issue-6617-in-path-right-diagnostic

Conversation

@os-sales

Copy link
Copy Markdown
Collaborator

Fixes#6617

Direction 1 (diagnose only), as graded by triage. Zero verdict change — no expression that evaluates today reaches a different answer, and that is measured below rather than asserted.

The gap

evalExpr's in branch matches /^(.+?)\s+in\s+(\[.*\])$/: the right side must be a bracketed literal set. A membership test whose right side is a path therefore never reaches that branch. Carrying no == / != either, it falls all the way to the bare-truthy tail, where the whole text is handed to resolveValue as one operand:

predicaterouteverdict
'admin' in current_user.positionsquote-leading, so resolveValue's literal shortcut hands it to parseLiteral; the quoted-string branch declines it (starts with a quote, does not end with one) and the tail returns it verbatimTRUE for every user, whatever positions holds
data.roles in current_user.positionspath-shaped, so resolveValue splits on dots into data / roles in current_user / positions and walks off the draft at segment twoFALSE for every row

The first is ADR-0068's own headline example and the spelling SelectOptionSchema's docblock names as the canonical use of the key, and its failure direction is permissive: an option, field or section gated to admins renders for everyone.

Both were silent. objectstack#6936's warning hangs on resolveValue's path branch, which quote-leading text never enters; objectui#4049's PATH_SHAPED_LITERAL only matches text starting with an identifier character.

Premise re-verified on the current ref, not inherited

The feasibility note was measured on origin/main @ bac7ba43. I re-measured all of it on 9101be57 (this branch's base) with a throwaway probe before writing a line — 20 rows, direction predicted before each run, 20/20 confirmed, probe then deleted.

The PM's correction on PR #6618 holds, and I measured it directly. These four rows are identical — TRUE, zero warnings — in all four worlds:

'admin' in current_user.positions with…verdictwarnings
current_user.positions = ['admin']TRUE0
current_user.positions = ['viewer']TRUE0
current_user.positions = []TRUE0
current_usernot bound at allTRUE0

The root is never resolved, so binding or not binding current_user cannot change the outcome and PATH_SHAPED_LITERAL never fired for it either. This gap is not a regression from #6247; it is a property of the operator's grammar, not of which names the scope declares.

The change

The hook sits at the bare-truthy tail, after the in branch has already declined the text, and asks one question: does the text nonetheless carry a top-level in? The entire executable footprint is:

  • a fourth warn-once Set (+ its line in resetPredicateWarnings),
  • const IN_OPERATOR = ' in ',
  • a pure carriesTopLevelIn(expr),
  • a void warn function guarded by isDev() and the memo,
  • one statement in evalExpr: if (carriesTopLevelIn(expr)) warnInWithoutLiteralSet(expr, source);

Nothing new is resolved. No operand handling is added. git diff shows exactly one removed line in predicate.ts — the comment // Bare truthy check, replaced by a longer one — and no existing executable line changed. That is triage's distinguishing test for direction 2 answered structurally: the evaluator is not taught to resolve anything.

The trap: the detection is quote-aware by REUSE

A naive expr.includes(' in ') is wrong. 'plug in adapter' is a bare quoted literal — correct code, a truthy string — and accusing it would be a false statement about the author's code, the precise failure this file's diagnostics exist to prevent.

carriesTopLevelIn is splitTopLevel(expr, IN_OPERATOR).length > 1 — the file's existinginStr/depth walk, the same one the && / || splitters and findUnparseableSetElement already run. Inside a quoted run it never even tests the operator. No second scanner, which is also what keeps this a detection rather than a parser.

Why there is no other false positive: an expression reaching the bare-truthy tail that is correct is either a path (which cannot contain a space) or a literal — and the only literal that can contain ' in ' is a quoted string, which the inStr walk protects.

Two spellings are deliberately not detected and fail to silence (the status quo), never to a false claim: a tab-separated in, and one nested at depth > 0 inside parentheses. Both are pinned as silent.

The message

Names the offending text and the predicate that carried it, names the supported subset path in ['a','b'], names the fail-open direction, and states plainly that a path on the right of in cannot be written on this surface today — "not with different punctuation, not with a different spelling, not at all" — rather than implying some other spelling would work. The author's next question is "then how do I write it?", and the honest answer here is "you cannot".

No overlap with #4266, and neither can mask the other

Mutually exclusive by construction: #4266 fires from parseLiteral's array branch, reachable only for text that already matched an operator branch; this one fires at the bare-truthy tail, reachable only when every operator branch declined. Pinned four ways in §9.6 — a #4266 predicate fires #4266 only, a #4049 predicate fires #4049 only, a #6617 predicate fires #6617 only, and one predicate carrying two gaps reports both.

⚠️ Those assertions key on a phrase unique to each message, not on the bare card number: #6617's own text cites objectui#4049 as the rule that paths resolve only on the left of an operator, so toContain('objectui#4049') is true of #6617's message too. Written the naive way the exclusivity test passed for the wrong reason in one direction and failed spuriously in the other — it did, on first run, and that is why the constants exist.

Verification — union run at ac5a59c2

Every result below was produced at the final commit; each exit code was captured before any pipe, and each line quotes the gate's own verdict.

Suites — repo root, all vitest projects (the package-scoped form is a known false-green here). --project unit alone silently ran only 1 of the 3 files, since the two SchemaForm suites are .tsx and live in another project; re-run without it:

npx vitest run packages/app-shell/src/views/metadata-admin/predicate.test.ts \
packages/app-shell/src/views/metadata-admin/SchemaForm.optionVisibleWhen.test.tsx \
packages/app-shell/src/views/metadata-admin/SchemaForm.unresolvedPredicate.test.tsx
Test Files 3 passed (3)
Tests 165 passed (165)

That is the full blast radius: ./predicate has exactly three importers in the repo. The 94 pre-existing predicate.test.ts tests and both SchemaForm suites pass untouched — the test file diff is 306 insertions, 0 deletions.

Gates (each printed its own verdict line):

gateexitverdict
@object-ui/app-shelltype-check0> tsc --noEmit && tsc -p tsconfig.test.json
dependency-closure build (29 pkgs)0built before type-check, so no stale dist/*.d.ts
check:changeset-presence0✅ 2 source file(s) of 1 released package(s) changed, and this change declares 1 changeset(s)
check:changeset-no-major0✅ No changeset declares a major bump.
check:changeset-fixed0✅ All workspace packages are in the changeset fixed group.
check:changeset-overwrite0✅ No pre-existing changeset was modified or deleted.
check:control-bytes0✅ OK (scanned 5496 tracked text file(s))
check:vi-mock-specifiers0✅ OK
check:i18n-keys0
check:self-import0✅ No package names itself inside its own src/.
check:shell-escape-residue0✅ OK

The changeset gate ruled the bump: packages/app-shell/src/** is guarded, so a declaration is required, and it is an honest patch on @object-ui/app-shell. No gate refused anything.

type-check actually covers the edited test file — not assumed: tsc -p tsconfig.test.json --listFiles reports predicate.test.ts1 occurrence and predicate.ts1. (A package typecheck that excludes **/*.test.ts would have been a true statement about nothing.)

Lint — a declared narrowing, with its three measurements. Repo-wide pnpm lint stays CI's run. Locally: eslint's own file selection for packages/app-shell/src/views/metadata-admin/ chose 380 files, count read from --format json, 0 errors; the two changed files show 0 errors and 1 pre-existing no-explicit-any warning at predicate.ts:680 (let cur: any = ctx in resolveValue, untouched by this diff — confirmed absent from git diff). Invariance: this config enables no type-aware linting (no projectService, no project:, no typeChecked), so each file's verdict is a pure function of its own source plus the shared config — neither of which this diff changes for any file it does not contain.

