Skip to content

fix(permissions): give usePermissions() a return identity React cannot discard - #6819

Merged
os-sam merged 1 commit into
mainfrom
claude/issue-6724-usepermissions-identity
Aug 30, 2026
Merged

fix(permissions): give usePermissions() a return identity React cannot discard#6819
os-sam merged 1 commit into
mainfrom
claude/issue-6724-usepermissions-identity

Conversation

@claude

@claudeclaudeBot commented Aug 29, 2026

Copy link
Copy Markdown
Contributor

Fixes#6724

usePermissions() cached its return in a useMemo keyed on [ctx], and both of its branches build a FRESH object — an object literal when no provider is mounted, a spread of ctx when one is. useMemo carries no semantic guarantee: React may discard the cache and recompute even when [ctx] compares equal, handing the caller a new identity while every permission it carries is unchanged. Consumers name that identity in dependency arrays, so a discard alone re-ran ListView's data-fetch effect (an extra dataSource.find) and DetailView's gatedSchema. Same family as #6018 / #5976 / #6591 / #6592 / #6697.

Measured first, because the card asked two questions

1. Is the extra fetch observable today? No — and that changes what this is. The card reasons from React's documented licence, not from a reproduction, so I went looking for one. On React 19.2.8 (this repo's pin) the cache is not discarded spontaneously: 51 re-renders with no provider, 51 with a provider, and 42 under StrictMode each returned exactly ONE identity. There is no Activity/Offscreen subtree anywhere in the repo either — that is the documented case where React really does throw memo caches away. So this is a latent hazard, not a bug reproducible from user actions: a correctness dependency resting on a licence React has not yet exercised here. The only way to exercise it is to force it, which the pin does with the module-level discard proxy from #6697's pins.

2. What do the consumers actually need — identity, or the values? Identity, and there is no narrower option available. What they read off this object is the VERDICT FUNCTIONS — perms.checkField(objectName, field, 'read'), perms.can(objectName, 'update') — over an OPEN set of field names, and those flatten to no fixed list of primitives the way #6592's dataConfig members did (provider, object, items). Measured spread of the by-identity dependency:

filedependency arrays naming the whole object
packages/plugin-list/src/ListView.tsx2 (the data-fetch effect, the column-gate memo)
packages/plugin-detail/src/DetailView.tsx3
packages/plugin-detail/src/RelatedList.tsx1
packages/plugin-form/src/ObjectForm.tsx4
packages/plugin-form/src/ModalForm.tsx2
packages/plugin-grid/src/ObjectGrid.tsx1

13 arrays across 6 files. Re-keying each on primitives is not available (no primitive expresses "which fields are readable"), and it would be 6 files of #6592-style surgery to fix one hook. So the by-identity dependency at the consumers is the correct shape and stays; the fix is at the hook, where the identity is made trustworthy.

The fix

The decoration stops being a React cache and becomes a plain function of ctx:

  • one decorated object per context value, held in a module-level WeakMap React has no say over (keyed weakly, so the entry dies with the provider's value);
  • the no-provider answer is one shared frozen module constant — every member there is a pure constant function, so there was never anything per-instance to keep.

That is strictly stronger than the memo it replaces: the identity is now stable across every component reading the same provider, not just across one component's re-renders. A new context value still yields a new identity, on purpose — that is a real permission change and every consumer must see it.

Two designs were tried and one was rejected on measurement: a useRef cache keyed on ctx works, but it reads and writes ref.current during render and pnpm --filter @object-ui/permissions run lint reported three react-hooks/refs warnings for it. #6745 and #6797 are open findings on exactly that smell in published hooks, so shipping three more of it here would have been filing my own next card. The WeakMap costs no hook at all and lints clean.

No ListView.tsx edit — the fix is entirely inside packages/permissions, so the #6800 / #6723 merge order is unaffected by this PR.

Tests

packages/permissions/src/__tests__/usePermissions.discardedIdentity.test.tsx, 7 cases. The discard is forced at the module level, not with vi.spyOn(React, 'useMemo'): the hook reaches its React bindings through a frozen [object Module] namespace that spying cannot patch, which would leave the pin unfalsifiable. First case is the canary proving the proxy reaches the same binding the hook uses.

Both ablation directions, run against the committed implementation (git checkout HEAD -- ... restore, blob hashes compared each leg, git diff HEAD empty after each restore):

  • Identity, reverting the fix — restored usePermissions.ts from 26896c689 (blob 9c74b56, on-disk check: return useMemo( present, NO_PROVIDER_PERMISSIONS absent): 4 failed | 3 passed, the two discard pins failing with expected 2 to be 1 on the identity count. Restored blob 247907b, tree clean, 7 passed.
  • Values, proving the values pin can fail — a values pin that is green in both legs proves nothing unless it can go red, so can was mutated to () => true (anchor matched exactly once; injected string count 1 to 2): 2 failed | 5 passed, the values case failing on the deep-equal of all 17 answers. Restored, 7 passed.

The values pin is green on BOTH the pre-fix and post-fix implementations, which is the point: this change moves no permission value. The object still spreads ctx by identity (asserted member by member), still derives can/cannot from ctx.check, and the documented no-provider fallbacks — isLoaded: false, userId: null (#5683), systemPermissions: undefined with hasCapabilities fail-open (#4656) — answer exactly as before.

