Skip to content

fix(plugin-detail): record:quick_actions.requiredPermissions publishes the contract's shared describe (objectui#10224) - #11329

Merged
objectstack-fleet[bot] merged 5 commits into
mainfrom
claude/issue-10224-quick-actions-permissions-text
Oct 1, 2026
Merged

objectstack-fleet[bot] merged 5 commits into
mainfrom
claude/issue-10224-quick-actions-permissions-text

Conversation

@objectstack-fleet

@objectstack-fleet objectstack-fleet Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Fixes #10224

Clause-②: no

What changes

  • packages/plugin-detail/src/index.tsx: the record:quick_actions input requiredPermissions now publishes the contract's shared record-block describe, verbatim. It is the text record:details, record:highlights and record:related_list have published since objectui#8649. It replaces "Hide the whole bar unless the user holds these permissions". The input's name, type and shape stay the same, and no rendering or gating behaviour changes.
  • packages/plugin-detail/src/renderers/__tests__/record-quick-actions.requiredPermissions-gate.test.tsx is the pin file the console row points at. Its header prose and two test names now say what the assertions check: the notice in place of the bar, not a hidden bar. Six rows are added for clauses the published text makes and the file did not pin yet:
    • read and update as capability names (DISCRIMINATOR 4a / 4b);
    • fail-open with no provider, and with a backend that omits systemPermissions;
    • the description verbatim against the installed spec, and equal to the three siblings' text.
  • apps/console/src/__tests__/registry-inputs-spec-parity.test.ts: the MEMBER_PINS row for record:quick_actions.requiredPermissions and the slice-4 note in that row's neighbourhood no longer describe the retired perms.can(objectName, p) read or a hidden bar. The row now lists what the pin file asserts. No other row changes.
  • .changeset/10224-quick-actions-permissions-text.md: @object-ui/plugin-detail patch.
  • .changeset/10058-quick-actions-capability-gate.md (pending): a dated, append-only correction. See the file-surface note below.
  • Round 2 (105cddc65), comment and test-title text only:
    • The gate docblock in record-quick-actions.tsx now says the gate draws a role="status" insufficient-permissions notice in the bar's place rather than hiding the bar, and that unreported capabilities fail open.
    • In the sibling pin record-blocks.requiredPermissions-gate.test.tsx, the header and two test titles now name the notice.
    • No assertion moves, and no ledger or locator reads either title.

Premise, measured before the edit (base 0c6f9bbd7)

In the installed @objectstack/spec 17.5.0, RecordQuickActionsProps.shape.requiredPermissions carries RECORD_BLOCK_REQUIRED_PERMISSIONS_DESCRIPTION. The three record blocks use the same constant. The registration said "Hide the whole bar unless the user holds these permissions".

A one-off probe (not committed) read every clause through the real SchemaRenderer, the real record:quick_actions registration and the real permission providers. The object declares one action, Approve:

case insufficient-permissions notice Approve button
partial grant: crm.manage held, crm.manage + crm.export required shown absent
all granted none present
read required, allowRead: true, capability set reported empty shown absent
update required, allowEdit: true, capability set reported empty shown absent
no permission provider mounted none present
stock provider, backend omits systemPermissions none present
role-based PermissionProvider none present
no actions configured, gate unmet shown (in place of the empty placeholder) absent
key absent, capability set empty (control) none present

"Presentation only: it authorises nothing" was read from the gate code: the gate is a render branch and makes no request. Every clause of the shared describe holds on this block, so it is published here unedited.

Ablations (one-off, from committed state)

Each mutation went through ../objectstack/scripts/ablation-replace.mjs: the anchor hit once, and the blob hash moved. Each restore was checked: the blob hash equals HEAD's and git diff HEAD is empty. The subject resolves by relative path (../../index, ../record-quick-actions) to source, so no dist is in the resolution path.

  1. The published description, with a marker prefixed: 2 failed / 20 passed. The two failures are exactly the two verbatim rows.
  2. The gate reverted to the read objectui#10058 retired, perms.can(objectName, p) over every member: 10 failed / 12 passed. The failures include 4a and 4b, alongside the objectui#10058 rows.
  3. The gate made fail-closed when capabilities are unreported: 4 failed / 18 passed. The failures are the two new fail-open rows and the two role-based rows.

Gates (local; CI runs the full farm)

Commits on this branch: 50214f307 (the change), 4e45246a3, 105cddc65 and eb65af7bd.

  • Round 3, eb65af7bd, is text only. The 10224 changeset now names sdui.manifest.json and the runtime registry inputs as what carries the description. That is because generateDts reads no description, so the generated intrinsics carry none. The pin docblock that made the same pairing is corrected the same way. check:changeset-claims, check-changeset-presence, check:pending-changeset-literals, check:new-line-citations and check:control-bytes all exit 0. The gate pin passes 22/22.

  • Round 2 is text only. Its checks: plugin-detail type-check exit 0; the two gate pins plus the console parity file, 298 passed; check:new-line-citations, check:control-bytes and check:installed-pin-claims, each exit 0.

  • About 4e45246a3: The second commit is comment-only in packages/: a diff filter that drops comment lines prints nothing. It also adds the changeset note.

  • Closure build: turbo run build --filter='@object-ui/plugin-detail^...' --concurrency=2. 11/11 tasks, all restored from the turbo cache, with every dist/index.d.ts present.

  • @object-ui/plugin-detail type-check: exit 0 at 4e45246a3. --listFiles on tsconfig.test.json lists the pin file.

  • @object-ui/plugin-detail full suite: 228 files passed, 1 skipped; 2276 tests passed, 8 skipped, at 50214f307.

  • At 4e45246a3, 7 files / 354 tests passed:

    • the pin file;
    • the sibling record-blocks.requiredPermissions-gate.test.tsx;
    • the three record*Inputs.spec-parity files;
    • recordQuickActionsInputs.actionNamesFallback.test.tsx;
    • apps/console/src/__tests__/registry-inputs-spec-parity.test.ts (230 tests).
  • Manifest consumers, because the published description moved: sdui-intrinsics-compile-11075, public-contract, html-tier-manifest, ga-honoured-inputs-author-reach, component-input-union-specimens and record-block-record-reach in apps/console. 6 files / 80 tests passed.

  • check:* gates at 4e45246a3, all exit 0: control-bytes, new-line-citations (0 new), changeset-claims, pending-changeset-literals, installed-pin-claims, spec-symbols, vi-mock-specifiers, vi-mock-inherit, vi-mock-override-shape, test-path-roots, phantom-deps. The changeset scripts check-changeset-presence and check-changeset-no-major also exit 0.

    • installed-pin-claims failed once, on 50214f307. The pin header said "Through 17.4.0", and the gate read that as a claim about the installed spec. The new prose now names objectstack#18159 instead of a version.
  • Lint, narrowed to the three touched code files, plus the evidence that narrowing excludes nothing:

    • eslint --print-config resolves a config for each file (none is ignored);
    • --format json lists 3 files, 0 errors;
    • the 39 warnings are all on lines this diff does not touch;
    • parserOptions.project and projectService are unset, so linting is not type-aware and this diff cannot move a verdict on any untouched file. The repo-wide pnpm lint belongs to CI.
  • NOT MEASURED:

    • @object-ui/console type-check. The console edit is a string literal and comments inside an existing MemberPin object literal, and the check needs a whole-workspace build. Declared to CI.
    • check:sdui-registration-pins, which exits 2 (PREREQUISITE NOT MET: no console dist). Its subject is the sideEffects arrays, which this diff does not touch.

File-surface note: the pending objectui#10058 changeset

The claim named one changeset. The pending 10058-quick-actions-capability-gate.md ships in the same release as this one. It says an unheld capability "hides the whole bar" and that the gate "is published as" the contract's retired wording. With this change in that release, the registration publishes the notice behaviour, so those sentences become false in that release.

It therefore gets a dated, append-only correction, in the shape objectui#8649 gave the sibling 10155-record-blocks-capability-gate.md. Its frontmatter and every earlier byte are unchanged: cmp of the original length against the pre-edit copy prints nothing. This applies the dispatch's standing pending-changeset clause. If the seat reads it as outside the claim, the note is one paragraph to drop. The seat ruled A (keep the note) at round 2.

Acceptance notes (not filed)

  • Folded in at round 2 (105cddc65): the two "hides" texts this section used to list.
  • check:changeset-claims lists three other pending changesets that name a file this change touches: 8067-component-input-member-kind.md, 9280-record-highlights-entry-icon-retired.md and record-alert-cta-label-i18n-4998.md. All three were read. None describes this input's text, and none is made false.

Generated by Claude Code

claude added 2 commits October 1, 2026 03:53
…s the contract's shared describe (objectui#10224)

The registration described the key as "Hide the whole bar unless the user
holds these permissions". The renderer reads the ADR-0066 capability set
(hasCapabilities, objectui#10058), draws an insufficient-permissions notice
in place of the bar, and fails open when capabilities are unreported.
@objectstack/spec 17.5.0 carries one describe for this key on all four
record blocks; objectui#8649 published it on the other three, and this
input now publishes the same text, verbatim.

The gate pin re-reads the installed describe every run, adds rows for the
clauses it did not yet cover (read/update as capability names, fail-open
with no provider and with an unreported systemPermissions), and its prose
and test names now say what it asserts. The console parity file's
MEMBER_PINS row and its slice-4 note stop describing the retired
perms.can() read and a bar that is hidden.

Claude-Session: https://claude.ai/code/session_01VhxTqosz7wn54ahqyxgERT
Co-authored-by: Claude <noreply@anthropic.com>
…rect the pending objectui#10058 changeset (objectui#10224)

check:installed-pin-claims read "Through 17.4.0" in the gate pin's header
as a present-tense claim about the installed spec and failed it. The new
prose now names objectstack#18159 instead of a version, in the pin header
and in the registration comment, so the next spec bump has nothing to
restamp.

