feat(types)!: DashboardWidgetSchema refuses undeclared keys (.strict()) - #7033

Merged
os-warren merged 2 commits into
mainfrom
claude/issue-6002-dashboard-widget-strict
Aug 31, 2026
Merged

feat(types)!: DashboardWidgetSchema refuses undeclared keys (.strict())#7033
os-warren merged 2 commits into
mainfrom
claude/issue-6002-dashboard-widget-strict

Conversation

@os-warren

Copy link
Copy Markdown
Collaborator

Fixes#6002

Route 1 step 2 of the maintainer ruling (issue comment 5406212152, 2026-08-25): after #6150's declaration catch-up, DashboardWidgetSchema flips from strip-in-silence to .strict() — an undeclared widget key now refuses the parse with zod's unrecognized_keys issue naming every offending key. The card's measured five-keys-in/three-keys-out ACCEPT is reproduced in this PR's pin suite as a loud refusal naming zzcanary / categoryField / aggregate.

Step 0 — premise re-verified on the merged ref

#6150 closed via PR #6945 (squash commit 2c45966, contained in this branch's base f7850ee). All 13 recorded renderer-consumed keys verified declared, key by key, against the interface blocks on that ref: TextSchema.content · CarouselSchema.opts/orientation/itemClassName · FilterBuilderSchema.wrapperClass · TreeViewSchema.nodes/onNodeClick/title · CheckboxSchema.required · FileUploadSchema.buttonText/wrapperClass · HoverCardSchema.align · ContextMenuSchema.trigger. 13/13 declared — premise holds. (Note: none of the 13 are dashboard-widget keys; the family-1 corpus measurement below is what answers whether any LIVE dashboard depends on a key nothing declares.)

Step 1 — blast radius, measured before the change (ruling: not assumed)

The strict-refusal delta over the live corpus is EMPTY — no per-key fork back to triage is needed.

  1. Stored dashboard corpus. A preflight parsed every candidate with both the current schema and a .strict() candidate, routing component-enum types to BaseSchema per the 2026-08-14 ruling: 575 JSON files under examples/apps/packages/e2e/public plus every dashboard-bearing fenced block in md/mdx docs — 10 dashboard documents, 30 widgets (11 of them component nodes). Newly-refused widgets: zero. Doc fences that the script could not auto-parse were hand-triaged (all shape references or component-node examples; details in the report comment on finding(types): DashboardWidgetSchema SILENTLY DROPS every undeclared widget key — the file's own docstring names this failure mode, and it still applies to the keys nothing declares #6002). Two pre-existing, non-delta facts recorded: packages/plugin-dashboard/README.md fence 8 authors a widget with type: 'card', which the closed type enum already refuses TODAY (doc drift predating this PR — reported to PM as an out-of-scope finding); apps/console/src/preview-samples.ts's dashboard sample is already in that suite's KNOWN_STALE ledger against the spec schema (value/format/chart — also not a delta of this change).
  2. Designer emit paths. Every widget-emitting site enumerated and read: metadata-admin DashboardPreview add-widget emits id/type/title (WIDGET_TYPE_META defines no defaults); DashboardWidgetInspector patches title/type/dataset/dimensions/values/colorVariant/filterBindings/layout; plugin-designer DashboardEditor adds id/title/type/layout and edits title/type/colorVariant/layout; plugin-dashboard WidgetConfigPanel emits id/title/description/type/dataset/dimensions/values/colorVariant plus layout, with the legacy analytics and retired action keys scrubbed by sanitizeDraftForType. Every emitted key is in the declared set.
  3. Widget-slot component nodes (schema-catalog: all 9 plugin-dashboard examples are refused by the spec's DashboardSchema — the AI few-shot corpus teaches the pre-ADR-0021 widget shape #4600's BaseSchema routing). Measured on the current build: with a bare .strict() and no routing, the 11 ruled-legal metric-card widgets in the catalog corpus would refuse at the whole-document parse on value / icon / trend / trendValue — live documents the 2026-08-14 ruling (objectstack#8593) declares legal. BaseSchema accepts all 11. The routing the ruling names (component node owned by passthrough BaseSchema) therefore moves into the shared DashboardComponentSchema widget slot in this PR, as a union whose component arm is gated on the closed component-type enum — it is structurally unreachable for spec-family widgets, so it cannot become a hatch around the refusal. The routing schema is deliberately NOT exported (internal slot property, no new authoring surface).

Step 2 — the change

Tests and gates (final head 7718ccc; every run below was re-run at this sha)

  • New pin suite packages/types/src/__tests__/dashboard-widget-strict-6002.test.ts: the card's probe refuses naming all three keys; the retired inline-analytics quartet refuses as a set; a declared-surface widget parses green with every key surviving; the legacy id/component/layout envelope parses; a component-node document parses whole with props kept; two not-a-hatch pins refuse stray keys at document level.
  • pnpm exec vitest run packages/types/ examples/schema-catalog/ packages/cli/112 files, 3113 tests, all passed (includes the schema-catalog: all 9 plugin-dashboard examples are refused by the spec's DashboardSchema — the AI few-shot corpus teaches the pre-ADR-0021 widget shape #4600 gate with updated counter-probes, the safe-validate corpus sweep, and the CLI validate tests).
  • pnpm exec vitest run packages/plugin-dashboard/ packages/plugin-designer/ — 99 files, 901 tests, all passed.
  • @object-ui/types type-check (tsc noEmit + examples + test tsconfigs) green; tsc --listFiles confirms the new test file is in the compiled closure (1 hit — not a NOT-MEASURED green).
  • check-changeset-presence ✅ (1 changeset, minor with breaking narrative per the accept-set-narrowing precedent, no major — repo version policy) · check-changeset-no-major ✅ · check:control-bytes ✅ (5826 files) · check:spec-symbols ✅ · eslint on the three changed files: 0 errors (2 pre-existing warnings on untouched lines).
  • Ablation (committed first, mutation and restore both verified on disk): removing .strict() turns exactly the 4 refusal pins red (5 routing/positive pins stay green, as predicted); restore verified byte-identical to the HEAD blob. The suite resolves the subject through the vitest root alias to src, so no dist build sits in the ablation loop.
  • Declared narrowings, owned by CI: full pnpm lint (repo-wide eslint) and the full cross-package pnpm test farm were not run locally; the targeted set above covers every suite that runtime-parses these schemas (enumerated by grep over safeParse/parse call sites).

Review parking

Clause-② yes (accept/reject behaviour change on a published contract): this PR is parked as draft with needs:contract-review on both carriers, to be released through the in-seat contract-review flow (objectstack#13795) — not self-merged.

Generated by Claude Code


Generated by Claude Code

Route 1 step 2 of the maintainer ruling on objectui#6002: after #6150
declared the genuinely-consumed keys, the widget schema flips from
strip-in-silence to loud refusal — zod `unrecognized_keys` names every
offending key. The widget-slot component route (objectstack#8593 ruling:
metric-card props belong to passthrough BaseSchema) moves into the shared
DashboardComponentSchema widget slot as a union, so ruled-legal component
nodes keep parsing whole with props intact.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PBjwYLS6BciTQW3c9xQiD2
…r, breaking narrative)
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PBjwYLS6BciTQW3c9xQiD2
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 45 chunks)3180.2 KB3222.7 KB
Main entry chunk (gzip)143.6 KB350 KB
Entry fileindex-tZ_USG_l.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (consoleActionDispatch.js)0.20KB0.19KB
app-shell (index.js)12.46KB4.71KB
app-shell (runtime-config.js)20.68KB7.36KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (ActiveOrganizationStorage.js)25.05KB9.16KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)2.07KB1.00KB
auth (AuthProvider.js)40.18KB10.59KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)8.46KB3.43KB
auth (index.js)3.19KB1.44KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.30KB1.02KB
auth (useWorkspaceAdminStatus.js)5.13KB2.35KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)512.08KB116.42KB
core (index.js)5.30KB2.13KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)177.67KB49.45KB
fields (index.js)243.64KB61.64KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (fallbackInterpolation.js)6.25KB2.77KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)26.89KB9.04KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)5.60KB2.33KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)11.71KB4.29KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)6.24KB2.16KB
permissions (discardProofCache.js)1.04KB0.55KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)4.83KB2.27KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.92KB12.93KB
plugin-charts (index.js)64.68KB18.35KB
plugin-chatbot (index.js)190.53KB45.18KB
plugin-dashboard (index.js)133.48KB34.51KB
plugin-designer (index.js)212.87KB43.19KB
plugin-detail (index.js)247.26KB63.17KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)133.11KB32.61KB
plugin-gantt (index.js)165.21KB40.37KB
plugin-grid (index.js)202.07KB54.61KB
plugin-kanban (index.js)53.14KB14.64KB
plugin-list (index.js)113.15KB27.59KB
plugin-map (index.js)20.20KB6.66KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.51KB11.94KB
plugin-timeline (index.js)29.27KB8.44KB
plugin-tree (index.js)8.98KB3.08KB
plugin-view (index.js)85.79KB21.10KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)4.47KB1.63KB
react (SchemaRenderer.js)81.07KB26.86KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)3.11KB1.48KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (dashboard-widget-options.js)3.08KB1.30KB
sdui-parser (index.js)4.93KB2.24KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)20.57KB5.88KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.28KB0.23KB
sdui-parser (validate.js)10.35KB3.60KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)2.74KB1.41KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)3.75KB1.85KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.85KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (icon-key-migration.js)4.26KB1.63KB
types (index.js)4.72KB2.24KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (spec-ui-namespace.js)0.20KB0.19KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)6.28KB2.87KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-warren
os-warren added this pull request to the merge queueAug 31, 2026
Merged via the queue into main with commit 7e19d03Aug 31, 2026
32 checks passed
@os-warren
os-warren deleted the claude/issue-6002-dashboard-widget-strict branch August 31, 2026 14:43
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants

@os-warren@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

feat(types)!: DashboardWidgetSchema refuses undeclared keys (.strict()) - #7033

Merged
os-warren merged 2 commits into
mainfrom
claude/issue-6002-dashboard-widget-strict
Aug 31, 2026
Merged

feat(types)!: DashboardWidgetSchema refuses undeclared keys (.strict())#7033
os-warren merged 2 commits into
mainfrom
claude/issue-6002-dashboard-widget-strict

Conversation

@os-warren

Copy link
Copy Markdown
Collaborator

Fixes#6002

Route 1 step 2 of the maintainer ruling (issue comment 5406212152, 2026-08-25): after #6150's declaration catch-up, DashboardWidgetSchema flips from strip-in-silence to .strict() — an undeclared widget key now refuses the parse with zod's unrecognized_keys issue naming every offending key. The card's measured five-keys-in/three-keys-out ACCEPT is reproduced in this PR's pin suite as a loud refusal naming zzcanary / categoryField / aggregate.