Proving zero-verdict-change instead of asserting it

In words. The single new statement is a void call placed on a path that already existed. It reads nothing from ctx, writes only its own memo Set, returns nothing, and splitTopLevel cannot throw on a string — so it cannot reach the catch in evaluatePredicate that would flip a verdict to fail-open. No operator branch was touched, no operand handling was added, resolveValue and parseLiteral are byte-identical. There is no channel by which an evaluated expression could reach a different answer.

Measured — ablation B. Removing the diagnostic call entirely (mutation proved on disk by grep counts on both the injected and the removed text; restored via git checkout HEAD -- PATH with an absolute PATH, and proved by git hash-object equalling the HEAD blob 22f014afandgit diff HEAD empty):

Tests 15 failed | 130 passed (145)
--- did ANY §9.3 verdict row fail? ---
none — every verdict row still passes with the diagnostic removed

15 diagnostic tests go red and zero verdict rows do. The §9.3 table is genuinely independent of the diagnostic. Together with the pre-change probe on 9101be57 (20/20 verdicts confirmed before the change), the verdicts are pinned identical on both sides of it.

Measured — ablation A, that the quote-aware reuse is load-bearing. Swapping splitTopLevel(...) for the naive expr.includes(IN_OPERATOR):

Tests 6 failed | 139 passed (145)
× a bare single-quoted literal containing the word does NOT warn — correct code is never accused
× the same, double-quoted does NOT warn — correct code is never accused
× a literal whose text is only the word does NOT warn — correct code is never accused
× a quoted literal carrying an apostrophe-free inner quote does NOT warn — correct code is never accused
× the negation of a quoted literal containing the word is silent too
× a parenthesised membership sits at depth > 0 and is not detected — silent, as before

Exactly the quote- and depth-protected controls, and nothing else. The trap pin discriminates: it would catch the naive implementation.

The both-directions pin

  • Warns:'admin' in current_user.positions (bound, unbound, empty and populated), 'x' in data.tags, data.roles in current_user.positions, inside ||, and with extra spaces around in.
  • Does NOT warn:'plug in adapter', "plug in adapter", ' in ', data.label == 'plug in adapter', data.label in ['plug in adapter','x'], "it in that", !'plug in adapter', and every supported literal-set form.

Warn-once memo keying is (sub-expression, predicate source) — the same ${text}::${source} scheme as the three existing sets, for the stated reason: keyed on the text alone, a form with fifteen gates spelling the same membership test would report one and hide the rest. No fourth scheme invented.

Out of scope, deliberately

Direction 3 (producer-side publish-time validation of predicate expressions) belongs to the objectstack#7010 family — another repo, another lane. No card opened from this surface, per the dispatch order; a note on whether it wants one is in my report.


Generated by Claude Code

…min predicates
The predicate evaluator matches membership as `path in ['a','b']` — the right
side must be a bracketed literal set. A membership test whose right side is a
PATH never matched that branch, carried no `==`/`!=` either, and fell to the
bare-truthy tail where the WHOLE text was evaluated as one operand.
`'admin' in current_user.positions` — ADR-0068's own headline example and the
spelling `SelectOptionSchema`'s docblock names as the canonical use of the key —
leads with a quote, so `parseLiteral`'s tail handed it back verbatim as a
non-empty string: TRUE for every user, whatever `positions` held. Fail-OPEN, so
a gate meant for admins rendered for everyone. `data.roles in
current_user.positions` walked off the draft mid-path and read FALSE for every
row instead. Both were silent: objectstack#6936's warning hangs on
`resolveValue`'s path branch, which quote-leading text never enters, and
objectui#4049's `PATH_SHAPED_LITERAL` only matches text starting with an
identifier character.
Diagnose only, zero semantic change — the third time this file takes the posture
#4049 and #4266 took. The hook sits at the bare-truthy tail, AFTER the `in`
branch has declined the text, and asks one question: does the text nonetheless
carry a top-level `in`? Nothing new is resolved and no operand handling is added.
The whole executable footprint is a fourth warn-once Set, a pure `carriesTopLevelIn`
predicate, a void warn function, and one `if` in `evalExpr`.
The detection reuses `splitTopLevel`'s existing quote-aware `inStr` walk rather
than a second scanner, so a predicate that is itself a quoted literal containing
the word (`'plug in adapter'` — correct code, a truthy string) is never accused;
a naive `includes(' in ')` would report it as broken, which is a worse defect
than the bug. Both directions pinned.
The message names the spelling, names the supported subset, and states plainly
that a path on the right of `in` cannot be written on this surface today, rather
than implying some other punctuation would work.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CRJge11jso9TpXRWFt1Z49
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 52 chunks)3237.8 KB3266.6 KB
Main entry chunk (gzip)157.3 KB350 KB
Entry fileindex-D2ACdgk0.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (consoleActionDispatch.js)0.20KB0.19KB
app-shell (index.js)11.89KB4.50KB
app-shell (runtime-config.js)20.61KB7.35KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (ActiveOrganizationStorage.js)25.05KB9.16KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)2.07KB1.00KB
auth (AuthProvider.js)40.18KB10.59KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)8.46KB3.43KB
auth (index.js)3.19KB1.44KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.30KB1.02KB
auth (useWorkspaceAdminStatus.js)5.13KB2.35KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)507.87KB115.07KB
core (index.js)5.30KB2.13KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)173.10KB47.96KB
fields (index.js)238.89KB60.02KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (fallbackInterpolation.js)6.25KB2.77KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)26.89KB9.04KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)5.60KB2.33KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)9.53KB3.38KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)4.64KB1.50KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)1.93KB0.88KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.85KB12.89KB
plugin-charts (index.js)64.66KB18.32KB
plugin-chatbot (index.js)190.33KB45.10KB
plugin-dashboard (index.js)133.41KB34.47KB
plugin-designer (index.js)212.80KB43.15KB
plugin-detail (index.js)245.29KB62.39KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)132.01KB32.23KB
plugin-gantt (index.js)165.16KB40.33KB
plugin-grid (index.js)201.66KB54.57KB
plugin-kanban (index.js)53.11KB14.62KB
plugin-list (index.js)112.86KB27.54KB
plugin-map (index.js)20.09KB6.62KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.51KB11.94KB
plugin-timeline (index.js)26.72KB7.71KB
plugin-tree (index.js)9.26KB3.13KB
plugin-view (index.js)85.87KB21.12KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)4.47KB1.63KB
react (SchemaRenderer.js)65.97KB21.98KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)2.44KB1.21KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (dashboard-widget-options.js)3.08KB1.30KB
sdui-parser (index.js)4.93KB2.24KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)12.13KB3.65KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.28KB0.23KB
sdui-parser (validate.js)9.30KB3.22KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)2.74KB1.41KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)3.75KB1.85KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.85KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (icon-key-migration.js)4.26KB1.63KB
types (index.js)4.72KB2.24KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (spec-ui-namespace.js)0.20KB0.19KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)6.28KB2.87KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-sales
os-sales marked this pull request as ready for review August 28, 2026 09:28
@os-sales
os-sales added this pull request to the merge queueAug 28, 2026
Merged via the queue into main with commit 813bf83Aug 28, 2026
30 checks passed
@os-sales
os-sales deleted the claude/issue-6617-in-path-right-diagnostic branch August 28, 2026 09:41
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

2 participants

@os-sales@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(app-shell): diagnose `in` with a path on the right in metadata-admin predicates by os-sales · Pull Request #6652 · objectstack-ai/objectui · GitHub
Skip to content

fix(app-shell): diagnose in with a path on the right in metadata-admin predicates - #6652

Merged
os-sales merged 1 commit into
mainfrom
claude/issue-6617-in-path-right-diagnostic
Aug 28, 2026
Merged

fix(app-shell): diagnose in with a path on the right in metadata-admin predicates#6652
os-sales merged 1 commit into
mainfrom
claude/issue-6617-in-path-right-diagnostic

Conversation

@os-sales

Copy link
Copy Markdown
Collaborator

Fixes#6617

Direction 1 (diagnose only), as graded by triage. Zero verdict change — no expression that evaluates today reaches a different answer, and that is measured below rather than asserted.

