feat(react): evaluate the spec-declared expression-bindable text keys - #6981

Merged
os-zhuang merged 3 commits into
mainfrom
claude/issue-4795-bindable-text-keys
Aug 31, 2026
Merged

feat(react): evaluate the spec-declared expression-bindable text keys#6981
os-zhuang merged 3 commits into
mainfrom
claude/issue-4795-bindable-text-keys

Conversation

@os-sam

@os-samos-sam commented Aug 31, 2026

Copy link
Copy Markdown
Collaborator

Refs #4795 — the evaluation half (ruling item 1) ships here in full. The
build-time rejection (ruling item 2) does not, for two independent reasons
stated below. This card must stay open: it still carries Direction 1's
restart record, the two parked sub-questions, and now item 2.

Authored in session session_013hfmP9hoMd3dJwTh85J4yB.

⛔ GOVERNED SURFACE — do not enqueue this PR

This diff touches four files under skills/, which is GOVERNED_SURFACES[2]
(id: 'skills-catalog') in scripts/check-governed-queue-guard.mjs. Asked
directly about this diff, the guard answers:

One governed path governs the WHOLE pull request — proportion is not a question.
⛔ Do not flip it ready, enqueue it, or arm auto-merge. Park it as a DRAFT and leave the merge
to the maintainer; a human merge IS the review record for a governed surface.

So this stays draft however green CI goes; a human (os-zhuang / hotlong)
merges it. ⚠️AGENTS.md line 378 says the opposite — that repo-root skills/**
is not governed and may take the ordinary self-enqueue path. That text is
stale (the guard landed under objectui#6596, 2026-08-27); the contradiction is
filed as #6975. The guard, not the doc, is authoritative here.

Premise re-verification (the unlock scan's mandatory re-pricing)

@objectstack/spec is installed and resolved in this worktree at 17.2.0, and it
does declare the closed set from objectstack#9599 — verified by reading the
installed package, not the card:

installed spec: 17.2.0
KEYS: [ 'title', 'label', 'value', 'description' ]
MAP: {"statistic":["label","value","description"],"card":["title","description"],"button":["label"]}

Hot controls, so the reading is a measurement rather than a hopeful grep:
COMPONENT_NODE_VISIBILITY_KEYS and ACTION_PARAM_BUILTIN_KEYS (both known
declared) → found; EXPRESSION_BINDABLE_NUMERIC_KEYS (a name that must not
exist) → 0 hits.

⚠️Correction, caught by a gate rather than by review. An earlier revision of
this PR said the declaration shipped in 17.2.0 and set packages/react's floor
to ^17.2.0. That was a misread of the spec CHANGELOG (the objectstack#9599
entry sits under the ## 17.1.0 heading, not the ## 17.2.0 one above it).
check:spec-floors computes the true floor from the built artifact and names it:
^17.1.0. Corrected down to the truth rather than left over-claiming — see
the CI-install section.

⚠️The upstream landing reshaped this card's Option 1. The ruling had a flat
four-key list in view; what actually shipped is that list plus a per-component
carriage map
statistic carries label/value/description, card
carries title/description, button carries label, and every other type
gets the frozen empty set. That difference is what most of the rest of this
PR body is about.

The card's title is false, and so was half of what the guides taught

Re-derived here rather than restated: with the properties envelope, value /
title / label were already both evaluated and read back before this PR (PR
#5122's evaluation leg plus the existing hoist). The two shapes that were
genuinely broken, and are what this PR fixes, are the top-level ones.

What ships

One leg in the evaluation memo (packages/react/src/SchemaRenderer.tsx),
beside the existing content leg:

for(constkeyofexpressionBindableTextKeysFor(typeofnewSchema.type==='string' ? newSchema.type : '',)){if(typeofnewSchema[key]==='string'){newSchema[key]=evaluator.evaluate(newSchema[key]);}}

Converged, not patched per component — this is the ruling's caution, and it is
a measurement here, not a promise.
data-display/statistic.tsx,
layout/card.tsx and form/button.tsx are not in this diff. They already
read these keys off the node; nothing was writing an evaluated value there. The
end-to-end test drives the real registered renderers and passes with those three
files untouched.

Two deliberate choices, both pinned:

  • The lookup is consumed, never copied. The only thing this file knows is
    the name of the function. A row added upstream starts working here with no
    edit.
  • The type string is passed verbatim — no ui: prefix stripping. The spec
    states the answer for an unlisted type is the empty set. Normalizing would
    look harmless and would in the same motion grant rows to element:button and
    page:card, whose renderers read config out of the bag via readProps() and
    never touch these keys on the node — re-manufacturing the
    evaluated-but-not-read-back half this card exists to close. The authored
    corpus also spells these types bare (statistic 42, card 135, button 158
    nodes; ui:* zero).

The CI install, and why the floor moves at all

The first push took all 13 checks red with the build skipped — the signature
of pnpm install dying before any job works. CI installs with
pnpm install --frozen-lockfile, which compares the recorded specifier, not
the resolved version. The manifest bump without a lockfile regen is exactly that
mismatch. Reproduced at 3012dafff before fixing:

ERR_PNPM_OUTDATED_LOCKFILE Cannot install with "frozen-lockfile" because
pnpm-lock.yaml is not up to date with <ROOT>/packages/react/package.json
specifiers in the lockfile don't match specifiers in package.json:

The bump is required on the merits, and that is measured, not assumed. With
^17.0.0 restored and packages/react rebuilt, check:spec-floors reports:

@object-ui/react [floor-too-low] packages/react/dist/SchemaRenderer.js references
`expressionBindableTextKeysFor` from @objectstack/spec/ui, which
@objectstack/spec@17.0.0 does not export
The lowest published spec that carries every symbol each package references:
@object-ui/react → "@objectstack/spec": "^17.1.0"

So reverting the manifest was not available: ^17.0.0 would be a false public
claim, objectui#5793's exact defect class ("the range is the claim, and the claim
is what is wrong"). Floor set to the gate-named ^17.1.0, lockfile regenerated
with pnpm install --lockfile-only. The lockfile diff is one line — the
specifier — and the resolved version stays 17.2.0, so nothing about what
installs changes. pnpm install --frozen-lockfile now exits 0.

Why the build-time rejection is NOT in this PR

Reason 1 — it would decide parked sub-question ③. Its only natural home is
objectui check (packages/cli/src/commands/check.ts). Whether to build the
publish-time half there is explicitly awaiting the maintainer. The file-contention
reason the earlier seat gave has lifted (no open PR touches packages/cli), so
this is the scope boundary, not a blocked file.

Reason 2 — the corpus measurement says the rejection's scope is undecided.
Clause-② required measuring before shipping the narrowing. Census over 736 JSON
documents and json doc fences (2747 typed nodes), counting top-level keys
whose value contains ${:

ClassCountUnder the ruling's literal wordingUnder the carriage map
Predicate keys (visible/hidden/disabled…)22exemptexempt
content5exemptexempt
Declared row (statistic.value, statistic.label)2accepted — now evaluatedaccepted
Closed-set key on an undeclared type32accepted (key is in the list)REJECTED
Key outside the closed set (badge.text, badge.variant, alert.message, chart.data, action.condition)8REJECTEDREJECTED

The two readings differ by 32 occurrences, and the difference is not a
detail:

  • 23 of them are type: "text" with value: "${…}" — taught across
    content/docs/guide/expressions.md and siblings. basic/text.tsx renders
    schema.content || schema.value, so text.value IS a real top-level
    read-back site; it simply has no spec row, so it renders the literal today.
    The literal reading accepts a form that visibly breaks; the carriage-map
    reading rejects the platform's own documented examples.
  • The remainder includes page.title — where type: "page" is a page
    document, not a component node, and title is the page's own title. A
    carriage-map gate needs a "what is a component node" rule the ruling never
    states.
  • Also stat-card.value ×4, on a type that is not registered at all.

The ruling's wording ("any key outside that closed list") selects the literal
reading; the ruling's stated goal ("no more blank renders or literal ${data.n}
reaching users") is only met by the carriage-map reading, which the wording
predates. That is a contract decision, and choosing it silently inside a
diagnostic is exactly what the dispatch forbids.

Docs

The published rules and three guides asserted the retired claim that these four
keys are never template-evaluated, and prescribed host pre-resolution as the
only route. page-builder.md went further: its "Also wrong" example was
{ "type": "statistic", "value": "${…}", "label": "${…}" } — which this PR
makes correct. Corrected surgically, with the still-true half (an undeclared
type reads these keys raw) kept and stated as the boundary.

Published-skills line readings, per the reporting rule:

FileBeforeAfterΔ
skills/objectui/rules/protocol.md275306+31
skills/objectui/guides/page-builder.md516522+6
skills/objectui/guides/schema-expressions.md625628+3
skills/objectui/guides/data-integration.md440441+1
Whole published package (18 files)56865726+40

Verification — all on the final commit ec519f94d

RunResult
pnpm install --frozen-lockfileexit 0 (reproduced failing at 3012dafff first)
vitest run packages/react/68 files / 838 tests passed
vitest run packages/components/220 files / 2018 tests passed
type-check (react, components)Done / exit 0 — react's runs tsc --noEmit && tsc -p tsconfig.test.json, so the new test files are typechecked
eslint . --no-inline-config (repo-wide, 4031 files)my 4 linted files: 0 errors; none of the 75 pre-existing error files are mine
check:spec-floors@object-ui/reactclears at ^17.1.0; 0floor-too-low; 3 residual findings all [no-artifact] on plugins outside this diff
check:governed-queue-guardself-test OK — 132 cases pass; asked about this diff, it names the four skills/ files and refuses the queue
check:skills-pathsOK (94/95 stated paths resolve; 1 baselined)
check:doc-fencesOK — every TypeScript block in 224 documents
check:doc-typesOK — every documented component type is registered
check:doc-snippets271 of 271 blocks judged, 0 failed (after the build it names)
check:control-bytes, check:phantom-deps, check:self-import, check:spec-symbolsall exit 0
check-changeset-presence✅ 4 source files of 2 released packages changed, 1 changeset

Ablation (the feature). Mutation: the lookup call replaced by
[] as string[], so the loop body survives and only the key source dies. Proven
on disk before running — removed-text grep -c = 0, injected-text = 1, and
git hash-object differed from the HEAD blob. Both test files resolve
@object-ui/react through the root vitest alias to packages/react/src, so
both legs are source-resolved and no rebuild leg is involved. Result:
8 failed | 10 passed (the 10 are the negative/inert pins, which correctly
still hold under ablation). Restore leg proven byte-identically:
git hash-object back to 7f9427de8f203e55d960ac5f86359ed46a7ce000, matching
HEAD, and git diff HEAD empty.

Ablation (the floor). Same discipline on the manifest: reverted to
^17.0.0, confirmed on disk (git hash-object differed from the HEAD blob),
rebuilt, and read the gate — [floor-too-low], quoted above. Restored via trap.

Before/after on the pin: 4 failed | 8 passed → 12 passed.

File overlap to flag for review

packages/components/src/__tests__/skill-guide-provider-envelope.test.tsx is
also touched by live PR #6963, in a disjoint region (its COLUMNS fixture at
~L57–70; this PR's edits are the docblock at ~L20 and the assertion at ~L161).
Its a node-level title is read but never evaluated case pinned exactly the
defect this ruling retires, so it is flipped, with the undeclared-key case added
beside it so the file still states both fates.

Out of scope, filed separately

  • objectstack#13670 — the spec carriage map has no row for textvalue,
    although basic/text.tsx reads it at the node's top level and the guides teach
    it. Directly gates the scope of ruling item 2.
  • objectstack#13672 — the spec's button row cites action/action-button.tsx,
    but the map is keyed on the bare name, so action:button (5 corpus nodes)
    resolves to the empty set.

⛔ Draft, and staying draft: governed surface. Not marked ready, not enqueued, no
auto-merge. Direction 2 untouched and still rejected; Direction 3's shipped
render-time half (PR #5129) unaffected.

objectui#4795 Direction 1, maintainer ruling 2026-08-25. The evaluation memo
now evaluates the top-level text keys `@objectstack/spec` declares as
expression-bindable, consuming `expressionBindableTextKeysFor` rather than
keeping a twin list. `statistic.value` / `card.title` / `button.label` and
their siblings are now evaluated at the one place that produces evaluated
schema, so the existing top-level read-back sites see the evaluated value with
no per-component patch.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
…e gap
The published rules and three guides carried the now-retired claim that
`title`/`label`/`value`/`description` are never template-evaluated, and
prescribed host pre-resolution or a `text` node's `content` as the only routes.
objectui#4795 makes that false for the spec-declared rows, so protocol.md gains
a "Bindable Text Keys" rule and the guides point at it; the still-true half (an
undeclared type reads these keys raw) is kept and stated as the boundary.
`skill-guide-provider-envelope.test.tsx`'s node-key reading is flipped to the
new behaviour with the undeclared-key case added beside it, so the file still
states both fates.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
@github-actions

Copy link
Copy Markdown
Contributor

ℹ️ Console Performance Budget — not measured

This run did not produce a console bundle to measure, so there is no pass/fail verdict for the performance budget.

This is not a budget violation. Nothing was measured — the numbers a real violation would carry are simply absent.

StepOutcome
Build packagesskipped
Check console performance budgetskipped

See the workflow run for details.

No package size report: it is only generated from a complete package build, so a partial one is never shown.

…kfile
CI installs with `--frozen-lockfile`, which compares the recorded SPECIFIER,
not the resolved version — so bumping packages/react's range without
regenerating pnpm-lock.yaml failed the install before any job did work, taking
all 13 checks red with the build skipped.
The bump itself is required, and measured rather than assumed: with `^17.0.0`
restored and react rebuilt, `check:spec-floors` reports
@object-ui/react [floor-too-low] packages/react/dist/SchemaRenderer.js
references `expressionBindableTextKeysFor` from @objectstack/spec/ui, which
@objectstack/spec@17.0.0 does not export
so `^17.0.0` would be a false public claim (objectui#5793's defect class). The
same gate names the lowest honest floor as ^17.1.0 — not ^17.2.0, which this
branch declared on a misread CHANGELOG heading; the declaration shipped in
17.1.0. Floor corrected down to the truth rather than left over-claiming.
Lockfile regenerated with `pnpm install --lockfile-only`; the only change is
that one specifier line, and the resolved version stays 17.2.0, so nothing
about what installs changes. `pnpm install --frozen-lockfile` now exits 0
(reproduced failing at 3012daf first).
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 45 chunks)3180.2 KB3222.7 KB
Main entry chunk (gzip)143.6 KB350 KB
Entry fileindex-CotrOk53.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (consoleActionDispatch.js)0.20KB0.19KB
app-shell (index.js)12.46KB4.71KB
app-shell (runtime-config.js)20.68KB7.36KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (ActiveOrganizationStorage.js)25.05KB9.16KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)2.07KB1.00KB
auth (AuthProvider.js)40.18KB10.59KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)8.46KB3.43KB
auth (index.js)3.19KB1.44KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.30KB1.02KB
auth (useWorkspaceAdminStatus.js)5.13KB2.35KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)512.09KB116.42KB
core (index.js)5.30KB2.13KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)177.67KB49.45KB
fields (index.js)243.65KB61.63KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (fallbackInterpolation.js)6.25KB2.77KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)26.89KB9.04KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)5.60KB2.33KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)11.71KB4.29KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)6.24KB2.16KB
permissions (discardProofCache.js)1.04KB0.55KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)4.83KB2.27KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.92KB12.93KB
plugin-charts (index.js)64.68KB18.35KB
plugin-chatbot (index.js)190.53KB45.18KB
plugin-dashboard (index.js)133.48KB34.51KB
plugin-designer (index.js)212.87KB43.19KB
plugin-detail (index.js)247.26KB63.17KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)133.11KB32.61KB
plugin-gantt (index.js)165.21KB40.37KB
plugin-grid (index.js)202.08KB54.61KB
plugin-kanban (index.js)53.14KB14.64KB
plugin-list (index.js)113.15KB27.59KB
plugin-map (index.js)20.20KB6.66KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.51KB11.94KB
plugin-timeline (index.js)29.05KB8.37KB
plugin-tree (index.js)8.98KB3.08KB
plugin-view (index.js)85.79KB21.10KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)4.47KB1.63KB
react (SchemaRenderer.js)81.07KB26.86KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)3.11KB1.48KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (dashboard-widget-options.js)3.08KB1.30KB
sdui-parser (index.js)4.93KB2.24KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)20.57KB5.88KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.28KB0.23KB
sdui-parser (validate.js)10.35KB3.60KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)2.74KB1.41KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)3.75KB1.85KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.85KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (icon-key-migration.js)4.26KB1.63KB
types (index.js)4.72KB2.24KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (spec-ui-namespace.js)0.20KB0.19KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)6.28KB2.87KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-zhuang
os-zhuang marked this pull request as ready for review August 31, 2026 07:31
@os-zhuang
os-zhuang added this pull request to the merge queueAug 31, 2026
Merged via the queue into main with commit 1b1d772Aug 31, 2026
32 checks passed
@os-zhuang
os-zhuang deleted the claude/issue-4795-bindable-text-keys branch August 31, 2026 07:45
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@os-sam@os-zhuang@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

feat(react): evaluate the spec-declared expression-bindable text keys - #6981

Merged
os-zhuang merged 3 commits into
mainfrom
claude/issue-4795-bindable-text-keys
Aug 31, 2026
Merged

feat(react): evaluate the spec-declared expression-bindable text keys#6981
os-zhuang merged 3 commits into
mainfrom
claude/issue-4795-bindable-text-keys

Conversation

@os-sam

@os-samos-sam commented Aug 31, 2026

Copy link
Copy Markdown
Collaborator

Refs #4795 — the evaluation half (ruling item 1) ships here in full. The
build-time rejection (ruling item 2) does not, for two independent reasons
stated below. This card must stay open: it still carries Direction 1's
restart record, the two parked sub-questions, and now item 2.