Step 0 — premise re-verified on the merged ref

#6150 closed via PR #6945 (squash commit 2c45966, contained in this branch's base f7850ee). All 13 recorded renderer-consumed keys verified declared, key by key, against the interface blocks on that ref: TextSchema.content · CarouselSchema.opts/orientation/itemClassName · FilterBuilderSchema.wrapperClass · TreeViewSchema.nodes/onNodeClick/title · CheckboxSchema.required · FileUploadSchema.buttonText/wrapperClass · HoverCardSchema.align · ContextMenuSchema.trigger. 13/13 declared — premise holds. (Note: none of the 13 are dashboard-widget keys; the family-1 corpus measurement below is what answers whether any LIVE dashboard depends on a key nothing declares.)

Step 1 — blast radius, measured before the change (ruling: not assumed)

The strict-refusal delta over the live corpus is EMPTY — no per-key fork back to triage is needed.

  1. Stored dashboard corpus. A preflight parsed every candidate with both the current schema and a .strict() candidate, routing component-enum types to BaseSchema per the 2026-08-14 ruling: 575 JSON files under examples/apps/packages/e2e/public plus every dashboard-bearing fenced block in md/mdx docs — 10 dashboard documents, 30 widgets (11 of them component nodes). Newly-refused widgets: zero. Doc fences that the script could not auto-parse were hand-triaged (all shape references or component-node examples; details in the report comment on finding(types): DashboardWidgetSchema SILENTLY DROPS every undeclared widget key — the file's own docstring names this failure mode, and it still applies to the keys nothing declares #6002). Two pre-existing, non-delta facts recorded: packages/plugin-dashboard/README.md fence 8 authors a widget with type: 'card', which the closed type enum already refuses TODAY (doc drift predating this PR — reported to PM as an out-of-scope finding); apps/console/src/preview-samples.ts's dashboard sample is already in that suite's KNOWN_STALE ledger against the spec schema (value/format/chart — also not a delta of this change).
  2. Designer emit paths. Every widget-emitting site enumerated and read: metadata-admin DashboardPreview add-widget emits id/type/title (WIDGET_TYPE_META defines no defaults); DashboardWidgetInspector patches title/type/dataset/dimensions/values/colorVariant/filterBindings/layout; plugin-designer DashboardEditor adds id/title/type/layout and edits title/type/colorVariant/layout; plugin-dashboard WidgetConfigPanel emits id/title/description/type/dataset/dimensions/values/colorVariant plus layout, with the legacy analytics and retired action keys scrubbed by sanitizeDraftForType. Every emitted key is in the declared set.
  3. Widget-slot component nodes (schema-catalog: all 9 plugin-dashboard examples are refused by the spec's DashboardSchema — the AI few-shot corpus teaches the pre-ADR-0021 widget shape #4600's BaseSchema routing). Measured on the current build: with a bare .strict() and no routing, the 11 ruled-legal metric-card widgets in the catalog corpus would refuse at the whole-document parse on value / icon / trend / trendValue — live documents the 2026-08-14 ruling (objectstack#8593) declares legal. BaseSchema accepts all 11. The routing the ruling names (component node owned by passthrough BaseSchema) therefore moves into the shared DashboardComponentSchema widget slot in this PR, as a union whose component arm is gated on the closed component-type enum — it is structurally unreachable for spec-family widgets, so it cannot become a hatch around the refusal. The routing schema is deliberately NOT exported (internal slot property, no new authoring surface).

Step 2 — the change

Tests and gates (final head 7718ccc; every run below was re-run at this sha)

  • New pin suite packages/types/src/__tests__/dashboard-widget-strict-6002.test.ts: the card's probe refuses naming all three keys; the retired inline-analytics quartet refuses as a set; a declared-surface widget parses green with every key surviving; the legacy id/component/layout envelope parses; a component-node document parses whole with props kept; two not-a-hatch pins refuse stray keys at document level.
  • pnpm exec vitest run packages/types/ examples/schema-catalog/ packages/cli/112 files, 3113 tests, all passed (includes the schema-catalog: all 9 plugin-dashboard examples are refused by the spec's DashboardSchema — the AI few-shot corpus teaches the pre-ADR-0021 widget shape #4600 gate with updated counter-probes, the safe-validate corpus sweep, and the CLI validate tests).
  • pnpm exec vitest run packages/plugin-dashboard/ packages/plugin-designer/ — 99 files, 901 tests, all passed.
  • @object-ui/types type-check (tsc noEmit + examples + test tsconfigs) green; tsc --listFiles confirms the new test file is in the compiled closure (1 hit — not a NOT-MEASURED green).
  • check-changeset-presence ✅ (1 changeset, minor with breaking narrative per the accept-set-narrowing precedent, no major — repo version policy) · check-changeset-no-major ✅ · check:control-bytes ✅ (5826 files) · check:spec-symbols ✅ · eslint on the three changed files: 0 errors (2 pre-existing warnings on untouched lines).
  • Ablation (committed first, mutation and restore both verified on disk): removing .strict() turns exactly the 4 refusal pins red (5 routing/positive pins stay green, as predicted); restore verified byte-identical to the HEAD blob. The suite resolves the subject through the vitest root alias to src, so no dist build sits in the ablation loop.
  • Declared narrowings, owned by CI: full pnpm lint (repo-wide eslint) and the full cross-package pnpm test farm were not run locally; the targeted set above covers every suite that runtime-parses these schemas (enumerated by grep over safeParse/parse call sites).

Review parking

Clause-② yes (accept/reject behaviour change on a published contract): this PR is parked as draft with needs:contract-review on both carriers, to be released through the in-seat contract-review flow (objectstack#13795) — not self-merged.

Generated by Claude Code


Generated by Claude Code

Route 1 step 2 of the maintainer ruling on objectui#6002: after #6150
declared the genuinely-consumed keys, the widget schema flips from
strip-in-silence to loud refusal — zod `unrecognized_keys` names every
offending key. The widget-slot component route (objectstack#8593 ruling:
metric-card props belong to passthrough BaseSchema) moves into the shared
DashboardComponentSchema widget slot as a union, so ruled-legal component
nodes keep parsing whole with props intact.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PBjwYLS6BciTQW3c9xQiD2
…r, breaking narrative)
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PBjwYLS6BciTQW3c9xQiD2
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 45 chunks)3180.2 KB3222.7 KB
Main entry chunk (gzip)143.6 KB350 KB
Entry fileindex-tZ_USG_l.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (consoleActionDispatch.js)0.20KB0.19KB
app-shell (index.js)12.46KB4.71KB
app-shell (runtime-config.js)20.68KB7.36KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (ActiveOrganizationStorage.js)25.05KB9.16KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)2.07KB1.00KB
auth (AuthProvider.js)40.18KB10.59KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)8.46KB3.43KB
auth (index.js)3.19KB1.44KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.30KB1.02KB
auth (useWorkspaceAdminStatus.js)5.13KB2.35KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)512.08KB116.42KB
core (index.js)5.30KB2.13KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)177.67KB49.45KB
fields (index.js)243.64KB61.64KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (fallbackInterpolation.js)6.25KB2.77KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)26.89KB9.04KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)5.60KB2.33KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)11.71KB4.29KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)6.24KB2.16KB
permissions (discardProofCache.js)1.04KB0.55KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)4.83KB2.27KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.92KB12.93KB
plugin-charts (index.js)64.68KB18.35KB
plugin-chatbot (index.js)190.53KB45.18KB
plugin-dashboard (index.js)133.48KB34.51KB
plugin-designer (index.js)212.87KB43.19KB
plugin-detail (index.js)247.26KB63.17KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)133.11KB32.61KB
plugin-gantt (index.js)165.21KB40.37KB
plugin-grid (index.js)202.07KB54.61KB
plugin-kanban (index.js)53.14KB14.64KB
plugin-list (index.js)113.15KB27.59KB
plugin-map (index.js)20.20KB6.66KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.51KB11.94KB
plugin-timeline (index.js)29.27KB8.44KB
plugin-tree (index.js)8.98KB3.08KB
plugin-view (index.js)85.79KB21.10KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)4.47KB1.63KB
react (SchemaRenderer.js)81.07KB26.86KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)3.11KB1.48KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (dashboard-widget-options.js)3.08KB1.30KB
sdui-parser (index.js)4.93KB2.24KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)20.57KB5.88KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.28KB0.23KB
sdui-parser (validate.js)10.35KB3.60KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)2.74KB1.41KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)3.75KB1.85KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.85KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (icon-key-migration.js)4.26KB1.63KB
types (index.js)4.72KB2.24KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (spec-ui-namespace.js)0.20KB0.19KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)6.28KB2.87KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-warren
os-warren added this pull request to the merge queueAug 31, 2026
Merged via the queue into main with commit 7e19d03Aug 31, 2026
32 checks passed
@os-warren
os-warren deleted the claude/issue-6002-dashboard-widget-strict branch August 31, 2026 14:43
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants

@os-warren@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(types)!: DashboardWidgetSchema refuses undeclared keys (.strict()) - #7033

Merged
os-warren merged 2 commits into
mainfrom
claude/issue-6002-dashboard-widget-strict
Aug 31, 2026
Merged

feat(types)!: DashboardWidgetSchema refuses undeclared keys (.strict())#7033
os-warren merged 2 commits into
mainfrom
claude/issue-6002-dashboard-widget-strict

Conversation

@os-warren

Copy link
Copy Markdown
Collaborator

Fixes#6002

Route 1 step 2 of the maintainer ruling (issue comment 5406212152, 2026-08-25): after #6150's declaration catch-up, DashboardWidgetSchema flips from strip-in-silence to .strict() — an undeclared widget key now refuses the parse with zod's unrecognized_keys issue naming every offending key. The card's measured five-keys-in/three-keys-out ACCEPT is reproduced in this PR's pin suite as a loud refusal naming zzcanary / categoryField / aggregate.