The gap

evalExpr's in branch matches /^(.+?)\s+in\s+(\[.*\])$/: the right side must be a bracketed literal set. A membership test whose right side is a path therefore never reaches that branch. Carrying no == / != either, it falls all the way to the bare-truthy tail, where the whole text is handed to resolveValue as one operand:

predicaterouteverdict
'admin' in current_user.positionsquote-leading, so resolveValue's literal shortcut hands it to parseLiteral; the quoted-string branch declines it (starts with a quote, does not end with one) and the tail returns it verbatimTRUE for every user, whatever positions holds
data.roles in current_user.positionspath-shaped, so resolveValue splits on dots into data / roles in current_user / positions and walks off the draft at segment twoFALSE for every row

The first is ADR-0068's own headline example and the spelling SelectOptionSchema's docblock names as the canonical use of the key, and its failure direction is permissive: an option, field or section gated to admins renders for everyone.

Both were silent. objectstack#6936's warning hangs on resolveValue's path branch, which quote-leading text never enters; objectui#4049's PATH_SHAPED_LITERAL only matches text starting with an identifier character.

Premise re-verified on the current ref, not inherited

The feasibility note was measured on origin/main @ bac7ba43. I re-measured all of it on 9101be57 (this branch's base) with a throwaway probe before writing a line — 20 rows, direction predicted before each run, 20/20 confirmed, probe then deleted.

The PM's correction on PR #6618 holds, and I measured it directly. These four rows are identical — TRUE, zero warnings — in all four worlds:

'admin' in current_user.positions with…verdictwarnings
current_user.positions = ['admin']TRUE0
current_user.positions = ['viewer']TRUE0
current_user.positions = []TRUE0
current_usernot bound at allTRUE0

The root is never resolved, so binding or not binding current_user cannot change the outcome and PATH_SHAPED_LITERAL never fired for it either. This gap is not a regression from #6247; it is a property of the operator's grammar, not of which names the scope declares.

The change

The hook sits at the bare-truthy tail, after the in branch has already declined the text, and asks one question: does the text nonetheless carry a top-level in? The entire executable footprint is:

  • a fourth warn-once Set (+ its line in resetPredicateWarnings),
  • const IN_OPERATOR = ' in ',
  • a pure carriesTopLevelIn(expr),
  • a void warn function guarded by isDev() and the memo,
  • one statement in evalExpr: if (carriesTopLevelIn(expr)) warnInWithoutLiteralSet(expr, source);

Nothing new is resolved. No operand handling is added. git diff shows exactly one removed line in predicate.ts — the comment // Bare truthy check, replaced by a longer one — and no existing executable line changed. That is triage's distinguishing test for direction 2 answered structurally: the evaluator is not taught to resolve anything.

The trap: the detection is quote-aware by REUSE

A naive expr.includes(' in ') is wrong. 'plug in adapter' is a bare quoted literal — correct code, a truthy string — and accusing it would be a false statement about the author's code, the precise failure this file's diagnostics exist to prevent.

carriesTopLevelIn is splitTopLevel(expr, IN_OPERATOR).length > 1 — the file's existinginStr/depth walk, the same one the && / || splitters and findUnparseableSetElement already run. Inside a quoted run it never even tests the operator. No second scanner, which is also what keeps this a detection rather than a parser.

Why there is no other false positive: an expression reaching the bare-truthy tail that is correct is either a path (which cannot contain a space) or a literal — and the only literal that can contain ' in ' is a quoted string, which the inStr walk protects.

Two spellings are deliberately not detected and fail to silence (the status quo), never to a false claim: a tab-separated in, and one nested at depth > 0 inside parentheses. Both are pinned as silent.

The message

Names the offending text and the predicate that carried it, names the supported subset path in ['a','b'], names the fail-open direction, and states plainly that a path on the right of in cannot be written on this surface today — "not with different punctuation, not with a different spelling, not at all" — rather than implying some other spelling would work. The author's next question is "then how do I write it?", and the honest answer here is "you cannot".

No overlap with #4266, and neither can mask the other

Mutually exclusive by construction: #4266 fires from parseLiteral's array branch, reachable only for text that already matched an operator branch; this one fires at the bare-truthy tail, reachable only when every operator branch declined. Pinned four ways in §9.6 — a #4266 predicate fires #4266 only, a #4049 predicate fires #4049 only, a #6617 predicate fires #6617 only, and one predicate carrying two gaps reports both.

⚠️ Those assertions key on a phrase unique to each message, not on the bare card number: #6617's own text cites objectui#4049 as the rule that paths resolve only on the left of an operator, so toContain('objectui#4049') is true of #6617's message too. Written the naive way the exclusivity test passed for the wrong reason in one direction and failed spuriously in the other — it did, on first run, and that is why the constants exist.

Verification — union run at ac5a59c2

Every result below was produced at the final commit; each exit code was captured before any pipe, and each line quotes the gate's own verdict.

Suites — repo root, all vitest projects (the package-scoped form is a known false-green here). --project unit alone silently ran only 1 of the 3 files, since the two SchemaForm suites are .tsx and live in another project; re-run without it:

npx vitest run packages/app-shell/src/views/metadata-admin/predicate.test.ts \
packages/app-shell/src/views/metadata-admin/SchemaForm.optionVisibleWhen.test.tsx \
packages/app-shell/src/views/metadata-admin/SchemaForm.unresolvedPredicate.test.tsx
Test Files 3 passed (3)
Tests 165 passed (165)

That is the full blast radius: ./predicate has exactly three importers in the repo. The 94 pre-existing predicate.test.ts tests and both SchemaForm suites pass untouched — the test file diff is 306 insertions, 0 deletions.

Gates (each printed its own verdict line):

gateexitverdict
@object-ui/app-shelltype-check0> tsc --noEmit && tsc -p tsconfig.test.json
dependency-closure build (29 pkgs)0built before type-check, so no stale dist/*.d.ts
check:changeset-presence0✅ 2 source file(s) of 1 released package(s) changed, and this change declares 1 changeset(s)
check:changeset-no-major0✅ No changeset declares a major bump.
check:changeset-fixed0✅ All workspace packages are in the changeset fixed group.
check:changeset-overwrite0✅ No pre-existing changeset was modified or deleted.
check:control-bytes0✅ OK (scanned 5496 tracked text file(s))
check:vi-mock-specifiers0✅ OK
check:i18n-keys0
check:self-import0✅ No package names itself inside its own src/.
check:shell-escape-residue0✅ OK

The changeset gate ruled the bump: packages/app-shell/src/** is guarded, so a declaration is required, and it is an honest patch on @object-ui/app-shell. No gate refused anything.

type-check actually covers the edited test file — not assumed: tsc -p tsconfig.test.json --listFiles reports predicate.test.ts1 occurrence and predicate.ts1. (A package typecheck that excludes **/*.test.ts would have been a true statement about nothing.)

Lint — a declared narrowing, with its three measurements. Repo-wide pnpm lint stays CI's run. Locally: eslint's own file selection for packages/app-shell/src/views/metadata-admin/ chose 380 files, count read from --format json, 0 errors; the two changed files show 0 errors and 1 pre-existing no-explicit-any warning at predicate.ts:680 (let cur: any = ctx in resolveValue, untouched by this diff — confirmed absent from git diff). Invariance: this config enables no type-aware linting (no projectService, no project:, no typeChecked), so each file's verdict is a pure function of its own source plus the shared config — neither of which this diff changes for any file it does not contain.