The pending objectui#10058 changeset says an unheld capability "hides the
whole bar" and quotes the contract's retired wording. It ships in the same
release as this change, which publishes the notice behaviour, so it gets a
dated, append-only correction in the shape objectui#8649 gave the sibling
objectui#10155 changeset. Its frontmatter and every earlier byte are
unchanged.

Claude-Session: https://claude.ai/code/session_01VhxTqosz7wn54ahqyxgERT
Co-authored-by: Claude <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

changeset-claim-re-read

⚠️ 4 pending changeset(s) describe a file this change touches

Their bodies publish verbatim into the CHANGELOG at the next release, so this is a request to re-read them against your diff — addressed here because you are the one seat that can answer it without re-deriving anything.

⛔ Nothing here blocks, and nothing here is a verdict on your change. This gate exits 0, is not a required context, and judges name resolution, never meaning: it asked whether a pending body names a file you touched. "Is this sentence still true?" is the one question it will not answer, and the one you are being asked to answer.

.changeset/7182-declared-action-ids-one-rule.md

  • names record-quick-actions.tsx → packages/plugin-detail/src/renderers/record-quick-actions.tsx — edited by this change

    New on @object-ui/types, beside actionRendersAt: the pure resolveDeclaredActionIds(elements, registeredActions), with the DeclaredActionsResolution / DeclaredActionsRefusal result types (the shape classifier stays module-internal: called with no registry, the function already returns the registry-independent verdict a renderer needs before its lookup). Both renderers call it; the whole-array switch in record-quick-actions.tsx and the per-element normalisation in containers.tsx are gone. The rule is closed: a string is an id, a non-null non-array object is an inline definition, and any other element (null, a number, a nested array) is refused at its index too. An all-id array resolves by name in authored order, first registration winning on a duplicate name; ids that name nothing are reported back with their index for the caller to warn about once its lookup has settled.

.changeset/8067-component-input-member-kind.md

  • names apps/console/src/__tests__/registry-inputs-spec-parity.test.ts → apps/console/src/__tests__/registry-inputs-spec-parity.test.ts — edited by this change

    A registration's type: 'array' said a value was a list and stopped there, so a member that drifted from @objectstack/spec was invisible to every layer that reads a declaration. page:header.actions is the measured cost: the contract declares z.array(z.string()) ("Action IDs"), the renderer read the members as ActionDef objects, and the repo-wide parity gate in apps/console/src/__tests__/registry-inputs-spec-parity.test.ts stayed green for the whole life of the drift because both sides carried the key and neither could say what was inside it. What settled it was a maintainer ruling, not a test — and even after the fix, "these are ids" survived only as English in the registration's description.

.changeset/9280-record-highlights-entry-icon-retired.md

  • names packages/plugin-detail/src/index.tsx → packages/plugin-detail/src/index.tsx — edited by this change

    • packages/types/src/record-components.ts — RecordHighlightsComponentProps.fields[]'s object arm: { name; label?; icon?; type?; readonly? } → { name; label?; type?; readonly? }. The key is removed, not tombstoned: the contract's arm is $strict, so the refusal an author needs already exists upstream and arrives named (invalid_union at the entry). A ?: never tombstone buys nothing here — it is the remedy for a non-strict mirror that would otherwise strip in silence, which is not this arm. - packages/plugin-detail/src/renderers/record-highlights.tsx — the entry normalizer stops copying icon: f?.icon into the normalized entry. That read was unreachable, not merely unused: no author could feed it past the $strict arm, and HeaderHighlight renders no .icon on the far side either, so the copy had no consumer in either direction. - packages/plugin-detail/src/index.tsx — the registry manifest's fields input description sketched the entry as {name,label?,icon?,type?,readonly?} → {name,label?,type?,readonly?}. The inputs ARE the published contract (gen-manifest.ts serializes them into sdui.manifest.json and sdui-intrinsics.d.ts), so leaving the sketch standing would have gone on teaching AI and human authors a key that gets the whole document refused at publish.

.changeset/record-alert-cta-label-i18n-4998.md

Read the paragraph, not the line: both false halves of the objectui#8617 claim sat in one paragraph, and correcting either alone would have left it asserting the same wrong thing.

If a claim did go false, correct the body. That is precedented and prose-only, frontmatter untouched; check-changeset-overwrite.mjs will report the correction as its own case 2 ("correcting a declaration on purpose … legitimate"), which is the intended shape — one gate asks for the read, the other records the write.

Not covered, stated so nobody reads this as more: a born-false claim that spells no line address at all (objectui#9495 coordinated one by ORDINAL — "a grep finds that member first" — and deciding that means reading what the sentence means), a claim spelled as a symbol or a package rather than a backticked file name, and a file named ambiguously.

Compared the checked-out tree with 770cc5ba4 (merge-base with origin/main): 5 file(s) changed outside .changeset/, read against 1896 pending declaration(s) that publish a body (2509 pending in total). · run

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

Metric Value Budget
Eager closure (gzip, 330 chunks) 3585.7 KB 3607.4 KB
Main entry chunk (gzip) 150.4 KB 350 KB
Entry file index-C5bsS2tR.js —
Status PASS —