Step 0 — premise re-verified on the merged ref

#6150 closed via PR #6945 (squash commit 2c45966, contained in this branch's base f7850ee). All 13 recorded renderer-consumed keys verified declared, key by key, against the interface blocks on that ref: TextSchema.content · CarouselSchema.opts/orientation/itemClassName · FilterBuilderSchema.wrapperClass · TreeViewSchema.nodes/onNodeClick/title · CheckboxSchema.required · FileUploadSchema.buttonText/wrapperClass · HoverCardSchema.align · ContextMenuSchema.trigger. 13/13 declared — premise holds. (Note: none of the 13 are dashboard-widget keys; the family-1 corpus measurement below is what answers whether any LIVE dashboard depends on a key nothing declares.)

Step 1 — blast radius, measured before the change (ruling: not assumed)

The strict-refusal delta over the live corpus is EMPTY — no per-key fork back to triage is needed.

  1. Stored dashboard corpus. A preflight parsed every candidate with both the current schema and a .strict() candidate, routing component-enum types to BaseSchema per the 2026-08-14 ruling: 575 JSON files under examples/apps/packages/e2e/public plus every dashboard-bearing fenced block in md/mdx docs — 10 dashboard documents, 30 widgets (11 of them component nodes). Newly-refused widgets: zero. Doc fences that the script could not auto-parse were hand-triaged (all shape references or component-node examples; details in the report comment on finding(types): DashboardWidgetSchema SILENTLY DROPS every undeclared widget key — the file's own docstring names this failure mode, and it still applies to the keys nothing declares #6002). Two pre-existing, non-delta facts recorded: packages/plugin-dashboard/README.md fence 8 authors a widget with type: 'card', which the closed type enum already refuses TODAY (doc drift predating this PR — reported to PM as an out-of-scope finding); apps/console/src/preview-samples.ts's dashboard sample is already in that suite's KNOWN_STALE ledger against the spec schema (value/format/chart — also not a delta of this change).
  2. Designer emit paths. Every widget-emitting site enumerated and read: metadata-admin DashboardPreview add-widget emits id/type/title (WIDGET_TYPE_META defines no defaults); DashboardWidgetInspector patches title/type/dataset/dimensions/values/colorVariant/filterBindings/layout; plugin-designer DashboardEditor adds id/title/type/layout and edits title/type/colorVariant/layout; plugin-dashboard WidgetConfigPanel emits id/title/description/type/dataset/dimensions/values/colorVariant plus layout, with the legacy analytics and retired action keys scrubbed by sanitizeDraftForType. Every emitted key is in the declared set.
  3. Widget-slot component nodes (schema-catalog: all 9 plugin-dashboard examples are refused by the spec's DashboardSchema — the AI few-shot corpus teaches the pre-ADR-0021 widget shape #4600's BaseSchema routing). Measured on the current build: with a bare .strict() and no routing, the 11 ruled-legal metric-card widgets in the catalog corpus would refuse at the whole-document parse on value / icon / trend / trendValue — live documents the 2026-08-14 ruling (objectstack#8593) declares legal. BaseSchema accepts all 11. The routing the ruling names (component node owned by passthrough BaseSchema) therefore moves into the shared DashboardComponentSchema widget slot in this PR, as a union whose component arm is gated on the closed component-type enum — it is structurally unreachable for spec-family widgets, so it cannot become a hatch around the refusal. The routing schema is deliberately NOT exported (internal slot property, no new authoring surface).

Step 2 — the change

Tests and gates (final head 7718ccc; every run below was re-run at this sha)

  • New pin suite packages/types/src/__tests__/dashboard-widget-strict-6002.test.ts: the card's probe refuses naming all three keys; the retired inline-analytics quartet refuses as a set; a declared-surface widget parses green with every key surviving; the legacy id/component/layout envelope parses; a component-node document parses whole with props kept; two not-a-hatch pins refuse stray keys at document level.
  • pnpm exec vitest run packages/types/ examples/schema-catalog/ packages/cli/112 files, 3113 tests, all passed (includes the schema-catalog: all 9 plugin-dashboard examples are refused by the spec's DashboardSchema — the AI few-shot corpus teaches the pre-ADR-0021 widget shape #4600 gate with updated counter-probes, the safe-validate corpus sweep, and the CLI validate tests).
  • pnpm exec vitest run packages/plugin-dashboard/ packages/plugin-designer/ — 99 files, 901 tests, all passed.
  • @object-ui/types type-check (tsc noEmit + examples + test tsconfigs) green; tsc --listFiles confirms the new test file is in the compiled closure (1 hit — not a NOT-MEASURED green).
  • check-changeset-presence ✅ (1 changeset, minor with breaking narrative per the accept-set-narrowing precedent, no major — repo version policy) · check-changeset-no-major ✅ · check:control-bytes ✅ (5826 files) · check:spec-symbols ✅ · eslint on the three changed files: 0 errors (2 pre-existing warnings on untouched lines).
  • Ablation (committed first, mutation and restore both verified on disk): removing .strict() turns exactly the 4 refusal pins red (5 routing/positive pins stay green, as predicted); restore verified byte-identical to the HEAD blob. The suite resolves the subject through the vitest root alias to src, so no dist build sits in the ablation loop.
  • Declared narrowings, owned by CI: full pnpm lint (repo-wide eslint) and the full cross-package pnpm test farm were not run locally; the targeted set above covers every suite that runtime-parses these schemas (enumerated by grep over safeParse/parse call sites).

Review parking

Clause-② yes (accept/reject behaviour change on a published contract): this PR is parked as draft with needs:contract-review on both carriers, to be released through the in-seat contract-review flow (objectstack#13795) — not self-merged.

Generated by Claude Code


Generated by Claude Code

Route 1 step 2 of the maintainer ruling on objectui#6002: after #6150
declared the genuinely-consumed keys, the widget schema flips from
strip-in-silence to loud refusal — zod `unrecognized_keys` names every
offending key. The widget-slot component route (objectstack#8593 ruling:
metric-card props belong to passthrough BaseSchema) moves into the shared
DashboardComponentSchema widget slot as a union, so ruled-legal component
nodes keep parsing whole with props intact.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PBjwYLS6BciTQW3c9xQiD2
…r, breaking narrative)
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PBjwYLS6BciTQW3c9xQiD2
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 45 chunks)3180.2 KB3222.7 KB
Main entry chunk (gzip)143.6 KB350 KB
Entry fileindex-tZ_USG_l.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (consoleActionDispatch.js)0.20KB0.19KB
app-shell (index.js)12.46KB4.71KB
app-shell (runtime-config.js)20.68KB7.36KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (ActiveOrganizationStorage.js)25.05KB9.16KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)2.07KB1.00KB
auth (AuthProvider.js)40.18KB10.59KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)8.46KB3.43KB
auth (index.js)3.19KB1.44KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.30KB1.02KB
auth (useWorkspaceAdminStatus.js)5.13KB2.35KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)512.08KB116.42KB
core (index.js)5.30KB2.13KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)177.67KB49.45KB
fields (index.js)243.64KB61.64KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (fallbackInterpolation.js)6.25KB2.77KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)26.89KB9.04KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)5.60KB2.33KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)11.71KB4.29KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)6.24KB2.16KB
permissions (discardProofCache.js)1.04KB0.55KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)4.83KB2.27KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.92KB12.93KB
plugin-charts (index.js)64.68KB18.35KB
plugin-chatbot (index.js)190.53KB45.18KB
plugin-dashboard (index.js)133.48KB34.51KB
plugin-designer (index.js)212.87KB43.19KB
plugin-detail (index.js)247.26KB63.17KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)133.11KB32.61KB
plugin-gantt (index.js)165.21KB40.37KB
plugin-grid (index.js)202.07KB54.61KB
plugin-kanban (index.js)53.14KB14.64KB
plugin-list (index.js)113.15KB27.59KB
plugin-map (index.js)20.20KB6.66KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.51KB11.94KB
plugin-timeline (index.js)29.27KB8.44KB
plugin-tree (index.js)8.98KB3.08KB
plugin-view (index.js)85.79KB21.10KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)4.47KB1.63KB
react (SchemaRenderer.js)81.07KB26.86KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)3.11KB1.48KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (dashboard-widget-options.js)3.08KB1.30KB
sdui-parser (index.js)4.93KB2.24KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)20.57KB5.88KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.28KB0.23KB
sdui-parser (validate.js)10.35KB3.60KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)2.74KB1.41KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)3.75KB1.85KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.85KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (icon-key-migration.js)4.26KB1.63KB
types (index.js)4.72KB2.24KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (spec-ui-namespace.js)0.20KB0.19KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)6.28KB2.87KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-warren
os-warren added this pull request to the merge queueAug 31, 2026
Merged via the queue into main with commit 7e19d03Aug 31, 2026
32 checks passed
@os-warren
os-warren deleted the claude/issue-6002-dashboard-widget-strict branch August 31, 2026 14:43
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants

@os-warren@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(types)!: DashboardWidgetSchema refuses undeclared keys (.strict()) - #7033

Merged
os-warren merged 2 commits into
mainfrom
claude/issue-6002-dashboard-widget-strict
Aug 31, 2026
Merged

feat(types)!: DashboardWidgetSchema refuses undeclared keys (.strict())#7033
os-warren merged 2 commits into
mainfrom
claude/issue-6002-dashboard-widget-strict

Conversation

@os-warren

Copy link
Copy Markdown
Collaborator

Fixes#6002

Route 1 step 2 of the maintainer ruling (issue comment 5406212152, 2026-08-25): after #6150's declaration catch-up, DashboardWidgetSchema flips from strip-in-silence to .strict() — an undeclared widget key now refuses the parse with zod's unrecognized_keys issue naming every offending key. The card's measured five-keys-in/three-keys-out ACCEPT is reproduced in this PR's pin suite as a loud refusal naming zzcanary / categoryField / aggregate.