Authored in session session_013hfmP9hoMd3dJwTh85J4yB.

⛔ GOVERNED SURFACE — do not enqueue this PR

This diff touches four files under skills/, which is GOVERNED_SURFACES[2]
(id: 'skills-catalog') in scripts/check-governed-queue-guard.mjs. Asked
directly about this diff, the guard answers:

One governed path governs the WHOLE pull request — proportion is not a question.
⛔ Do not flip it ready, enqueue it, or arm auto-merge. Park it as a DRAFT and leave the merge
to the maintainer; a human merge IS the review record for a governed surface.

So this stays draft however green CI goes; a human (os-zhuang / hotlong)
merges it. ⚠️AGENTS.md line 378 says the opposite — that repo-root skills/**
is not governed and may take the ordinary self-enqueue path. That text is
stale (the guard landed under objectui#6596, 2026-08-27); the contradiction is
filed as #6975. The guard, not the doc, is authoritative here.

Premise re-verification (the unlock scan's mandatory re-pricing)

@objectstack/spec is installed and resolved in this worktree at 17.2.0, and it
does declare the closed set from objectstack#9599 — verified by reading the
installed package, not the card:

installed spec: 17.2.0
KEYS: [ 'title', 'label', 'value', 'description' ]
MAP: {"statistic":["label","value","description"],"card":["title","description"],"button":["label"]}

Hot controls, so the reading is a measurement rather than a hopeful grep:
COMPONENT_NODE_VISIBILITY_KEYS and ACTION_PARAM_BUILTIN_KEYS (both known
declared) → found; EXPRESSION_BINDABLE_NUMERIC_KEYS (a name that must not
exist) → 0 hits.

⚠️Correction, caught by a gate rather than by review. An earlier revision of
this PR said the declaration shipped in 17.2.0 and set packages/react's floor
to ^17.2.0. That was a misread of the spec CHANGELOG (the objectstack#9599
entry sits under the ## 17.1.0 heading, not the ## 17.2.0 one above it).
check:spec-floors computes the true floor from the built artifact and names it:
^17.1.0. Corrected down to the truth rather than left over-claiming — see
the CI-install section.

⚠️The upstream landing reshaped this card's Option 1. The ruling had a flat
four-key list in view; what actually shipped is that list plus a per-component
carriage map
statistic carries label/value/description, card
carries title/description, button carries label, and every other type
gets the frozen empty set. That difference is what most of the rest of this
PR body is about.

The card's title is false, and so was half of what the guides taught

Re-derived here rather than restated: with the properties envelope, value /
title / label were already both evaluated and read back before this PR (PR
#5122's evaluation leg plus the existing hoist). The two shapes that were
genuinely broken, and are what this PR fixes, are the top-level ones.

What ships

One leg in the evaluation memo (packages/react/src/SchemaRenderer.tsx),
beside the existing content leg:

for(constkeyofexpressionBindableTextKeysFor(typeofnewSchema.type==='string' ? newSchema.type : '',)){if(typeofnewSchema[key]==='string'){newSchema[key]=evaluator.evaluate(newSchema[key]);}}

Converged, not patched per component — this is the ruling's caution, and it is
a measurement here, not a promise.
data-display/statistic.tsx,
layout/card.tsx and form/button.tsx are not in this diff. They already
read these keys off the node; nothing was writing an evaluated value there. The
end-to-end test drives the real registered renderers and passes with those three
files untouched.

Two deliberate choices, both pinned:

  • The lookup is consumed, never copied. The only thing this file knows is
    the name of the function. A row added upstream starts working here with no
    edit.
  • The type string is passed verbatim — no ui: prefix stripping. The spec
    states the answer for an unlisted type is the empty set. Normalizing would
    look harmless and would in the same motion grant rows to element:button and
    page:card, whose renderers read config out of the bag via readProps() and
    never touch these keys on the node — re-manufacturing the
    evaluated-but-not-read-back half this card exists to close. The authored
    corpus also spells these types bare (statistic 42, card 135, button 158
    nodes; ui:* zero).

The CI install, and why the floor moves at all

The first push took all 13 checks red with the build skipped — the signature
of pnpm install dying before any job works. CI installs with
pnpm install --frozen-lockfile, which compares the recorded specifier, not
the resolved version. The manifest bump without a lockfile regen is exactly that
mismatch. Reproduced at 3012dafff before fixing:

ERR_PNPM_OUTDATED_LOCKFILE Cannot install with "frozen-lockfile" because
pnpm-lock.yaml is not up to date with <ROOT>/packages/react/package.json
specifiers in the lockfile don't match specifiers in package.json:

The bump is required on the merits, and that is measured, not assumed. With
^17.0.0 restored and packages/react rebuilt, check:spec-floors reports:

@object-ui/react [floor-too-low] packages/react/dist/SchemaRenderer.js references
`expressionBindableTextKeysFor` from @objectstack/spec/ui, which
@objectstack/spec@17.0.0 does not export
The lowest published spec that carries every symbol each package references:
@object-ui/react → "@objectstack/spec": "^17.1.0"

So reverting the manifest was not available: ^17.0.0 would be a false public
claim, objectui#5793's exact defect class ("the range is the claim, and the claim
is what is wrong"). Floor set to the gate-named ^17.1.0, lockfile regenerated
with pnpm install --lockfile-only. The lockfile diff is one line — the
specifier — and the resolved version stays 17.2.0, so nothing about what
installs changes. pnpm install --frozen-lockfile now exits 0.

Why the build-time rejection is NOT in this PR

Reason 1 — it would decide parked sub-question ③. Its only natural home is
objectui check (packages/cli/src/commands/check.ts). Whether to build the
publish-time half there is explicitly awaiting the maintainer. The file-contention
reason the earlier seat gave has lifted (no open PR touches packages/cli), so
this is the scope boundary, not a blocked file.

Reason 2 — the corpus measurement says the rejection's scope is undecided.
Clause-② required measuring before shipping the narrowing. Census over 736 JSON
documents and json doc fences (2747 typed nodes), counting top-level keys
whose value contains ${:

ClassCountUnder the ruling's literal wordingUnder the carriage map
Predicate keys (visible/hidden/disabled…)22exemptexempt
content5exemptexempt
Declared row (statistic.value, statistic.label)2accepted — now evaluatedaccepted
Closed-set key on an undeclared type32accepted (key is in the list)REJECTED
Key outside the closed set (badge.text, badge.variant, alert.message, chart.data, action.condition)8REJECTEDREJECTED

The two readings differ by 32 occurrences, and the difference is not a
detail:

  • 23 of them are type: "text" with value: "${…}" — taught across
    content/docs/guide/expressions.md and siblings. basic/text.tsx renders
    schema.content || schema.value, so text.value IS a real top-level
    read-back site; it simply has no spec row, so it renders the literal today.
    The literal reading accepts a form that visibly breaks; the carriage-map
    reading rejects the platform's own documented examples.
  • The remainder includes page.title — where type: "page" is a page
    document, not a component node, and title is the page's own title. A
    carriage-map gate needs a "what is a component node" rule the ruling never
    states.
  • Also stat-card.value ×4, on a type that is not registered at all.

The ruling's wording ("any key outside that closed list") selects the literal
reading; the ruling's stated goal ("no more blank renders or literal ${data.n}
reaching users") is only met by the carriage-map reading, which the wording
predates. That is a contract decision, and choosing it silently inside a
diagnostic is exactly what the dispatch forbids.

Docs

The published rules and three guides asserted the retired claim that these four
keys are never template-evaluated, and prescribed host pre-resolution as the
only route. page-builder.md went further: its "Also wrong" example was
{ "type": "statistic", "value": "${…}", "label": "${…}" } — which this PR
makes correct. Corrected surgically, with the still-true half (an undeclared
type reads these keys raw) kept and stated as the boundary.

Published-skills line readings, per the reporting rule:

FileBeforeAfterΔ
skills/objectui/rules/protocol.md275306+31
skills/objectui/guides/page-builder.md516522+6
skills/objectui/guides/schema-expressions.md625628+3
skills/objectui/guides/data-integration.md440441+1
Whole published package (18 files)56865726+40

Verification — all on the final commit ec519f94d

RunResult
pnpm install --frozen-lockfileexit 0 (reproduced failing at 3012dafff first)
vitest run packages/react/68 files / 838 tests passed
vitest run packages/components/220 files / 2018 tests passed
type-check (react, components)Done / exit 0 — react's runs tsc --noEmit && tsc -p tsconfig.test.json, so the new test files are typechecked
eslint . --no-inline-config (repo-wide, 4031 files)my 4 linted files: 0 errors; none of the 75 pre-existing error files are mine
check:spec-floors@object-ui/reactclears at ^17.1.0; 0floor-too-low; 3 residual findings all [no-artifact] on plugins outside this diff
check:governed-queue-guardself-test OK — 132 cases pass; asked about this diff, it names the four skills/ files and refuses the queue
check:skills-pathsOK (94/95 stated paths resolve; 1 baselined)
check:doc-fencesOK — every TypeScript block in 224 documents
check:doc-typesOK — every documented component type is registered
check:doc-snippets271 of 271 blocks judged, 0 failed (after the build it names)
check:control-bytes, check:phantom-deps, check:self-import, check:spec-symbolsall exit 0
check-changeset-presence✅ 4 source files of 2 released packages changed, 1 changeset

Ablation (the feature). Mutation: the lookup call replaced by
[] as string[], so the loop body survives and only the key source dies. Proven
on disk before running — removed-text grep -c = 0, injected-text = 1, and
git hash-object differed from the HEAD blob. Both test files resolve
@object-ui/react through the root vitest alias to packages/react/src, so
both legs are source-resolved and no rebuild leg is involved. Result:
8 failed | 10 passed (the 10 are the negative/inert pins, which correctly
still hold under ablation). Restore leg proven byte-identically:
git hash-object back to 7f9427de8f203e55d960ac5f86359ed46a7ce000, matching
HEAD, and git diff HEAD empty.

Ablation (the floor). Same discipline on the manifest: reverted to
^17.0.0, confirmed on disk (git hash-object differed from the HEAD blob),
rebuilt, and read the gate — [floor-too-low], quoted above. Restored via trap.

Before/after on the pin: 4 failed | 8 passed → 12 passed.

File overlap to flag for review

packages/components/src/__tests__/skill-guide-provider-envelope.test.tsx is
also touched by live PR #6963, in a disjoint region (its COLUMNS fixture at
~L57–70; this PR's edits are the docblock at ~L20 and the assertion at ~L161).
Its a node-level title is read but never evaluated case pinned exactly the
defect this ruling retires, so it is flipped, with the undeclared-key case added
beside it so the file still states both fates.

Out of scope, filed separately

  • objectstack#13670 — the spec carriage map has no row for textvalue,
    although basic/text.tsx reads it at the node's top level and the guides teach
    it. Directly gates the scope of ruling item 2.
  • objectstack#13672 — the spec's button row cites action/action-button.tsx,
    but the map is keyed on the bare name, so action:button (5 corpus nodes)
    resolves to the empty set.

⛔ Draft, and staying draft: governed surface. Not marked ready, not enqueued, no
auto-merge. Direction 2 untouched and still rejected; Direction 3's shipped
render-time half (PR #5129) unaffected.

objectui#4795 Direction 1, maintainer ruling 2026-08-25. The evaluation memo
now evaluates the top-level text keys `@objectstack/spec` declares as
expression-bindable, consuming `expressionBindableTextKeysFor` rather than
keeping a twin list. `statistic.value` / `card.title` / `button.label` and
their siblings are now evaluated at the one place that produces evaluated
schema, so the existing top-level read-back sites see the evaluated value with
no per-component patch.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
…e gap
The published rules and three guides carried the now-retired claim that
`title`/`label`/`value`/`description` are never template-evaluated, and
prescribed host pre-resolution or a `text` node's `content` as the only routes.
objectui#4795 makes that false for the spec-declared rows, so protocol.md gains
a "Bindable Text Keys" rule and the guides point at it; the still-true half (an
undeclared type reads these keys raw) is kept and stated as the boundary.
`skill-guide-provider-envelope.test.tsx`'s node-key reading is flipped to the
new behaviour with the undeclared-key case added beside it, so the file still
states both fates.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
@github-actions

Copy link
Copy Markdown
Contributor

ℹ️ Console Performance Budget — not measured

This run did not produce a console bundle to measure, so there is no pass/fail verdict for the performance budget.

This is not a budget violation. Nothing was measured — the numbers a real violation would carry are simply absent.

StepOutcome
Build packagesskipped
Check console performance budgetskipped

See the workflow run for details.

No package size report: it is only generated from a complete package build, so a partial one is never shown.

…kfile
CI installs with `--frozen-lockfile`, which compares the recorded SPECIFIER,
not the resolved version — so bumping packages/react's range without
regenerating pnpm-lock.yaml failed the install before any job did work, taking
all 13 checks red with the build skipped.
The bump itself is required, and measured rather than assumed: with `^17.0.0`
restored and react rebuilt, `check:spec-floors` reports
@object-ui/react [floor-too-low] packages/react/dist/SchemaRenderer.js
references `expressionBindableTextKeysFor` from @objectstack/spec/ui, which
@objectstack/spec@17.0.0 does not export
so `^17.0.0` would be a false public claim (objectui#5793's defect class). The
same gate names the lowest honest floor as ^17.1.0 — not ^17.2.0, which this
branch declared on a misread CHANGELOG heading; the declaration shipped in
17.1.0. Floor corrected down to the truth rather than left over-claiming.
Lockfile regenerated with `pnpm install --lockfile-only`; the only change is
that one specifier line, and the resolved version stays 17.2.0, so nothing
about what installs changes. `pnpm install --frozen-lockfile` now exits 0
(reproduced failing at 3012daf first).
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 45 chunks)3180.2 KB3222.7 KB
Main entry chunk (gzip)143.6 KB350 KB
Entry fileindex-CotrOk53.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (consoleActionDispatch.js)0.20KB0.19KB
app-shell (index.js)12.46KB4.71KB
app-shell (runtime-config.js)20.68KB7.36KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (ActiveOrganizationStorage.js)25.05KB9.16KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)2.07KB1.00KB
auth (AuthProvider.js)40.18KB10.59KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)8.46KB3.43KB
auth (index.js)3.19KB1.44KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.30KB1.02KB
auth (useWorkspaceAdminStatus.js)5.13KB2.35KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)512.09KB116.42KB
core (index.js)5.30KB2.13KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)177.67KB49.45KB
fields (index.js)243.65KB61.63KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (fallbackInterpolation.js)6.25KB2.77KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)26.89KB9.04KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)5.60KB2.33KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)11.71KB4.29KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)6.24KB2.16KB
permissions (discardProofCache.js)1.04KB0.55KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)4.83KB2.27KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.92KB12.93KB
plugin-charts (index.js)64.68KB18.35KB
plugin-chatbot (index.js)190.53KB45.18KB
plugin-dashboard (index.js)133.48KB34.51KB
plugin-designer (index.js)212.87KB43.19KB
plugin-detail (index.js)247.26KB63.17KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)133.11KB32.61KB
plugin-gantt (index.js)165.21KB40.37KB
plugin-grid (index.js)202.08KB54.61KB
plugin-kanban (index.js)53.14KB14.64KB
plugin-list (index.js)113.15KB27.59KB
plugin-map (index.js)20.20KB6.66KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.51KB11.94KB
plugin-timeline (index.js)29.05KB8.37KB
plugin-tree (index.js)8.98KB3.08KB
plugin-view (index.js)85.79KB21.10KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)4.47KB1.63KB
react (SchemaRenderer.js)81.07KB26.86KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)3.11KB1.48KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (dashboard-widget-options.js)3.08KB1.30KB
sdui-parser (index.js)4.93KB2.24KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)20.57KB5.88KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.28KB0.23KB
sdui-parser (validate.js)10.35KB3.60KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)2.74KB1.41KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)3.75KB1.85KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.85KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (icon-key-migration.js)4.26KB1.63KB
types (index.js)4.72KB2.24KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (spec-ui-namespace.js)0.20KB0.19KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)6.28KB2.87KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-zhuang
os-zhuang marked this pull request as ready for review August 31, 2026 07:31
@os-zhuang
os-zhuang added this pull request to the merge queueAug 31, 2026
Merged via the queue into main with commit 1b1d772Aug 31, 2026
32 checks passed
@os-zhuang
os-zhuang deleted the claude/issue-4795-bindable-text-keys branch August 31, 2026 07:45
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@os-sam@os-zhuang@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(react): evaluate the spec-declared expression-bindable text keys - #6981

Merged
os-zhuang merged 3 commits into
mainfrom
claude/issue-4795-bindable-text-keys
Aug 31, 2026
Merged

feat(react): evaluate the spec-declared expression-bindable text keys#6981
os-zhuang merged 3 commits into
mainfrom
claude/issue-4795-bindable-text-keys

Conversation

@os-sam

@os-samos-sam commented Aug 31, 2026

Copy link
Copy Markdown
Collaborator

Refs #4795 — the evaluation half (ruling item 1) ships here in full. The
build-time rejection (ruling item 2) does not, for two independent reasons
stated below. This card must stay open: it still carries Direction 1's
restart record, the two parked sub-questions, and now item 2.