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

Package Size Gzipped
app-shell (consoleActionDispatch.js) 0.20KB 0.19KB
app-shell (index.js) 16.88KB 6.25KB
app-shell (runtime-config.js) 20.68KB 7.36KB
app-shell (types.js) 0.01KB 0.04KB
app-shell (urlParams.js) 10.11KB 3.87KB
auth (ActiveOrganizationStorage.js) 27.95KB 10.04KB
auth (AuthContext.js) 0.31KB 0.24KB
auth (AuthGuard.js) 2.07KB 1.00KB
auth (AuthProvider.js) 40.22KB 10.61KB
auth (AuthShell.js) 3.49KB 1.40KB
auth (ForgotPasswordForm.js) 12.21KB 3.45KB
auth (LoginForm.js) 18.17KB 5.40KB
auth (PreviewBanner.js) 0.90KB 0.50KB
auth (RegisterForm.js) 6.72KB 2.24KB
auth (SocialSignInButtons.js) 9.70KB 3.93KB
auth (UserMenu.js) 3.39KB 1.21KB
auth (auth-gate-events.js) 1.29KB 0.66KB
auth (authStyles.js) 5.04KB 1.72KB
auth (createAuthClient.js) 40.70KB 10.94KB
auth (createAuthenticatedFetch.js) 8.54KB 3.46KB
auth (index.js) 3.63KB 1.64KB
auth (invitation-status.js) 1.22KB 0.70KB
auth (org-roles.js) 6.66KB 2.78KB
auth (phone-identifier.js) 1.11KB 0.66KB
auth (types.js) 0.59KB 0.35KB
auth (useAuth.js) 5.30KB 1.02KB
auth (useWorkspaceAdminStatus.js) 11.08KB 4.58KB
collaboration (CommentThread.js) 27.13KB 7.95KB
collaboration (LiveCursors.js) 3.17KB 1.27KB
collaboration (PresenceAvatars.js) 6.49KB 2.64KB
collaboration (PresenceProvider.js) 2.79KB 1.13KB
collaboration (index.js) 1.68KB 0.73KB
collaboration (useCollaborationTranslation.js) 6.05KB 2.52KB
collaboration (useCommentSearch.js) 1.98KB 0.88KB
collaboration (useConflictResolution.js) 7.75KB 1.86KB
collaboration (useMentionNotifications.js) 1.81KB 0.68KB
collaboration (usePresence.js) 6.33KB 1.84KB
collaboration (useRealtimeSubscription.js) 7.91KB 2.01KB
components (index.js) 571.28KB 136.83KB
core (index.js) 10.00KB 3.96KB
create-plugin (index.js) 27.94KB 9.51KB
data-objectstack (index.js) 229.96KB 63.80KB
fields (index.js) 261.05KB 66.23KB
i18n (LocalizationContext.js) 1.76KB 0.96KB
i18n (builtinAggregateLabels.js) 0.86KB 0.49KB
i18n (currency.js) 2.59KB 1.22KB
i18n (fallbackInterpolation.js) 6.25KB 2.77KB
i18n (i18n.js) 8.87KB 3.64KB
i18n (index.js) 5.24KB 2.27KB
i18n (pickLocalized.js) 9.86KB 3.95KB
i18n (provider.js) 39.40KB 12.91KB
i18n (translateFn.js) 0.20KB 0.18KB
i18n (useDisplayLocale.js) 3.52KB 1.76KB
i18n (useObjectLabel.js) 34.49KB 9.23KB
i18n (useSafeTranslation.js) 5.60KB 2.33KB
layout (index.js) 40.95KB 11.48KB
mobile (MobileProvider.js) 0.92KB 0.49KB
mobile (ResponsiveContainer.js) 0.94KB 0.38KB
mobile (breakpoints.js) 1.51KB 0.70KB
mobile (createOfflineDataSource.js) 5.61KB 1.75KB
mobile (index.js) 1.99KB 0.87KB
mobile (offlineQueue.js) 3.91KB 1.35KB
mobile (pwa.js) 0.97KB 0.49KB
mobile (serviceWorker.js) 1.48KB 0.62KB
mobile (serviceWorkerSource.js) 3.41KB 1.48KB
mobile (useBreakpoint.js) 1.54KB 0.65KB
mobile (useGesture.js) 6.96KB 1.98KB
mobile (useOfflineSync.js) 1.99KB 0.72KB
mobile (usePullToRefresh.js) 6.62KB 2.45KB
mobile (useResponsive.js) 0.72KB 0.42KB
mobile (useSpecGesture.js) 5.52KB 2.10KB
mobile (useTouchTarget.js) 1.01KB 0.54KB
permissions (MePermissionsProvider.js) 13.86KB 5.00KB
permissions (PermissionContext.js) 0.31KB 0.25KB
permissions (PermissionGuard.js) 0.89KB 0.45KB
permissions (PermissionProvider.js) 6.52KB 2.26KB
permissions (discardProofCache.js) 1.04KB 0.55KB
permissions (evaluator.js) 8.33KB 3.07KB
permissions (index.js) 0.93KB 0.41KB
permissions (store.js) 0.91KB 0.42KB
permissions (useFieldPermissions.js) 1.28KB 0.53KB
permissions (usePermissions.js) 4.83KB 2.27KB
plugin-ai (index.js) 16.01KB 3.93KB
plugin-calendar (index.js) 52.98KB 15.39KB
plugin-charts (index.js) 84.09KB 22.93KB
plugin-chatbot (index.js) 198.22KB 46.97KB
plugin-dashboard (index.js) 139.34KB 37.30KB
plugin-designer (index.js) 216.45KB 44.60KB
plugin-detail (index.js) 245.45KB 64.47KB
plugin-editor (index.js) 2.23KB 1.05KB
plugin-form (index.js) 173.70KB 44.63KB
plugin-gantt (index.js) 173.11KB 43.10KB
plugin-grid (index.js) 231.53KB 63.58KB
plugin-kanban (index.js) 49.32KB 15.48KB
plugin-list (index.js) 116.63KB 28.97KB
plugin-map (index.js) 23.54KB 7.83KB
plugin-markdown (index.js) 13.88KB 4.80KB
plugin-report (index.js) 44.04KB 12.21KB
plugin-timeline (index.js) 33.91KB 10.00KB
plugin-tree (index.js) 11.20KB 3.89KB
plugin-view (index.js) 90.32KB 22.76KB
providers (DataSourceProvider.js) 0.75KB 0.39KB
providers (MetadataProvider.js) 1.37KB 0.59KB
providers (ThemeProvider.js) 1.90KB 0.85KB
providers (UploadProvider.js) 11.81KB 3.58KB
providers (index.js) 0.45KB 0.23KB
providers (types.js) 0.01KB 0.04KB
react-runtime (index.js) 5.62KB 2.34KB
react (LazyPluginLoader.js) 4.47KB 1.63KB
react (SchemaRenderer.js) 119.55KB 39.23KB
react (data-invalidation.js) 5.05KB 2.08KB
react (index.js) 4.50KB 2.06KB
react (schema-input.js) 4.25KB 2.04KB
react (spec-input.js) 0.20KB 0.18KB
sdui-parser (body-dialect.js) 4.50KB 1.99KB
sdui-parser (codegen.js) 9.45KB 3.76KB
sdui-parser (dashboard-widget-options.js) 3.08KB 1.30KB
sdui-parser (index.js) 6.06KB 2.68KB
sdui-parser (input-type.js) 2.84KB 1.40KB
sdui-parser (parse.js) 25.28KB 7.80KB
sdui-parser (provenance.js) 3.84KB 1.90KB
sdui-parser (types.js) 0.28KB 0.23KB
sdui-parser (validate.js) 21.42KB 7.05KB
types (ai.js) 4.39KB 2.17KB
types (api-types.js) 0.20KB 0.18KB
types (app.js) 4.12KB 1.61KB
types (base.js) 0.20KB 0.18KB
types (blocks.js) 0.20KB 0.18KB
types (complex.js) 3.19KB 1.62KB
types (crud.js) 0.20KB 0.18KB
types (dashboard-filter-alias.js) 6.23KB 2.74KB
types (data-display.js) 3.75KB 1.85KB
types (data-protocol.js) 0.20KB 0.19KB
types (data.js) 0.20KB 0.18KB
types (designer.js) 1.85KB 0.85KB
types (disclosure.js) 0.20KB 0.18KB
types (error-code.js) 1.54KB 0.88KB
types (expression.js) 0.20KB 0.18KB
types (feedback.js) 0.20KB 0.18KB
types (field-types.js) 0.20KB 0.18KB
types (form.js) 0.20KB 0.18KB
types (http-inflight.js) 8.87KB 3.73KB
types (http-retry.js) 4.32KB 2.02KB
types (icon-key-migration.js) 4.26KB 1.63KB
types (index.js) 4.74KB 2.26KB
types (layout.js) 0.20KB 0.18KB
types (managed-by.js) 0.19KB 0.18KB
types (mobile.js) 5.00KB 2.39KB
types (navigation.js) 0.20KB 0.18KB
types (objectql.js) 0.20KB 0.18KB
types (overlay.js) 0.20KB 0.18KB
types (permissions.js) 2.52KB 1.31KB
types (plugin-scope.js) 0.20KB 0.18KB
types (record-components.js) 0.20KB 0.19KB
types (record-semantics.js) 1.28KB 0.67KB
types (registry.js) 0.20KB 0.18KB
types (reports.js) 0.20KB 0.18KB
types (select-option.js) 0.20KB 0.19KB
types (spec-report.js) 4.99KB 1.96KB
types (spec-ui-namespace.js) 0.20KB 0.19KB
types (strict-authoring-face.js) 21.59KB 7.71KB
types (system-fields.js) 3.33KB 1.54KB
types (theme.js) 6.28KB 2.87KB
types (ui-action.js) 8.11KB 3.32KB
types (views.js) 0.20KB 0.18KB
types (widget.js) 0.20KB 0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

…a notice, not that they hide (objectui#10224)

Round 2, comment and test-title text only. The record:quick_actions gate
docblock said an unheld capability "hides the whole bar", directly above
the code that renders a role=status insufficient-permissions notice in the
bar's place. It now says that, cites the shared record-block describe the
registration publishes, and points at its existing paragraph on the
fail-open for unreported capabilities.

The sibling pin record-blocks.requiredPermissions-gate.test.tsx carried the
same "hides" wording in its header and two test titles for blocks that draw
the notice. Those texts now name the notice. No assertion, fixture or
helper moves, and no ledger or locator reads either title.

Claude-Session: https://claude.ai/code/session_01VhxTqosz7wn54ahqyxgERT
Co-authored-by: Claude <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

Metric Value Budget
Eager closure (gzip, 330 chunks) 3585.7 KB 3607.4 KB
Main entry chunk (gzip) 150.4 KB 350 KB
Entry file index-C5bsS2tR.js —
Status PASS —