Step 0 — premise re-verified on the merged ref

#6150 closed via PR #6945 (squash commit 2c45966, contained in this branch's base f7850ee). All 13 recorded renderer-consumed keys verified declared, key by key, against the interface blocks on that ref: TextSchema.content · CarouselSchema.opts/orientation/itemClassName · FilterBuilderSchema.wrapperClass · TreeViewSchema.nodes/onNodeClick/title · CheckboxSchema.required · FileUploadSchema.buttonText/wrapperClass · HoverCardSchema.align · ContextMenuSchema.trigger. 13/13 declared — premise holds. (Note: none of the 13 are dashboard-widget keys; the family-1 corpus measurement below is what answers whether any LIVE dashboard depends on a key nothing declares.)

Step 1 — blast radius, measured before the change (ruling: not assumed)

The strict-refusal delta over the live corpus is EMPTY — no per-key fork back to triage is needed.

  1. Stored dashboard corpus. A preflight parsed every candidate with both the current schema and a .strict() candidate, routing component-enum types to BaseSchema per the 2026-08-14 ruling: 575 JSON files under examples/apps/packages/e2e/public plus every dashboard-bearing fenced block in md/mdx docs — 10 dashboard documents, 30 widgets (11 of them component nodes). Newly-refused widgets: zero. Doc fences that the script could not auto-parse were hand-triaged (all shape references or component-node examples; details in the report comment on finding(types): DashboardWidgetSchema SILENTLY DROPS every undeclared widget key — the file's own docstring names this failure mode, and it still applies to the keys nothing declares #6002). Two pre-existing, non-delta facts recorded: packages/plugin-dashboard/README.md fence 8 authors a widget with type: 'card', which the closed type enum already refuses TODAY (doc drift predating this PR — reported to PM as an out-of-scope finding); apps/console/src/preview-samples.ts's dashboard sample is already in that suite's KNOWN_STALE ledger against the spec schema (value/format/chart — also not a delta of this change).
  2. Designer emit paths. Every widget-emitting site enumerated and read: metadata-admin DashboardPreview add-widget emits id/type/title (WIDGET_TYPE_META defines no defaults); DashboardWidgetInspector patches title/type/dataset/dimensions/values/colorVariant/filterBindings/layout; plugin-designer DashboardEditor adds id/title/type/layout and edits title/type/colorVariant/layout; plugin-dashboard WidgetConfigPanel emits id/title/description/type/dataset/dimensions/values/colorVariant plus layout, with the legacy analytics and retired action keys scrubbed by sanitizeDraftForType. Every emitted key is in the declared set.
  3. Widget-slot component nodes (schema-catalog: all 9 plugin-dashboard examples are refused by the spec's DashboardSchema — the AI few-shot corpus teaches the pre-ADR-0021 widget shape #4600's BaseSchema routing). Measured on the current build: with a bare .strict() and no routing, the 11 ruled-legal metric-card widgets in the catalog corpus would refuse at the whole-document parse on value / icon / trend / trendValue — live documents the 2026-08-14 ruling (objectstack#8593) declares legal. BaseSchema accepts all 11. The routing the ruling names (component node owned by passthrough BaseSchema) therefore moves into the shared DashboardComponentSchema widget slot in this PR, as a union whose component arm is gated on the closed component-type enum — it is structurally unreachable for spec-family widgets, so it cannot become a hatch around the refusal. The routing schema is deliberately NOT exported (internal slot property, no new authoring surface).

Step 2 — the change

Tests and gates (final head 7718ccc; every run below was re-run at this sha)

  • New pin suite packages/types/src/__tests__/dashboard-widget-strict-6002.test.ts: the card's probe refuses naming all three keys; the retired inline-analytics quartet refuses as a set; a declared-surface widget parses green with every key surviving; the legacy id/component/layout envelope parses; a component-node document parses whole with props kept; two not-a-hatch pins refuse stray keys at document level.
  • pnpm exec vitest run packages/types/ examples/schema-catalog/ packages/cli/112 files, 3113 tests, all passed (includes the schema-catalog: all 9 plugin-dashboard examples are refused by the spec's DashboardSchema — the AI few-shot corpus teaches the pre-ADR-0021 widget shape #4600 gate with updated counter-probes, the safe-validate corpus sweep, and the CLI validate tests).
  • pnpm exec vitest run packages/plugin-dashboard/ packages/plugin-designer/ — 99 files, 901 tests, all passed.
  • @object-ui/types type-check (tsc noEmit + examples + test tsconfigs) green; tsc --listFiles confirms the new test file is in the compiled closure (1 hit — not a NOT-MEASURED green).
  • check-changeset-presence ✅ (1 changeset, minor with breaking narrative per the accept-set-narrowing precedent, no major — repo version policy) · check-changeset-no-major ✅ · check:control-bytes ✅ (5826 files) · check:spec-symbols ✅ · eslint on the three changed files: 0 errors (2 pre-existing warnings on untouched lines).
  • Ablation (committed first, mutation and restore both verified on disk): removing .strict() turns exactly the 4 refusal pins red (5 routing/positive pins stay green, as predicted); restore verified byte-identical to the HEAD blob. The suite resolves the subject through the vitest root alias to src, so no dist build sits in the ablation loop.
  • Declared narrowings, owned by CI: full pnpm lint (repo-wide eslint) and the full cross-package pnpm test farm were not run locally; the targeted set above covers every suite that runtime-parses these schemas (enumerated by grep over safeParse/parse call sites).

Review parking

Clause-② yes (accept/reject behaviour change on a published contract): this PR is parked as draft with needs:contract-review on both carriers, to be released through the in-seat contract-review flow (objectstack#13795) — not self-merged.

Generated by Claude Code


Generated by Claude Code

Route 1 step 2 of the maintainer ruling on objectui#6002: after #6150
declared the genuinely-consumed keys, the widget schema flips from
strip-in-silence to loud refusal — zod `unrecognized_keys` names every
offending key. The widget-slot component route (objectstack#8593 ruling:
metric-card props belong to passthrough BaseSchema) moves into the shared
DashboardComponentSchema widget slot as a union, so ruled-legal component
nodes keep parsing whole with props intact.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PBjwYLS6BciTQW3c9xQiD2
…r, breaking narrative)
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PBjwYLS6BciTQW3c9xQiD2
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 45 chunks)3180.2 KB3222.7 KB
Main entry chunk (gzip)143.6 KB350 KB
Entry fileindex-tZ_USG_l.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (consoleActionDispatch.js)0.20KB0.19KB
app-shell (index.js)12.46KB4.71KB
app-shell (runtime-config.js)20.68KB7.36KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (ActiveOrganizationStorage.js)25.05KB9.16KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)2.07KB1.00KB
auth (AuthProvider.js)40.18KB10.59KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)8.46KB3.43KB
auth (index.js)3.19KB1.44KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.30KB1.02KB
auth (useWorkspaceAdminStatus.js)5.13KB2.35KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)512.08KB116.42KB
core (index.js)5.30KB2.13KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)177.67KB49.45KB
fields (index.js)243.64KB61.64KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (fallbackInterpolation.js)6.25KB2.77KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)26.89KB9.04KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)5.60KB2.33KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)11.71KB4.29KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)6.24KB2.16KB
permissions (discardProofCache.js)1.04KB0.55KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)4.83KB2.27KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.92KB12.93KB
plugin-charts (index.js)64.68KB18.35KB
plugin-chatbot (index.js)190.53KB45.18KB
plugin-dashboard (index.js)133.48KB34.51KB
plugin-designer (index.js)212.87KB43.19KB
plugin-detail (index.js)247.26KB63.17KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)133.11KB32.61KB
plugin-gantt (index.js)165.21KB40.37KB
plugin-grid (index.js)202.07KB54.61KB
plugin-kanban (index.js)53.14KB14.64KB
plugin-list (index.js)113.15KB27.59KB
plugin-map (index.js)20.20KB6.66KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.51KB11.94KB
plugin-timeline (index.js)29.27KB8.44KB
plugin-tree (index.js)8.98KB3.08KB
plugin-view (index.js)85.79KB21.10KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)4.47KB1.63KB
react (SchemaRenderer.js)81.07KB26.86KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)3.11KB1.48KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (dashboard-widget-options.js)3.08KB1.30KB
sdui-parser (index.js)4.93KB2.24KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)20.57KB5.88KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.28KB0.23KB
sdui-parser (validate.js)10.35KB3.60KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)2.74KB1.41KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)3.75KB1.85KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.85KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (icon-key-migration.js)4.26KB1.63KB
types (index.js)4.72KB2.24KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (spec-ui-namespace.js)0.20KB0.19KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)6.28KB2.87KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-warren
os-warren added this pull request to the merge queueAug 31, 2026
Merged via the queue into main with commit 7e19d03Aug 31, 2026
32 checks passed
@os-warren
os-warren deleted the claude/issue-6002-dashboard-widget-strict branch August 31, 2026 14:43
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants

@os-warren@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

feat(types)!: DashboardWidgetSchema refuses undeclared keys (.strict()) - #7033

Merged
os-warren merged 2 commits into
mainfrom
claude/issue-6002-dashboard-widget-strict
Aug 31, 2026
Merged

feat(types)!: DashboardWidgetSchema refuses undeclared keys (.strict())#7033
os-warren merged 2 commits into
mainfrom
claude/issue-6002-dashboard-widget-strict

Conversation

@os-warren

Copy link
Copy Markdown
Collaborator

Fixes#6002

Route 1 step 2 of the maintainer ruling (issue comment 5406212152, 2026-08-25): after #6150's declaration catch-up, DashboardWidgetSchema flips from strip-in-silence to .strict() — an undeclared widget key now refuses the parse with zod's unrecognized_keys issue naming every offending key. The card's measured five-keys-in/three-keys-out ACCEPT is reproduced in this PR's pin suite as a loud refusal naming zzcanary / categoryField / aggregate.

Step 0 — premise re-verified on the merged ref

#6150 closed via PR #6945 (squash commit 2c45966, contained in this branch's base f7850ee). All 13 recorded renderer-consumed keys verified declared, key by key, against the interface blocks on that ref: TextSchema.content · CarouselSchema.opts/orientation/itemClassName · FilterBuilderSchema.wrapperClass · TreeViewSchema.nodes/onNodeClick/title · CheckboxSchema.required · FileUploadSchema.buttonText/wrapperClass · HoverCardSchema.align · ContextMenuSchema.trigger. 13/13 declared — premise holds. (Note: none of the 13 are dashboard-widget keys; the family-1 corpus measurement below is what answers whether any LIVE dashboard depends on a key nothing declares.)