Proving zero-verdict-change instead of asserting it

In words. The single new statement is a void call placed on a path that already existed. It reads nothing from ctx, writes only its own memo Set, returns nothing, and splitTopLevel cannot throw on a string — so it cannot reach the catch in evaluatePredicate that would flip a verdict to fail-open. No operator branch was touched, no operand handling was added, resolveValue and parseLiteral are byte-identical. There is no channel by which an evaluated expression could reach a different answer.

Measured — ablation B. Removing the diagnostic call entirely (mutation proved on disk by grep counts on both the injected and the removed text; restored via git checkout HEAD -- PATH with an absolute PATH, and proved by git hash-object equalling the HEAD blob 22f014afandgit diff HEAD empty):

Tests 15 failed | 130 passed (145)
--- did ANY §9.3 verdict row fail? ---
none — every verdict row still passes with the diagnostic removed

15 diagnostic tests go red and zero verdict rows do. The §9.3 table is genuinely independent of the diagnostic. Together with the pre-change probe on 9101be57 (20/20 verdicts confirmed before the change), the verdicts are pinned identical on both sides of it.

Measured — ablation A, that the quote-aware reuse is load-bearing. Swapping splitTopLevel(...) for the naive expr.includes(IN_OPERATOR):

Tests 6 failed | 139 passed (145)
× a bare single-quoted literal containing the word does NOT warn — correct code is never accused
× the same, double-quoted does NOT warn — correct code is never accused
× a literal whose text is only the word does NOT warn — correct code is never accused
× a quoted literal carrying an apostrophe-free inner quote does NOT warn — correct code is never accused
× the negation of a quoted literal containing the word is silent too
× a parenthesised membership sits at depth > 0 and is not detected — silent, as before

Exactly the quote- and depth-protected controls, and nothing else. The trap pin discriminates: it would catch the naive implementation.

The both-directions pin

  • Warns:'admin' in current_user.positions (bound, unbound, empty and populated), 'x' in data.tags, data.roles in current_user.positions, inside ||, and with extra spaces around in.
  • Does NOT warn:'plug in adapter', "plug in adapter", ' in ', data.label == 'plug in adapter', data.label in ['plug in adapter','x'], "it in that", !'plug in adapter', and every supported literal-set form.

Warn-once memo keying is (sub-expression, predicate source) — the same ${text}::${source} scheme as the three existing sets, for the stated reason: keyed on the text alone, a form with fifteen gates spelling the same membership test would report one and hide the rest. No fourth scheme invented.

Out of scope, deliberately

Direction 3 (producer-side publish-time validation of predicate expressions) belongs to the objectstack#7010 family — another repo, another lane. No card opened from this surface, per the dispatch order; a note on whether it wants one is in my report.


Generated by Claude Code

…min predicates
The predicate evaluator matches membership as `path in ['a','b']` — the right
side must be a bracketed literal set. A membership test whose right side is a
PATH never matched that branch, carried no `==`/`!=` either, and fell to the
bare-truthy tail where the WHOLE text was evaluated as one operand.
`'admin' in current_user.positions` — ADR-0068's own headline example and the
spelling `SelectOptionSchema`'s docblock names as the canonical use of the key —
leads with a quote, so `parseLiteral`'s tail handed it back verbatim as a
non-empty string: TRUE for every user, whatever `positions` held. Fail-OPEN, so
a gate meant for admins rendered for everyone. `data.roles in
current_user.positions` walked off the draft mid-path and read FALSE for every
row instead. Both were silent: objectstack#6936's warning hangs on
`resolveValue`'s path branch, which quote-leading text never enters, and
objectui#4049's `PATH_SHAPED_LITERAL` only matches text starting with an
identifier character.
Diagnose only, zero semantic change — the third time this file takes the posture
#4049 and #4266 took. The hook sits at the bare-truthy tail, AFTER the `in`
branch has declined the text, and asks one question: does the text nonetheless
carry a top-level `in`? Nothing new is resolved and no operand handling is added.
The whole executable footprint is a fourth warn-once Set, a pure `carriesTopLevelIn`
predicate, a void warn function, and one `if` in `evalExpr`.
The detection reuses `splitTopLevel`'s existing quote-aware `inStr` walk rather
than a second scanner, so a predicate that is itself a quoted literal containing
the word (`'plug in adapter'` — correct code, a truthy string) is never accused;
a naive `includes(' in ')` would report it as broken, which is a worse defect
than the bug. Both directions pinned.
The message names the spelling, names the supported subset, and states plainly
that a path on the right of `in` cannot be written on this surface today, rather
than implying some other punctuation would work.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CRJge11jso9TpXRWFt1Z49
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 52 chunks)3237.8 KB3266.6 KB
Main entry chunk (gzip)157.3 KB350 KB
Entry fileindex-D2ACdgk0.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (consoleActionDispatch.js)0.20KB0.19KB
app-shell (index.js)11.89KB4.50KB
app-shell (runtime-config.js)20.61KB7.35KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (ActiveOrganizationStorage.js)25.05KB9.16KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)2.07KB1.00KB
auth (AuthProvider.js)40.18KB10.59KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)8.46KB3.43KB
auth (index.js)3.19KB1.44KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.30KB1.02KB
auth (useWorkspaceAdminStatus.js)5.13KB2.35KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)507.87KB115.07KB
core (index.js)5.30KB2.13KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)173.10KB47.96KB
fields (index.js)238.89KB60.02KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (fallbackInterpolation.js)6.25KB2.77KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)26.89KB9.04KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)5.60KB2.33KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)9.53KB3.38KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)4.64KB1.50KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)1.93KB0.88KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.85KB12.89KB
plugin-charts (index.js)64.66KB18.32KB
plugin-chatbot (index.js)190.33KB45.10KB
plugin-dashboard (index.js)133.41KB34.47KB
plugin-designer (index.js)212.80KB43.15KB
plugin-detail (index.js)245.29KB62.39KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)132.01KB32.23KB
plugin-gantt (index.js)165.16KB40.33KB
plugin-grid (index.js)201.66KB54.57KB
plugin-kanban (index.js)53.11KB14.62KB
plugin-list (index.js)112.86KB27.54KB
plugin-map (index.js)20.09KB6.62KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.51KB11.94KB
plugin-timeline (index.js)26.72KB7.71KB
plugin-tree (index.js)9.26KB3.13KB
plugin-view (index.js)85.87KB21.12KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)4.47KB1.63KB
react (SchemaRenderer.js)65.97KB21.98KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)2.44KB1.21KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (dashboard-widget-options.js)3.08KB1.30KB
sdui-parser (index.js)4.93KB2.24KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)12.13KB3.65KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.28KB0.23KB
sdui-parser (validate.js)9.30KB3.22KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)2.74KB1.41KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)3.75KB1.85KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.85KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (icon-key-migration.js)4.26KB1.63KB
types (index.js)4.72KB2.24KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (spec-ui-namespace.js)0.20KB0.19KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)6.28KB2.87KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-sales
os-sales marked this pull request as ready for review August 28, 2026 09:28
@os-sales
os-sales added this pull request to the merge queueAug 28, 2026
Merged via the queue into main with commit 813bf83Aug 28, 2026
30 checks passed
@os-sales
os-sales deleted the claude/issue-6617-in-path-right-diagnostic branch August 28, 2026 09:41
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

2 participants

@os-sales@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(app-shell): diagnose `in` with a path on the right in metadata-admin predicates by os-sales · Pull Request #6652 · objectstack-ai/objectui · GitHub
Skip to content

fix(app-shell): diagnose in with a path on the right in metadata-admin predicates - #6652

Merged
os-sales merged 1 commit into
mainfrom
claude/issue-6617-in-path-right-diagnostic
Aug 28, 2026
Merged

fix(app-shell): diagnose in with a path on the right in metadata-admin predicates#6652
os-sales merged 1 commit into
mainfrom
claude/issue-6617-in-path-right-diagnostic

Conversation

@os-sales

Copy link
Copy Markdown
Collaborator

Fixes#6617

Direction 1 (diagnose only), as graded by triage. Zero verdict change — no expression that evaluates today reaches a different answer, and that is measured below rather than asserted.