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

Package Size Gzipped
app-shell (consoleActionDispatch.js) 0.20KB 0.19KB
app-shell (index.js) 16.88KB 6.25KB
app-shell (runtime-config.js) 20.68KB 7.36KB
app-shell (types.js) 0.01KB 0.04KB
app-shell (urlParams.js) 10.11KB 3.87KB
auth (ActiveOrganizationStorage.js) 27.95KB 10.04KB
auth (AuthContext.js) 0.31KB 0.24KB
auth (AuthGuard.js) 2.07KB 1.00KB
auth (AuthProvider.js) 40.22KB 10.61KB
auth (AuthShell.js) 3.49KB 1.40KB
auth (ForgotPasswordForm.js) 12.21KB 3.45KB
auth (LoginForm.js) 18.17KB 5.40KB
auth (PreviewBanner.js) 0.90KB 0.50KB
auth (RegisterForm.js) 6.72KB 2.24KB
auth (SocialSignInButtons.js) 9.70KB 3.93KB
auth (UserMenu.js) 3.39KB 1.21KB
auth (auth-gate-events.js) 1.29KB 0.66KB
auth (authStyles.js) 5.04KB 1.72KB
auth (createAuthClient.js) 40.70KB 10.94KB
auth (createAuthenticatedFetch.js) 8.54KB 3.46KB
auth (index.js) 3.63KB 1.64KB
auth (invitation-status.js) 1.22KB 0.70KB
auth (org-roles.js) 6.66KB 2.78KB
auth (phone-identifier.js) 1.11KB 0.66KB
auth (types.js) 0.59KB 0.35KB
auth (useAuth.js) 5.30KB 1.02KB
auth (useWorkspaceAdminStatus.js) 11.08KB 4.58KB
collaboration (CommentThread.js) 27.13KB 7.95KB
collaboration (LiveCursors.js) 3.17KB 1.27KB
collaboration (PresenceAvatars.js) 6.49KB 2.64KB
collaboration (PresenceProvider.js) 2.79KB 1.13KB
collaboration (index.js) 1.68KB 0.73KB
collaboration (useCollaborationTranslation.js) 6.05KB 2.52KB
collaboration (useCommentSearch.js) 1.98KB 0.88KB
collaboration (useConflictResolution.js) 7.75KB 1.86KB
collaboration (useMentionNotifications.js) 1.81KB 0.68KB
collaboration (usePresence.js) 6.33KB 1.84KB
collaboration (useRealtimeSubscription.js) 7.91KB 2.01KB
components (index.js) 571.28KB 136.83KB
core (index.js) 10.00KB 3.96KB
create-plugin (index.js) 27.94KB 9.51KB
data-objectstack (index.js) 229.96KB 63.80KB
fields (index.js) 261.05KB 66.23KB
i18n (LocalizationContext.js) 1.76KB 0.96KB
i18n (builtinAggregateLabels.js) 0.86KB 0.49KB
i18n (currency.js) 2.59KB 1.22KB
i18n (fallbackInterpolation.js) 6.25KB 2.77KB
i18n (i18n.js) 8.87KB 3.64KB
i18n (index.js) 5.24KB 2.27KB
i18n (pickLocalized.js) 9.86KB 3.95KB
i18n (provider.js) 39.40KB 12.91KB
i18n (translateFn.js) 0.20KB 0.18KB
i18n (useDisplayLocale.js) 3.52KB 1.76KB
i18n (useObjectLabel.js) 34.49KB 9.23KB
i18n (useSafeTranslation.js) 5.60KB 2.33KB
layout (index.js) 40.95KB 11.48KB
mobile (MobileProvider.js) 0.92KB 0.49KB
mobile (ResponsiveContainer.js) 0.94KB 0.38KB
mobile (breakpoints.js) 1.51KB 0.70KB
mobile (createOfflineDataSource.js) 5.61KB 1.75KB
mobile (index.js) 1.99KB 0.87KB
mobile (offlineQueue.js) 3.91KB 1.35KB
mobile (pwa.js) 0.97KB 0.49KB
mobile (serviceWorker.js) 1.48KB 0.62KB
mobile (serviceWorkerSource.js) 3.41KB 1.48KB
mobile (useBreakpoint.js) 1.54KB 0.65KB
mobile (useGesture.js) 6.96KB 1.98KB
mobile (useOfflineSync.js) 1.99KB 0.72KB
mobile (usePullToRefresh.js) 6.62KB 2.45KB
mobile (useResponsive.js) 0.72KB 0.42KB
mobile (useSpecGesture.js) 5.52KB 2.10KB
mobile (useTouchTarget.js) 1.01KB 0.54KB
permissions (MePermissionsProvider.js) 13.86KB 5.00KB
permissions (PermissionContext.js) 0.31KB 0.25KB
permissions (PermissionGuard.js) 0.89KB 0.45KB
permissions (PermissionProvider.js) 6.52KB 2.26KB
permissions (discardProofCache.js) 1.04KB 0.55KB
permissions (evaluator.js) 8.33KB 3.07KB
permissions (index.js) 0.93KB 0.41KB
permissions (store.js) 0.91KB 0.42KB
permissions (useFieldPermissions.js) 1.28KB 0.53KB
permissions (usePermissions.js) 4.83KB 2.27KB
plugin-ai (index.js) 16.01KB 3.93KB
plugin-calendar (index.js) 52.98KB 15.39KB
plugin-charts (index.js) 84.09KB 22.93KB
plugin-chatbot (index.js) 198.22KB 46.97KB
plugin-dashboard (index.js) 139.34KB 37.30KB
plugin-designer (index.js) 216.45KB 44.60KB
plugin-detail (index.js) 245.45KB 64.47KB
plugin-editor (index.js) 2.23KB 1.05KB
plugin-form (index.js) 173.70KB 44.63KB
plugin-gantt (index.js) 173.11KB 43.10KB
plugin-grid (index.js) 231.53KB 63.58KB
plugin-kanban (index.js) 49.32KB 15.48KB
plugin-list (index.js) 116.63KB 28.97KB
plugin-map (index.js) 23.54KB 7.83KB
plugin-markdown (index.js) 13.88KB 4.80KB
plugin-report (index.js) 44.04KB 12.21KB
plugin-timeline (index.js) 33.91KB 10.00KB
plugin-tree (index.js) 11.20KB 3.89KB
plugin-view (index.js) 90.32KB 22.76KB
providers (DataSourceProvider.js) 0.75KB 0.39KB
providers (MetadataProvider.js) 1.37KB 0.59KB
providers (ThemeProvider.js) 1.90KB 0.85KB
providers (UploadProvider.js) 11.81KB 3.58KB
providers (index.js) 0.45KB 0.23KB
providers (types.js) 0.01KB 0.04KB
react-runtime (index.js) 5.62KB 2.34KB
react (LazyPluginLoader.js) 4.47KB 1.63KB
react (SchemaRenderer.js) 119.55KB 39.23KB
react (data-invalidation.js) 5.05KB 2.08KB
react (index.js) 4.50KB 2.06KB
react (schema-input.js) 4.25KB 2.04KB
react (spec-input.js) 0.20KB 0.18KB
sdui-parser (body-dialect.js) 4.50KB 1.99KB
sdui-parser (codegen.js) 9.45KB 3.76KB
sdui-parser (dashboard-widget-options.js) 3.08KB 1.30KB
sdui-parser (index.js) 6.06KB 2.68KB
sdui-parser (input-type.js) 2.84KB 1.40KB
sdui-parser (parse.js) 25.28KB 7.80KB
sdui-parser (provenance.js) 3.84KB 1.90KB
sdui-parser (types.js) 0.28KB 0.23KB
sdui-parser (validate.js) 21.42KB 7.05KB
types (ai.js) 4.39KB 2.17KB
types (api-types.js) 0.20KB 0.18KB
types (app.js) 4.12KB 1.61KB
types (base.js) 0.20KB 0.18KB
types (blocks.js) 0.20KB 0.18KB
types (complex.js) 3.19KB 1.62KB
types (crud.js) 0.20KB 0.18KB
types (dashboard-filter-alias.js) 6.23KB 2.74KB
types (data-display.js) 3.75KB 1.85KB
types (data-protocol.js) 0.20KB 0.19KB
types (data.js) 0.20KB 0.18KB
types (designer.js) 1.85KB 0.85KB
types (disclosure.js) 0.20KB 0.18KB
types (error-code.js) 1.54KB 0.88KB
types (expression.js) 0.20KB 0.18KB
types (feedback.js) 0.20KB 0.18KB
types (field-types.js) 0.20KB 0.18KB
types (form.js) 0.20KB 0.18KB
types (http-inflight.js) 8.87KB 3.73KB
types (http-retry.js) 4.32KB 2.02KB
types (icon-key-migration.js) 4.26KB 1.63KB
types (index.js) 4.74KB 2.26KB
types (layout.js) 0.20KB 0.18KB
types (managed-by.js) 0.19KB 0.18KB
types (mobile.js) 5.00KB 2.39KB
types (navigation.js) 0.20KB 0.18KB
types (objectql.js) 0.20KB 0.18KB
types (overlay.js) 0.20KB 0.18KB
types (permissions.js) 2.52KB 1.31KB
types (plugin-scope.js) 0.20KB 0.18KB
types (record-components.js) 0.20KB 0.19KB
types (record-semantics.js) 1.28KB 0.67KB
types (registry.js) 0.20KB 0.18KB
types (reports.js) 0.20KB 0.18KB
types (select-option.js) 0.20KB 0.19KB
types (spec-report.js) 4.99KB 1.96KB
types (spec-ui-namespace.js) 0.20KB 0.19KB
types (strict-authoring-face.js) 21.59KB 7.71KB
types (system-fields.js) 3.33KB 1.54KB
types (theme.js) 6.28KB 2.87KB
types (ui-action.js) 8.11KB 3.32KB
types (views.js) 0.20KB 0.18KB
types (widget.js) 0.20KB 0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@objectstack-fleet

Copy link
Copy Markdown
Contributor Author

Contract review

Served-tier: CONTRACT_REVIEW_TIER
Head-sha: 105cddc65af61a82b1bb8ca32f16e0a6697301b6
Local-runs: none

Read, over REST and git show only: card #10224's body and all eight comments (5818033767 through 5924688403); PR #11329's body, its 7-file list and the 330-line net diff against main at this head; the head's own copies of the touched files and of MePermissionsProvider.tsx, PermissionProvider.tsx, usePermissions.ts, codegen.ts and the parity file; objectui AGENTS.md at origin/main; the installed spec 17.5.0 source at objectstack 0f6dcac5e9 (packages/spec/src/ui/component.zod.ts); and the head's check-runs, last. Nothing was built, run or re-run; the only computation was string equality over fetched text. The round-1 os-dev-report (5924625537), the seat's ACCEPT (5924688403) and the PR body's round-2 lines were read as claims, and each claim below was re-measured.