Step 1 — blast radius, measured before the change (ruling: not assumed)

The strict-refusal delta over the live corpus is EMPTY — no per-key fork back to triage is needed.

  1. Stored dashboard corpus. A preflight parsed every candidate with both the current schema and a .strict() candidate, routing component-enum types to BaseSchema per the 2026-08-14 ruling: 575 JSON files under examples/apps/packages/e2e/public plus every dashboard-bearing fenced block in md/mdx docs — 10 dashboard documents, 30 widgets (11 of them component nodes). Newly-refused widgets: zero. Doc fences that the script could not auto-parse were hand-triaged (all shape references or component-node examples; details in the report comment on finding(types): DashboardWidgetSchema SILENTLY DROPS every undeclared widget key — the file's own docstring names this failure mode, and it still applies to the keys nothing declares #6002). Two pre-existing, non-delta facts recorded: packages/plugin-dashboard/README.md fence 8 authors a widget with type: 'card', which the closed type enum already refuses TODAY (doc drift predating this PR — reported to PM as an out-of-scope finding); apps/console/src/preview-samples.ts's dashboard sample is already in that suite's KNOWN_STALE ledger against the spec schema (value/format/chart — also not a delta of this change).
  2. Designer emit paths. Every widget-emitting site enumerated and read: metadata-admin DashboardPreview add-widget emits id/type/title (WIDGET_TYPE_META defines no defaults); DashboardWidgetInspector patches title/type/dataset/dimensions/values/colorVariant/filterBindings/layout; plugin-designer DashboardEditor adds id/title/type/layout and edits title/type/colorVariant/layout; plugin-dashboard WidgetConfigPanel emits id/title/description/type/dataset/dimensions/values/colorVariant plus layout, with the legacy analytics and retired action keys scrubbed by sanitizeDraftForType. Every emitted key is in the declared set.
  3. Widget-slot component nodes (schema-catalog: all 9 plugin-dashboard examples are refused by the spec's DashboardSchema — the AI few-shot corpus teaches the pre-ADR-0021 widget shape #4600's BaseSchema routing). Measured on the current build: with a bare .strict() and no routing, the 11 ruled-legal metric-card widgets in the catalog corpus would refuse at the whole-document parse on value / icon / trend / trendValue — live documents the 2026-08-14 ruling (objectstack#8593) declares legal. BaseSchema accepts all 11. The routing the ruling names (component node owned by passthrough BaseSchema) therefore moves into the shared DashboardComponentSchema widget slot in this PR, as a union whose component arm is gated on the closed component-type enum — it is structurally unreachable for spec-family widgets, so it cannot become a hatch around the refusal. The routing schema is deliberately NOT exported (internal slot property, no new authoring surface).

Step 2 — the change

Tests and gates (final head 7718ccc; every run below was re-run at this sha)

  • New pin suite packages/types/src/__tests__/dashboard-widget-strict-6002.test.ts: the card's probe refuses naming all three keys; the retired inline-analytics quartet refuses as a set; a declared-surface widget parses green with every key surviving; the legacy id/component/layout envelope parses; a component-node document parses whole with props kept; two not-a-hatch pins refuse stray keys at document level.
  • pnpm exec vitest run packages/types/ examples/schema-catalog/ packages/cli/112 files, 3113 tests, all passed (includes the schema-catalog: all 9 plugin-dashboard examples are refused by the spec's DashboardSchema — the AI few-shot corpus teaches the pre-ADR-0021 widget shape #4600 gate with updated counter-probes, the safe-validate corpus sweep, and the CLI validate tests).
  • pnpm exec vitest run packages/plugin-dashboard/ packages/plugin-designer/ — 99 files, 901 tests, all passed.
  • @object-ui/types type-check (tsc noEmit + examples + test tsconfigs) green; tsc --listFiles confirms the new test file is in the compiled closure (1 hit — not a NOT-MEASURED green).
  • check-changeset-presence ✅ (1 changeset, minor with breaking narrative per the accept-set-narrowing precedent, no major — repo version policy) · check-changeset-no-major ✅ · check:control-bytes ✅ (5826 files) · check:spec-symbols ✅ · eslint on the three changed files: 0 errors (2 pre-existing warnings on untouched lines).
  • Ablation (committed first, mutation and restore both verified on disk): removing .strict() turns exactly the 4 refusal pins red (5 routing/positive pins stay green, as predicted); restore verified byte-identical to the HEAD blob. The suite resolves the subject through the vitest root alias to src, so no dist build sits in the ablation loop.
  • Declared narrowings, owned by CI: full pnpm lint (repo-wide eslint) and the full cross-package pnpm test farm were not run locally; the targeted set above covers every suite that runtime-parses these schemas (enumerated by grep over safeParse/parse call sites).

Review parking

Clause-② yes (accept/reject behaviour change on a published contract): this PR is parked as draft with needs:contract-review on both carriers, to be released through the in-seat contract-review flow (objectstack#13795) — not self-merged.

Generated by Claude Code


Generated by Claude Code

Route 1 step 2 of the maintainer ruling on objectui#6002: after #6150
declared the genuinely-consumed keys, the widget schema flips from
strip-in-silence to loud refusal — zod `unrecognized_keys` names every
offending key. The widget-slot component route (objectstack#8593 ruling:
metric-card props belong to passthrough BaseSchema) moves into the shared
DashboardComponentSchema widget slot as a union, so ruled-legal component
nodes keep parsing whole with props intact.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PBjwYLS6BciTQW3c9xQiD2
…r, breaking narrative)
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PBjwYLS6BciTQW3c9xQiD2
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 45 chunks)3180.2 KB3222.7 KB
Main entry chunk (gzip)143.6 KB350 KB
Entry fileindex-tZ_USG_l.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (consoleActionDispatch.js)0.20KB0.19KB
app-shell (index.js)12.46KB4.71KB
app-shell (runtime-config.js)20.68KB7.36KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (ActiveOrganizationStorage.js)25.05KB9.16KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)2.07KB1.00KB
auth (AuthProvider.js)40.18KB10.59KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)8.46KB3.43KB
auth (index.js)3.19KB1.44KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.30KB1.02KB
auth (useWorkspaceAdminStatus.js)5.13KB2.35KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)512.08KB116.42KB
core (index.js)5.30KB2.13KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)177.67KB49.45KB
fields (index.js)243.64KB61.64KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (fallbackInterpolation.js)6.25KB2.77KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)26.89KB9.04KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)5.60KB2.33KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)11.71KB4.29KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)6.24KB2.16KB
permissions (discardProofCache.js)1.04KB0.55KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)4.83KB2.27KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.92KB12.93KB
plugin-charts (index.js)64.68KB18.35KB
plugin-chatbot (index.js)190.53KB45.18KB
plugin-dashboard (index.js)133.48KB34.51KB
plugin-designer (index.js)212.87KB43.19KB
plugin-detail (index.js)247.26KB63.17KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)133.11KB32.61KB
plugin-gantt (index.js)165.21KB40.37KB
plugin-grid (index.js)202.07KB54.61KB
plugin-kanban (index.js)53.14KB14.64KB
plugin-list (index.js)113.15KB27.59KB
plugin-map (index.js)20.20KB6.66KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.51KB11.94KB
plugin-timeline (index.js)29.27KB8.44KB
plugin-tree (index.js)8.98KB3.08KB
plugin-view (index.js)85.79KB21.10KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)4.47KB1.63KB
react (SchemaRenderer.js)81.07KB26.86KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)3.11KB1.48KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (dashboard-widget-options.js)3.08KB1.30KB
sdui-parser (index.js)4.93KB2.24KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)20.57KB5.88KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.28KB0.23KB
sdui-parser (validate.js)10.35KB3.60KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)2.74KB1.41KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)3.75KB1.85KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.85KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (icon-key-migration.js)4.26KB1.63KB
types (index.js)4.72KB2.24KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (spec-ui-namespace.js)0.20KB0.19KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)6.28KB2.87KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-warren
os-warren added this pull request to the merge queueAug 31, 2026
Merged via the queue into main with commit 7e19d03Aug 31, 2026
32 checks passed
@os-warren
os-warren deleted the claude/issue-6002-dashboard-widget-strict branch August 31, 2026 14:43
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants

@os-warren@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(types)!: DashboardWidgetSchema refuses undeclared keys (.strict()) - #7033

Merged
os-warren merged 2 commits into
mainfrom
claude/issue-6002-dashboard-widget-strict
Aug 31, 2026
Merged

feat(types)!: DashboardWidgetSchema refuses undeclared keys (.strict())#7033
os-warren merged 2 commits into
mainfrom
claude/issue-6002-dashboard-widget-strict

Conversation

@os-warren

Copy link
Copy Markdown
Collaborator

Fixes#6002

Route 1 step 2 of the maintainer ruling (issue comment 5406212152, 2026-08-25): after #6150's declaration catch-up, DashboardWidgetSchema flips from strip-in-silence to .strict() — an undeclared widget key now refuses the parse with zod's unrecognized_keys issue naming every offending key. The card's measured five-keys-in/three-keys-out ACCEPT is reproduced in this PR's pin suite as a loud refusal naming zzcanary / categoryField / aggregate.

Step 0 — premise re-verified on the merged ref

#6150 closed via PR #6945 (squash commit 2c45966, contained in this branch's base f7850ee). All 13 recorded renderer-consumed keys verified declared, key by key, against the interface blocks on that ref: TextSchema.content · CarouselSchema.opts/orientation/itemClassName · FilterBuilderSchema.wrapperClass · TreeViewSchema.nodes/onNodeClick/title · CheckboxSchema.required · FileUploadSchema.buttonText/wrapperClass · HoverCardSchema.align · ContextMenuSchema.trigger. 13/13 declared — premise holds. (Note: none of the 13 are dashboard-widget keys; the family-1 corpus measurement below is what answers whether any LIVE dashboard depends on a key nothing declares.)

Step 1 — blast radius, measured before the change (ruling: not assumed)

The strict-refusal delta over the live corpus is EMPTY — no per-key fork back to triage is needed.