Authored in session session_013hfmP9hoMd3dJwTh85J4yB.

⛔ GOVERNED SURFACE — do not enqueue this PR

This diff touches four files under skills/, which is GOVERNED_SURFACES[2]
(id: 'skills-catalog') in scripts/check-governed-queue-guard.mjs. Asked
directly about this diff, the guard answers:

One governed path governs the WHOLE pull request — proportion is not a question.
⛔ Do not flip it ready, enqueue it, or arm auto-merge. Park it as a DRAFT and leave the merge
to the maintainer; a human merge IS the review record for a governed surface.

So this stays draft however green CI goes; a human (os-zhuang / hotlong)
merges it. ⚠️AGENTS.md line 378 says the opposite — that repo-root skills/**
is not governed and may take the ordinary self-enqueue path. That text is
stale (the guard landed under objectui#6596, 2026-08-27); the contradiction is
filed as #6975. The guard, not the doc, is authoritative here.

Premise re-verification (the unlock scan's mandatory re-pricing)

@objectstack/spec is installed and resolved in this worktree at 17.2.0, and it
does declare the closed set from objectstack#9599 — verified by reading the
installed package, not the card:

installed spec: 17.2.0
KEYS: [ 'title', 'label', 'value', 'description' ]
MAP: {"statistic":["label","value","description"],"card":["title","description"],"button":["label"]}

Hot controls, so the reading is a measurement rather than a hopeful grep:
COMPONENT_NODE_VISIBILITY_KEYS and ACTION_PARAM_BUILTIN_KEYS (both known
declared) → found; EXPRESSION_BINDABLE_NUMERIC_KEYS (a name that must not
exist) → 0 hits.

⚠️Correction, caught by a gate rather than by review. An earlier revision of
this PR said the declaration shipped in 17.2.0 and set packages/react's floor
to ^17.2.0. That was a misread of the spec CHANGELOG (the objectstack#9599
entry sits under the ## 17.1.0 heading, not the ## 17.2.0 one above it).
check:spec-floors computes the true floor from the built artifact and names it:
^17.1.0. Corrected down to the truth rather than left over-claiming — see
the CI-install section.

⚠️The upstream landing reshaped this card's Option 1. The ruling had a flat
four-key list in view; what actually shipped is that list plus a per-component
carriage map
statistic carries label/value/description, card
carries title/description, button carries label, and every other type
gets the frozen empty set. That difference is what most of the rest of this
PR body is about.

The card's title is false, and so was half of what the guides taught

Re-derived here rather than restated: with the properties envelope, value /
title / label were already both evaluated and read back before this PR (PR
#5122's evaluation leg plus the existing hoist). The two shapes that were
genuinely broken, and are what this PR fixes, are the top-level ones.

What ships

One leg in the evaluation memo (packages/react/src/SchemaRenderer.tsx),
beside the existing content leg:

for(constkeyofexpressionBindableTextKeysFor(typeofnewSchema.type==='string' ? newSchema.type : '',)){if(typeofnewSchema[key]==='string'){newSchema[key]=evaluator.evaluate(newSchema[key]);}}

Converged, not patched per component — this is the ruling's caution, and it is
a measurement here, not a promise.
data-display/statistic.tsx,
layout/card.tsx and form/button.tsx are not in this diff. They already
read these keys off the node; nothing was writing an evaluated value there. The
end-to-end test drives the real registered renderers and passes with those three
files untouched.

Two deliberate choices, both pinned:

  • The lookup is consumed, never copied. The only thing this file knows is
    the name of the function. A row added upstream starts working here with no
    edit.
  • The type string is passed verbatim — no ui: prefix stripping. The spec
    states the answer for an unlisted type is the empty set. Normalizing would
    look harmless and would in the same motion grant rows to element:button and
    page:card, whose renderers read config out of the bag via readProps() and
    never touch these keys on the node — re-manufacturing the
    evaluated-but-not-read-back half this card exists to close. The authored
    corpus also spells these types bare (statistic 42, card 135, button 158
    nodes; ui:* zero).

The CI install, and why the floor moves at all

The first push took all 13 checks red with the build skipped — the signature
of pnpm install dying before any job works. CI installs with
pnpm install --frozen-lockfile, which compares the recorded specifier, not
the resolved version. The manifest bump without a lockfile regen is exactly that
mismatch. Reproduced at 3012dafff before fixing:

ERR_PNPM_OUTDATED_LOCKFILE Cannot install with "frozen-lockfile" because
pnpm-lock.yaml is not up to date with <ROOT>/packages/react/package.json
specifiers in the lockfile don't match specifiers in package.json:

The bump is required on the merits, and that is measured, not assumed. With
^17.0.0 restored and packages/react rebuilt, check:spec-floors reports:

@object-ui/react [floor-too-low] packages/react/dist/SchemaRenderer.js references
`expressionBindableTextKeysFor` from @objectstack/spec/ui, which
@objectstack/spec@17.0.0 does not export
The lowest published spec that carries every symbol each package references:
@object-ui/react → "@objectstack/spec": "^17.1.0"

So reverting the manifest was not available: ^17.0.0 would be a false public
claim, objectui#5793's exact defect class ("the range is the claim, and the claim
is what is wrong"). Floor set to the gate-named ^17.1.0, lockfile regenerated
with pnpm install --lockfile-only. The lockfile diff is one line — the
specifier — and the resolved version stays 17.2.0, so nothing about what
installs changes. pnpm install --frozen-lockfile now exits 0.

Why the build-time rejection is NOT in this PR

Reason 1 — it would decide parked sub-question ③. Its only natural home is
objectui check (packages/cli/src/commands/check.ts). Whether to build the
publish-time half there is explicitly awaiting the maintainer. The file-contention
reason the earlier seat gave has lifted (no open PR touches packages/cli), so
this is the scope boundary, not a blocked file.

Reason 2 — the corpus measurement says the rejection's scope is undecided.
Clause-② required measuring before shipping the narrowing. Census over 736 JSON
documents and json doc fences (2747 typed nodes), counting top-level keys
whose value contains ${:

ClassCountUnder the ruling's literal wordingUnder the carriage map
Predicate keys (visible/hidden/disabled…)22exemptexempt
content5exemptexempt
Declared row (statistic.value, statistic.label)2accepted — now evaluatedaccepted
Closed-set key on an undeclared type32accepted (key is in the list)REJECTED
Key outside the closed set (badge.text, badge.variant, alert.message, chart.data, action.condition)8REJECTEDREJECTED

The two readings differ by 32 occurrences, and the difference is not a
detail:

  • 23 of them are type: "text" with value: "${…}" — taught across
    content/docs/guide/expressions.md and siblings. basic/text.tsx renders
    schema.content || schema.value, so text.value IS a real top-level
    read-back site; it simply has no spec row, so it renders the literal today.
    The literal reading accepts a form that visibly breaks; the carriage-map
    reading rejects the platform's own documented examples.
  • The remainder includes page.title — where type: "page" is a page
    document, not a component node, and title is the page's own title. A
    carriage-map gate needs a "what is a component node" rule the ruling never
    states.
  • Also stat-card.value ×4, on a type that is not registered at all.

The ruling's wording ("any key outside that closed list") selects the literal
reading; the ruling's stated goal ("no more blank renders or literal ${data.n}
reaching users") is only met by the carriage-map reading, which the wording
predates. That is a contract decision, and choosing it silently inside a
diagnostic is exactly what the dispatch forbids.

Docs

The published rules and three guides asserted the retired claim that these four
keys are never template-evaluated, and prescribed host pre-resolution as the
only route. page-builder.md went further: its "Also wrong" example was
{ "type": "statistic", "value": "${…}", "label": "${…}" } — which this PR
makes correct. Corrected surgically, with the still-true half (an undeclared
type reads these keys raw) kept and stated as the boundary.

Published-skills line readings, per the reporting rule:

FileBeforeAfterΔ
skills/objectui/rules/protocol.md275306+31
skills/objectui/guides/page-builder.md516522+6
skills/objectui/guides/schema-expressions.md625628+3
skills/objectui/guides/data-integration.md440441+1
Whole published package (18 files)56865726+40

Verification — all on the final commit ec519f94d

RunResult
pnpm install --frozen-lockfileexit 0 (reproduced failing at 3012dafff first)
vitest run packages/react/68 files / 838 tests passed
vitest run packages/components/220 files / 2018 tests passed
type-check (react, components)Done / exit 0 — react's runs tsc --noEmit && tsc -p tsconfig.test.json, so the new test files are typechecked
eslint . --no-inline-config (repo-wide, 4031 files)my 4 linted files: 0 errors; none of the 75 pre-existing error files are mine
check:spec-floors@object-ui/reactclears at ^17.1.0; 0floor-too-low; 3 residual findings all [no-artifact] on plugins outside this diff
check:governed-queue-guardself-test OK — 132 cases pass; asked about this diff, it names the four skills/ files and refuses the queue
check:skills-pathsOK (94/95 stated paths resolve; 1 baselined)
check:doc-fencesOK — every TypeScript block in 224 documents
check:doc-typesOK — every documented component type is registered
check:doc-snippets271 of 271 blocks judged, 0 failed (after the build it names)
check:control-bytes, check:phantom-deps, check:self-import, check:spec-symbolsall exit 0
check-changeset-presence✅ 4 source files of 2 released packages changed, 1 changeset

Ablation (the feature). Mutation: the lookup call replaced by
[] as string[], so the loop body survives and only the key source dies. Proven
on disk before running — removed-text grep -c = 0, injected-text = 1, and
git hash-object differed from the HEAD blob. Both test files resolve
@object-ui/react through the root vitest alias to packages/react/src, so
both legs are source-resolved and no rebuild leg is involved. Result:
8 failed | 10 passed (the 10 are the negative/inert pins, which correctly
still hold under ablation). Restore leg proven byte-identically:
git hash-object back to 7f9427de8f203e55d960ac5f86359ed46a7ce000, matching
HEAD, and git diff HEAD empty.

Ablation (the floor). Same discipline on the manifest: reverted to
^17.0.0, confirmed on disk (git hash-object differed from the HEAD blob),
rebuilt, and read the gate — [floor-too-low], quoted above. Restored via trap.

Before/after on the pin: 4 failed | 8 passed → 12 passed.

File overlap to flag for review

packages/components/src/__tests__/skill-guide-provider-envelope.test.tsx is
also touched by live PR #6963, in a disjoint region (its COLUMNS fixture at
~L57–70; this PR's edits are the docblock at ~L20 and the assertion at ~L161).
Its a node-level title is read but never evaluated case pinned exactly the
defect this ruling retires, so it is flipped, with the undeclared-key case added
beside it so the file still states both fates.

Out of scope, filed separately

  • objectstack#13670 — the spec carriage map has no row for textvalue,
    although basic/text.tsx reads it at the node's top level and the guides teach
    it. Directly gates the scope of ruling item 2.
  • objectstack#13672 — the spec's button row cites action/action-button.tsx,
    but the map is keyed on the bare name, so action:button (5 corpus nodes)
    resolves to the empty set.

⛔ Draft, and staying draft: governed surface. Not marked ready, not enqueued, no
auto-merge. Direction 2 untouched and still rejected; Direction 3's shipped
render-time half (PR #5129) unaffected.

objectui#4795 Direction 1, maintainer ruling 2026-08-25. The evaluation memo
now evaluates the top-level text keys `@objectstack/spec` declares as
expression-bindable, consuming `expressionBindableTextKeysFor` rather than
keeping a twin list. `statistic.value` / `card.title` / `button.label` and
their siblings are now evaluated at the one place that produces evaluated
schema, so the existing top-level read-back sites see the evaluated value with
no per-component patch.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
…e gap
The published rules and three guides carried the now-retired claim that
`title`/`label`/`value`/`description` are never template-evaluated, and
prescribed host pre-resolution or a `text` node's `content` as the only routes.
objectui#4795 makes that false for the spec-declared rows, so protocol.md gains
a "Bindable Text Keys" rule and the guides point at it; the still-true half (an
undeclared type reads these keys raw) is kept and stated as the boundary.
`skill-guide-provider-envelope.test.tsx`'s node-key reading is flipped to the
new behaviour with the undeclared-key case added beside it, so the file still
states both fates.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
@github-actions

Copy link
Copy Markdown
Contributor

ℹ️ Console Performance Budget — not measured

This run did not produce a console bundle to measure, so there is no pass/fail verdict for the performance budget.

This is not a budget violation. Nothing was measured — the numbers a real violation would carry are simply absent.

StepOutcome
Build packagesskipped
Check console performance budgetskipped

See the workflow run for details.

No package size report: it is only generated from a complete package build, so a partial one is never shown.

…kfile
CI installs with `--frozen-lockfile`, which compares the recorded SPECIFIER,
not the resolved version — so bumping packages/react's range without
regenerating pnpm-lock.yaml failed the install before any job did work, taking
all 13 checks red with the build skipped.
The bump itself is required, and measured rather than assumed: with `^17.0.0`
restored and react rebuilt, `check:spec-floors` reports
@object-ui/react [floor-too-low] packages/react/dist/SchemaRenderer.js
references `expressionBindableTextKeysFor` from @objectstack/spec/ui, which
@objectstack/spec@17.0.0 does not export
so `^17.0.0` would be a false public claim (objectui#5793's defect class). The
same gate names the lowest honest floor as ^17.1.0 — not ^17.2.0, which this
branch declared on a misread CHANGELOG heading; the declaration shipped in
17.1.0. Floor corrected down to the truth rather than left over-claiming.
Lockfile regenerated with `pnpm install --lockfile-only`; the only change is
that one specifier line, and the resolved version stays 17.2.0, so nothing
about what installs changes. `pnpm install --frozen-lockfile` now exits 0
(reproduced failing at 3012daf first).
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 45 chunks)3180.2 KB3222.7 KB
Main entry chunk (gzip)143.6 KB350 KB
Entry fileindex-CotrOk53.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (consoleActionDispatch.js)0.20KB0.19KB
app-shell (index.js)12.46KB4.71KB
app-shell (runtime-config.js)20.68KB7.36KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (ActiveOrganizationStorage.js)25.05KB9.16KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)2.07KB1.00KB
auth (AuthProvider.js)40.18KB10.59KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)8.46KB3.43KB
auth (index.js)3.19KB1.44KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.30KB1.02KB
auth (useWorkspaceAdminStatus.js)5.13KB2.35KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)512.09KB116.42KB
core (index.js)5.30KB2.13KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)177.67KB49.45KB
fields (index.js)243.65KB61.63KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (fallbackInterpolation.js)6.25KB2.77KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)26.89KB9.04KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)5.60KB2.33KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)11.71KB4.29KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)6.24KB2.16KB
permissions (discardProofCache.js)1.04KB0.55KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)4.83KB2.27KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.92KB12.93KB
plugin-charts (index.js)64.68KB18.35KB
plugin-chatbot (index.js)190.53KB45.18KB
plugin-dashboard (index.js)133.48KB34.51KB
plugin-designer (index.js)212.87KB43.19KB
plugin-detail (index.js)247.26KB63.17KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)133.11KB32.61KB
plugin-gantt (index.js)165.21KB40.37KB
plugin-grid (index.js)202.08KB54.61KB
plugin-kanban (index.js)53.14KB14.64KB
plugin-list (index.js)113.15KB27.59KB
plugin-map (index.js)20.20KB6.66KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.51KB11.94KB
plugin-timeline (index.js)29.05KB8.37KB
plugin-tree (index.js)8.98KB3.08KB
plugin-view (index.js)85.79KB21.10KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)4.47KB1.63KB
react (SchemaRenderer.js)81.07KB26.86KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)3.11KB1.48KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (dashboard-widget-options.js)3.08KB1.30KB
sdui-parser (index.js)4.93KB2.24KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)20.57KB5.88KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.28KB0.23KB
sdui-parser (validate.js)10.35KB3.60KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)2.74KB1.41KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)3.75KB1.85KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.85KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (icon-key-migration.js)4.26KB1.63KB
types (index.js)4.72KB2.24KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (spec-ui-namespace.js)0.20KB0.19KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)6.28KB2.87KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-zhuang
os-zhuang marked this pull request as ready for review August 31, 2026 07:31
@os-zhuang
os-zhuang added this pull request to the merge queueAug 31, 2026
Merged via the queue into main with commit 1b1d772Aug 31, 2026
32 checks passed
@os-zhuang
os-zhuang deleted the claude/issue-4795-bindable-text-keys branch August 31, 2026 07:45
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@os-sam@os-zhuang@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(react): evaluate the spec-declared expression-bindable text keys - #6981

Merged
os-zhuang merged 3 commits into
mainfrom
claude/issue-4795-bindable-text-keys
Aug 31, 2026
Merged

feat(react): evaluate the spec-declared expression-bindable text keys#6981
os-zhuang merged 3 commits into
mainfrom
claude/issue-4795-bindable-text-keys

Conversation

@os-sam

@os-samos-sam commented Aug 31, 2026

Copy link
Copy Markdown
Collaborator

Refs #4795 — the evaluation half (ruling item 1) ships here in full. The
build-time rejection (ruling item 2) does not, for two independent reasons
stated below. This card must stay open: it still carries Direction 1's
restart record, the two parked sub-questions, and now item 2.