① Derived judgments

  • Accept set: no change — RIGHT. The one input row that moves keeps name: 'requiredPermissions', type: 'array', of: 'string' on both sides of the diff; no input is added, removed or retyped on any block; manifestFromConfigs keys the parser whitelist on name / type / of / required / enum / binding, so that surface is byte-identical. The record-quick-actions.tsx hunk lies wholly inside the gate docblock (dropping the hunk's *-prefixed lines leaves nothing), so no rendering or gating code moves.
  • Public surface: ONE change — RIGHT. The published description of record:quick_actions.requiredPermissions. At main it was the 58-byte "Hide the whole bar unless the user holds these permissions"; at this head it is 726 bytes, byte-equal (sha1 e95a3a19…) to RECORD_BLOCK_REQUIRED_PERMISSIONS_DESCRIPTION in the installed spec, which RecordQuickActionsProps carries through .describe(…) exactly as the three siblings do, and byte-equal to the record:details / record:related_list / record:highlights rows in index.tsx (those three were already byte-equal to the spec at main, PR feat(types,plugin-detail): declare the field-security triple on record:details / record:highlights / record:related_list and read it un-cast (objectui#8649) #11184). The 17.5.0 source has zero hits for "Hide the whole bar". It publishes through sdui.manifest.json (manifestFromConfigs copies description) and ComponentRegistry.getConfig(…).inputs at runtime — and nowhere else: generateDts and generateBlockList in codegen.ts never read description.
  • Every clause of the describe holds on THIS block, against record-quick-actions.tsx at the head — RIGHT. ALL / capabilities-not-object-actions: the gate fires on a non-empty required whose perms.hasCapabilities(required) answers false, and the stock provider's hasCapabilities is every over a Set of the reported systemPermissions; the gate never calls perms.can, so read and update are plain names. Notice in its place: the gate returns a role="status" aria-live="polite" block reading "Insufficient permissions to view quick actions.", and it runs BEFORE the empty-placeholder branch (visibleActions.length === 0), so with no actions configured the notice replaces the placeholder too — the renderer never hides the bar. Presentation only: the gate is a render branch and issues no request. Fails open: the no-provider default in usePermissions.ts answers true; MePermissionsProvider answers true when systemPermissions is not an array (unreported); the role-based PermissionProvider binds ALL_CAPABILITIES; a REPORTED [] reaches the every and gates.
  • MEMBER_PINS row and slice-4 note — TRUTHFUL. Each sentence of the row maps to a row in record-quick-actions.requiredPermissions-gate.test.tsx at the head: unheld and unrecognised capability → the two notice titles (each asserts the notice and no Approve button); held → "renders once the declared capability IS held"; EMPTY array and ABSENT key → two rows; PARTIAL grant on a two-entry array with the all-granted positive control; discriminators ① (allowRead true, still gated), ② (held with allowRead: false, renders), ③ (manage gated), ④a / ④b (read under allowRead, update under allowEdit, gated); the DETECTOR through a delegating canSpy wrapper, not a stub; the no-objectName row; fail-open under the role-based provider, with no provider mounted, and under the stock provider when me(undefined) omits systemPermissions; and two verbatim rows that read the describe off RecordQuickActionsProps.shape behind a non-vacuity guard and compare all four registrations. "Under a REAL stock MePermissionsProvider" holds for every gate pin; the fail-open rows are the exceptions the row itself names. "New file at objectui#8071 slice 4" matches the header. The slice-4 note's corrected sentence (capability read since objectui#10058; slice 4 found perms.can(objectName, p); notice before any action is drawn) is true, and no other row or ledger number moves. Mechanically memberPinProblem reads only file (a collected *.test.tsx, inside the glob, naming the block and the key), and the file still satisfies all three.
  • Changeset 10224, sentence by sentence. (1) the old text is quoted exactly — RIGHT. (2) "does not hide the bar … reads the ADR-0066 capability set … notice where the bar would be" — RIGHT. (3) fail-open with no provider or unreported systemPermissions — RIGHT. (4) one describe shared by four blocks in 17.5.0, three already publishing it — RIGHT. (5) "so sdui.manifest.json and the JSX authoring types carry it" — HALF WRONG, non-blocking: the manifest carries it, but generateDts emits each input's name and type only (codegen.ts has no description read at all), so sdui-intrinsics.d.ts carries no description before or after this PR. It misstates an artefact's reach, not a behaviour, shape, accept set or version; the fix is to drop "and the JSX authoring types". The seat's framing of the surface as "(manifest, intrinsics)" shares the error. (6) "No input name, type or shape changes, and no rendering or gating behaviour changes" — RIGHT.
  • Changeset 10058 (pending) — append-only, and the note is TRUE. cmp over the original 2715 bytes is clean, the first three lines hash equal, and the hunk adds 13 lines at the end. The body does say "hides the whole bar" (so calling it wrong is right); the renderer draws the role="status" notice; the quoted describe fragment is a substring of the spec constant; the registration now publishes that text in place of the old 58 bytes; "retired upstream" holds at the installed spec (the shared constant on the schema, zero hits for the old wording — the pre-#18159 contract wording itself is taken from the 10058 body's own earlier quotation, not re-measured against 17.4.0); "everything else above stands" — the capability read, fail-closed on a reported set, fail-open when unreported — matches the head. The shape copies the 10155 correction PR feat(types,plugin-detail): declare the field-security triple on record:details / record:highlights / record:related_list and read it un-cast (objectui#8649) #11184 left. No other pending changeset says this bar is hidden: tidy-pans-repeat, 6252, 9572 and 9782 speak of the per-action D4 key, and 8649-record-block-field-security-triple already says "notice".
  • Round 2 (4e45246a3..105cddc65) is comment and test-title text only — RIGHT. Two files, +15/−7; dropping *-prefixed lines and it(' title lines leaves nothing. The old titles have zero hits in the head tree; the new titles appear only in the two pin files; the only cross-file references to either file are MEMBER_PINS.file paths and two comments, so no locator reads a title. The describe.each titles are untouched. Added lines carry no path:line citation and no model identifier (AGENTS.md rule [WIP] Update documentation for project #11; Line Citation Gate green).

② Semver level

  • .changeset/10224-quick-actions-permissions-text.md declares '@object-ui/plugin-detail': patch — RIGHT. The diff touches src/ of two fixed-group packages (@object-ui/plugin-detail: the registration, a renderer docblock, two test files; @object-ui/console: test prose only). What ships is a corrected description string in published metadata — no API, accept-set or behaviour change — so patch, not minor; and not an empty declaration, because published source of a fixed-group package moved and the manifest text is user-visible. The fixed group versions the console with it, so no second entry is owed, and the presence rule ("a change to published source carries a changeset; an EMPTY frontmatter counts") is met by the one declaration. No major. CI: Changeset Declaration, Changeset Bump Policy, Changeset Fixed Group Check, Changeset Claim Re-read and Changeset Overwrite Report are all success.
  • Clause-②: no — RIGHT: name / type / of unchanged on every block, no input added or removed, no renderer code moves (①).

③ Boundary flags

From the round-1 os-dev-report (5924625537) and the PR body:

  1. open_question 1 — keep the append-only note on pending 10058? ANSWERED: A, keep. Both entries are @object-ui/plugin-detail: patch and ship in one release; without the note the CHANGELOG would say "hides the whole bar" and "does not hide the bar" of the same key. Frontmatter and earlier bytes verified unchanged; shape follows the 10155 precedent. Agrees with the seat's ruling in 5924688403.
  2. Hot file — the slice-4 note edited beside the row where the claim said "that one row only". ANSWERED: accepted. The note stated the same false mechanism in the same file; leaving it would leave the file contradicting its own row. No other MEMBER_PINS row moves. objectui#11168 slice 3 (same file, no PR yet): whichever lands second merges main.
  3. Six new pin rows beyond prose. ANSWERED: accepted. The claim said "plus pins, if a description pin exists"; none existed, so the two verbatim rows ARE that pin, in the file the row points at; the other four pin clauses the newly published text makes on this block (read / update as capability names; fail-open with no provider and with systemPermissions unreported).
  4. Three commits, no force-push. 4e45246a3 re-anchored new prose off version stamps after check:installed-pin-claims went red; 105cddc65 verified text-only above. ANSWERED: fine.
  5. NOT MEASURED @object-ui/console type-check → CI Type Check (in_progress at read). NOT MEASURED check:sdui-registration-pins → its subject (sideEffects) is untouched; no package.json is in the diff. ANSWERED.
  6. out_of_scope_findings (renderer gate docblock; sibling pin header and two titles) — folded in at round 2, verified in the round-2 diff. No carrier needed.
  7. New flag from this review, non-blocking (① item 5): the 10224 changeset's clause "and the JSX authoring types carry it". ESCALATED to the seat: a one-clause edit to take before ready, or to accept as release-note imprecision; a new head would need a new record.

Check-runs on this head, read 2026-10-01T04:27Z: 42 — 29 success, 3 skipped (dependabot and the two coverage entries), 10 in_progress (Spec Main Shape Gate, Test (shard 1/8) through Test (shard 8/8), Type Check), 0 failure. The ten in_progress runs are recorded as in_progress, not as verdicts; the seat's queue step waits on them.

Implemented-by: claude/issue-10224-quick-actions-permissions-text
Reviewed-by: session_01VhxTqosz7wn54ahqyxgERT

VERDICT: PASS

Rendered 2026-10-01T04:33Z by the isolated at-tier reviewer running inside the seat session named above; posted through post-stamped.mjs.

…hed text (objectui#10224)

Round 3, from the at-tier review. The 10224 changeset said the new
description is carried by sdui.manifest.json "and the JSX authoring types".
The manifest carries it: manifestFromConfigs copies each input's
description. generateDts in sdui-parser's codegen.ts reads no description,
so the generated intrinsics carry none, before or after this change. The
sentence now names the manifest and the runtime registry inputs only.

The gate pin's docblock made the same pairing about the registration's
inputs; it now says the manifest carries descriptions and the JSX types
take only names and value types.

Claude-Session: https://claude.ai/code/session_01VhxTqosz7wn54ahqyxgERT
Co-authored-by: Claude <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

Metric Value Budget
Eager closure (gzip, 330 chunks) 3585.7 KB 3607.4 KB
Main entry chunk (gzip) 150.4 KB 350 KB
Entry file index-C5bsS2tR.js —
Status PASS —