  1. Stored dashboard corpus. A preflight parsed every candidate with both the current schema and a .strict() candidate, routing component-enum types to BaseSchema per the 2026-08-14 ruling: 575 JSON files under examples/apps/packages/e2e/public plus every dashboard-bearing fenced block in md/mdx docs — 10 dashboard documents, 30 widgets (11 of them component nodes). Newly-refused widgets: zero. Doc fences that the script could not auto-parse were hand-triaged (all shape references or component-node examples; details in the report comment on finding(types): DashboardWidgetSchema SILENTLY DROPS every undeclared widget key — the file's own docstring names this failure mode, and it still applies to the keys nothing declares #6002). Two pre-existing, non-delta facts recorded: packages/plugin-dashboard/README.md fence 8 authors a widget with type: 'card', which the closed type enum already refuses TODAY (doc drift predating this PR — reported to PM as an out-of-scope finding); apps/console/src/preview-samples.ts's dashboard sample is already in that suite's KNOWN_STALE ledger against the spec schema (value/format/chart — also not a delta of this change).
  2. Designer emit paths. Every widget-emitting site enumerated and read: metadata-admin DashboardPreview add-widget emits id/type/title (WIDGET_TYPE_META defines no defaults); DashboardWidgetInspector patches title/type/dataset/dimensions/values/colorVariant/filterBindings/layout; plugin-designer DashboardEditor adds id/title/type/layout and edits title/type/colorVariant/layout; plugin-dashboard WidgetConfigPanel emits id/title/description/type/dataset/dimensions/values/colorVariant plus layout, with the legacy analytics and retired action keys scrubbed by sanitizeDraftForType. Every emitted key is in the declared set.
  3. Widget-slot component nodes (schema-catalog: all 9 plugin-dashboard examples are refused by the spec's DashboardSchema — the AI few-shot corpus teaches the pre-ADR-0021 widget shape #4600's BaseSchema routing). Measured on the current build: with a bare .strict() and no routing, the 11 ruled-legal metric-card widgets in the catalog corpus would refuse at the whole-document parse on value / icon / trend / trendValue — live documents the 2026-08-14 ruling (objectstack#8593) declares legal. BaseSchema accepts all 11. The routing the ruling names (component node owned by passthrough BaseSchema) therefore moves into the shared DashboardComponentSchema widget slot in this PR, as a union whose component arm is gated on the closed component-type enum — it is structurally unreachable for spec-family widgets, so it cannot become a hatch around the refusal. The routing schema is deliberately NOT exported (internal slot property, no new authoring surface).

Step 2 — the change

Tests and gates (final head 7718ccc; every run below was re-run at this sha)

  • New pin suite packages/types/src/__tests__/dashboard-widget-strict-6002.test.ts: the card's probe refuses naming all three keys; the retired inline-analytics quartet refuses as a set; a declared-surface widget parses green with every key surviving; the legacy id/component/layout envelope parses; a component-node document parses whole with props kept; two not-a-hatch pins refuse stray keys at document level.
  • pnpm exec vitest run packages/types/ examples/schema-catalog/ packages/cli/112 files, 3113 tests, all passed (includes the schema-catalog: all 9 plugin-dashboard examples are refused by the spec's DashboardSchema — the AI few-shot corpus teaches the pre-ADR-0021 widget shape #4600 gate with updated counter-probes, the safe-validate corpus sweep, and the CLI validate tests).
  • pnpm exec vitest run packages/plugin-dashboard/ packages/plugin-designer/ — 99 files, 901 tests, all passed.
  • @object-ui/types type-check (tsc noEmit + examples + test tsconfigs) green; tsc --listFiles confirms the new test file is in the compiled closure (1 hit — not a NOT-MEASURED green).
  • check-changeset-presence ✅ (1 changeset, minor with breaking narrative per the accept-set-narrowing precedent, no major — repo version policy) · check-changeset-no-major ✅ · check:control-bytes ✅ (5826 files) · check:spec-symbols ✅ · eslint on the three changed files: 0 errors (2 pre-existing warnings on untouched lines).
  • Ablation (committed first, mutation and restore both verified on disk): removing .strict() turns exactly the 4 refusal pins red (5 routing/positive pins stay green, as predicted); restore verified byte-identical to the HEAD blob. The suite resolves the subject through the vitest root alias to src, so no dist build sits in the ablation loop.
  • Declared narrowings, owned by CI: full pnpm lint (repo-wide eslint) and the full cross-package pnpm test farm were not run locally; the targeted set above covers every suite that runtime-parses these schemas (enumerated by grep over safeParse/parse call sites).

Review parking

Clause-② yes (accept/reject behaviour change on a published contract): this PR is parked as draft with needs:contract-review on both carriers, to be released through the in-seat contract-review flow (objectstack#13795) — not self-merged.

Generated by Claude Code


Generated by Claude Code

Route 1 step 2 of the maintainer ruling on objectui#6002: after #6150
declared the genuinely-consumed keys, the widget schema flips from
strip-in-silence to loud refusal — zod `unrecognized_keys` names every
offending key. The widget-slot component route (objectstack#8593 ruling:
metric-card props belong to passthrough BaseSchema) moves into the shared
DashboardComponentSchema widget slot as a union, so ruled-legal component
nodes keep parsing whole with props intact.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PBjwYLS6BciTQW3c9xQiD2
…r, breaking narrative)
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PBjwYLS6BciTQW3c9xQiD2
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 45 chunks)3180.2 KB3222.7 KB
Main entry chunk (gzip)143.6 KB350 KB
Entry fileindex-tZ_USG_l.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (consoleActionDispatch.js)0.20KB0.19KB
app-shell (index.js)12.46KB4.71KB
app-shell (runtime-config.js)20.68KB7.36KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (ActiveOrganizationStorage.js)25.05KB9.16KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)2.07KB1.00KB
auth (AuthProvider.js)40.18KB10.59KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)8.46KB3.43KB
auth (index.js)3.19KB1.44KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.30KB1.02KB
auth (useWorkspaceAdminStatus.js)5.13KB2.35KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)512.08KB116.42KB
core (index.js)5.30KB2.13KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)177.67KB49.45KB
fields (index.js)243.64KB61.64KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (fallbackInterpolation.js)6.25KB2.77KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)26.89KB9.04KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)5.60KB2.33KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)11.71KB4.29KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)6.24KB2.16KB
permissions (discardProofCache.js)1.04KB0.55KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)4.83KB2.27KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.92KB12.93KB
plugin-charts (index.js)64.68KB18.35KB
plugin-chatbot (index.js)190.53KB45.18KB
plugin-dashboard (index.js)133.48KB34.51KB
plugin-designer (index.js)212.87KB43.19KB
plugin-detail (index.js)247.26KB63.17KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)133.11KB32.61KB
plugin-gantt (index.js)165.21KB40.37KB
plugin-grid (index.js)202.07KB54.61KB
plugin-kanban (index.js)53.14KB14.64KB
plugin-list (index.js)113.15KB27.59KB
plugin-map (index.js)20.20KB6.66KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.51KB11.94KB
plugin-timeline (index.js)29.27KB8.44KB
plugin-tree (index.js)8.98KB3.08KB
plugin-view (index.js)85.79KB21.10KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)4.47KB1.63KB
react (SchemaRenderer.js)81.07KB26.86KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)3.11KB1.48KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (dashboard-widget-options.js)3.08KB1.30KB
sdui-parser (index.js)4.93KB2.24KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)20.57KB5.88KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.28KB0.23KB
sdui-parser (validate.js)10.35KB3.60KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)2.74KB1.41KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)3.75KB1.85KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.85KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (icon-key-migration.js)4.26KB1.63KB
types (index.js)4.72KB2.24KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (spec-ui-namespace.js)0.20KB0.19KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)6.28KB2.87KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-warren
os-warren added this pull request to the merge queueAug 31, 2026
Merged via the queue into main with commit 7e19d03Aug 31, 2026
32 checks passed
@os-warren
os-warren deleted the claude/issue-6002-dashboard-widget-strict branch August 31, 2026 14:43
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants

@os-warren@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(types)!: DashboardWidgetSchema refuses undeclared keys (.strict()) - #7033

Merged
os-warren merged 2 commits into
mainfrom
claude/issue-6002-dashboard-widget-strict
Aug 31, 2026
Merged

feat(types)!: DashboardWidgetSchema refuses undeclared keys (.strict())#7033
os-warren merged 2 commits into
mainfrom
claude/issue-6002-dashboard-widget-strict

Conversation

@os-warren

Copy link
Copy Markdown
Collaborator

Fixes#6002

Route 1 step 2 of the maintainer ruling (issue comment 5406212152, 2026-08-25): after #6150's declaration catch-up, DashboardWidgetSchema flips from strip-in-silence to .strict() — an undeclared widget key now refuses the parse with zod's unrecognized_keys issue naming every offending key. The card's measured five-keys-in/three-keys-out ACCEPT is reproduced in this PR's pin suite as a loud refusal naming zzcanary / categoryField / aggregate.

Step 0 — premise re-verified on the merged ref

#6150 closed via PR #6945 (squash commit 2c45966, contained in this branch's base f7850ee). All 13 recorded renderer-consumed keys verified declared, key by key, against the interface blocks on that ref: TextSchema.content · CarouselSchema.opts/orientation/itemClassName · FilterBuilderSchema.wrapperClass · TreeViewSchema.nodes/onNodeClick/title · CheckboxSchema.required · FileUploadSchema.buttonText/wrapperClass · HoverCardSchema.align · ContextMenuSchema.trigger. 13/13 declared — premise holds. (Note: none of the 13 are dashboard-widget keys; the family-1 corpus measurement below is what answers whether any LIVE dashboard depends on a key nothing declares.)

Step 1 — blast radius, measured before the change (ruling: not assumed)

The strict-refusal delta over the live corpus is EMPTY — no per-key fork back to triage is needed.