The gap

evalExpr's in branch matches /^(.+?)\s+in\s+(\[.*\])$/: the right side must be a bracketed literal set. A membership test whose right side is a path therefore never reaches that branch. Carrying no == / != either, it falls all the way to the bare-truthy tail, where the whole text is handed to resolveValue as one operand:

predicaterouteverdict
'admin' in current_user.positionsquote-leading, so resolveValue's literal shortcut hands it to parseLiteral; the quoted-string branch declines it (starts with a quote, does not end with one) and the tail returns it verbatimTRUE for every user, whatever positions holds
data.roles in current_user.positionspath-shaped, so resolveValue splits on dots into data / roles in current_user / positions and walks off the draft at segment twoFALSE for every row

The first is ADR-0068's own headline example and the spelling SelectOptionSchema's docblock names as the canonical use of the key, and its failure direction is permissive: an option, field or section gated to admins renders for everyone.

Both were silent. objectstack#6936's warning hangs on resolveValue's path branch, which quote-leading text never enters; objectui#4049's PATH_SHAPED_LITERAL only matches text starting with an identifier character.

Premise re-verified on the current ref, not inherited

The feasibility note was measured on origin/main @ bac7ba43. I re-measured all of it on 9101be57 (this branch's base) with a throwaway probe before writing a line — 20 rows, direction predicted before each run, 20/20 confirmed, probe then deleted.

The PM's correction on PR #6618 holds, and I measured it directly. These four rows are identical — TRUE, zero warnings — in all four worlds:

'admin' in current_user.positions with…verdictwarnings
current_user.positions = ['admin']TRUE0
current_user.positions = ['viewer']TRUE0
current_user.positions = []TRUE0
current_usernot bound at allTRUE0

The root is never resolved, so binding or not binding current_user cannot change the outcome and PATH_SHAPED_LITERAL never fired for it either. This gap is not a regression from #6247; it is a property of the operator's grammar, not of which names the scope declares.

The change

The hook sits at the bare-truthy tail, after the in branch has already declined the text, and asks one question: does the text nonetheless carry a top-level in? The entire executable footprint is:

  • a fourth warn-once Set (+ its line in resetPredicateWarnings),
  • const IN_OPERATOR = ' in ',
  • a pure carriesTopLevelIn(expr),
  • a void warn function guarded by isDev() and the memo,
  • one statement in evalExpr: if (carriesTopLevelIn(expr)) warnInWithoutLiteralSet(expr, source);

Nothing new is resolved. No operand handling is added. git diff shows exactly one removed line in predicate.ts — the comment // Bare truthy check, replaced by a longer one — and no existing executable line changed. That is triage's distinguishing test for direction 2 answered structurally: the evaluator is not taught to resolve anything.

The trap: the detection is quote-aware by REUSE

A naive expr.includes(' in ') is wrong. 'plug in adapter' is a bare quoted literal — correct code, a truthy string — and accusing it would be a false statement about the author's code, the precise failure this file's diagnostics exist to prevent.

carriesTopLevelIn is splitTopLevel(expr, IN_OPERATOR).length > 1 — the file's existinginStr/depth walk, the same one the && / || splitters and findUnparseableSetElement already run. Inside a quoted run it never even tests the operator. No second scanner, which is also what keeps this a detection rather than a parser.

Why there is no other false positive: an expression reaching the bare-truthy tail that is correct is either a path (which cannot contain a space) or a literal — and the only literal that can contain ' in ' is a quoted string, which the inStr walk protects.

Two spellings are deliberately not detected and fail to silence (the status quo), never to a false claim: a tab-separated in, and one nested at depth > 0 inside parentheses. Both are pinned as silent.

The message

Names the offending text and the predicate that carried it, names the supported subset path in ['a','b'], names the fail-open direction, and states plainly that a path on the right of in cannot be written on this surface today — "not with different punctuation, not with a different spelling, not at all" — rather than implying some other spelling would work. The author's next question is "then how do I write it?", and the honest answer here is "you cannot".

No overlap with #4266, and neither can mask the other

Mutually exclusive by construction: #4266 fires from parseLiteral's array branch, reachable only for text that already matched an operator branch; this one fires at the bare-truthy tail, reachable only when every operator branch declined. Pinned four ways in §9.6 — a #4266 predicate fires #4266 only, a #4049 predicate fires #4049 only, a #6617 predicate fires #6617 only, and one predicate carrying two gaps reports both.

⚠️ Those assertions key on a phrase unique to each message, not on the bare card number: #6617's own text cites objectui#4049 as the rule that paths resolve only on the left of an operator, so toContain('objectui#4049') is true of #6617's message too. Written the naive way the exclusivity test passed for the wrong reason in one direction and failed spuriously in the other — it did, on first run, and that is why the constants exist.

Verification — union run at ac5a59c2

Every result below was produced at the final commit; each exit code was captured before any pipe, and each line quotes the gate's own verdict.

Suites — repo root, all vitest projects (the package-scoped form is a known false-green here). --project unit alone silently ran only 1 of the 3 files, since the two SchemaForm suites are .tsx and live in another project; re-run without it:

npx vitest run packages/app-shell/src/views/metadata-admin/predicate.test.ts \
packages/app-shell/src/views/metadata-admin/SchemaForm.optionVisibleWhen.test.tsx \
packages/app-shell/src/views/metadata-admin/SchemaForm.unresolvedPredicate.test.tsx
Test Files 3 passed (3)
Tests 165 passed (165)

That is the full blast radius: ./predicate has exactly three importers in the repo. The 94 pre-existing predicate.test.ts tests and both SchemaForm suites pass untouched — the test file diff is 306 insertions, 0 deletions.

Gates (each printed its own verdict line):

gateexitverdict
@object-ui/app-shelltype-check0> tsc --noEmit && tsc -p tsconfig.test.json
dependency-closure build (29 pkgs)0built before type-check, so no stale dist/*.d.ts
check:changeset-presence0✅ 2 source file(s) of 1 released package(s) changed, and this change declares 1 changeset(s)
check:changeset-no-major0✅ No changeset declares a major bump.
check:changeset-fixed0✅ All workspace packages are in the changeset fixed group.
check:changeset-overwrite0✅ No pre-existing changeset was modified or deleted.
check:control-bytes0✅ OK (scanned 5496 tracked text file(s))
check:vi-mock-specifiers0✅ OK
check:i18n-keys0
check:self-import0✅ No package names itself inside its own src/.
check:shell-escape-residue0✅ OK

The changeset gate ruled the bump: packages/app-shell/src/** is guarded, so a declaration is required, and it is an honest patch on @object-ui/app-shell. No gate refused anything.

type-check actually covers the edited test file — not assumed: tsc -p tsconfig.test.json --listFiles reports predicate.test.ts1 occurrence and predicate.ts1. (A package typecheck that excludes **/*.test.ts would have been a true statement about nothing.)

Lint — a declared narrowing, with its three measurements. Repo-wide pnpm lint stays CI's run. Locally: eslint's own file selection for packages/app-shell/src/views/metadata-admin/ chose 380 files, count read from --format json, 0 errors; the two changed files show 0 errors and 1 pre-existing no-explicit-any warning at predicate.ts:680 (let cur: any = ctx in resolveValue, untouched by this diff — confirmed absent from git diff). Invariance: this config enables no type-aware linting (no projectService, no project:, no typeChecked), so each file's verdict is a pure function of its own source plus the shared config — neither of which this diff changes for any file it does not contain.