Authored in session session_013hfmP9hoMd3dJwTh85J4yB.

⛔ GOVERNED SURFACE — do not enqueue this PR

This diff touches four files under skills/, which is GOVERNED_SURFACES[2]
(id: 'skills-catalog') in scripts/check-governed-queue-guard.mjs. Asked
directly about this diff, the guard answers:

One governed path governs the WHOLE pull request — proportion is not a question.
⛔ Do not flip it ready, enqueue it, or arm auto-merge. Park it as a DRAFT and leave the merge
to the maintainer; a human merge IS the review record for a governed surface.

So this stays draft however green CI goes; a human (os-zhuang / hotlong)
merges it. ⚠️AGENTS.md line 378 says the opposite — that repo-root skills/**
is not governed and may take the ordinary self-enqueue path. That text is
stale (the guard landed under objectui#6596, 2026-08-27); the contradiction is
filed as #6975. The guard, not the doc, is authoritative here.

Premise re-verification (the unlock scan's mandatory re-pricing)

@objectstack/spec is installed and resolved in this worktree at 17.2.0, and it
does declare the closed set from objectstack#9599 — verified by reading the
installed package, not the card:

installed spec: 17.2.0
KEYS: [ 'title', 'label', 'value', 'description' ]
MAP: {"statistic":["label","value","description"],"card":["title","description"],"button":["label"]}

Hot controls, so the reading is a measurement rather than a hopeful grep:
COMPONENT_NODE_VISIBILITY_KEYS and ACTION_PARAM_BUILTIN_KEYS (both known
declared) → found; EXPRESSION_BINDABLE_NUMERIC_KEYS (a name that must not
exist) → 0 hits.

⚠️Correction, caught by a gate rather than by review. An earlier revision of
this PR said the declaration shipped in 17.2.0 and set packages/react's floor
to ^17.2.0. That was a misread of the spec CHANGELOG (the objectstack#9599
entry sits under the ## 17.1.0 heading, not the ## 17.2.0 one above it).
check:spec-floors computes the true floor from the built artifact and names it:
^17.1.0. Corrected down to the truth rather than left over-claiming — see
the CI-install section.

⚠️The upstream landing reshaped this card's Option 1. The ruling had a flat
four-key list in view; what actually shipped is that list plus a per-component
carriage map
statistic carries label/value/description, card
carries title/description, button carries label, and every other type
gets the frozen empty set. That difference is what most of the rest of this
PR body is about.

The card's title is false, and so was half of what the guides taught

Re-derived here rather than restated: with the properties envelope, value /
title / label were already both evaluated and read back before this PR (PR
#5122's evaluation leg plus the existing hoist). The two shapes that were
genuinely broken, and are what this PR fixes, are the top-level ones.

What ships

One leg in the evaluation memo (packages/react/src/SchemaRenderer.tsx),
beside the existing content leg:

for(constkeyofexpressionBindableTextKeysFor(typeofnewSchema.type==='string' ? newSchema.type : '',)){if(typeofnewSchema[key]==='string'){newSchema[key]=evaluator.evaluate(newSchema[key]);}}

Converged, not patched per component — this is the ruling's caution, and it is
a measurement here, not a promise.
data-display/statistic.tsx,
layout/card.tsx and form/button.tsx are not in this diff. They already
read these keys off the node; nothing was writing an evaluated value there. The
end-to-end test drives the real registered renderers and passes with those three
files untouched.

Two deliberate choices, both pinned:

  • The lookup is consumed, never copied. The only thing this file knows is
    the name of the function. A row added upstream starts working here with no
    edit.
  • The type string is passed verbatim — no ui: prefix stripping. The spec
    states the answer for an unlisted type is the empty set. Normalizing would
    look harmless and would in the same motion grant rows to element:button and
    page:card, whose renderers read config out of the bag via readProps() and
    never touch these keys on the node — re-manufacturing the
    evaluated-but-not-read-back half this card exists to close. The authored
    corpus also spells these types bare (statistic 42, card 135, button 158
    nodes; ui:* zero).

The CI install, and why the floor moves at all

The first push took all 13 checks red with the build skipped — the signature
of pnpm install dying before any job works. CI installs with
pnpm install --frozen-lockfile, which compares the recorded specifier, not
the resolved version. The manifest bump without a lockfile regen is exactly that
mismatch. Reproduced at 3012dafff before fixing:

ERR_PNPM_OUTDATED_LOCKFILE Cannot install with "frozen-lockfile" because
pnpm-lock.yaml is not up to date with <ROOT>/packages/react/package.json
specifiers in the lockfile don't match specifiers in package.json:

The bump is required on the merits, and that is measured, not assumed. With
^17.0.0 restored and packages/react rebuilt, check:spec-floors reports:

@object-ui/react [floor-too-low] packages/react/dist/SchemaRenderer.js references
`expressionBindableTextKeysFor` from @objectstack/spec/ui, which
@objectstack/spec@17.0.0 does not export
The lowest published spec that carries every symbol each package references:
@object-ui/react → "@objectstack/spec": "^17.1.0"

So reverting the manifest was not available: ^17.0.0 would be a false public
claim, objectui#5793's exact defect class ("the range is the claim, and the claim
is what is wrong"). Floor set to the gate-named ^17.1.0, lockfile regenerated
with pnpm install --lockfile-only. The lockfile diff is one line — the
specifier — and the resolved version stays 17.2.0, so nothing about what
installs changes. pnpm install --frozen-lockfile now exits 0.

Why the build-time rejection is NOT in this PR

Reason 1 — it would decide parked sub-question ③. Its only natural home is
objectui check (packages/cli/src/commands/check.ts). Whether to build the
publish-time half there is explicitly awaiting the maintainer. The file-contention
reason the earlier seat gave has lifted (no open PR touches packages/cli), so
this is the scope boundary, not a blocked file.

Reason 2 — the corpus measurement says the rejection's scope is undecided.
Clause-② required measuring before shipping the narrowing. Census over 736 JSON
documents and json doc fences (2747 typed nodes), counting top-level keys
whose value contains ${:

ClassCountUnder the ruling's literal wordingUnder the carriage map
Predicate keys (visible/hidden/disabled…)22exemptexempt
content5exemptexempt
Declared row (statistic.value, statistic.label)2accepted — now evaluatedaccepted
Closed-set key on an undeclared type32accepted (key is in the list)REJECTED
Key outside the closed set (badge.text, badge.variant, alert.message, chart.data, action.condition)8REJECTEDREJECTED

The two readings differ by 32 occurrences, and the difference is not a
detail:

  • 23 of them are type: "text" with value: "${…}" — taught across
    content/docs/guide/expressions.md and siblings. basic/text.tsx renders
    schema.content || schema.value, so text.value IS a real top-level
    read-back site; it simply has no spec row, so it renders the literal today.
    The literal reading accepts a form that visibly breaks; the carriage-map
    reading rejects the platform's own documented examples.
  • The remainder includes page.title — where type: "page" is a page
    document, not a component node, and title is the page's own title. A
    carriage-map gate needs a "what is a component node" rule the ruling never
    states.
  • Also stat-card.value ×4, on a type that is not registered at all.

The ruling's wording ("any key outside that closed list") selects the literal
reading; the ruling's stated goal ("no more blank renders or literal ${data.n}
reaching users") is only met by the carriage-map reading, which the wording
predates. That is a contract decision, and choosing it silently inside a
diagnostic is exactly what the dispatch forbids.

Docs

The published rules and three guides asserted the retired claim that these four
keys are never template-evaluated, and prescribed host pre-resolution as the
only route. page-builder.md went further: its "Also wrong" example was
{ "type": "statistic", "value": "${…}", "label": "${…}" } — which this PR
makes correct. Corrected surgically, with the still-true half (an undeclared
type reads these keys raw) kept and stated as the boundary.

Published-skills line readings, per the reporting rule:

FileBeforeAfterΔ
skills/objectui/rules/protocol.md275306+31
skills/objectui/guides/page-builder.md516522+6
skills/objectui/guides/schema-expressions.md625628+3
skills/objectui/guides/data-integration.md440441+1
Whole published package (18 files)56865726+40

Verification — all on the final commit ec519f94d

RunResult
pnpm install --frozen-lockfileexit 0 (reproduced failing at 3012dafff first)
vitest run packages/react/68 files / 838 tests passed
vitest run packages/components/220 files / 2018 tests passed
type-check (react, components)Done / exit 0 — react's runs tsc --noEmit && tsc -p tsconfig.test.json, so the new test files are typechecked
eslint . --no-inline-config (repo-wide, 4031 files)my 4 linted files: 0 errors; none of the 75 pre-existing error files are mine
check:spec-floors@object-ui/reactclears at ^17.1.0; 0floor-too-low; 3 residual findings all [no-artifact] on plugins outside this diff
check:governed-queue-guardself-test OK — 132 cases pass; asked about this diff, it names the four skills/ files and refuses the queue
check:skills-pathsOK (94/95 stated paths resolve; 1 baselined)
check:doc-fencesOK — every TypeScript block in 224 documents
check:doc-typesOK — every documented component type is registered
check:doc-snippets271 of 271 blocks judged, 0 failed (after the build it names)
check:control-bytes, check:phantom-deps, check:self-import, check:spec-symbolsall exit 0
check-changeset-presence✅ 4 source files of 2 released packages changed, 1 changeset

Ablation (the feature). Mutation: the lookup call replaced by
[] as string[], so the loop body survives and only the key source dies. Proven
on disk before running — removed-text grep -c = 0, injected-text = 1, and
git hash-object differed from the HEAD blob. Both test files resolve
@object-ui/react through the root vitest alias to packages/react/src, so
both legs are source-resolved and no rebuild leg is involved. Result:
8 failed | 10 passed (the 10 are the negative/inert pins, which correctly
still hold under ablation). Restore leg proven byte-identically:
git hash-object back to 7f9427de8f203e55d960ac5f86359ed46a7ce000, matching
HEAD, and git diff HEAD empty.

Ablation (the floor). Same discipline on the manifest: reverted to
^17.0.0, confirmed on disk (git hash-object differed from the HEAD blob),
rebuilt, and read the gate — [floor-too-low], quoted above. Restored via trap.

Before/after on the pin: 4 failed | 8 passed → 12 passed.

File overlap to flag for review

packages/components/src/__tests__/skill-guide-provider-envelope.test.tsx is
also touched by live PR #6963, in a disjoint region (its COLUMNS fixture at
~L57–70; this PR's edits are the docblock at ~L20 and the assertion at ~L161).
Its a node-level title is read but never evaluated case pinned exactly the
defect this ruling retires, so it is flipped, with the undeclared-key case added
beside it so the file still states both fates.

Out of scope, filed separately

  • objectstack#13670 — the spec carriage map has no row for textvalue,
    although basic/text.tsx reads it at the node's top level and the guides teach
    it. Directly gates the scope of ruling item 2.
  • objectstack#13672 — the spec's button row cites action/action-button.tsx,
    but the map is keyed on the bare name, so action:button (5 corpus nodes)
    resolves to the empty set.

⛔ Draft, and staying draft: governed surface. Not marked ready, not enqueued, no
auto-merge. Direction 2 untouched and still rejected; Direction 3's shipped
render-time half (PR #5129) unaffected.

objectui#4795 Direction 1, maintainer ruling 2026-08-25. The evaluation memo
now evaluates the top-level text keys `@objectstack/spec` declares as
expression-bindable, consuming `expressionBindableTextKeysFor` rather than
keeping a twin list. `statistic.value` / `card.title` / `button.label` and
their siblings are now evaluated at the one place that produces evaluated
schema, so the existing top-level read-back sites see the evaluated value with
no per-component patch.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
…e gap
The published rules and three guides carried the now-retired claim that
`title`/`label`/`value`/`description` are never template-evaluated, and
prescribed host pre-resolution or a `text` node's `content` as the only routes.
objectui#4795 makes that false for the spec-declared rows, so protocol.md gains
a "Bindable Text Keys" rule and the guides point at it; the still-true half (an
undeclared type reads these keys raw) is kept and stated as the boundary.
`skill-guide-provider-envelope.test.tsx`'s node-key reading is flipped to the
new behaviour with the undeclared-key case added beside it, so the file still
states both fates.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
@github-actions

Copy link
Copy Markdown
Contributor

ℹ️ Console Performance Budget — not measured

This run did not produce a console bundle to measure, so there is no pass/fail verdict for the performance budget.

This is not a budget violation. Nothing was measured — the numbers a real violation would carry are simply absent.

StepOutcome
Build packagesskipped
Check console performance budgetskipped

See the workflow run for details.

No package size report: it is only generated from a complete package build, so a partial one is never shown.

…kfile
CI installs with `--frozen-lockfile`, which compares the recorded SPECIFIER,
not the resolved version — so bumping packages/react's range without
regenerating pnpm-lock.yaml failed the install before any job did work, taking
all 13 checks red with the build skipped.
The bump itself is required, and measured rather than assumed: with `^17.0.0`
restored and react rebuilt, `check:spec-floors` reports
@object-ui/react [floor-too-low] packages/react/dist/SchemaRenderer.js
references `expressionBindableTextKeysFor` from @objectstack/spec/ui, which
@objectstack/spec@17.0.0 does not export
so `^17.0.0` would be a false public claim (objectui#5793's defect class). The
same gate names the lowest honest floor as ^17.1.0 — not ^17.2.0, which this
branch declared on a misread CHANGELOG heading; the declaration shipped in
17.1.0. Floor corrected down to the truth rather than left over-claiming.
Lockfile regenerated with `pnpm install --lockfile-only`; the only change is
that one specifier line, and the resolved version stays 17.2.0, so nothing
about what installs changes. `pnpm install --frozen-lockfile` now exits 0
(reproduced failing at 3012daf first).
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 45 chunks)3180.2 KB3222.7 KB
Main entry chunk (gzip)143.6 KB350 KB
Entry fileindex-CotrOk53.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (consoleActionDispatch.js)0.20KB0.19KB
app-shell (index.js)12.46KB4.71KB
app-shell (runtime-config.js)20.68KB7.36KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (ActiveOrganizationStorage.js)25.05KB9.16KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)2.07KB1.00KB
auth (AuthProvider.js)40.18KB10.59KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)8.46KB3.43KB
auth (index.js)3.19KB1.44KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.30KB1.02KB
auth (useWorkspaceAdminStatus.js)5.13KB2.35KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)512.09KB116.42KB
core (index.js)5.30KB2.13KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)177.67KB49.45KB
fields (index.js)243.65KB61.63KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (fallbackInterpolation.js)6.25KB2.77KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)26.89KB9.04KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)5.60KB2.33KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)11.71KB4.29KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)6.24KB2.16KB
permissions (discardProofCache.js)1.04KB0.55KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)4.83KB2.27KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.92KB12.93KB
plugin-charts (index.js)64.68KB18.35KB
plugin-chatbot (index.js)190.53KB45.18KB
plugin-dashboard (index.js)133.48KB34.51KB
plugin-designer (index.js)212.87KB43.19KB
plugin-detail (index.js)247.26KB63.17KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)133.11KB32.61KB
plugin-gantt (index.js)165.21KB40.37KB
plugin-grid (index.js)202.08KB54.61KB
plugin-kanban (index.js)53.14KB14.64KB
plugin-list (index.js)113.15KB27.59KB
plugin-map (index.js)20.20KB6.66KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.51KB11.94KB
plugin-timeline (index.js)29.05KB8.37KB
plugin-tree (index.js)8.98KB3.08KB
plugin-view (index.js)85.79KB21.10KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)4.47KB1.63KB
react (SchemaRenderer.js)81.07KB26.86KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)3.11KB1.48KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (dashboard-widget-options.js)3.08KB1.30KB
sdui-parser (index.js)4.93KB2.24KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)20.57KB5.88KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.28KB0.23KB
sdui-parser (validate.js)10.35KB3.60KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)2.74KB1.41KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)3.75KB1.85KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.85KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (icon-key-migration.js)4.26KB1.63KB
types (index.js)4.72KB2.24KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (spec-ui-namespace.js)0.20KB0.19KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)6.28KB2.87KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-zhuang
os-zhuang marked this pull request as ready for review August 31, 2026 07:31
@os-zhuang
os-zhuang added this pull request to the merge queueAug 31, 2026
Merged via the queue into main with commit 1b1d772Aug 31, 2026
32 checks passed
@os-zhuang
os-zhuang deleted the claude/issue-4795-bindable-text-keys branch August 31, 2026 07:45
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@os-sam@os-zhuang@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

feat(react): evaluate the spec-declared expression-bindable text keys - #6981

Merged
os-zhuang merged 3 commits into
mainfrom
claude/issue-4795-bindable-text-keys
Aug 31, 2026
Merged

feat(react): evaluate the spec-declared expression-bindable text keys#6981
os-zhuang merged 3 commits into
mainfrom
claude/issue-4795-bindable-text-keys

Conversation

@os-sam

@os-samos-sam commented Aug 31, 2026

Copy link
Copy Markdown
Collaborator

Refs #4795 — the evaluation half (ruling item 1) ships here in full. The
build-time rejection (ruling item 2) does not, for two independent reasons
stated below. This card must stay open: it still carries Direction 1's
restart record, the two parked sub-questions, and now item 2.