  1. Stored dashboard corpus. A preflight parsed every candidate with both the current schema and a .strict() candidate, routing component-enum types to BaseSchema per the 2026-08-14 ruling: 575 JSON files under examples/apps/packages/e2e/public plus every dashboard-bearing fenced block in md/mdx docs — 10 dashboard documents, 30 widgets (11 of them component nodes). Newly-refused widgets: zero. Doc fences that the script could not auto-parse were hand-triaged (all shape references or component-node examples; details in the report comment on finding(types): DashboardWidgetSchema SILENTLY DROPS every undeclared widget key — the file's own docstring names this failure mode, and it still applies to the keys nothing declares #6002). Two pre-existing, non-delta facts recorded: packages/plugin-dashboard/README.md fence 8 authors a widget with type: 'card', which the closed type enum already refuses TODAY (doc drift predating this PR — reported to PM as an out-of-scope finding); apps/console/src/preview-samples.ts's dashboard sample is already in that suite's KNOWN_STALE ledger against the spec schema (value/format/chart — also not a delta of this change).
  2. Designer emit paths. Every widget-emitting site enumerated and read: metadata-admin DashboardPreview add-widget emits id/type/title (WIDGET_TYPE_META defines no defaults); DashboardWidgetInspector patches title/type/dataset/dimensions/values/colorVariant/filterBindings/layout; plugin-designer DashboardEditor adds id/title/type/layout and edits title/type/colorVariant/layout; plugin-dashboard WidgetConfigPanel emits id/title/description/type/dataset/dimensions/values/colorVariant plus layout, with the legacy analytics and retired action keys scrubbed by sanitizeDraftForType. Every emitted key is in the declared set.
  3. Widget-slot component nodes (schema-catalog: all 9 plugin-dashboard examples are refused by the spec's DashboardSchema — the AI few-shot corpus teaches the pre-ADR-0021 widget shape #4600's BaseSchema routing). Measured on the current build: with a bare .strict() and no routing, the 11 ruled-legal metric-card widgets in the catalog corpus would refuse at the whole-document parse on value / icon / trend / trendValue — live documents the 2026-08-14 ruling (objectstack#8593) declares legal. BaseSchema accepts all 11. The routing the ruling names (component node owned by passthrough BaseSchema) therefore moves into the shared DashboardComponentSchema widget slot in this PR, as a union whose component arm is gated on the closed component-type enum — it is structurally unreachable for spec-family widgets, so it cannot become a hatch around the refusal. The routing schema is deliberately NOT exported (internal slot property, no new authoring surface).

Step 2 — the change

Tests and gates (final head 7718ccc; every run below was re-run at this sha)

  • New pin suite packages/types/src/__tests__/dashboard-widget-strict-6002.test.ts: the card's probe refuses naming all three keys; the retired inline-analytics quartet refuses as a set; a declared-surface widget parses green with every key surviving; the legacy id/component/layout envelope parses; a component-node document parses whole with props kept; two not-a-hatch pins refuse stray keys at document level.
  • pnpm exec vitest run packages/types/ examples/schema-catalog/ packages/cli/112 files, 3113 tests, all passed (includes the schema-catalog: all 9 plugin-dashboard examples are refused by the spec's DashboardSchema — the AI few-shot corpus teaches the pre-ADR-0021 widget shape #4600 gate with updated counter-probes, the safe-validate corpus sweep, and the CLI validate tests).
  • pnpm exec vitest run packages/plugin-dashboard/ packages/plugin-designer/ — 99 files, 901 tests, all passed.
  • @object-ui/types type-check (tsc noEmit + examples + test tsconfigs) green; tsc --listFiles confirms the new test file is in the compiled closure (1 hit — not a NOT-MEASURED green).
  • check-changeset-presence ✅ (1 changeset, minor with breaking narrative per the accept-set-narrowing precedent, no major — repo version policy) · check-changeset-no-major ✅ · check:control-bytes ✅ (5826 files) · check:spec-symbols ✅ · eslint on the three changed files: 0 errors (2 pre-existing warnings on untouched lines).
  • Ablation (committed first, mutation and restore both verified on disk): removing .strict() turns exactly the 4 refusal pins red (5 routing/positive pins stay green, as predicted); restore verified byte-identical to the HEAD blob. The suite resolves the subject through the vitest root alias to src, so no dist build sits in the ablation loop.
  • Declared narrowings, owned by CI: full pnpm lint (repo-wide eslint) and the full cross-package pnpm test farm were not run locally; the targeted set above covers every suite that runtime-parses these schemas (enumerated by grep over safeParse/parse call sites).

Review parking

Clause-② yes (accept/reject behaviour change on a published contract): this PR is parked as draft with needs:contract-review on both carriers, to be released through the in-seat contract-review flow (objectstack#13795) — not self-merged.

Generated by Claude Code


Generated by Claude Code

Route 1 step 2 of the maintainer ruling on objectui#6002: after #6150
declared the genuinely-consumed keys, the widget schema flips from
strip-in-silence to loud refusal — zod `unrecognized_keys` names every
offending key. The widget-slot component route (objectstack#8593 ruling:
metric-card props belong to passthrough BaseSchema) moves into the shared
DashboardComponentSchema widget slot as a union, so ruled-legal component
nodes keep parsing whole with props intact.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PBjwYLS6BciTQW3c9xQiD2
…r, breaking narrative)
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PBjwYLS6BciTQW3c9xQiD2
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 45 chunks)3180.2 KB3222.7 KB
Main entry chunk (gzip)143.6 KB350 KB
Entry fileindex-tZ_USG_l.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (consoleActionDispatch.js)0.20KB0.19KB
app-shell (index.js)12.46KB4.71KB
app-shell (runtime-config.js)20.68KB7.36KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (ActiveOrganizationStorage.js)25.05KB9.16KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)2.07KB1.00KB
auth (AuthProvider.js)40.18KB10.59KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)8.46KB3.43KB
auth (index.js)3.19KB1.44KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.30KB1.02KB
auth (useWorkspaceAdminStatus.js)5.13KB2.35KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)512.08KB116.42KB
core (index.js)5.30KB2.13KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)177.67KB49.45KB
fields (index.js)243.64KB61.64KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (fallbackInterpolation.js)6.25KB2.77KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)26.89KB9.04KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)5.60KB2.33KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)11.71KB4.29KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)6.24KB2.16KB
permissions (discardProofCache.js)1.04KB0.55KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)4.83KB2.27KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.92KB12.93KB
plugin-charts (index.js)64.68KB18.35KB
plugin-chatbot (index.js)190.53KB45.18KB
plugin-dashboard (index.js)133.48KB34.51KB
plugin-designer (index.js)212.87KB43.19KB
plugin-detail (index.js)247.26KB63.17KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)133.11KB32.61KB
plugin-gantt (index.js)165.21KB40.37KB
plugin-grid (index.js)202.07KB54.61KB
plugin-kanban (index.js)53.14KB14.64KB
plugin-list (index.js)113.15KB27.59KB
plugin-map (index.js)20.20KB6.66KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.51KB11.94KB
plugin-timeline (index.js)29.27KB8.44KB
plugin-tree (index.js)8.98KB3.08KB
plugin-view (index.js)85.79KB21.10KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)4.47KB1.63KB
react (SchemaRenderer.js)81.07KB26.86KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)3.11KB1.48KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (dashboard-widget-options.js)3.08KB1.30KB
sdui-parser (index.js)4.93KB2.24KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)20.57KB5.88KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.28KB0.23KB
sdui-parser (validate.js)10.35KB3.60KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)2.74KB1.41KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)3.75KB1.85KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.85KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (icon-key-migration.js)4.26KB1.63KB
types (index.js)4.72KB2.24KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (spec-ui-namespace.js)0.20KB0.19KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)6.28KB2.87KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-warren
os-warren added this pull request to the merge queueAug 31, 2026
Merged via the queue into main with commit 7e19d03Aug 31, 2026
32 checks passed
@os-warren
os-warren deleted the claude/issue-6002-dashboard-widget-strict branch August 31, 2026 14:43
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants

@os-warren@claude
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

feat(types)!: DashboardWidgetSchema refuses undeclared keys (.strict()) - #7033

Merged
os-warren merged 2 commits into
mainfrom
claude/issue-6002-dashboard-widget-strict
Aug 31, 2026
Merged

feat(types)!: DashboardWidgetSchema refuses undeclared keys (.strict())#7033
os-warren merged 2 commits into
mainfrom
claude/issue-6002-dashboard-widget-strict

Conversation

@os-warren

Copy link
Copy Markdown
Collaborator

Fixes#6002

Route 1 step 2 of the maintainer ruling (issue comment 5406212152, 2026-08-25): after #6150's declaration catch-up, DashboardWidgetSchema flips from strip-in-silence to .strict() — an undeclared widget key now refuses the parse with zod's unrecognized_keys issue naming every offending key. The card's measured five-keys-in/three-keys-out ACCEPT is reproduced in this PR's pin suite as a loud refusal naming zzcanary / categoryField / aggregate.

Step 0 — premise re-verified on the merged ref

#6150 closed via PR #6945 (squash commit 2c45966, contained in this branch's base f7850ee). All 13 recorded renderer-consumed keys verified declared, key by key, against the interface blocks on that ref: TextSchema.content · CarouselSchema.opts/orientation/itemClassName · FilterBuilderSchema.wrapperClass · TreeViewSchema.nodes/onNodeClick/title · CheckboxSchema.required · FileUploadSchema.buttonText/wrapperClass · HoverCardSchema.align · ContextMenuSchema.trigger. 13/13 declared — premise holds. (Note: none of the 13 are dashboard-widget keys; the family-1 corpus measurement below is what answers whether any LIVE dashboard depends on a key nothing declares.)

Step 1 — blast radius, measured before the change (ruling: not assumed)

The strict-refusal delta over the live corpus is EMPTY — no per-key fork back to triage is needed.