Proving zero-verdict-change instead of asserting it

In words. The single new statement is a void call placed on a path that already existed. It reads nothing from ctx, writes only its own memo Set, returns nothing, and splitTopLevel cannot throw on a string — so it cannot reach the catch in evaluatePredicate that would flip a verdict to fail-open. No operator branch was touched, no operand handling was added, resolveValue and parseLiteral are byte-identical. There is no channel by which an evaluated expression could reach a different answer.

Measured — ablation B. Removing the diagnostic call entirely (mutation proved on disk by grep counts on both the injected and the removed text; restored via git checkout HEAD -- PATH with an absolute PATH, and proved by git hash-object equalling the HEAD blob 22f014afandgit diff HEAD empty):

Tests 15 failed | 130 passed (145)
--- did ANY §9.3 verdict row fail? ---
none — every verdict row still passes with the diagnostic removed

15 diagnostic tests go red and zero verdict rows do. The §9.3 table is genuinely independent of the diagnostic. Together with the pre-change probe on 9101be57 (20/20 verdicts confirmed before the change), the verdicts are pinned identical on both sides of it.

Measured — ablation A, that the quote-aware reuse is load-bearing. Swapping splitTopLevel(...) for the naive expr.includes(IN_OPERATOR):

Tests 6 failed | 139 passed (145)
× a bare single-quoted literal containing the word does NOT warn — correct code is never accused
× the same, double-quoted does NOT warn — correct code is never accused
× a literal whose text is only the word does NOT warn — correct code is never accused
× a quoted literal carrying an apostrophe-free inner quote does NOT warn — correct code is never accused
× the negation of a quoted literal containing the word is silent too
× a parenthesised membership sits at depth > 0 and is not detected — silent, as before

Exactly the quote- and depth-protected controls, and nothing else. The trap pin discriminates: it would catch the naive implementation.

The both-directions pin

  • Warns:'admin' in current_user.positions (bound, unbound, empty and populated), 'x' in data.tags, data.roles in current_user.positions, inside ||, and with extra spaces around in.
  • Does NOT warn:'plug in adapter', "plug in adapter", ' in ', data.label == 'plug in adapter', data.label in ['plug in adapter','x'], "it in that", !'plug in adapter', and every supported literal-set form.

Warn-once memo keying is (sub-expression, predicate source) — the same ${text}::${source} scheme as the three existing sets, for the stated reason: keyed on the text alone, a form with fifteen gates spelling the same membership test would report one and hide the rest. No fourth scheme invented.

Out of scope, deliberately

Direction 3 (producer-side publish-time validation of predicate expressions) belongs to the objectstack#7010 family — another repo, another lane. No card opened from this surface, per the dispatch order; a note on whether it wants one is in my report.


Generated by Claude Code

…min predicates
The predicate evaluator matches membership as `path in ['a','b']` — the right
side must be a bracketed literal set. A membership test whose right side is a
PATH never matched that branch, carried no `==`/`!=` either, and fell to the
bare-truthy tail where the WHOLE text was evaluated as one operand.
`'admin' in current_user.positions` — ADR-0068's own headline example and the
spelling `SelectOptionSchema`'s docblock names as the canonical use of the key —
leads with a quote, so `parseLiteral`'s tail handed it back verbatim as a
non-empty string: TRUE for every user, whatever `positions` held. Fail-OPEN, so
a gate meant for admins rendered for everyone. `data.roles in
current_user.positions` walked off the draft mid-path and read FALSE for every
row instead. Both were silent: objectstack#6936's warning hangs on
`resolveValue`'s path branch, which quote-leading text never enters, and
objectui#4049's `PATH_SHAPED_LITERAL` only matches text starting with an
identifier character.
Diagnose only, zero semantic change — the third time this file takes the posture
#4049 and #4266 took. The hook sits at the bare-truthy tail, AFTER the `in`
branch has declined the text, and asks one question: does the text nonetheless
carry a top-level `in`? Nothing new is resolved and no operand handling is added.
The whole executable footprint is a fourth warn-once Set, a pure `carriesTopLevelIn`
predicate, a void warn function, and one `if` in `evalExpr`.
The detection reuses `splitTopLevel`'s existing quote-aware `inStr` walk rather
than a second scanner, so a predicate that is itself a quoted literal containing
the word (`'plug in adapter'` — correct code, a truthy string) is never accused;
a naive `includes(' in ')` would report it as broken, which is a worse defect
than the bug. Both directions pinned.
The message names the spelling, names the supported subset, and states plainly
that a path on the right of `in` cannot be written on this surface today, rather
than implying some other punctuation would work.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CRJge11jso9TpXRWFt1Z49
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 52 chunks)3237.8 KB3266.6 KB
Main entry chunk (gzip)157.3 KB350 KB
Entry fileindex-D2ACdgk0.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (consoleActionDispatch.js)0.20KB0.19KB
app-shell (index.js)11.89KB4.50KB
app-shell (runtime-config.js)20.61KB7.35KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (ActiveOrganizationStorage.js)25.05KB9.16KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)2.07KB1.00KB
auth (AuthProvider.js)40.18KB10.59KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)8.46KB3.43KB
auth (index.js)3.19KB1.44KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.30KB1.02KB
auth (useWorkspaceAdminStatus.js)5.13KB2.35KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)507.87KB115.07KB
core (index.js)5.30KB2.13KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)173.10KB47.96KB
fields (index.js)238.89KB60.02KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (fallbackInterpolation.js)6.25KB2.77KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)26.89KB9.04KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)5.60KB2.33KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)9.53KB3.38KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)4.64KB1.50KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)1.93KB0.88KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.85KB12.89KB
plugin-charts (index.js)64.66KB18.32KB
plugin-chatbot (index.js)190.33KB45.10KB
plugin-dashboard (index.js)133.41KB34.47KB
plugin-designer (index.js)212.80KB43.15KB
plugin-detail (index.js)245.29KB62.39KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)132.01KB32.23KB
plugin-gantt (index.js)165.16KB40.33KB
plugin-grid (index.js)201.66KB54.57KB
plugin-kanban (index.js)53.11KB14.62KB
plugin-list (index.js)112.86KB27.54KB
plugin-map (index.js)20.09KB6.62KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.51KB11.94KB
plugin-timeline (index.js)26.72KB7.71KB
plugin-tree (index.js)9.26KB3.13KB
plugin-view (index.js)85.87KB21.12KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)4.47KB1.63KB
react (SchemaRenderer.js)65.97KB21.98KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)2.44KB1.21KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (dashboard-widget-options.js)3.08KB1.30KB
sdui-parser (index.js)4.93KB2.24KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)12.13KB3.65KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.28KB0.23KB
sdui-parser (validate.js)9.30KB3.22KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)2.74KB1.41KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)3.75KB1.85KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.85KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (icon-key-migration.js)4.26KB1.63KB
types (index.js)4.72KB2.24KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (spec-ui-namespace.js)0.20KB0.19KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)6.28KB2.87KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-sales
os-sales marked this pull request as ready for review August 28, 2026 09:28
@os-sales
os-sales added this pull request to the merge queueAug 28, 2026
Merged via the queue into main with commit 813bf83Aug 28, 2026
30 checks passed
@os-sales
os-sales deleted the claude/issue-6617-in-path-right-diagnostic branch August 28, 2026 09:41
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

2 participants

@os-sales@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); fix(app-shell): diagnose `in` with a path on the right in metadata-admin predicates by os-sales · Pull Request #6652 · objectstack-ai/objectui · GitHub
Skip to content

fix(app-shell): diagnose in with a path on the right in metadata-admin predicates - #6652

Merged
os-sales merged 1 commit into
mainfrom
claude/issue-6617-in-path-right-diagnostic
Aug 28, 2026
Merged

fix(app-shell): diagnose in with a path on the right in metadata-admin predicates#6652
os-sales merged 1 commit into
mainfrom
claude/issue-6617-in-path-right-diagnostic

Conversation

@os-sales

Copy link
Copy Markdown
Collaborator

Fixes#6617

Direction 1 (diagnose only), as graded by triage. Zero verdict change — no expression that evaluates today reaches a different answer, and that is measured below rather than asserted.