No existing test moved. Not one existing file is edited by this PR, and the suites of every consumer named above pass unchanged on 8a3d94d5e:

pnpm exec vitest run packages/permissions/ 7 files, 76 tests passed
pnpm exec vitest run packages/plugin-list/ packages/plugin-detail/ 165 files, 1756 tests passed
pnpm exec vitest run packages/plugin-form/ packages/plugin-grid/ + 3 app-shell permission tests
175 files, 1698 tests passed
pnpm exec vitest run apps/console/.../ApprovalsInboxPage.* 4 files, 19 tests passed
pnpm --filter @object-ui/permissions run lint 0 errors, 27 warnings
pnpm --filter @object-ui/permissions run type-check clean (tsc --noEmit + tsconfig.test.json)
node scripts/check-changeset-presence.mjs OK
node scripts/check-control-bytes.mjs OK
node scripts/check-vi-mock-specifiers.mjs OK
pnpm changeset:check / check:phantom-deps / check:self-import OK

The one new lint warning is importOriginal(any) in the pin, matching the 16 files that already spell it that way — a precise module type makes the patched useMemo's deps parameter DependencyList, which the proxy signature cannot satisfy (measured: error TS2345). check:readme-exports is unrelated-prerequisite-not-met on this tree (it wants packages/react/dist built); it reads no file this PR touches.

Filed, not folded in

#6813 — both permission providers build their context value in a useMemo too (PermissionProvider.tsx line 124, MePermissionsProvider.tsx line 285). A discard there moves ctx itself, which is the key this fix caches on, so the chain is discard-immune at the hook but not yet end to end. Same family, one link up; #6724's scope-lock says file it.

Generated by Claude Code


Generated by Claude Code

…t discard
`usePermissions()` cached its return in a `useMemo` keyed on `[ctx]`, and both
of its branches build a fresh object — an object literal with no provider, a
spread of `ctx` with one. `useMemo` carries no semantic guarantee: React may
discard the cache and recompute even when `[ctx]` compares equal, which moves
the identity while every permission it carries is unchanged. Consumers name
that identity in dependency arrays (13 arrays across 6 files), so a discard
alone re-ran `ListView`'s data-fetch effect and `DetailView`'s gatedSchema.
The decoration becomes a plain function of `ctx` instead: one object per
context value, held in a module-level `WeakMap` React has no say over, plus
one shared frozen constant for the no-provider answer. What the value is, and
when it changes, are both unchanged.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CRJge11jso9TpXRWFt1Z49
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 45 chunks)3174.0 KB3222.7 KB
Main entry chunk (gzip)148.1 KB350 KB
Entry fileindex-C-JDwpjf.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (consoleActionDispatch.js)0.20KB0.19KB
app-shell (index.js)11.89KB4.50KB
app-shell (runtime-config.js)20.61KB7.35KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (ActiveOrganizationStorage.js)25.05KB9.16KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)2.07KB1.00KB
auth (AuthProvider.js)40.18KB10.59KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)8.46KB3.43KB
auth (index.js)3.19KB1.44KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.30KB1.02KB
auth (useWorkspaceAdminStatus.js)5.13KB2.35KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)511.50KB116.32KB
core (index.js)5.30KB2.13KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)173.10KB47.96KB
fields (index.js)240.93KB60.76KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (fallbackInterpolation.js)6.25KB2.77KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)26.89KB9.04KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)5.60KB2.33KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)9.53KB3.38KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)4.64KB1.50KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)4.83KB2.27KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.92KB12.93KB
plugin-charts (index.js)64.68KB18.35KB
plugin-chatbot (index.js)190.33KB45.10KB
plugin-dashboard (index.js)133.48KB34.51KB
plugin-designer (index.js)212.87KB43.19KB
plugin-detail (index.js)245.46KB62.46KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)133.03KB32.64KB
plugin-gantt (index.js)165.23KB40.37KB
plugin-grid (index.js)201.57KB54.55KB
plugin-kanban (index.js)53.14KB14.64KB
plugin-list (index.js)113.15KB27.59KB
plugin-map (index.js)20.20KB6.66KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.51KB11.94KB
plugin-timeline (index.js)28.95KB8.33KB
plugin-tree (index.js)9.00KB3.08KB
plugin-view (index.js)85.87KB21.12KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)4.47KB1.63KB
react (SchemaRenderer.js)76.75KB25.49KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)3.11KB1.48KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (dashboard-widget-options.js)3.08KB1.30KB
sdui-parser (index.js)4.93KB2.24KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)20.57KB5.88KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.28KB0.23KB
sdui-parser (validate.js)10.35KB3.60KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)2.74KB1.41KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)3.75KB1.85KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.85KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (icon-key-migration.js)4.26KB1.63KB
types (index.js)4.72KB2.24KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (spec-ui-namespace.js)0.20KB0.19KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)6.28KB2.87KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

census(finding): usePermissions()'s memoised return is consumed by effect-dependency identity, outside objectui#6592's census heuristic

2 participants

@os-sam@os-sales