Authored in session session_013hfmP9hoMd3dJwTh85J4yB.

⛔ GOVERNED SURFACE — do not enqueue this PR

This diff touches four files under skills/, which is GOVERNED_SURFACES[2]
(id: 'skills-catalog') in scripts/check-governed-queue-guard.mjs. Asked
directly about this diff, the guard answers:

One governed path governs the WHOLE pull request — proportion is not a question.
⛔ Do not flip it ready, enqueue it, or arm auto-merge. Park it as a DRAFT and leave the merge
to the maintainer; a human merge IS the review record for a governed surface.

So this stays draft however green CI goes; a human (os-zhuang / hotlong)
merges it. ⚠️AGENTS.md line 378 says the opposite — that repo-root skills/**
is not governed and may take the ordinary self-enqueue path. That text is
stale (the guard landed under objectui#6596, 2026-08-27); the contradiction is
filed as #6975. The guard, not the doc, is authoritative here.

Premise re-verification (the unlock scan's mandatory re-pricing)

@objectstack/spec is installed and resolved in this worktree at 17.2.0, and it
does declare the closed set from objectstack#9599 — verified by reading the
installed package, not the card:

installed spec: 17.2.0
KEYS: [ 'title', 'label', 'value', 'description' ]
MAP: {"statistic":["label","value","description"],"card":["title","description"],"button":["label"]}

Hot controls, so the reading is a measurement rather than a hopeful grep:
COMPONENT_NODE_VISIBILITY_KEYS and ACTION_PARAM_BUILTIN_KEYS (both known
declared) → found; EXPRESSION_BINDABLE_NUMERIC_KEYS (a name that must not
exist) → 0 hits.

⚠️Correction, caught by a gate rather than by review. An earlier revision of
this PR said the declaration shipped in 17.2.0 and set packages/react's floor
to ^17.2.0. That was a misread of the spec CHANGELOG (the objectstack#9599
entry sits under the ## 17.1.0 heading, not the ## 17.2.0 one above it).
check:spec-floors computes the true floor from the built artifact and names it:
^17.1.0. Corrected down to the truth rather than left over-claiming — see
the CI-install section.

⚠️The upstream landing reshaped this card's Option 1. The ruling had a flat
four-key list in view; what actually shipped is that list plus a per-component
carriage map
statistic carries label/value/description, card
carries title/description, button carries label, and every other type
gets the frozen empty set. That difference is what most of the rest of this
PR body is about.

The card's title is false, and so was half of what the guides taught

Re-derived here rather than restated: with the properties envelope, value /
title / label were already both evaluated and read back before this PR (PR
#5122's evaluation leg plus the existing hoist). The two shapes that were
genuinely broken, and are what this PR fixes, are the top-level ones.

What ships

One leg in the evaluation memo (packages/react/src/SchemaRenderer.tsx),
beside the existing content leg:

for(constkeyofexpressionBindableTextKeysFor(typeofnewSchema.type==='string' ? newSchema.type : '',)){if(typeofnewSchema[key]==='string'){newSchema[key]=evaluator.evaluate(newSchema[key]);}}

Converged, not patched per component — this is the ruling's caution, and it is
a measurement here, not a promise.
data-display/statistic.tsx,
layout/card.tsx and form/button.tsx are not in this diff. They already
read these keys off the node; nothing was writing an evaluated value there. The
end-to-end test drives the real registered renderers and passes with those three
files untouched.

Two deliberate choices, both pinned:

  • The lookup is consumed, never copied. The only thing this file knows is
    the name of the function. A row added upstream starts working here with no
    edit.
  • The type string is passed verbatim — no ui: prefix stripping. The spec
    states the answer for an unlisted type is the empty set. Normalizing would
    look harmless and would in the same motion grant rows to element:button and
    page:card, whose renderers read config out of the bag via readProps() and
    never touch these keys on the node — re-manufacturing the
    evaluated-but-not-read-back half this card exists to close. The authored
    corpus also spells these types bare (statistic 42, card 135, button 158
    nodes; ui:* zero).

The CI install, and why the floor moves at all

The first push took all 13 checks red with the build skipped — the signature
of pnpm install dying before any job works. CI installs with
pnpm install --frozen-lockfile, which compares the recorded specifier, not
the resolved version. The manifest bump without a lockfile regen is exactly that
mismatch. Reproduced at 3012dafff before fixing:

ERR_PNPM_OUTDATED_LOCKFILE Cannot install with "frozen-lockfile" because
pnpm-lock.yaml is not up to date with <ROOT>/packages/react/package.json
specifiers in the lockfile don't match specifiers in package.json:

The bump is required on the merits, and that is measured, not assumed. With
^17.0.0 restored and packages/react rebuilt, check:spec-floors reports:

@object-ui/react [floor-too-low] packages/react/dist/SchemaRenderer.js references
`expressionBindableTextKeysFor` from @objectstack/spec/ui, which
@objectstack/spec@17.0.0 does not export
The lowest published spec that carries every symbol each package references:
@object-ui/react → "@objectstack/spec": "^17.1.0"

So reverting the manifest was not available: ^17.0.0 would be a false public
claim, objectui#5793's exact defect class ("the range is the claim, and the claim
is what is wrong"). Floor set to the gate-named ^17.1.0, lockfile regenerated
with pnpm install --lockfile-only. The lockfile diff is one line — the
specifier — and the resolved version stays 17.2.0, so nothing about what
installs changes. pnpm install --frozen-lockfile now exits 0.

Why the build-time rejection is NOT in this PR

Reason 1 — it would decide parked sub-question ③. Its only natural home is
objectui check (packages/cli/src/commands/check.ts). Whether to build the
publish-time half there is explicitly awaiting the maintainer. The file-contention
reason the earlier seat gave has lifted (no open PR touches packages/cli), so
this is the scope boundary, not a blocked file.

Reason 2 — the corpus measurement says the rejection's scope is undecided.
Clause-② required measuring before shipping the narrowing. Census over 736 JSON
documents and json doc fences (2747 typed nodes), counting top-level keys
whose value contains ${:

ClassCountUnder the ruling's literal wordingUnder the carriage map
Predicate keys (visible/hidden/disabled…)22exemptexempt
content5exemptexempt
Declared row (statistic.value, statistic.label)2accepted — now evaluatedaccepted
Closed-set key on an undeclared type32accepted (key is in the list)REJECTED
Key outside the closed set (badge.text, badge.variant, alert.message, chart.data, action.condition)8REJECTEDREJECTED

The two readings differ by 32 occurrences, and the difference is not a
detail:

  • 23 of them are type: "text" with value: "${…}" — taught across
    content/docs/guide/expressions.md and siblings. basic/text.tsx renders
    schema.content || schema.value, so text.value IS a real top-level
    read-back site; it simply has no spec row, so it renders the literal today.
    The literal reading accepts a form that visibly breaks; the carriage-map
    reading rejects the platform's own documented examples.
  • The remainder includes page.title — where type: "page" is a page
    document, not a component node, and title is the page's own title. A
    carriage-map gate needs a "what is a component node" rule the ruling never
    states.
  • Also stat-card.value ×4, on a type that is not registered at all.

The ruling's wording ("any key outside that closed list") selects the literal
reading; the ruling's stated goal ("no more blank renders or literal ${data.n}
reaching users") is only met by the carriage-map reading, which the wording
predates. That is a contract decision, and choosing it silently inside a
diagnostic is exactly what the dispatch forbids.

Docs

The published rules and three guides asserted the retired claim that these four
keys are never template-evaluated, and prescribed host pre-resolution as the
only route. page-builder.md went further: its "Also wrong" example was
{ "type": "statistic", "value": "${…}", "label": "${…}" } — which this PR
makes correct. Corrected surgically, with the still-true half (an undeclared
type reads these keys raw) kept and stated as the boundary.

Published-skills line readings, per the reporting rule:

FileBeforeAfterΔ
skills/objectui/rules/protocol.md275306+31
skills/objectui/guides/page-builder.md516522+6
skills/objectui/guides/schema-expressions.md625628+3
skills/objectui/guides/data-integration.md440441+1
Whole published package (18 files)56865726+40

Verification — all on the final commit ec519f94d

RunResult
pnpm install --frozen-lockfileexit 0 (reproduced failing at 3012dafff first)
vitest run packages/react/68 files / 838 tests passed
vitest run packages/components/220 files / 2018 tests passed
type-check (react, components)Done / exit 0 — react's runs tsc --noEmit && tsc -p tsconfig.test.json, so the new test files are typechecked
eslint . --no-inline-config (repo-wide, 4031 files)my 4 linted files: 0 errors; none of the 75 pre-existing error files are mine
check:spec-floors@object-ui/reactclears at ^17.1.0; 0floor-too-low; 3 residual findings all [no-artifact] on plugins outside this diff
check:governed-queue-guardself-test OK — 132 cases pass; asked about this diff, it names the four skills/ files and refuses the queue
check:skills-pathsOK (94/95 stated paths resolve; 1 baselined)
check:doc-fencesOK — every TypeScript block in 224 documents
check:doc-typesOK — every documented component type is registered
check:doc-snippets271 of 271 blocks judged, 0 failed (after the build it names)
check:control-bytes, check:phantom-deps, check:self-import, check:spec-symbolsall exit 0
check-changeset-presence✅ 4 source files of 2 released packages changed, 1 changeset

Ablation (the feature). Mutation: the lookup call replaced by
[] as string[], so the loop body survives and only the key source dies. Proven
on disk before running — removed-text grep -c = 0, injected-text = 1, and
git hash-object differed from the HEAD blob. Both test files resolve
@object-ui/react through the root vitest alias to packages/react/src, so
both legs are source-resolved and no rebuild leg is involved. Result:
8 failed | 10 passed (the 10 are the negative/inert pins, which correctly
still hold under ablation). Restore leg proven byte-identically:
git hash-object back to 7f9427de8f203e55d960ac5f86359ed46a7ce000, matching
HEAD, and git diff HEAD empty.

Ablation (the floor). Same discipline on the manifest: reverted to
^17.0.0, confirmed on disk (git hash-object differed from the HEAD blob),
rebuilt, and read the gate — [floor-too-low], quoted above. Restored via trap.

Before/after on the pin: 4 failed | 8 passed → 12 passed.

File overlap to flag for review

packages/components/src/__tests__/skill-guide-provider-envelope.test.tsx is
also touched by live PR #6963, in a disjoint region (its COLUMNS fixture at
~L57–70; this PR's edits are the docblock at ~L20 and the assertion at ~L161).
Its a node-level title is read but never evaluated case pinned exactly the
defect this ruling retires, so it is flipped, with the undeclared-key case added
beside it so the file still states both fates.

Out of scope, filed separately

  • objectstack#13670 — the spec carriage map has no row for textvalue,
    although basic/text.tsx reads it at the node's top level and the guides teach
    it. Directly gates the scope of ruling item 2.
  • objectstack#13672 — the spec's button row cites action/action-button.tsx,
    but the map is keyed on the bare name, so action:button (5 corpus nodes)
    resolves to the empty set.

⛔ Draft, and staying draft: governed surface. Not marked ready, not enqueued, no
auto-merge. Direction 2 untouched and still rejected; Direction 3's shipped
render-time half (PR #5129) unaffected.

objectui#4795 Direction 1, maintainer ruling 2026-08-25. The evaluation memo
now evaluates the top-level text keys `@objectstack/spec` declares as
expression-bindable, consuming `expressionBindableTextKeysFor` rather than
keeping a twin list. `statistic.value` / `card.title` / `button.label` and
their siblings are now evaluated at the one place that produces evaluated
schema, so the existing top-level read-back sites see the evaluated value with
no per-component patch.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
…e gap
The published rules and three guides carried the now-retired claim that
`title`/`label`/`value`/`description` are never template-evaluated, and
prescribed host pre-resolution or a `text` node's `content` as the only routes.
objectui#4795 makes that false for the spec-declared rows, so protocol.md gains
a "Bindable Text Keys" rule and the guides point at it; the still-true half (an
undeclared type reads these keys raw) is kept and stated as the boundary.
`skill-guide-provider-envelope.test.tsx`'s node-key reading is flipped to the
new behaviour with the undeclared-key case added beside it, so the file still
states both fates.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
@github-actions

Copy link
Copy Markdown
Contributor

ℹ️ Console Performance Budget — not measured

This run did not produce a console bundle to measure, so there is no pass/fail verdict for the performance budget.

This is not a budget violation. Nothing was measured — the numbers a real violation would carry are simply absent.

StepOutcome
Build packagesskipped
Check console performance budgetskipped

See the workflow run for details.

No package size report: it is only generated from a complete package build, so a partial one is never shown.

…kfile
CI installs with `--frozen-lockfile`, which compares the recorded SPECIFIER,
not the resolved version — so bumping packages/react's range without
regenerating pnpm-lock.yaml failed the install before any job did work, taking
all 13 checks red with the build skipped.
The bump itself is required, and measured rather than assumed: with `^17.0.0`
restored and react rebuilt, `check:spec-floors` reports
@object-ui/react [floor-too-low] packages/react/dist/SchemaRenderer.js
references `expressionBindableTextKeysFor` from @objectstack/spec/ui, which
@objectstack/spec@17.0.0 does not export
so `^17.0.0` would be a false public claim (objectui#5793's defect class). The
same gate names the lowest honest floor as ^17.1.0 — not ^17.2.0, which this
branch declared on a misread CHANGELOG heading; the declaration shipped in
17.1.0. Floor corrected down to the truth rather than left over-claiming.
Lockfile regenerated with `pnpm install --lockfile-only`; the only change is
that one specifier line, and the resolved version stays 17.2.0, so nothing
about what installs changes. `pnpm install --frozen-lockfile` now exits 0
(reproduced failing at 3012daf first).
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 45 chunks)3180.2 KB3222.7 KB
Main entry chunk (gzip)143.6 KB350 KB
Entry fileindex-CotrOk53.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (consoleActionDispatch.js)0.20KB0.19KB
app-shell (index.js)12.46KB4.71KB
app-shell (runtime-config.js)20.68KB7.36KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (ActiveOrganizationStorage.js)25.05KB9.16KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)2.07KB1.00KB
auth (AuthProvider.js)40.18KB10.59KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)8.46KB3.43KB
auth (index.js)3.19KB1.44KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.30KB1.02KB
auth (useWorkspaceAdminStatus.js)5.13KB2.35KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)512.09KB116.42KB
core (index.js)5.30KB2.13KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)177.67KB49.45KB
fields (index.js)243.65KB61.63KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (fallbackInterpolation.js)6.25KB2.77KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)26.89KB9.04KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)5.60KB2.33KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)11.71KB4.29KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)6.24KB2.16KB
permissions (discardProofCache.js)1.04KB0.55KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)4.83KB2.27KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.92KB12.93KB
plugin-charts (index.js)64.68KB18.35KB
plugin-chatbot (index.js)190.53KB45.18KB
plugin-dashboard (index.js)133.48KB34.51KB
plugin-designer (index.js)212.87KB43.19KB
plugin-detail (index.js)247.26KB63.17KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)133.11KB32.61KB
plugin-gantt (index.js)165.21KB40.37KB
plugin-grid (index.js)202.08KB54.61KB
plugin-kanban (index.js)53.14KB14.64KB
plugin-list (index.js)113.15KB27.59KB
plugin-map (index.js)20.20KB6.66KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.51KB11.94KB
plugin-timeline (index.js)29.05KB8.37KB
plugin-tree (index.js)8.98KB3.08KB
plugin-view (index.js)85.79KB21.10KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)4.47KB1.63KB
react (SchemaRenderer.js)81.07KB26.86KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)3.11KB1.48KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (dashboard-widget-options.js)3.08KB1.30KB
sdui-parser (index.js)4.93KB2.24KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)20.57KB5.88KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.28KB0.23KB
sdui-parser (validate.js)10.35KB3.60KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)2.74KB1.41KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)3.75KB1.85KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.85KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (icon-key-migration.js)4.26KB1.63KB
types (index.js)4.72KB2.24KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (spec-ui-namespace.js)0.20KB0.19KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)6.28KB2.87KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-zhuang
os-zhuang marked this pull request as ready for review August 31, 2026 07:31
@os-zhuang
os-zhuang added this pull request to the merge queueAug 31, 2026
Merged via the queue into main with commit 1b1d772Aug 31, 2026
32 checks passed
@os-zhuang
os-zhuang deleted the claude/issue-4795-bindable-text-keys branch August 31, 2026 07:45
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@os-sam@os-zhuang@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(react): evaluate the spec-declared expression-bindable text keys - #6981

Merged
os-zhuang merged 3 commits into
mainfrom
claude/issue-4795-bindable-text-keys
Aug 31, 2026
Merged

feat(react): evaluate the spec-declared expression-bindable text keys#6981
os-zhuang merged 3 commits into
mainfrom
claude/issue-4795-bindable-text-keys

Conversation

@os-sam

@os-samos-sam commented Aug 31, 2026

Copy link
Copy Markdown
Collaborator

Refs #4795 — the evaluation half (ruling item 1) ships here in full. The
build-time rejection (ruling item 2) does not, for two independent reasons
stated below. This card must stay open: it still carries Direction 1's
restart record, the two parked sub-questions, and now item 2.