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

Package Size Gzipped
app-shell (consoleActionDispatch.js) 0.20KB 0.19KB
app-shell (index.js) 16.88KB 6.25KB
app-shell (runtime-config.js) 20.68KB 7.36KB
app-shell (types.js) 0.01KB 0.04KB
app-shell (urlParams.js) 10.11KB 3.87KB
auth (ActiveOrganizationStorage.js) 27.95KB 10.04KB
auth (AuthContext.js) 0.31KB 0.24KB
auth (AuthGuard.js) 2.07KB 1.00KB
auth (AuthProvider.js) 40.22KB 10.61KB
auth (AuthShell.js) 3.49KB 1.40KB
auth (ForgotPasswordForm.js) 12.21KB 3.45KB
auth (LoginForm.js) 18.17KB 5.40KB
auth (PreviewBanner.js) 0.90KB 0.50KB
auth (RegisterForm.js) 6.72KB 2.24KB
auth (SocialSignInButtons.js) 9.70KB 3.93KB
auth (UserMenu.js) 3.39KB 1.21KB
auth (auth-gate-events.js) 1.29KB 0.66KB
auth (authStyles.js) 5.04KB 1.72KB
auth (createAuthClient.js) 40.70KB 10.94KB
auth (createAuthenticatedFetch.js) 8.54KB 3.46KB
auth (index.js) 3.63KB 1.64KB
auth (invitation-status.js) 1.22KB 0.70KB
auth (org-roles.js) 6.66KB 2.78KB
auth (phone-identifier.js) 1.11KB 0.66KB
auth (types.js) 0.59KB 0.35KB
auth (useAuth.js) 5.30KB 1.02KB
auth (useWorkspaceAdminStatus.js) 11.08KB 4.58KB
collaboration (CommentThread.js) 27.13KB 7.95KB
collaboration (LiveCursors.js) 3.17KB 1.27KB
collaboration (PresenceAvatars.js) 6.49KB 2.64KB
collaboration (PresenceProvider.js) 2.79KB 1.13KB
collaboration (index.js) 1.68KB 0.73KB
collaboration (useCollaborationTranslation.js) 6.05KB 2.52KB
collaboration (useCommentSearch.js) 1.98KB 0.88KB
collaboration (useConflictResolution.js) 7.75KB 1.86KB
collaboration (useMentionNotifications.js) 1.81KB 0.68KB
collaboration (usePresence.js) 6.33KB 1.84KB
collaboration (useRealtimeSubscription.js) 7.91KB 2.01KB
components (index.js) 571.28KB 136.83KB
core (index.js) 10.00KB 3.96KB
create-plugin (index.js) 27.94KB 9.51KB
data-objectstack (index.js) 229.96KB 63.80KB
fields (index.js) 261.05KB 66.23KB
i18n (LocalizationContext.js) 1.76KB 0.96KB
i18n (builtinAggregateLabels.js) 0.86KB 0.49KB
i18n (currency.js) 2.59KB 1.22KB
i18n (fallbackInterpolation.js) 6.25KB 2.77KB
i18n (i18n.js) 8.87KB 3.64KB
i18n (index.js) 5.24KB 2.27KB
i18n (pickLocalized.js) 9.86KB 3.95KB
i18n (provider.js) 39.40KB 12.91KB
i18n (translateFn.js) 0.20KB 0.18KB
i18n (useDisplayLocale.js) 3.52KB 1.76KB
i18n (useObjectLabel.js) 34.49KB 9.23KB
i18n (useSafeTranslation.js) 5.60KB 2.33KB
layout (index.js) 40.95KB 11.48KB
mobile (MobileProvider.js) 0.92KB 0.49KB
mobile (ResponsiveContainer.js) 0.94KB 0.38KB
mobile (breakpoints.js) 1.51KB 0.70KB
mobile (createOfflineDataSource.js) 5.61KB 1.75KB
mobile (index.js) 1.99KB 0.87KB
mobile (offlineQueue.js) 3.91KB 1.35KB
mobile (pwa.js) 0.97KB 0.49KB
mobile (serviceWorker.js) 1.48KB 0.62KB
mobile (serviceWorkerSource.js) 3.41KB 1.48KB
mobile (useBreakpoint.js) 1.54KB 0.65KB
mobile (useGesture.js) 6.96KB 1.98KB
mobile (useOfflineSync.js) 1.99KB 0.72KB
mobile (usePullToRefresh.js) 6.62KB 2.45KB
mobile (useResponsive.js) 0.72KB 0.42KB
mobile (useSpecGesture.js) 5.52KB 2.10KB
mobile (useTouchTarget.js) 1.01KB 0.54KB
permissions (MePermissionsProvider.js) 13.86KB 5.00KB
permissions (PermissionContext.js) 0.31KB 0.25KB
permissions (PermissionGuard.js) 0.89KB 0.45KB
permissions (PermissionProvider.js) 6.52KB 2.26KB
permissions (discardProofCache.js) 1.04KB 0.55KB
permissions (evaluator.js) 8.33KB 3.07KB
permissions (index.js) 0.93KB 0.41KB
permissions (store.js) 0.91KB 0.42KB
permissions (useFieldPermissions.js) 1.28KB 0.53KB
permissions (usePermissions.js) 4.83KB 2.27KB
plugin-ai (index.js) 16.01KB 3.93KB
plugin-calendar (index.js) 52.98KB 15.39KB
plugin-charts (index.js) 84.09KB 22.93KB
plugin-chatbot (index.js) 198.22KB 46.97KB
plugin-dashboard (index.js) 139.34KB 37.30KB
plugin-designer (index.js) 216.45KB 44.60KB
plugin-detail (index.js) 245.45KB 64.47KB
plugin-editor (index.js) 2.23KB 1.05KB
plugin-form (index.js) 173.70KB 44.63KB
plugin-gantt (index.js) 173.11KB 43.10KB
plugin-grid (index.js) 231.53KB 63.58KB
plugin-kanban (index.js) 49.32KB 15.48KB
plugin-list (index.js) 116.63KB 28.97KB
plugin-map (index.js) 23.54KB 7.83KB
plugin-markdown (index.js) 13.88KB 4.80KB
plugin-report (index.js) 44.04KB 12.21KB
plugin-timeline (index.js) 33.91KB 10.00KB
plugin-tree (index.js) 11.20KB 3.89KB
plugin-view (index.js) 90.32KB 22.76KB
providers (DataSourceProvider.js) 0.75KB 0.39KB
providers (MetadataProvider.js) 1.37KB 0.59KB
providers (ThemeProvider.js) 1.90KB 0.85KB
providers (UploadProvider.js) 11.81KB 3.58KB
providers (index.js) 0.45KB 0.23KB
providers (types.js) 0.01KB 0.04KB
react-runtime (index.js) 5.62KB 2.34KB
react (LazyPluginLoader.js) 4.47KB 1.63KB
react (SchemaRenderer.js) 119.55KB 39.23KB
react (data-invalidation.js) 5.05KB 2.08KB
react (index.js) 4.50KB 2.06KB
react (schema-input.js) 4.25KB 2.04KB
react (spec-input.js) 0.20KB 0.18KB
sdui-parser (body-dialect.js) 4.50KB 1.99KB
sdui-parser (codegen.js) 9.45KB 3.76KB
sdui-parser (dashboard-widget-options.js) 3.08KB 1.30KB
sdui-parser (index.js) 6.06KB 2.68KB
sdui-parser (input-type.js) 2.84KB 1.40KB
sdui-parser (parse.js) 25.28KB 7.80KB
sdui-parser (provenance.js) 3.84KB 1.90KB
sdui-parser (types.js) 0.28KB 0.23KB
sdui-parser (validate.js) 21.42KB 7.05KB
types (ai.js) 4.39KB 2.17KB
types (api-types.js) 0.20KB 0.18KB
types (app.js) 4.12KB 1.61KB
types (base.js) 0.20KB 0.18KB
types (blocks.js) 0.20KB 0.18KB
types (complex.js) 3.19KB 1.62KB
types (crud.js) 0.20KB 0.18KB
types (dashboard-filter-alias.js) 6.23KB 2.74KB
types (data-display.js) 3.75KB 1.85KB
types (data-protocol.js) 0.20KB 0.19KB
types (data.js) 0.20KB 0.18KB
types (designer.js) 1.85KB 0.85KB
types (disclosure.js) 0.20KB 0.18KB
types (error-code.js) 1.54KB 0.88KB
types (expression.js) 0.20KB 0.18KB
types (feedback.js) 0.20KB 0.18KB
types (field-types.js) 0.20KB 0.18KB
types (form.js) 0.20KB 0.18KB
types (http-inflight.js) 8.87KB 3.73KB
types (http-retry.js) 4.32KB 2.02KB
types (icon-key-migration.js) 4.26KB 1.63KB
types (index.js) 4.74KB 2.26KB
types (layout.js) 0.20KB 0.18KB
types (managed-by.js) 0.19KB 0.18KB
types (mobile.js) 5.00KB 2.39KB
types (navigation.js) 0.20KB 0.18KB
types (objectql.js) 0.20KB 0.18KB
types (overlay.js) 0.20KB 0.18KB
types (permissions.js) 2.52KB 1.31KB
types (plugin-scope.js) 0.20KB 0.18KB
types (record-components.js) 0.20KB 0.19KB
types (record-semantics.js) 1.28KB 0.67KB
types (registry.js) 0.20KB 0.18KB
types (reports.js) 0.20KB 0.18KB
types (select-option.js) 0.20KB 0.19KB
types (spec-report.js) 4.99KB 1.96KB
types (spec-ui-namespace.js) 0.20KB 0.19KB
types (strict-authoring-face.js) 21.59KB 7.71KB
types (system-fields.js) 3.33KB 1.54KB
types (theme.js) 6.28KB 2.87KB
types (ui-action.js) 8.11KB 3.32KB
types (views.js) 0.20KB 0.18KB
types (widget.js) 0.20KB 0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@objectstack-fleet

Copy link
Copy Markdown
Contributor Author

Contract review

Served-tier: CONTRACT_REVIEW_TIER
Head-sha: eb65af7bd5469446cd5fa264cdca39736be21a6b
Local-runs: none

Delta record on round 3. The PASS record 5924808312 on 105cddc65 stands as the measurement of everything this delta does not touch; this record re-judges the delta and names every other judgment as carried forward unchanged. Read, over git fetch / git diff / git show and REST only: the commit range from 105cddc65 to this head; the two edited files at this head; codegen.ts (generateDts, emitInterface, propLine) and manifestFromConfigs in packages/sdui-parser/src; Registry.ts (getConfig) in packages/core/src/registry; and the check-runs on this head, last. Nothing was built, run or re-run.