The gap

evalExpr's in branch matches /^(.+?)\s+in\s+(\[.*\])$/: the right side must be a bracketed literal set. A membership test whose right side is a path therefore never reaches that branch. Carrying no == / != either, it falls all the way to the bare-truthy tail, where the whole text is handed to resolveValue as one operand:

predicaterouteverdict
'admin' in current_user.positionsquote-leading, so resolveValue's literal shortcut hands it to parseLiteral; the quoted-string branch declines it (starts with a quote, does not end with one) and the tail returns it verbatimTRUE for every user, whatever positions holds
data.roles in current_user.positionspath-shaped, so resolveValue splits on dots into data / roles in current_user / positions and walks off the draft at segment twoFALSE for every row

The first is ADR-0068's own headline example and the spelling SelectOptionSchema's docblock names as the canonical use of the key, and its failure direction is permissive: an option, field or section gated to admins renders for everyone.

Both were silent. objectstack#6936's warning hangs on resolveValue's path branch, which quote-leading text never enters; objectui#4049's PATH_SHAPED_LITERAL only matches text starting with an identifier character.

Premise re-verified on the current ref, not inherited

The feasibility note was measured on origin/main @ bac7ba43. I re-measured all of it on 9101be57 (this branch's base) with a throwaway probe before writing a line — 20 rows, direction predicted before each run, 20/20 confirmed, probe then deleted.

The PM's correction on PR #6618 holds, and I measured it directly. These four rows are identical — TRUE, zero warnings — in all four worlds:

'admin' in current_user.positions with…verdictwarnings
current_user.positions = ['admin']TRUE0
current_user.positions = ['viewer']TRUE0
current_user.positions = []TRUE0
current_usernot bound at allTRUE0

The root is never resolved, so binding or not binding current_user cannot change the outcome and PATH_SHAPED_LITERAL never fired for it either. This gap is not a regression from #6247; it is a property of the operator's grammar, not of which names the scope declares.

The change

The hook sits at the bare-truthy tail, after the in branch has already declined the text, and asks one question: does the text nonetheless carry a top-level in? The entire executable footprint is:

  • a fourth warn-once Set (+ its line in resetPredicateWarnings),
  • const IN_OPERATOR = ' in ',
  • a pure carriesTopLevelIn(expr),
  • a void warn function guarded by isDev() and the memo,
  • one statement in evalExpr: if (carriesTopLevelIn(expr)) warnInWithoutLiteralSet(expr, source);

Nothing new is resolved. No operand handling is added. git diff shows exactly one removed line in predicate.ts — the comment // Bare truthy check, replaced by a longer one — and no existing executable line changed. That is triage's distinguishing test for direction 2 answered structurally: the evaluator is not taught to resolve anything.

The trap: the detection is quote-aware by REUSE

A naive expr.includes(' in ') is wrong. 'plug in adapter' is a bare quoted literal — correct code, a truthy string — and accusing it would be a false statement about the author's code, the precise failure this file's diagnostics exist to prevent.

carriesTopLevelIn is splitTopLevel(expr, IN_OPERATOR).length > 1 — the file's existinginStr/depth walk, the same one the && / || splitters and findUnparseableSetElement already run. Inside a quoted run it never even tests the operator. No second scanner, which is also what keeps this a detection rather than a parser.

Why there is no other false positive: an expression reaching the bare-truthy tail that is correct is either a path (which cannot contain a space) or a literal — and the only literal that can contain ' in ' is a quoted string, which the inStr walk protects.

Two spellings are deliberately not detected and fail to silence (the status quo), never to a false claim: a tab-separated in, and one nested at depth > 0 inside parentheses. Both are pinned as silent.

The message

Names the offending text and the predicate that carried it, names the supported subset path in ['a','b'], names the fail-open direction, and states plainly that a path on the right of in cannot be written on this surface today — "not with different punctuation, not with a different spelling, not at all" — rather than implying some other spelling would work. The author's next question is "then how do I write it?", and the honest answer here is "you cannot".

No overlap with #4266, and neither can mask the other

Mutually exclusive by construction: #4266 fires from parseLiteral's array branch, reachable only for text that already matched an operator branch; this one fires at the bare-truthy tail, reachable only when every operator branch declined. Pinned four ways in §9.6 — a #4266 predicate fires #4266 only, a #4049 predicate fires #4049 only, a #6617 predicate fires #6617 only, and one predicate carrying two gaps reports both.

⚠️ Those assertions key on a phrase unique to each message, not on the bare card number: #6617's own text cites objectui#4049 as the rule that paths resolve only on the left of an operator, so toContain('objectui#4049') is true of #6617's message too. Written the naive way the exclusivity test passed for the wrong reason in one direction and failed spuriously in the other — it did, on first run, and that is why the constants exist.

Verification — union run at ac5a59c2

Every result below was produced at the final commit; each exit code was captured before any pipe, and each line quotes the gate's own verdict.

Suites — repo root, all vitest projects (the package-scoped form is a known false-green here). --project unit alone silently ran only 1 of the 3 files, since the two SchemaForm suites are .tsx and live in another project; re-run without it:

npx vitest run packages/app-shell/src/views/metadata-admin/predicate.test.ts \
packages/app-shell/src/views/metadata-admin/SchemaForm.optionVisibleWhen.test.tsx \
packages/app-shell/src/views/metadata-admin/SchemaForm.unresolvedPredicate.test.tsx
Test Files 3 passed (3)
Tests 165 passed (165)

That is the full blast radius: ./predicate has exactly three importers in the repo. The 94 pre-existing predicate.test.ts tests and both SchemaForm suites pass untouched — the test file diff is 306 insertions, 0 deletions.

Gates (each printed its own verdict line):

gateexitverdict
@object-ui/app-shelltype-check0> tsc --noEmit && tsc -p tsconfig.test.json
dependency-closure build (29 pkgs)0built before type-check, so no stale dist/*.d.ts
check:changeset-presence0✅ 2 source file(s) of 1 released package(s) changed, and this change declares 1 changeset(s)
check:changeset-no-major0✅ No changeset declares a major bump.
check:changeset-fixed0✅ All workspace packages are in the changeset fixed group.
check:changeset-overwrite0✅ No pre-existing changeset was modified or deleted.
check:control-bytes0✅ OK (scanned 5496 tracked text file(s))
check:vi-mock-specifiers0✅ OK
check:i18n-keys0
check:self-import0✅ No package names itself inside its own src/.
check:shell-escape-residue0✅ OK

The changeset gate ruled the bump: packages/app-shell/src/** is guarded, so a declaration is required, and it is an honest patch on @object-ui/app-shell. No gate refused anything.

type-check actually covers the edited test file — not assumed: tsc -p tsconfig.test.json --listFiles reports predicate.test.ts1 occurrence and predicate.ts1. (A package typecheck that excludes **/*.test.ts would have been a true statement about nothing.)