  1. Stored dashboard corpus. A preflight parsed every candidate with both the current schema and a .strict() candidate, routing component-enum types to BaseSchema per the 2026-08-14 ruling: 575 JSON files under examples/apps/packages/e2e/public plus every dashboard-bearing fenced block in md/mdx docs — 10 dashboard documents, 30 widgets (11 of them component nodes). Newly-refused widgets: zero. Doc fences that the script could not auto-parse were hand-triaged (all shape references or component-node examples; details in the report comment on finding(types): DashboardWidgetSchema SILENTLY DROPS every undeclared widget key — the file's own docstring names this failure mode, and it still applies to the keys nothing declares #6002). Two pre-existing, non-delta facts recorded: packages/plugin-dashboard/README.md fence 8 authors a widget with type: 'card', which the closed type enum already refuses TODAY (doc drift predating this PR — reported to PM as an out-of-scope finding); apps/console/src/preview-samples.ts's dashboard sample is already in that suite's KNOWN_STALE ledger against the spec schema (value/format/chart — also not a delta of this change).
  2. Designer emit paths. Every widget-emitting site enumerated and read: metadata-admin DashboardPreview add-widget emits id/type/title (WIDGET_TYPE_META defines no defaults); DashboardWidgetInspector patches title/type/dataset/dimensions/values/colorVariant/filterBindings/layout; plugin-designer DashboardEditor adds id/title/type/layout and edits title/type/colorVariant/layout; plugin-dashboard WidgetConfigPanel emits id/title/description/type/dataset/dimensions/values/colorVariant plus layout, with the legacy analytics and retired action keys scrubbed by sanitizeDraftForType. Every emitted key is in the declared set.
  3. Widget-slot component nodes (schema-catalog: all 9 plugin-dashboard examples are refused by the spec's DashboardSchema — the AI few-shot corpus teaches the pre-ADR-0021 widget shape #4600's BaseSchema routing). Measured on the current build: with a bare .strict() and no routing, the 11 ruled-legal metric-card widgets in the catalog corpus would refuse at the whole-document parse on value / icon / trend / trendValue — live documents the 2026-08-14 ruling (objectstack#8593) declares legal. BaseSchema accepts all 11. The routing the ruling names (component node owned by passthrough BaseSchema) therefore moves into the shared DashboardComponentSchema widget slot in this PR, as a union whose component arm is gated on the closed component-type enum — it is structurally unreachable for spec-family widgets, so it cannot become a hatch around the refusal. The routing schema is deliberately NOT exported (internal slot property, no new authoring surface).

Step 2 — the change

Tests and gates (final head 7718ccc; every run below was re-run at this sha)

  • New pin suite packages/types/src/__tests__/dashboard-widget-strict-6002.test.ts: the card's probe refuses naming all three keys; the retired inline-analytics quartet refuses as a set; a declared-surface widget parses green with every key surviving; the legacy id/component/layout envelope parses; a component-node document parses whole with props kept; two not-a-hatch pins refuse stray keys at document level.
  • pnpm exec vitest run packages/types/ examples/schema-catalog/ packages/cli/112 files, 3113 tests, all passed (includes the schema-catalog: all 9 plugin-dashboard examples are refused by the spec's DashboardSchema — the AI few-shot corpus teaches the pre-ADR-0021 widget shape #4600 gate with updated counter-probes, the safe-validate corpus sweep, and the CLI validate tests).
  • pnpm exec vitest run packages/plugin-dashboard/ packages/plugin-designer/ — 99 files, 901 tests, all passed.
  • @object-ui/types type-check (tsc noEmit + examples + test tsconfigs) green; tsc --listFiles confirms the new test file is in the compiled closure (1 hit — not a NOT-MEASURED green).
  • check-changeset-presence ✅ (1 changeset, minor with breaking narrative per the accept-set-narrowing precedent, no major — repo version policy) · check-changeset-no-major ✅ · check:control-bytes ✅ (5826 files) · check:spec-symbols ✅ · eslint on the three changed files: 0 errors (2 pre-existing warnings on untouched lines).
  • Ablation (committed first, mutation and restore both verified on disk): removing .strict() turns exactly the 4 refusal pins red (5 routing/positive pins stay green, as predicted); restore verified byte-identical to the HEAD blob. The suite resolves the subject through the vitest root alias to src, so no dist build sits in the ablation loop.
  • Declared narrowings, owned by CI: full pnpm lint (repo-wide eslint) and the full cross-package pnpm test farm were not run locally; the targeted set above covers every suite that runtime-parses these schemas (enumerated by grep over safeParse/parse call sites).

Review parking

Clause-② yes (accept/reject behaviour change on a published contract): this PR is parked as draft with needs:contract-review on both carriers, to be released through the in-seat contract-review flow (objectstack#13795) — not self-merged.

Generated by Claude Code


Generated by Claude Code

Route 1 step 2 of the maintainer ruling on objectui#6002: after #6150
declared the genuinely-consumed keys, the widget schema flips from
strip-in-silence to loud refusal — zod `unrecognized_keys` names every
offending key. The widget-slot component route (objectstack#8593 ruling:
metric-card props belong to passthrough BaseSchema) moves into the shared
DashboardComponentSchema widget slot as a union, so ruled-legal component
nodes keep parsing whole with props intact.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PBjwYLS6BciTQW3c9xQiD2
…r, breaking narrative)
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PBjwYLS6BciTQW3c9xQiD2
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Eager closure (gzip, 45 chunks)3180.2 KB3222.7 KB
Main entry chunk (gzip)143.6 KB350 KB
Entry fileindex-tZ_USG_l.js
StatusPASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

PackageSizeGzipped
app-shell (consoleActionDispatch.js)0.20KB0.19KB
app-shell (index.js)12.46KB4.71KB
app-shell (runtime-config.js)20.68KB7.36KB
app-shell (types.js)0.01KB0.04KB
app-shell (urlParams.js)10.06KB3.86KB
auth (ActiveOrganizationStorage.js)25.05KB9.16KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)2.07KB1.00KB
auth (AuthProvider.js)40.18KB10.59KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)12.21KB3.45KB
auth (LoginForm.js)18.15KB5.39KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.65KB2.22KB
auth (SocialSignInButtons.js)9.61KB3.89KB
auth (UserMenu.js)3.41KB1.23KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)40.21KB10.80KB
auth (createAuthenticatedFetch.js)8.46KB3.43KB
auth (index.js)3.19KB1.44KB
auth (invitation-status.js)1.22KB0.70KB
auth (org-roles.js)6.66KB2.78KB
auth (phone-identifier.js)1.11KB0.66KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)5.30KB1.02KB
auth (useWorkspaceAdminStatus.js)5.13KB2.35KB
collaboration (CommentThread.js)26.08KB7.56KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)6.49KB2.64KB
collaboration (PresenceProvider.js)2.79KB1.13KB
collaboration (index.js)1.68KB0.73KB
collaboration (useCollaborationTranslation.js)6.05KB2.52KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)512.08KB116.42KB
core (index.js)5.30KB2.13KB
create-plugin (index.js)10.08KB3.26KB
data-objectstack (index.js)177.67KB49.45KB
fields (index.js)243.64KB61.64KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (fallbackInterpolation.js)6.25KB2.77KB
i18n (i18n.js)4.28KB1.75KB
i18n (index.js)3.44KB1.39KB
i18n (pickLocalized.js)7.62KB3.26KB
i18n (provider.js)26.89KB9.04KB
i18n (useDisplayLocale.js)2.85KB1.45KB
i18n (useObjectLabel.js)33.40KB8.71KB
i18n (useSafeTranslation.js)5.60KB2.33KB
layout (index.js)38.95KB10.97KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.75KB
mobile (index.js)1.55KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)6.96KB1.98KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.72KB0.42KB
mobile (useResponsiveConfig.js)1.37KB0.63KB
mobile (useSpecGesture.js)4.32KB1.64KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)11.71KB4.29KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)6.24KB2.16KB
permissions (discardProofCache.js)1.04KB0.55KB
permissions (evaluator.js)5.12KB1.74KB
permissions (index.js)0.93KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.53KB
permissions (usePermissions.js)4.83KB2.27KB
plugin-ai (index.js)15.75KB3.80KB
plugin-calendar (index.js)46.92KB12.93KB
plugin-charts (index.js)64.68KB18.35KB
plugin-chatbot (index.js)190.53KB45.18KB
plugin-dashboard (index.js)133.48KB34.51KB
plugin-designer (index.js)212.87KB43.19KB
plugin-detail (index.js)247.26KB63.17KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)133.11KB32.61KB
plugin-gantt (index.js)165.21KB40.37KB
plugin-grid (index.js)202.07KB54.61KB
plugin-kanban (index.js)53.14KB14.64KB
plugin-list (index.js)113.15KB27.59KB
plugin-map (index.js)20.20KB6.66KB
plugin-markdown (index.js)13.72KB4.69KB
plugin-report (index.js)43.51KB11.94KB
plugin-timeline (index.js)29.27KB8.44KB
plugin-tree (index.js)8.98KB3.08KB
plugin-view (index.js)85.79KB21.10KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.90KB0.85KB
providers (UploadProvider.js)11.66KB3.50KB
providers (index.js)0.45KB0.23KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)5.62KB2.34KB
react (LazyPluginLoader.js)4.47KB1.63KB
react (SchemaRenderer.js)81.07KB26.86KB
react (data-invalidation.js)5.05KB2.08KB
react (index.js)3.11KB1.48KB
react (schema-input.js)2.32KB1.24KB
react (spec-input.js)0.20KB0.18KB
sdui-parser (codegen.js)5.41KB2.34KB
sdui-parser (dashboard-widget-options.js)3.08KB1.30KB
sdui-parser (index.js)4.93KB2.24KB
sdui-parser (input-type.js)2.84KB1.40KB
sdui-parser (parse.js)20.57KB5.88KB
sdui-parser (provenance.js)3.66KB1.82KB
sdui-parser (types.js)0.28KB0.23KB
sdui-parser (validate.js)10.35KB3.60KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)2.74KB1.41KB
types (crud.js)0.20KB0.18KB
types (dashboard-filter-alias.js)6.23KB2.74KB
types (data-display.js)3.75KB1.85KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)1.85KB0.85KB
types (disclosure.js)0.20KB0.18KB
types (error-code.js)1.54KB0.88KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (http-inflight.js)8.87KB3.73KB
types (http-retry.js)4.32KB2.02KB
types (icon-key-migration.js)4.26KB1.63KB
types (index.js)4.72KB2.24KB
types (layout.js)0.20KB0.18KB
types (managed-by.js)0.19KB0.18KB
types (mobile.js)2.59KB1.31KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (record-semantics.js)1.28KB0.67KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.05KB1.93KB
types (spec-ui-namespace.js)0.20KB0.19KB
types (system-fields.js)3.33KB1.54KB
types (theme.js)6.28KB2.87KB
types (ui-action.js)3.40KB1.71KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-warren
os-warren added this pull request to the merge queueAug 31, 2026
Merged via the queue into main with commit 7e19d03Aug 31, 2026
32 checks passed
@os-warren
os-warren deleted the claude/issue-6002-dashboard-widget-strict branch August 31, 2026 14:43
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants

@os-warren@claude