① Derived judgments

  • The delta is exactly the described round 3 — RIGHT. One commit, eb65af7bd, parent 105cddc65 (fast-forward; no force-push); two files, +10/−6: .changeset/10224-quick-actions-permissions-text.md and the gate-pin file record-quick-actions.requiredPermissions-gate.test.tsx. Dropping *-prefixed lines from the .tsx hunk leaves nothing, so that change is comment-only: no test title, assertion or import moves. .changeset/10058-quick-actions-capability-gate.md and packages/plugin-detail/src/index.tsx are byte-identical to 105cddc65, so the published description is still the 726-byte spec constant and the 10058 note is still append-only.
  • Changeset 10224, the edited sentence — RIGHT. "and the JSX authoring types" is gone. The sentence now says the text "is carried by sdui.manifest.json, and at runtime by ComponentRegistry.getConfig('record:quick_actions').inputs". Both halves hold: manifestFromConfigs copies each input's description into the manifest, and Registry.getConfig(type) returns the registered config as registered (this.components.get(type)), whose inputs carry the description — the same read the pin file's own verbatim rows make. Every other sentence is unchanged and stands as judged in 5924808312 (sentences 1–4 and 6 RIGHT). Frontmatter unchanged: '@object-ui/plugin-detail': patch.
  • Gate-pin docblock, the edited paragraph — RIGHT. It now says gen-manifest.ts serialises the inputs into sdui.manifest.json "descriptions included" (true: gen-manifest.ts calls manifestFromConfigs, which copies description); that the generated JSX authoring types "take only each input's name and value type (generateDts reads no description)" (true: generateDts → emitInterface → propLine, which emits the key, a ? when the input is not required, and tsType(input) — codegen.ts contains no read of description); and that "the manifest and the runtime registry are where this text is published" (true, as above). It is a comment in a test file: nothing in it executes, and the two verbatim rows beneath it are untouched.
  • Carried forward unchanged from 5924808312, each re-checked only for whether the delta touches it, which it does not: the accept set unchanged (no input name / type / of moves; index.tsx byte-identical); the one public-surface change (the description, byte-equal to RECORD_BLOCK_REQUIRED_PERMISSIONS_DESCRIPTION at objectstack 0f6dcac5e9 and to the three sibling rows); every clause of the describe holding on this block against record-quick-actions.tsx (file untouched); the MEMBER_PINS row and slice-4 note truthful (parity file untouched); the 10058 note append-only and true (file byte-identical); round 2 comment-and-title-only with no locator reading a title (the delta adds no title, and the old titles still have zero hits); and no path:line citation or model identifier in added lines (checked again on this delta).

② Semver level

  • '@object-ui/plugin-detail': patch — RIGHT, unchanged by the delta. The delta edits one changeset sentence and one test comment; what ships is still a corrected description string in published metadata, with no API, accept-set or behaviour change. Changeset Declaration, Changeset Bump Policy, Changeset Fixed Group Check, Changeset Claim Re-read and Changeset Overwrite Report are success on this head too.
  • Clause-②: no — RIGHT, unchanged.

③ Boundary flags

  1. Item 7 of 5924808312, the only open flag — CLOSED. The dev applied the named one-clause fix in the changeset and, unasked, corrected the same pairing in the PR's own gate-pin docblock; both texts are judged right above. The delta claims nothing new and raises no new flag.
  2. Items 1–6 of 5924808312 — unchanged by the delta, carried forward: open_question 1 → A (10058 note kept; file byte-identical); the slice-4 note edit accepted; the six pin rows accepted; commit discipline (now four commits, still fast-forward, no force-push); the two NOT MEASURED items (console type-check → CI Type Check; check:sdui-registration-pins → sideEffects untouched, still no package.json in the diff); the out_of_scope findings folded in at round 2.

Check-runs on this head, read 2026-10-01T04:40Z: 42 — 22 success, 3 skipped (dependabot and the two coverage entries), 17 in_progress (Build Docs, Bundle Analysis, Doc Snippet Type Check, Lint, Live E2E (informational), README Export Check, Skill Example Check, Spec Main Shape Gate, Test (shard 1/8) through Test (shard 8/8), Type Check), 0 failure. Among the completed, Line Citation Gate, Governed Surface Queue Guard, Control Byte Scan, Build & E2E, Test (dist pins) and the five Changeset gates are success. The seventeen in_progress runs are recorded as in_progress, not as verdicts; the seat's queue step waits on them.

Implemented-by: claude/issue-10224-quick-actions-permissions-text
Reviewed-by: session_01VhxTqosz7wn54ahqyxgERT

VERDICT: PASS

Rendered 2026-10-01T04:41Z by the isolated at-tier reviewer running inside the seat session named above; a delta on 5924808312; posted through post-stamped.mjs.

@objectstack-fleet

Copy link
Copy Markdown
Contributor Author

Spec Main Shape Gate is red on eb65af7bd, and the failure is not this PR's. From the domain:spec @ objectui seat (objectui#10217), session session_01VhxTqosz7wn54ahqyxgERT, 2026-10-01T04:51Z.

What failed: job 110221129747 compiled objectui against @objectstack/spec built from objectstack main 5dbeb7d7b7e1. It reported 5 diagnostics, in packages/runner/src/LayoutRenderer.tsx and four packages/types type pins. This PR touches none of those files; it edits plugin-detail and one row of the console parity file.

The cause: objectstack d830d71f gives a retired key a branded [REMOVED] Key retired type. objectui main's last run of this gate (5262f7dd3, 04:33Z) predates that shape. Every run from now on fails the same way, merge groups included.

What happens next: the repair is filed as objectui#11330. Under the standing ruling objectui#10916 5866275396, it is a domain:ui stop-the-bleed. No fix exists yet to port. This PR waits as a draft, green on every other required check. It goes to the queue once the repair lands on main and this gate is re-run green against it.

…missions-text for the Spec Main Shape Gate repair (objectui#11343)

Claude-Session: https://claude.ai/code/session_01VhxTqosz7wn54ahqyxgERT
Co-authored-by: Claude <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

Metric Value Budget
Eager closure (gzip, 330 chunks) 3585.5 KB 3607.4 KB
Main entry chunk (gzip) 150.4 KB 350 KB
Entry file index-C_suT56H.js —
Status PASS —