Authored in session session_013hfmP9hoMd3dJwTh85J4yB.

⛔ GOVERNED SURFACE — do not enqueue this PR

This diff touches four files under skills/, which is GOVERNED_SURFACES[2]
(id: 'skills-catalog') in scripts/check-governed-queue-guard.mjs. Asked
directly about this diff, the guard answers:

One governed path governs the WHOLE pull request — proportion is not a question.
⛔ Do not flip it ready, enqueue it, or arm auto-merge. Park it as a DRAFT and leave the merge
to the maintainer; a human merge IS the review record for a governed surface.

So this stays draft however green CI goes; a human (os-zhuang / hotlong)
merges it. ⚠️AGENTS.md line 378 says the opposite — that repo-root skills/**
is not governed and may take the ordinary self-enqueue path. That text is
stale (the guard landed under objectui#6596, 2026-08-27); the contradiction is
filed as #6975. The guard, not the doc, is authoritative here.

Premise re-verification (the unlock scan's mandatory re-pricing)

@objectstack/spec is installed and resolved in this worktree at 17.2.0, and it
does declare the closed set from objectstack#9599 — verified by reading the
installed package, not the card:

installed spec: 17.2.0
KEYS: [ 'title', 'label', 'value', 'description' ]
MAP: {"statistic":["label","value","description"],"card":["title","description"],"button":["label"]}

Hot controls, so the reading is a measurement rather than a hopeful grep:
COMPONENT_NODE_VISIBILITY_KEYS and ACTION_PARAM_BUILTIN_KEYS (both known
declared) → found; EXPRESSION_BINDABLE_NUMERIC_KEYS (a name that must not
exist) → 0 hits.

⚠️Correction, caught by a gate rather than by review. An earlier revision of
this PR said the declaration shipped in 17.2.0 and set packages/react's floor
to ^17.2.0. That was a misread of the spec CHANGELOG (the objectstack#9599
entry sits under the ## 17.1.0 heading, not the ## 17.2.0 one above it).
check:spec-floors computes the true floor from the built artifact and names it:
^17.1.0. Corrected down to the truth rather than left over-claiming — see
the CI-install section.

⚠️The upstream landing reshaped this card's Option 1. The ruling had a flat
four-key list in view; what actually shipped is that list plus a per-component
carriage map
statistic carries label/value/description, card
carries title/description, button carries label, and every other type
gets the frozen empty set. That difference is what most of the rest of this
PR body is about.

The card's title is false, and so was half of what the guides taught

Re-derived here rather than restated: with the properties envelope, value /
title / label were already both evaluated and read back before this PR (PR
#5122's evaluation leg plus the existing hoist). The two shapes that were
genuinely broken, and are what this PR fixes, are the top-level ones.

What ships

One leg in the evaluation memo (packages/react/src/SchemaRenderer.tsx),
beside the existing content leg:

for(constkeyofexpressionBindableTextKeysFor(typeofnewSchema.type==='string' ? newSchema.type : '',)){if(typeofnewSchema[key]==='string'){newSchema[key]=evaluator.evaluate(newSchema[key]);}}

Converged, not patched per component — this is the ruling's caution, and it is
a measurement here, not a promise.
data-display/statistic.tsx,
layout/card.tsx and form/button.tsx are not in this diff. They already
read these keys off the node; nothing was writing an evaluated value there. The
end-to-end test drives the real registered renderers and passes with those three
files untouched.

Two deliberate choices, both pinned:

  • The lookup is consumed, never copied. The only thing this file knows is
    the name of the function. A row added upstream starts working here with no
    edit.
  • The type string is passed verbatim — no ui: prefix stripping. The spec
    states the answer for an unlisted type is the empty set. Normalizing would
    look harmless and would in the same motion grant rows to element:button and
    page:card, whose renderers read config out of the bag via readProps() and
    never touch these keys on the node — re-manufacturing the
    evaluated-but-not-read-back half this card exists to close. The authored
    corpus also spells these types bare (statistic 42, card 135, button 158
    nodes; ui:* zero).

The CI install, and why the floor moves at all

The first push took all 13 checks red with the build skipped — the signature
of pnpm install dying before any job works. CI installs with
pnpm install --frozen-lockfile, which compares the recorded specifier, not
the resolved version. The manifest bump without a lockfile regen is exactly that
mismatch. Reproduced at 3012dafff before fixing:

ERR_PNPM_OUTDATED_LOCKFILE Cannot install with "frozen-lockfile" because
pnpm-lock.yaml is not up to date with <ROOT>/packages/react/package.json
specifiers in the lockfile don't match specifiers in package.json:

The bump is required on the merits, and that is measured, not assumed. With
^17.0.0 restored and packages/react rebuilt, check:spec-floors reports:

@object-ui/react [floor-too-low] packages/react/dist/SchemaRenderer.js references
`expressionBindableTextKeysFor` from @objectstack/spec/ui, which
@objectstack/spec@17.0.0 does not export
The lowest published spec that carries every symbol each package references:
@object-ui/react → "@objectstack/spec": "^17.1.0"

So reverting the manifest was not available: ^17.0.0 would be a false public
claim, objectui#5793's exact defect class ("the range is the claim, and the claim
is what is wrong"). Floor set to the gate-named ^17.1.0, lockfile regenerated
with pnpm install --lockfile-only. The lockfile diff is one line — the
specifier — and the resolved version stays 17.2.0, so nothing about what
installs changes. pnpm install --frozen-lockfile now exits 0.

Why the build-time rejection is NOT in this PR

Reason 1 — it would decide parked sub-question ③. Its only natural home is
objectui check (packages/cli/src/commands/check.ts). Whether to build the
publish-time half there is explicitly awaiting the maintainer. The file-contention
reason the earlier seat gave has lifted (no open PR touches packages/cli), so
this is the scope boundary, not a blocked file.

Reason 2 — the corpus measurement says the rejection's scope is undecided.
Clause-② required measuring before shipping the narrowing. Census over 736 JSON
documents and json doc fences (2747 typed nodes), counting top-level keys
whose value contains ${:

ClassCountUnder the ruling's literal wordingUnder the carriage map
Predicate keys (visible/hidden/disabled…)22exemptexempt
content5exemptexempt
Declared row (statistic.value, statistic.label)2accepted — now evaluatedaccepted
Closed-set key on an undeclared type32accepted (key is in the list)REJECTED
Key outside the closed set (badge.text, badge.variant, alert.message, chart.data, action.condition)8REJECTEDREJECTED

The two readings differ by 32 occurrences, and the difference is not a
detail:

  • 23 of them are type: "text" with value: "${…}" — taught across
    content/docs/guide/expressions.md and siblings. basic/text.tsx renders
    schema.content || schema.value, so text.value IS a real top-level
    read-back site; it simply has no spec row, so it renders the literal today.
    The literal reading accepts a form that visibly breaks; the carriage-map
    reading rejects the platform's own documented examples.
  • The remainder includes page.title — where type: "page" is a page
    document, not a component node, and title is the page's own title. A
    carriage-map gate needs a "what is a component node" rule the ruling never
    states.
  • Also stat-card.value ×4, on a type that is not registered at all.

The ruling's wording ("any key outside that closed list") selects the literal
reading; the ruling's stated goal ("no more blank renders or literal ${data.n}
reaching users") is only met by the carriage-map reading, which the wording
predates. That is a contract decision, and choosing it silently inside a
diagnostic is exactly what the dispatch forbids.

Docs

The published rules and three guides asserted the retired claim that these four
keys are never template-evaluated, and prescribed host pre-resolution as the
only route. page-builder.md went further: its "Also wrong" example was
{ "type": "statistic", "value": "${…}", "label": "${…}" } — which this PR
makes correct. Corrected surgically, with the still-true half (an undeclared
type reads these keys raw) kept and stated as the boundary.

Published-skills line readings, per the reporting rule:

FileBeforeAfterΔ
skills/objectui/rules/protocol.md275306+31
skills/objectui/guides/page-builder.md516522+6
skills/objectui/guides/schema-expressions.md625628+3
skills/objectui/guides/data-integration.md440441+1
Whole published package (18 files)56865726+40

Verification — all on the final commit ec519f94d

RunResult
pnpm install --frozen-lockfileexit 0 (reproduced failing at 3012dafff first)
vitest run packages/react/68 files / 838 tests passed
vitest run packages/components/220 files / 2018 tests passed
type-check (react, components)Done / exit 0 — react's runs tsc --noEmit && tsc -p tsconfig.test.json, so the new test files are typechecked
eslint . --no-inline-config (repo-wide, 4031 files)my 4 linted files: 0 errors; none of the 75 pre-existing error files are mine
check:spec-floors@object-ui/reactclears at ^17.1.0; 0floor-too-low; 3 residual findings all [no-artifact] on plugins outside this diff
check:governed-queue-guardself-test OK — 132 cases pass; asked about this diff, it names the four skills/ files and refuses the queue
check:skills-pathsOK (94/95 stated paths resolve; 1 baselined)
check:doc-fencesOK — every TypeScript block in 224 documents
check:doc-typesOK — every documented component type is registered
check:doc-snippets271 of 271 blocks judged, 0 failed (after the build it names)
check:control-bytes, check:phantom-deps, check:self-import, check:spec-symbolsall exit 0
check-changeset-presence✅ 4 source files of 2 released packages changed, 1 changeset

Ablation (the feature). Mutation: the lookup call replaced by
[] as string[], so the loop body survives and only the key source dies. Proven
on disk before running — removed-text grep -c = 0, injected-text = 1, and
git hash-object differed from the HEAD blob. Both test files resolve
@object-ui/react through the root vitest alias to packages/react/src, so
both legs are source-resolved and no rebuild leg is involved. Result:
8 failed | 10 passed (the 10 are the negative/inert pins, which correctly
still hold under ablation). Restore leg proven byte-identically:
git hash-object back to 7f9427de8f203e55d960ac5f86359ed46a7ce000, matching
HEAD, and git diff HEAD empty.

Ablation (the floor). Same discipline on the manifest: reverted to
^17.0.0, confirmed on disk (git hash-object differed from the HEAD blob),
rebuilt, and read the gate — [floor-too-low], quoted above. Restored via trap.

Before/after on the pin: 4 failed | 8 passed → 12 passed.

File overlap to flag for review

packages/components/src/__tests__/skill-guide-provider-envelope.test.tsx is
also touched by live PR #6963, in a disjoint region (its COLUMNS fixture at
~L57–70; this PR's edits are the docblock at ~L20 and the assertion at ~L161).
Its a node-level title is read but never evaluated case pinned exactly the
defect this ruling retires, so it is flipped, with the undeclared-key case added
beside it so the file still states both fates.

Out of scope, filed separately

  • objectstack#13670 — the spec carriage map has no row for textvalue,
    although basic/text.tsx reads it at the node's top level and the guides teach
    it. Directly gates the scope of ruling item 2.
  • objectstack#13672 — the spec's button row cites action/action-button.tsx,
    but the map is keyed on the bare name, so action:button (5 corpus nodes)
    resolves to the empty set.

⛔ Draft, and staying draft: governed surface. Not marked ready, not enqueued, no
auto-merge. Direction 2 untouched and still rejected; Direction 3's shipped
render-time half (PR #5129) unaffected.

objectui#4795 Direction 1, maintainer ruling 2026-08-25. The evaluation memo
now evaluates the top-level text keys `@objectstack/spec` declares as
expression-bindable, consuming `expressionBindableTextKeysFor` rather than
keeping a twin list. `statistic.value` / `card.title` / `button.label` and
their siblings are now evaluated at the one place that produces evaluated
schema, so the existing top-level read-back sites see the evaluated value with
no per-component patch.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
…e gap
The published rules and three guides carried the now-retired claim that
`title`/`label`/`value`/`description` are never template-evaluated, and
prescribed host pre-resolution or a `text` node's `content` as the only routes.
objectui#4795 makes that false for the spec-declared rows, so protocol.md gains
a "Bindable Text Keys" rule and the guides point at it; the still-true half (an
undeclared type reads these keys raw) is kept and stated as the boundary.
`skill-guide-provider-envelope.test.tsx`'s node-key reading is flipped to the
new behaviour with the undeclared-key case added beside it, so the file still
states both fates.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
@github-actions

Copy link
Copy Markdown
Contributor

ℹ️ Console Performance Budget — not measured

This run did not produce a console bundle to measure, so there is no pass/fail verdict for the performance budget.

This is not a budget violation. Nothing was measured — the numbers a real violation would carry are simply absent.

StepOutcome
Build packagesskipped
Check console performance budgetskipped

See the workflow run for details.

No package size report: it is only generated from a complete package build, so a partial one is never shown.

…kfile
CI installs with `--frozen-lockfile`, which compares the recorded SPECIFIER,
not the resolved version — so bumping packages/react's range without
regenerating pnpm-lock.yaml failed the install before any job did work, taking
all 13 checks red with the build skipped.
The bump itself is required, and measured rather than assumed: with `^17.0.0`
restored and react rebuilt, `check:spec-floors` reports
@object-ui/react [floor-too-low] packages/react/dist/SchemaRenderer.js
references `expressionBindableTextKeysFor` from @objectstack/spec/ui, which
@objectstack/spec@17.0.0 does not export
so `^17.0.0` would be a false public claim (objectui#5793's defect class). The
same gate names the lowest honest floor as ^17.1.0 — not ^17.2.0, which this
branch declared on a misread CHANGELOG heading; the declaration shipped in
17.1.0. Floor corrected down to the truth rather than left over-claiming.
Lockfile regenerated with `pnpm install --lockfile-only`; the only change is
that one specifier line, and the resolved version stays 17.2.0, so nothing
about what installs changes. `pnpm install --frozen-lockfile` now exits 0
(reproduced failing at 3012daf first).
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 45 chunks)3180.2 KB3222.7 KB
Main entry chunk (gzip)143.6 KB350 KB
Entry fileindex-CotrOk53.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (consoleActionDispatch.js)0.20KB0.19KB
app-shell (index.js)12.46KB4.71KB
app-shell (runtime-config.js)20.68KB7.36KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (ActiveOrganizationStorage.js)25.05KB9.16KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)2.07KB1.00KB
auth (AuthProvider.js)40.18KB10.59KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)8.46KB3.43KB
auth (index.js)3.19KB1.44KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.30KB1.02KB
auth (useWorkspaceAdminStatus.js)5.13KB2.35KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)512.09KB116.42KB
core (index.js)5.30KB2.13KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)177.67KB49.45KB
fields (index.js)243.65KB61.63KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (fallbackInterpolation.js)6.25KB2.77KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)26.89KB9.04KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)5.60KB2.33KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)11.71KB4.29KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)6.24KB2.16KB
permissions (discardProofCache.js)1.04KB0.55KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)4.83KB2.27KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.92KB12.93KB
plugin-charts (index.js)64.68KB18.35KB
plugin-chatbot (index.js)190.53KB45.18KB
plugin-dashboard (index.js)133.48KB34.51KB
plugin-designer (index.js)212.87KB43.19KB
plugin-detail (index.js)247.26KB63.17KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)133.11KB32.61KB
plugin-gantt (index.js)165.21KB40.37KB
plugin-grid (index.js)202.08KB54.61KB
plugin-kanban (index.js)53.14KB14.64KB
plugin-list (index.js)113.15KB27.59KB
plugin-map (index.js)20.20KB6.66KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.51KB11.94KB
plugin-timeline (index.js)29.05KB8.37KB
plugin-tree (index.js)8.98KB3.08KB
plugin-view (index.js)85.79KB21.10KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)4.47KB1.63KB
react (SchemaRenderer.js)81.07KB26.86KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)3.11KB1.48KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (dashboard-widget-options.js)3.08KB1.30KB
sdui-parser (index.js)4.93KB2.24KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)20.57KB5.88KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.28KB0.23KB
sdui-parser (validate.js)10.35KB3.60KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)2.74KB1.41KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)3.75KB1.85KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.85KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (icon-key-migration.js)4.26KB1.63KB
types (index.js)4.72KB2.24KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (spec-ui-namespace.js)0.20KB0.19KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)6.28KB2.87KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-zhuang
os-zhuang marked this pull request as ready for review August 31, 2026 07:31
@os-zhuang
os-zhuang added this pull request to the merge queueAug 31, 2026
Merged via the queue into main with commit 1b1d772Aug 31, 2026
32 checks passed
@os-zhuang
os-zhuang deleted the claude/issue-4795-bindable-text-keys branch August 31, 2026 07:45
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@os-sam@os-zhuang@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(react): evaluate the spec-declared expression-bindable text keys - #6981

Merged
os-zhuang merged 3 commits into
mainfrom
claude/issue-4795-bindable-text-keys
Aug 31, 2026
Merged

feat(react): evaluate the spec-declared expression-bindable text keys#6981
os-zhuang merged 3 commits into
mainfrom
claude/issue-4795-bindable-text-keys

Conversation

@os-sam

@os-samos-sam commented Aug 31, 2026

Copy link
Copy Markdown
Collaborator

Refs #4795 — the evaluation half (ruling item 1) ships here in full. The
build-time rejection (ruling item 2) does not, for two independent reasons
stated below. This card must stay open: it still carries Direction 1's
restart record, the two parked sub-questions, and now item 2.