Lint — a declared narrowing, with its three measurements. Repo-wide pnpm lint stays CI's run. Locally: eslint's own file selection for packages/app-shell/src/views/metadata-admin/ chose 380 files, count read from --format json, 0 errors; the two changed files show 0 errors and 1 pre-existing no-explicit-any warning at predicate.ts:680 (let cur: any = ctx in resolveValue, untouched by this diff — confirmed absent from git diff). Invariance: this config enables no type-aware linting (no projectService, no project:, no typeChecked), so each file's verdict is a pure function of its own source plus the shared config — neither of which this diff changes for any file it does not contain.

Proving zero-verdict-change instead of asserting it

In words. The single new statement is a void call placed on a path that already existed. It reads nothing from ctx, writes only its own memo Set, returns nothing, and splitTopLevel cannot throw on a string — so it cannot reach the catch in evaluatePredicate that would flip a verdict to fail-open. No operator branch was touched, no operand handling was added, resolveValue and parseLiteral are byte-identical. There is no channel by which an evaluated expression could reach a different answer.

Measured — ablation B. Removing the diagnostic call entirely (mutation proved on disk by grep counts on both the injected and the removed text; restored via git checkout HEAD -- PATH with an absolute PATH, and proved by git hash-object equalling the HEAD blob 22f014afandgit diff HEAD empty):

Tests 15 failed | 130 passed (145)
--- did ANY §9.3 verdict row fail? ---
none — every verdict row still passes with the diagnostic removed

15 diagnostic tests go red and zero verdict rows do. The §9.3 table is genuinely independent of the diagnostic. Together with the pre-change probe on 9101be57 (20/20 verdicts confirmed before the change), the verdicts are pinned identical on both sides of it.

Measured — ablation A, that the quote-aware reuse is load-bearing. Swapping splitTopLevel(...) for the naive expr.includes(IN_OPERATOR):

Tests 6 failed | 139 passed (145)
× a bare single-quoted literal containing the word does NOT warn — correct code is never accused
× the same, double-quoted does NOT warn — correct code is never accused
× a literal whose text is only the word does NOT warn — correct code is never accused
× a quoted literal carrying an apostrophe-free inner quote does NOT warn — correct code is never accused
× the negation of a quoted literal containing the word is silent too
× a parenthesised membership sits at depth > 0 and is not detected — silent, as before

Exactly the quote- and depth-protected controls, and nothing else. The trap pin discriminates: it would catch the naive implementation.

The both-directions pin

  • Warns:'admin' in current_user.positions (bound, unbound, empty and populated), 'x' in data.tags, data.roles in current_user.positions, inside ||, and with extra spaces around in.
  • Does NOT warn:'plug in adapter', "plug in adapter", ' in ', data.label == 'plug in adapter', data.label in ['plug in adapter','x'], "it in that", !'plug in adapter', and every supported literal-set form.

Warn-once memo keying is (sub-expression, predicate source) — the same ${text}::${source} scheme as the three existing sets, for the stated reason: keyed on the text alone, a form with fifteen gates spelling the same membership test would report one and hide the rest. No fourth scheme invented.

Out of scope, deliberately

Direction 3 (producer-side publish-time validation of predicate expressions) belongs to the objectstack#7010 family — another repo, another lane. No card opened from this surface, per the dispatch order; a note on whether it wants one is in my report.


Generated by Claude Code

…min predicates
The predicate evaluator matches membership as `path in ['a','b']` — the right
side must be a bracketed literal set. A membership test whose right side is a
PATH never matched that branch, carried no `==`/`!=` either, and fell to the
bare-truthy tail where the WHOLE text was evaluated as one operand.
`'admin' in current_user.positions` — ADR-0068's own headline example and the
spelling `SelectOptionSchema`'s docblock names as the canonical use of the key —
leads with a quote, so `parseLiteral`'s tail handed it back verbatim as a
non-empty string: TRUE for every user, whatever `positions` held. Fail-OPEN, so
a gate meant for admins rendered for everyone. `data.roles in
current_user.positions` walked off the draft mid-path and read FALSE for every
row instead. Both were silent: objectstack#6936's warning hangs on
`resolveValue`'s path branch, which quote-leading text never enters, and
objectui#4049's `PATH_SHAPED_LITERAL` only matches text starting with an
identifier character.
Diagnose only, zero semantic change — the third time this file takes the posture
#4049 and #4266 took. The hook sits at the bare-truthy tail, AFTER the `in`
branch has declined the text, and asks one question: does the text nonetheless
carry a top-level `in`? Nothing new is resolved and no operand handling is added.
The whole executable footprint is a fourth warn-once Set, a pure `carriesTopLevelIn`
predicate, a void warn function, and one `if` in `evalExpr`.
The detection reuses `splitTopLevel`'s existing quote-aware `inStr` walk rather
than a second scanner, so a predicate that is itself a quoted literal containing
the word (`'plug in adapter'` — correct code, a truthy string) is never accused;
a naive `includes(' in ')` would report it as broken, which is a worse defect
than the bug. Both directions pinned.
The message names the spelling, names the supported subset, and states plainly
that a path on the right of `in` cannot be written on this surface today, rather
than implying some other punctuation would work.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CRJge11jso9TpXRWFt1Z49
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 52 chunks)3237.8 KB3266.6 KB
Main entry chunk (gzip)157.3 KB350 KB
Entry fileindex-D2ACdgk0.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (consoleActionDispatch.js)0.20KB0.19KB
app-shell (index.js)11.89KB4.50KB
app-shell (runtime-config.js)20.61KB7.35KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (ActiveOrganizationStorage.js)25.05KB9.16KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)2.07KB1.00KB
auth (AuthProvider.js)40.18KB10.59KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)8.46KB3.43KB
auth (index.js)3.19KB1.44KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.30KB1.02KB
auth (useWorkspaceAdminStatus.js)5.13KB2.35KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)507.87KB115.07KB
core (index.js)5.30KB2.13KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)173.10KB47.96KB
fields (index.js)238.89KB60.02KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (fallbackInterpolation.js)6.25KB2.77KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)26.89KB9.04KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)5.60KB2.33KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)9.53KB3.38KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)4.64KB1.50KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)1.93KB0.88KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.85KB12.89KB
plugin-charts (index.js)64.66KB18.32KB
plugin-chatbot (index.js)190.33KB45.10KB
plugin-dashboard (index.js)133.41KB34.47KB
plugin-designer (index.js)212.80KB43.15KB
plugin-detail (index.js)245.29KB62.39KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)132.01KB32.23KB
plugin-gantt (index.js)165.16KB40.33KB
plugin-grid (index.js)201.66KB54.57KB
plugin-kanban (index.js)53.11KB14.62KB
plugin-list (index.js)112.86KB27.54KB
plugin-map (index.js)20.09KB6.62KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.51KB11.94KB
plugin-timeline (index.js)26.72KB7.71KB
plugin-tree (index.js)9.26KB3.13KB
plugin-view (index.js)85.87KB21.12KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)4.47KB1.63KB
react (SchemaRenderer.js)65.97KB21.98KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)2.44KB1.21KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (dashboard-widget-options.js)3.08KB1.30KB
sdui-parser (index.js)4.93KB2.24KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)12.13KB3.65KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.28KB0.23KB
sdui-parser (validate.js)9.30KB3.22KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)2.74KB1.41KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)3.75KB1.85KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.85KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (icon-key-migration.js)4.26KB1.63KB
types (index.js)4.72KB2.24KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (spec-ui-namespace.js)0.20KB0.19KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)6.28KB2.87KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-sales
os-sales marked this pull request as ready for review August 28, 2026 09:28
@os-sales
os-sales added this pull request to the merge queueAug 28, 2026
Merged via the queue into main with commit 813bf83Aug 28, 2026
30 checks passed
@os-sales
os-sales deleted the claude/issue-6617-in-path-right-diagnostic branch August 28, 2026 09:41
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

2 participants

@os-sales@claude