Authored in session session_013hfmP9hoMd3dJwTh85J4yB.

⛔ GOVERNED SURFACE — do not enqueue this PR

This diff touches four files under skills/, which is GOVERNED_SURFACES[2]
(id: 'skills-catalog') in scripts/check-governed-queue-guard.mjs. Asked
directly about this diff, the guard answers:

One governed path governs the WHOLE pull request — proportion is not a question.
⛔ Do not flip it ready, enqueue it, or arm auto-merge. Park it as a DRAFT and leave the merge
to the maintainer; a human merge IS the review record for a governed surface.

So this stays draft however green CI goes; a human (os-zhuang / hotlong)
merges it. ⚠️AGENTS.md line 378 says the opposite — that repo-root skills/**
is not governed and may take the ordinary self-enqueue path. That text is
stale (the guard landed under objectui#6596, 2026-08-27); the contradiction is
filed as #6975. The guard, not the doc, is authoritative here.

Premise re-verification (the unlock scan's mandatory re-pricing)

@objectstack/spec is installed and resolved in this worktree at 17.2.0, and it
does declare the closed set from objectstack#9599 — verified by reading the
installed package, not the card:

installed spec: 17.2.0
KEYS: [ 'title', 'label', 'value', 'description' ]
MAP: {"statistic":["label","value","description"],"card":["title","description"],"button":["label"]}

Hot controls, so the reading is a measurement rather than a hopeful grep:
COMPONENT_NODE_VISIBILITY_KEYS and ACTION_PARAM_BUILTIN_KEYS (both known
declared) → found; EXPRESSION_BINDABLE_NUMERIC_KEYS (a name that must not
exist) → 0 hits.

⚠️Correction, caught by a gate rather than by review. An earlier revision of
this PR said the declaration shipped in 17.2.0 and set packages/react's floor
to ^17.2.0. That was a misread of the spec CHANGELOG (the objectstack#9599
entry sits under the ## 17.1.0 heading, not the ## 17.2.0 one above it).
check:spec-floors computes the true floor from the built artifact and names it:
^17.1.0. Corrected down to the truth rather than left over-claiming — see
the CI-install section.

⚠️The upstream landing reshaped this card's Option 1. The ruling had a flat
four-key list in view; what actually shipped is that list plus a per-component
carriage map
statistic carries label/value/description, card
carries title/description, button carries label, and every other type
gets the frozen empty set. That difference is what most of the rest of this
PR body is about.

The card's title is false, and so was half of what the guides taught

Re-derived here rather than restated: with the properties envelope, value /
title / label were already both evaluated and read back before this PR (PR
#5122's evaluation leg plus the existing hoist). The two shapes that were
genuinely broken, and are what this PR fixes, are the top-level ones.

What ships

One leg in the evaluation memo (packages/react/src/SchemaRenderer.tsx),
beside the existing content leg:

for(constkeyofexpressionBindableTextKeysFor(typeofnewSchema.type==='string' ? newSchema.type : '',)){if(typeofnewSchema[key]==='string'){newSchema[key]=evaluator.evaluate(newSchema[key]);}}

Converged, not patched per component — this is the ruling's caution, and it is
a measurement here, not a promise.
data-display/statistic.tsx,
layout/card.tsx and form/button.tsx are not in this diff. They already
read these keys off the node; nothing was writing an evaluated value there. The
end-to-end test drives the real registered renderers and passes with those three
files untouched.

Two deliberate choices, both pinned:

  • The lookup is consumed, never copied. The only thing this file knows is
    the name of the function. A row added upstream starts working here with no
    edit.
  • The type string is passed verbatim — no ui: prefix stripping. The spec
    states the answer for an unlisted type is the empty set. Normalizing would
    look harmless and would in the same motion grant rows to element:button and
    page:card, whose renderers read config out of the bag via readProps() and
    never touch these keys on the node — re-manufacturing the
    evaluated-but-not-read-back half this card exists to close. The authored
    corpus also spells these types bare (statistic 42, card 135, button 158
    nodes; ui:* zero).

The CI install, and why the floor moves at all

The first push took all 13 checks red with the build skipped — the signature
of pnpm install dying before any job works. CI installs with
pnpm install --frozen-lockfile, which compares the recorded specifier, not
the resolved version. The manifest bump without a lockfile regen is exactly that
mismatch. Reproduced at 3012dafff before fixing:

ERR_PNPM_OUTDATED_LOCKFILE Cannot install with "frozen-lockfile" because
pnpm-lock.yaml is not up to date with <ROOT>/packages/react/package.json
specifiers in the lockfile don't match specifiers in package.json:

The bump is required on the merits, and that is measured, not assumed. With
^17.0.0 restored and packages/react rebuilt, check:spec-floors reports:

@object-ui/react [floor-too-low] packages/react/dist/SchemaRenderer.js references
`expressionBindableTextKeysFor` from @objectstack/spec/ui, which
@objectstack/spec@17.0.0 does not export
The lowest published spec that carries every symbol each package references:
@object-ui/react → "@objectstack/spec": "^17.1.0"

So reverting the manifest was not available: ^17.0.0 would be a false public
claim, objectui#5793's exact defect class ("the range is the claim, and the claim
is what is wrong"). Floor set to the gate-named ^17.1.0, lockfile regenerated
with pnpm install --lockfile-only. The lockfile diff is one line — the
specifier — and the resolved version stays 17.2.0, so nothing about what
installs changes. pnpm install --frozen-lockfile now exits 0.

Why the build-time rejection is NOT in this PR

Reason 1 — it would decide parked sub-question ③. Its only natural home is
objectui check (packages/cli/src/commands/check.ts). Whether to build the
publish-time half there is explicitly awaiting the maintainer. The file-contention
reason the earlier seat gave has lifted (no open PR touches packages/cli), so
this is the scope boundary, not a blocked file.

Reason 2 — the corpus measurement says the rejection's scope is undecided.
Clause-② required measuring before shipping the narrowing. Census over 736 JSON
documents and json doc fences (2747 typed nodes), counting top-level keys
whose value contains ${:

ClassCountUnder the ruling's literal wordingUnder the carriage map
Predicate keys (visible/hidden/disabled…)22exemptexempt
content5exemptexempt
Declared row (statistic.value, statistic.label)2accepted — now evaluatedaccepted
Closed-set key on an undeclared type32accepted (key is in the list)REJECTED
Key outside the closed set (badge.text, badge.variant, alert.message, chart.data, action.condition)8REJECTEDREJECTED

The two readings differ by 32 occurrences, and the difference is not a
detail:

  • 23 of them are type: "text" with value: "${…}" — taught across
    content/docs/guide/expressions.md and siblings. basic/text.tsx renders
    schema.content || schema.value, so text.value IS a real top-level
    read-back site; it simply has no spec row, so it renders the literal today.
    The literal reading accepts a form that visibly breaks; the carriage-map
    reading rejects the platform's own documented examples.
  • The remainder includes page.title — where type: "page" is a page
    document, not a component node, and title is the page's own title. A
    carriage-map gate needs a "what is a component node" rule the ruling never
    states.
  • Also stat-card.value ×4, on a type that is not registered at all.

The ruling's wording ("any key outside that closed list") selects the literal
reading; the ruling's stated goal ("no more blank renders or literal ${data.n}
reaching users") is only met by the carriage-map reading, which the wording
predates. That is a contract decision, and choosing it silently inside a
diagnostic is exactly what the dispatch forbids.

Docs

The published rules and three guides asserted the retired claim that these four
keys are never template-evaluated, and prescribed host pre-resolution as the
only route. page-builder.md went further: its "Also wrong" example was
{ "type": "statistic", "value": "${…}", "label": "${…}" } — which this PR
makes correct. Corrected surgically, with the still-true half (an undeclared
type reads these keys raw) kept and stated as the boundary.

Published-skills line readings, per the reporting rule:

FileBeforeAfterΔ
skills/objectui/rules/protocol.md275306+31
skills/objectui/guides/page-builder.md516522+6
skills/objectui/guides/schema-expressions.md625628+3
skills/objectui/guides/data-integration.md440441+1
Whole published package (18 files)56865726+40

Verification — all on the final commit ec519f94d

RunResult
pnpm install --frozen-lockfileexit 0 (reproduced failing at 3012dafff first)
vitest run packages/react/68 files / 838 tests passed
vitest run packages/components/220 files / 2018 tests passed
type-check (react, components)Done / exit 0 — react's runs tsc --noEmit && tsc -p tsconfig.test.json, so the new test files are typechecked
eslint . --no-inline-config (repo-wide, 4031 files)my 4 linted files: 0 errors; none of the 75 pre-existing error files are mine
check:spec-floors@object-ui/reactclears at ^17.1.0; 0floor-too-low; 3 residual findings all [no-artifact] on plugins outside this diff
check:governed-queue-guardself-test OK — 132 cases pass; asked about this diff, it names the four skills/ files and refuses the queue
check:skills-pathsOK (94/95 stated paths resolve; 1 baselined)
check:doc-fencesOK — every TypeScript block in 224 documents
check:doc-typesOK — every documented component type is registered
check:doc-snippets271 of 271 blocks judged, 0 failed (after the build it names)
check:control-bytes, check:phantom-deps, check:self-import, check:spec-symbolsall exit 0
check-changeset-presence✅ 4 source files of 2 released packages changed, 1 changeset

Ablation (the feature). Mutation: the lookup call replaced by
[] as string[], so the loop body survives and only the key source dies. Proven
on disk before running — removed-text grep -c = 0, injected-text = 1, and
git hash-object differed from the HEAD blob. Both test files resolve
@object-ui/react through the root vitest alias to packages/react/src, so
both legs are source-resolved and no rebuild leg is involved. Result:
8 failed | 10 passed (the 10 are the negative/inert pins, which correctly
still hold under ablation). Restore leg proven byte-identically:
git hash-object back to 7f9427de8f203e55d960ac5f86359ed46a7ce000, matching
HEAD, and git diff HEAD empty.

Ablation (the floor). Same discipline on the manifest: reverted to
^17.0.0, confirmed on disk (git hash-object differed from the HEAD blob),
rebuilt, and read the gate — [floor-too-low], quoted above. Restored via trap.

Before/after on the pin: 4 failed | 8 passed → 12 passed.

File overlap to flag for review

packages/components/src/__tests__/skill-guide-provider-envelope.test.tsx is
also touched by live PR #6963, in a disjoint region (its COLUMNS fixture at
~L57–70; this PR's edits are the docblock at ~L20 and the assertion at ~L161).
Its a node-level title is read but never evaluated case pinned exactly the
defect this ruling retires, so it is flipped, with the undeclared-key case added
beside it so the file still states both fates.

Out of scope, filed separately

  • objectstack#13670 — the spec carriage map has no row for textvalue,
    although basic/text.tsx reads it at the node's top level and the guides teach
    it. Directly gates the scope of ruling item 2.
  • objectstack#13672 — the spec's button row cites action/action-button.tsx,
    but the map is keyed on the bare name, so action:button (5 corpus nodes)
    resolves to the empty set.

⛔ Draft, and staying draft: governed surface. Not marked ready, not enqueued, no
auto-merge. Direction 2 untouched and still rejected; Direction 3's shipped
render-time half (PR #5129) unaffected.

objectui#4795 Direction 1, maintainer ruling 2026-08-25. The evaluation memo
now evaluates the top-level text keys `@objectstack/spec` declares as
expression-bindable, consuming `expressionBindableTextKeysFor` rather than
keeping a twin list. `statistic.value` / `card.title` / `button.label` and
their siblings are now evaluated at the one place that produces evaluated
schema, so the existing top-level read-back sites see the evaluated value with
no per-component patch.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
…e gap
The published rules and three guides carried the now-retired claim that
`title`/`label`/`value`/`description` are never template-evaluated, and
prescribed host pre-resolution or a `text` node's `content` as the only routes.
objectui#4795 makes that false for the spec-declared rows, so protocol.md gains
a "Bindable Text Keys" rule and the guides point at it; the still-true half (an
undeclared type reads these keys raw) is kept and stated as the boundary.
`skill-guide-provider-envelope.test.tsx`'s node-key reading is flipped to the
new behaviour with the undeclared-key case added beside it, so the file still
states both fates.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
@github-actions

Copy link
Copy Markdown
Contributor

ℹ️ Console Performance Budget — not measured

This run did not produce a console bundle to measure, so there is no pass/fail verdict for the performance budget.

This is not a budget violation. Nothing was measured — the numbers a real violation would carry are simply absent.

StepOutcome
Build packagesskipped
Check console performance budgetskipped

See the workflow run for details.

No package size report: it is only generated from a complete package build, so a partial one is never shown.

…kfile
CI installs with `--frozen-lockfile`, which compares the recorded SPECIFIER,
not the resolved version — so bumping packages/react's range without
regenerating pnpm-lock.yaml failed the install before any job did work, taking
all 13 checks red with the build skipped.
The bump itself is required, and measured rather than assumed: with `^17.0.0`
restored and react rebuilt, `check:spec-floors` reports
@object-ui/react [floor-too-low] packages/react/dist/SchemaRenderer.js
references `expressionBindableTextKeysFor` from @objectstack/spec/ui, which
@objectstack/spec@17.0.0 does not export
so `^17.0.0` would be a false public claim (objectui#5793's defect class). The
same gate names the lowest honest floor as ^17.1.0 — not ^17.2.0, which this
branch declared on a misread CHANGELOG heading; the declaration shipped in
17.1.0. Floor corrected down to the truth rather than left over-claiming.
Lockfile regenerated with `pnpm install --lockfile-only`; the only change is
that one specifier line, and the resolved version stays 17.2.0, so nothing
about what installs changes. `pnpm install --frozen-lockfile` now exits 0
(reproduced failing at 3012daf first).
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 45 chunks)3180.2 KB3222.7 KB
Main entry chunk (gzip)143.6 KB350 KB
Entry fileindex-CotrOk53.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (consoleActionDispatch.js)0.20KB0.19KB
app-shell (index.js)12.46KB4.71KB
app-shell (runtime-config.js)20.68KB7.36KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (ActiveOrganizationStorage.js)25.05KB9.16KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)2.07KB1.00KB
auth (AuthProvider.js)40.18KB10.59KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)8.46KB3.43KB
auth (index.js)3.19KB1.44KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.30KB1.02KB
auth (useWorkspaceAdminStatus.js)5.13KB2.35KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)512.09KB116.42KB
core (index.js)5.30KB2.13KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)177.67KB49.45KB
fields (index.js)243.65KB61.63KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (fallbackInterpolation.js)6.25KB2.77KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)26.89KB9.04KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)5.60KB2.33KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)11.71KB4.29KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)6.24KB2.16KB
permissions (discardProofCache.js)1.04KB0.55KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)4.83KB2.27KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.92KB12.93KB
plugin-charts (index.js)64.68KB18.35KB
plugin-chatbot (index.js)190.53KB45.18KB
plugin-dashboard (index.js)133.48KB34.51KB
plugin-designer (index.js)212.87KB43.19KB
plugin-detail (index.js)247.26KB63.17KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)133.11KB32.61KB
plugin-gantt (index.js)165.21KB40.37KB
plugin-grid (index.js)202.08KB54.61KB
plugin-kanban (index.js)53.14KB14.64KB
plugin-list (index.js)113.15KB27.59KB
plugin-map (index.js)20.20KB6.66KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.51KB11.94KB
plugin-timeline (index.js)29.05KB8.37KB
plugin-tree (index.js)8.98KB3.08KB
plugin-view (index.js)85.79KB21.10KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)4.47KB1.63KB
react (SchemaRenderer.js)81.07KB26.86KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)3.11KB1.48KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (dashboard-widget-options.js)3.08KB1.30KB
sdui-parser (index.js)4.93KB2.24KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)20.57KB5.88KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.28KB0.23KB
sdui-parser (validate.js)10.35KB3.60KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)2.74KB1.41KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)3.75KB1.85KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.85KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (icon-key-migration.js)4.26KB1.63KB
types (index.js)4.72KB2.24KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (spec-ui-namespace.js)0.20KB0.19KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)6.28KB2.87KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-zhuang
os-zhuang marked this pull request as ready for review August 31, 2026 07:31
@os-zhuang
os-zhuang added this pull request to the merge queueAug 31, 2026
Merged via the queue into main with commit 1b1d772Aug 31, 2026
32 checks passed
@os-zhuang
os-zhuang deleted the claude/issue-4795-bindable-text-keys branch August 31, 2026 07:45
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@os-sam@os-zhuang@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

feat(react): evaluate the spec-declared expression-bindable text keys - #6981

Merged
os-zhuang merged 3 commits into
mainfrom
claude/issue-4795-bindable-text-keys
Aug 31, 2026
Merged

feat(react): evaluate the spec-declared expression-bindable text keys#6981
os-zhuang merged 3 commits into
mainfrom
claude/issue-4795-bindable-text-keys

Conversation

@os-sam

@os-samos-sam commented Aug 31, 2026

Copy link
Copy Markdown
Collaborator

Refs #4795 — the evaluation half (ruling item 1) ships here in full. The
build-time rejection (ruling item 2) does not, for two independent reasons
stated below. This card must stay open: it still carries Direction 1's
restart record, the two parked sub-questions, and now item 2.

Authored in session session_013hfmP9hoMd3dJwTh85J4yB.

⛔ GOVERNED SURFACE — do not enqueue this PR

This diff touches four files under skills/, which is GOVERNED_SURFACES[2]
(id: 'skills-catalog') in scripts/check-governed-queue-guard.mjs. Asked
directly about this diff, the guard answers:

One governed path governs the WHOLE pull request — proportion is not a question.
⛔ Do not flip it ready, enqueue it, or arm auto-merge. Park it as a DRAFT and leave the merge
to the maintainer; a human merge IS the review record for a governed surface.

So this stays draft however green CI goes; a human (os-zhuang / hotlong)
merges it. ⚠️AGENTS.md line 378 says the opposite — that repo-root skills/**
is not governed and may take the ordinary self-enqueue path. That text is
stale (the guard landed under objectui#6596, 2026-08-27); the contradiction is
filed as #6975. The guard, not the doc, is authoritative here.

Premise re-verification (the unlock scan's mandatory re-pricing)

@objectstack/spec is installed and resolved in this worktree at 17.2.0, and it
does declare the closed set from objectstack#9599 — verified by reading the
installed package, not the card:

installed spec: 17.2.0
KEYS: [ 'title', 'label', 'value', 'description' ]
MAP: {"statistic":["label","value","description"],"card":["title","description"],"button":["label"]}

Hot controls, so the reading is a measurement rather than a hopeful grep:
COMPONENT_NODE_VISIBILITY_KEYS and ACTION_PARAM_BUILTIN_KEYS (both known
declared) → found; EXPRESSION_BINDABLE_NUMERIC_KEYS (a name that must not
exist) → 0 hits.

⚠️Correction, caught by a gate rather than by review. An earlier revision of
this PR said the declaration shipped in 17.2.0 and set packages/react's floor
to ^17.2.0. That was a misread of the spec CHANGELOG (the objectstack#9599
entry sits under the ## 17.1.0 heading, not the ## 17.2.0 one above it).
check:spec-floors computes the true floor from the built artifact and names it:
^17.1.0. Corrected down to the truth rather than left over-claiming — see
the CI-install section.

⚠️The upstream landing reshaped this card's Option 1. The ruling had a flat
four-key list in view; what actually shipped is that list plus a per-component
carriage map
statistic carries label/value/description, card
carries title/description, button carries label, and every other type
gets the frozen empty set. That difference is what most of the rest of this
PR body is about.

The card's title is false, and so was half of what the guides taught

Re-derived here rather than restated: with the properties envelope, value /
title / label were already both evaluated and read back before this PR (PR
#5122's evaluation leg plus the existing hoist). The two shapes that were
genuinely broken, and are what this PR fixes, are the top-level ones.

What ships

One leg in the evaluation memo (packages/react/src/SchemaRenderer.tsx),
beside the existing content leg:

for(constkeyofexpressionBindableTextKeysFor(typeofnewSchema.type==='string' ? newSchema.type : '',)){if(typeofnewSchema[key]==='string'){newSchema[key]=evaluator.evaluate(newSchema[key]);}}

Converged, not patched per component — this is the ruling's caution, and it is
a measurement here, not a promise.
data-display/statistic.tsx,
layout/card.tsx and form/button.tsx are not in this diff. They already
read these keys off the node; nothing was writing an evaluated value there. The
end-to-end test drives the real registered renderers and passes with those three
files untouched.

Two deliberate choices, both pinned:

  • The lookup is consumed, never copied. The only thing this file knows is
    the name of the function. A row added upstream starts working here with no
    edit.
  • The type string is passed verbatim — no ui: prefix stripping. The spec
    states the answer for an unlisted type is the empty set. Normalizing would
    look harmless and would in the same motion grant rows to element:button and
    page:card, whose renderers read config out of the bag via readProps() and
    never touch these keys on the node — re-manufacturing the
    evaluated-but-not-read-back half this card exists to close. The authored
    corpus also spells these types bare (statistic 42, card 135, button 158
    nodes; ui:* zero).

The CI install, and why the floor moves at all

The first push took all 13 checks red with the build skipped — the signature
of pnpm install dying before any job works. CI installs with
pnpm install --frozen-lockfile, which compares the recorded specifier, not
the resolved version. The manifest bump without a lockfile regen is exactly that
mismatch. Reproduced at 3012dafff before fixing:

ERR_PNPM_OUTDATED_LOCKFILE Cannot install with "frozen-lockfile" because
pnpm-lock.yaml is not up to date with <ROOT>/packages/react/package.json
specifiers in the lockfile don't match specifiers in package.json:

The bump is required on the merits, and that is measured, not assumed. With
^17.0.0 restored and packages/react rebuilt, check:spec-floors reports:

@object-ui/react [floor-too-low] packages/react/dist/SchemaRenderer.js references
`expressionBindableTextKeysFor` from @objectstack/spec/ui, which
@objectstack/spec@17.0.0 does not export
The lowest published spec that carries every symbol each package references:
@object-ui/react → "@objectstack/spec": "^17.1.0"

So reverting the manifest was not available: ^17.0.0 would be a false public
claim, objectui#5793's exact defect class ("the range is the claim, and the claim
is what is wrong"). Floor set to the gate-named ^17.1.0, lockfile regenerated
with pnpm install --lockfile-only. The lockfile diff is one line — the
specifier — and the resolved version stays 17.2.0, so nothing about what
installs changes. pnpm install --frozen-lockfile now exits 0.

Why the build-time rejection is NOT in this PR

Reason 1 — it would decide parked sub-question ③. Its only natural home is
objectui check (packages/cli/src/commands/check.ts). Whether to build the
publish-time half there is explicitly awaiting the maintainer. The file-contention
reason the earlier seat gave has lifted (no open PR touches packages/cli), so
this is the scope boundary, not a blocked file.

Reason 2 — the corpus measurement says the rejection's scope is undecided.
Clause-② required measuring before shipping the narrowing. Census over 736 JSON
documents and json doc fences (2747 typed nodes), counting top-level keys
whose value contains ${:

ClassCountUnder the ruling's literal wordingUnder the carriage map
Predicate keys (visible/hidden/disabled…)22exemptexempt
content5exemptexempt
Declared row (statistic.value, statistic.label)2accepted — now evaluatedaccepted
Closed-set key on an undeclared type32accepted (key is in the list)REJECTED
Key outside the closed set (badge.text, badge.variant, alert.message, chart.data, action.condition)8REJECTEDREJECTED

The two readings differ by 32 occurrences, and the difference is not a
detail:

  • 23 of them are type: "text" with value: "${…}" — taught across
    content/docs/guide/expressions.md and siblings. basic/text.tsx renders
    schema.content || schema.value, so text.value IS a real top-level
    read-back site; it simply has no spec row, so it renders the literal today.
    The literal reading accepts a form that visibly breaks; the carriage-map
    reading rejects the platform's own documented examples.
  • The remainder includes page.title — where type: "page" is a page
    document, not a component node, and title is the page's own title. A
    carriage-map gate needs a "what is a component node" rule the ruling never
    states.
  • Also stat-card.value ×4, on a type that is not registered at all.

The ruling's wording ("any key outside that closed list") selects the literal
reading; the ruling's stated goal ("no more blank renders or literal ${data.n}
reaching users") is only met by the carriage-map reading, which the wording
predates. That is a contract decision, and choosing it silently inside a
diagnostic is exactly what the dispatch forbids.

Docs

The published rules and three guides asserted the retired claim that these four
keys are never template-evaluated, and prescribed host pre-resolution as the
only route. page-builder.md went further: its "Also wrong" example was
{ "type": "statistic", "value": "${…}", "label": "${…}" } — which this PR
makes correct. Corrected surgically, with the still-true half (an undeclared
type reads these keys raw) kept and stated as the boundary.

Published-skills line readings, per the reporting rule:

FileBeforeAfterΔ
skills/objectui/rules/protocol.md275306+31
skills/objectui/guides/page-builder.md516522+6
skills/objectui/guides/schema-expressions.md625628+3
skills/objectui/guides/data-integration.md440441+1
Whole published package (18 files)56865726+40

Verification — all on the final commit ec519f94d

RunResult
pnpm install --frozen-lockfileexit 0 (reproduced failing at 3012dafff first)
vitest run packages/react/68 files / 838 tests passed
vitest run packages/components/220 files / 2018 tests passed
type-check (react, components)Done / exit 0 — react's runs tsc --noEmit && tsc -p tsconfig.test.json, so the new test files are typechecked
eslint . --no-inline-config (repo-wide, 4031 files)my 4 linted files: 0 errors; none of the 75 pre-existing error files are mine
check:spec-floors@object-ui/reactclears at ^17.1.0; 0floor-too-low; 3 residual findings all [no-artifact] on plugins outside this diff
check:governed-queue-guardself-test OK — 132 cases pass; asked about this diff, it names the four skills/ files and refuses the queue
check:skills-pathsOK (94/95 stated paths resolve; 1 baselined)
check:doc-fencesOK — every TypeScript block in 224 documents
check:doc-typesOK — every documented component type is registered
check:doc-snippets271 of 271 blocks judged, 0 failed (after the build it names)
check:control-bytes, check:phantom-deps, check:self-import, check:spec-symbolsall exit 0
check-changeset-presence✅ 4 source files of 2 released packages changed, 1 changeset

Ablation (the feature). Mutation: the lookup call replaced by
[] as string[], so the loop body survives and only the key source dies. Proven
on disk before running — removed-text grep -c = 0, injected-text = 1, and
git hash-object differed from the HEAD blob. Both test files resolve
@object-ui/react through the root vitest alias to packages/react/src, so
both legs are source-resolved and no rebuild leg is involved. Result:
8 failed | 10 passed (the 10 are the negative/inert pins, which correctly
still hold under ablation). Restore leg proven byte-identically:
git hash-object back to 7f9427de8f203e55d960ac5f86359ed46a7ce000, matching
HEAD, and git diff HEAD empty.

Ablation (the floor). Same discipline on the manifest: reverted to
^17.0.0, confirmed on disk (git hash-object differed from the HEAD blob),
rebuilt, and read the gate — [floor-too-low], quoted above. Restored via trap.

Before/after on the pin: 4 failed | 8 passed → 12 passed.

File overlap to flag for review

packages/components/src/__tests__/skill-guide-provider-envelope.test.tsx is
also touched by live PR #6963, in a disjoint region (its COLUMNS fixture at
~L57–70; this PR's edits are the docblock at ~L20 and the assertion at ~L161).
Its a node-level title is read but never evaluated case pinned exactly the
defect this ruling retires, so it is flipped, with the undeclared-key case added
beside it so the file still states both fates.

Out of scope, filed separately

  • objectstack#13670 — the spec carriage map has no row for textvalue,
    although basic/text.tsx reads it at the node's top level and the guides teach
    it. Directly gates the scope of ruling item 2.
  • objectstack#13672 — the spec's button row cites action/action-button.tsx,
    but the map is keyed on the bare name, so action:button (5 corpus nodes)
    resolves to the empty set.

⛔ Draft, and staying draft: governed surface. Not marked ready, not enqueued, no
auto-merge. Direction 2 untouched and still rejected; Direction 3's shipped
render-time half (PR #5129) unaffected.

objectui#4795 Direction 1, maintainer ruling 2026-08-25. The evaluation memo
now evaluates the top-level text keys `@objectstack/spec` declares as
expression-bindable, consuming `expressionBindableTextKeysFor` rather than
keeping a twin list. `statistic.value` / `card.title` / `button.label` and
their siblings are now evaluated at the one place that produces evaluated
schema, so the existing top-level read-back sites see the evaluated value with
no per-component patch.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
…e gap
The published rules and three guides carried the now-retired claim that
`title`/`label`/`value`/`description` are never template-evaluated, and
prescribed host pre-resolution or a `text` node's `content` as the only routes.
objectui#4795 makes that false for the spec-declared rows, so protocol.md gains
a "Bindable Text Keys" rule and the guides point at it; the still-true half (an
undeclared type reads these keys raw) is kept and stated as the boundary.
`skill-guide-provider-envelope.test.tsx`'s node-key reading is flipped to the
new behaviour with the undeclared-key case added beside it, so the file still
states both fates.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
@github-actions

Copy link
Copy Markdown
Contributor

ℹ️ Console Performance Budget — not measured

This run did not produce a console bundle to measure, so there is no pass/fail verdict for the performance budget.

This is not a budget violation. Nothing was measured — the numbers a real violation would carry are simply absent.

StepOutcome
Build packagesskipped
Check console performance budgetskipped

See the workflow run for details.

No package size report: it is only generated from a complete package build, so a partial one is never shown.

…kfile
CI installs with `--frozen-lockfile`, which compares the recorded SPECIFIER,
not the resolved version — so bumping packages/react's range without
regenerating pnpm-lock.yaml failed the install before any job did work, taking
all 13 checks red with the build skipped.
The bump itself is required, and measured rather than assumed: with `^17.0.0`
restored and react rebuilt, `check:spec-floors` reports
@object-ui/react [floor-too-low] packages/react/dist/SchemaRenderer.js
references `expressionBindableTextKeysFor` from @objectstack/spec/ui, which
@objectstack/spec@17.0.0 does not export
so `^17.0.0` would be a false public claim (objectui#5793's defect class). The
same gate names the lowest honest floor as ^17.1.0 — not ^17.2.0, which this
branch declared on a misread CHANGELOG heading; the declaration shipped in
17.1.0. Floor corrected down to the truth rather than left over-claiming.
Lockfile regenerated with `pnpm install --lockfile-only`; the only change is
that one specifier line, and the resolved version stays 17.2.0, so nothing
about what installs changes. `pnpm install --frozen-lockfile` now exits 0
(reproduced failing at 3012daf first).
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013hfmP9hoMd3dJwTh85J4yB
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 45 chunks)3180.2 KB3222.7 KB
Main entry chunk (gzip)143.6 KB350 KB
Entry fileindex-CotrOk53.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (consoleActionDispatch.js)0.20KB0.19KB
app-shell (index.js)12.46KB4.71KB
app-shell (runtime-config.js)20.68KB7.36KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (ActiveOrganizationStorage.js)25.05KB9.16KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)2.07KB1.00KB
auth (AuthProvider.js)40.18KB10.59KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)8.46KB3.43KB
auth (index.js)3.19KB1.44KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.30KB1.02KB
auth (useWorkspaceAdminStatus.js)5.13KB2.35KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)512.09KB116.42KB
core (index.js)5.30KB2.13KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)177.67KB49.45KB
fields (index.js)243.65KB61.63KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (fallbackInterpolation.js)6.25KB2.77KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)26.89KB9.04KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)5.60KB2.33KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)11.71KB4.29KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)6.24KB2.16KB
permissions (discardProofCache.js)1.04KB0.55KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)4.83KB2.27KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.92KB12.93KB
plugin-charts (index.js)64.68KB18.35KB
plugin-chatbot (index.js)190.53KB45.18KB
plugin-dashboard (index.js)133.48KB34.51KB
plugin-designer (index.js)212.87KB43.19KB
plugin-detail (index.js)247.26KB63.17KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)133.11KB32.61KB
plugin-gantt (index.js)165.21KB40.37KB
plugin-grid (index.js)202.08KB54.61KB
plugin-kanban (index.js)53.14KB14.64KB
plugin-list (index.js)113.15KB27.59KB
plugin-map (index.js)20.20KB6.66KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.51KB11.94KB
plugin-timeline (index.js)29.05KB8.37KB
plugin-tree (index.js)8.98KB3.08KB
plugin-view (index.js)85.79KB21.10KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)4.47KB1.63KB
react (SchemaRenderer.js)81.07KB26.86KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)3.11KB1.48KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (dashboard-widget-options.js)3.08KB1.30KB
sdui-parser (index.js)4.93KB2.24KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)20.57KB5.88KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.28KB0.23KB
sdui-parser (validate.js)10.35KB3.60KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)2.74KB1.41KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)3.75KB1.85KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.85KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (icon-key-migration.js)4.26KB1.63KB
types (index.js)4.72KB2.24KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (spec-ui-namespace.js)0.20KB0.19KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)6.28KB2.87KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-zhuang
os-zhuang marked this pull request as ready for review August 31, 2026 07:31
@os-zhuang
os-zhuang added this pull request to the merge queueAug 31, 2026
Merged via the queue into main with commit 1b1d772Aug 31, 2026
32 checks passed
@os-zhuang
os-zhuang deleted the claude/issue-4795-bindable-text-keys branch August 31, 2026 07:45
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@os-sam@os-zhuang@claude