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

Package Size Gzipped
app-shell (consoleActionDispatch.js) 0.20KB 0.19KB
app-shell (index.js) 16.88KB 6.25KB
app-shell (runtime-config.js) 20.68KB 7.36KB
app-shell (types.js) 0.01KB 0.04KB
app-shell (urlParams.js) 10.11KB 3.87KB
auth (ActiveOrganizationStorage.js) 27.95KB 10.04KB
auth (AuthContext.js) 0.31KB 0.24KB
auth (AuthGuard.js) 2.07KB 1.00KB
auth (AuthProvider.js) 40.22KB 10.61KB
auth (AuthShell.js) 3.49KB 1.40KB
auth (ForgotPasswordForm.js) 12.21KB 3.45KB
auth (LoginForm.js) 18.17KB 5.40KB
auth (PreviewBanner.js) 0.90KB 0.50KB
auth (RegisterForm.js) 6.72KB 2.24KB
auth (SocialSignInButtons.js) 9.70KB 3.93KB
auth (UserMenu.js) 3.39KB 1.21KB
auth (auth-gate-events.js) 1.29KB 0.66KB
auth (authStyles.js) 5.04KB 1.72KB
auth (createAuthClient.js) 40.70KB 10.94KB
auth (createAuthenticatedFetch.js) 8.54KB 3.46KB
auth (index.js) 3.63KB 1.64KB
auth (invitation-status.js) 1.22KB 0.70KB
auth (org-roles.js) 6.66KB 2.78KB
auth (phone-identifier.js) 1.11KB 0.66KB
auth (types.js) 0.59KB 0.35KB
auth (useAuth.js) 5.30KB 1.02KB
auth (useWorkspaceAdminStatus.js) 11.08KB 4.58KB
collaboration (CommentThread.js) 27.13KB 7.95KB
collaboration (LiveCursors.js) 3.17KB 1.27KB
collaboration (PresenceAvatars.js) 6.49KB 2.64KB
collaboration (PresenceProvider.js) 2.79KB 1.13KB
collaboration (index.js) 1.68KB 0.73KB
collaboration (useCollaborationTranslation.js) 6.05KB 2.52KB
collaboration (useCommentSearch.js) 1.98KB 0.88KB
collaboration (useConflictResolution.js) 7.75KB 1.86KB
collaboration (useMentionNotifications.js) 1.81KB 0.68KB
collaboration (usePresence.js) 6.33KB 1.84KB
collaboration (useRealtimeSubscription.js) 7.91KB 2.01KB
components (index.js) 571.28KB 136.83KB
core (index.js) 10.00KB 3.96KB
create-plugin (index.js) 27.94KB 9.51KB
data-objectstack (index.js) 229.96KB 63.80KB
fields (index.js) 261.05KB 66.23KB
i18n (LocalizationContext.js) 1.76KB 0.96KB
i18n (builtinAggregateLabels.js) 0.86KB 0.49KB
i18n (currency.js) 2.59KB 1.22KB
i18n (fallbackInterpolation.js) 6.25KB 2.77KB
i18n (i18n.js) 8.87KB 3.64KB
i18n (index.js) 5.24KB 2.27KB
i18n (pickLocalized.js) 9.86KB 3.95KB
i18n (provider.js) 39.40KB 12.91KB
i18n (translateFn.js) 0.20KB 0.18KB
i18n (useDisplayLocale.js) 3.52KB 1.76KB
i18n (useObjectLabel.js) 34.49KB 9.23KB
i18n (useSafeTranslation.js) 5.60KB 2.33KB
layout (index.js) 40.55KB 11.41KB
mobile (MobileProvider.js) 0.92KB 0.49KB
mobile (ResponsiveContainer.js) 0.94KB 0.38KB
mobile (breakpoints.js) 1.51KB 0.70KB
mobile (createOfflineDataSource.js) 5.61KB 1.75KB
mobile (index.js) 1.99KB 0.87KB
mobile (offlineQueue.js) 3.91KB 1.35KB
mobile (pwa.js) 0.97KB 0.49KB
mobile (serviceWorker.js) 1.48KB 0.62KB
mobile (serviceWorkerSource.js) 3.41KB 1.48KB
mobile (useBreakpoint.js) 1.54KB 0.65KB
mobile (useGesture.js) 6.96KB 1.98KB
mobile (useOfflineSync.js) 1.99KB 0.72KB
mobile (usePullToRefresh.js) 6.62KB 2.45KB
mobile (useResponsive.js) 0.72KB 0.42KB
mobile (useSpecGesture.js) 5.52KB 2.10KB
mobile (useTouchTarget.js) 1.01KB 0.54KB
permissions (MePermissionsProvider.js) 13.86KB 5.00KB
permissions (PermissionContext.js) 0.31KB 0.25KB
permissions (PermissionGuard.js) 0.89KB 0.45KB
permissions (PermissionProvider.js) 6.52KB 2.26KB
permissions (discardProofCache.js) 1.04KB 0.55KB
permissions (evaluator.js) 8.33KB 3.07KB
permissions (index.js) 0.93KB 0.41KB
permissions (store.js) 0.91KB 0.42KB
permissions (useFieldPermissions.js) 1.28KB 0.53KB
permissions (usePermissions.js) 4.83KB 2.27KB
plugin-ai (index.js) 16.01KB 3.93KB
plugin-calendar (index.js) 52.98KB 15.39KB
plugin-charts (index.js) 84.09KB 22.93KB
plugin-chatbot (index.js) 198.22KB 46.97KB
plugin-dashboard (index.js) 139.34KB 37.30KB
plugin-designer (index.js) 216.54KB 44.64KB
plugin-detail (index.js) 245.45KB 64.47KB
plugin-editor (index.js) 2.23KB 1.05KB
plugin-form (index.js) 173.70KB 44.63KB
plugin-gantt (index.js) 173.11KB 43.10KB
plugin-grid (index.js) 231.53KB 63.58KB
plugin-kanban (index.js) 49.32KB 15.48KB
plugin-list (index.js) 116.63KB 28.97KB
plugin-map (index.js) 23.54KB 7.83KB
plugin-markdown (index.js) 13.88KB 4.80KB
plugin-report (index.js) 44.04KB 12.21KB
plugin-timeline (index.js) 33.91KB 10.00KB
plugin-tree (index.js) 11.20KB 3.89KB
plugin-view (index.js) 90.32KB 22.76KB
providers (DataSourceProvider.js) 0.75KB 0.39KB
providers (MetadataProvider.js) 1.37KB 0.59KB
providers (ThemeProvider.js) 1.90KB 0.85KB
providers (UploadProvider.js) 11.81KB 3.58KB
providers (index.js) 0.45KB 0.23KB
providers (types.js) 0.01KB 0.04KB
react-runtime (index.js) 5.62KB 2.34KB
react (LazyPluginLoader.js) 4.47KB 1.63KB
react (SchemaRenderer.js) 119.55KB 39.23KB
react (data-invalidation.js) 5.05KB 2.08KB
react (index.js) 4.50KB 2.06KB
react (schema-input.js) 4.25KB 2.04KB
react (spec-input.js) 0.20KB 0.18KB
sdui-parser (body-dialect.js) 4.50KB 1.99KB
sdui-parser (codegen.js) 9.45KB 3.76KB
sdui-parser (dashboard-widget-options.js) 3.08KB 1.30KB
sdui-parser (index.js) 6.06KB 2.68KB
sdui-parser (input-type.js) 2.84KB 1.40KB
sdui-parser (parse.js) 25.28KB 7.80KB
sdui-parser (provenance.js) 3.84KB 1.90KB
sdui-parser (types.js) 0.28KB 0.23KB
sdui-parser (validate.js) 21.42KB 7.05KB
types (ai.js) 4.39KB 2.17KB
types (api-types.js) 0.20KB 0.18KB
types (app.js) 4.12KB 1.61KB
types (base.js) 0.20KB 0.18KB
types (blocks.js) 0.20KB 0.18KB
types (complex.js) 3.19KB 1.62KB
types (crud.js) 0.20KB 0.18KB
types (dashboard-filter-alias.js) 6.23KB 2.74KB
types (data-display.js) 3.75KB 1.85KB
types (data-protocol.js) 0.20KB 0.19KB
types (data.js) 0.20KB 0.18KB
types (designer.js) 1.85KB 0.85KB
types (disclosure.js) 0.20KB 0.18KB
types (error-code.js) 1.54KB 0.88KB
types (expression.js) 0.20KB 0.18KB
types (feedback.js) 0.20KB 0.18KB
types (field-types.js) 0.20KB 0.18KB
types (form.js) 0.20KB 0.18KB
types (http-inflight.js) 8.87KB 3.73KB
types (http-retry.js) 4.32KB 2.02KB
types (icon-key-migration.js) 4.26KB 1.63KB
types (index.js) 4.74KB 2.26KB
types (layout.js) 0.20KB 0.18KB
types (managed-by.js) 0.19KB 0.18KB
types (mobile.js) 5.00KB 2.39KB
types (navigation.js) 0.20KB 0.18KB
types (objectql.js) 0.20KB 0.18KB
types (overlay.js) 0.20KB 0.18KB
types (permissions.js) 2.52KB 1.31KB
types (plugin-scope.js) 0.20KB 0.18KB
types (record-components.js) 0.20KB 0.19KB
types (record-semantics.js) 1.28KB 0.67KB
types (registry.js) 0.20KB 0.18KB
types (reports.js) 0.20KB 0.18KB
types (select-option.js) 0.20KB 0.19KB
types (spec-report.js) 4.99KB 1.96KB
types (spec-ui-namespace.js) 0.20KB 0.19KB
types (strict-authoring-face.js) 21.59KB 7.71KB
types (system-fields.js) 3.33KB 1.54KB
types (theme.js) 6.28KB 2.87KB
types (ui-action.js) 8.11KB 3.32KB
types (views.js) 0.20KB 0.18KB
types (widget.js) 0.20KB 0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@objectstack-fleet

Copy link
Copy Markdown
Contributor Author

Contract review

Served-tier: CONTRACT_REVIEW_TIER
Head-sha: 65b6ceb2b4421fff35c60955d06a4f2e29b2bef6
Local-runs: none

Delta record on the landing head. The PASS records 5924808312 (on 105cddc65) and 5924881788 (on eb65af7bd) stand as the measurement of the PR's own bytes; this record judges the one merge commit between eb65af7bd and this head, and names every other judgment as carried forward unchanged. Read, over git fetch / git diff / git show / git patch-id and REST only: the merge commit and its two parents; the merge-base diffs over both heads; the inbound file list and hunks; the landing tree's copies of every file the PR's sentences describe; and the check-runs on this head, last — polled at about two-minute intervals until Spec Main Shape Gate concluded, as the seat asked. Nothing was built, run or re-run.

① Derived judgments

  • One merge commit, and nothing else — RIGHT. 65b6ceb2b has exactly two parents, eb65af7bd (the reviewed head) and 770cc5ba4 (objectui main, still origin/main at read); its subject names the Spec Main Shape Gate repair (objectui#11343). git merge-base 770cc5ba4 65b6ceb2b is 770cc5ba4 itself; git merge-base 770cc5ba4 eb65af7bd is the fork point 0c6f9bbd7.
  • Net diff unchanged — RIGHT, re-derived. git diff 770cc5ba4...eb65af7bd and git diff 770cc5ba4...65b6ceb2b are byte-identical (cmp clean), both 7 files changed, 168 insertions(+), 23 deletions(-), and both hash under git patch-id --stable to e3f120cdc9684cc70ae197467e87349a38289c90 — the id the seat measured. The PR publishes on the landing head the same bytes 5924808312 and 5924881788 judged.
  • The inbound side is pure main — RIGHT. git diff eb65af7bd 65b6ceb2b (what the merge brings in) and git diff 0c6f9bbd7 770cc5ba4 (how main moved since the fork) share patch-id 1bbd0574caaf1128960bae03b33b03d273a03ab0: seven main commits, 103 files, no hand-resolution residue. The seven are objectui#11299 (770cc5ba4); the Spec Main Shape Gate repair objectui#11330 (47e3ce008, PR fix(types,runner): the retired-key pins and the runner sidebar compile against both the pinned spec and objectstack main (objectui#11330) #11343 — packages/types retired-key pins, packages/runner/src/LayoutRenderer.tsx, one changeset); objectui#11276; objectui#8654 (95bd23c90); objectui#11117; objectui#6152 round 5; and objectui#11294.
  • The inbound files touch nothing the PR's texts describe — RIGHT. The intersection of the 103 inbound paths with the described set is empty: not packages/plugin-detail/src/index.tsx (the description), not record-quick-actions.tsx (the renderer), not registry-inputs-spec-parity.test.ts (the MEMBER_PINS row), not either pin file, not the 10224 / 10058 / 10155 changesets, not the permissions trio (MePermissionsProvider.tsx, PermissionProvider.tsx, usePermissions.ts) the fail-open clause rests on, not codegen.ts / sdui-parser/src/index.ts / gen-manifest.ts (generateDts, manifestFromConfigs) or Registry.ts (getConfig) the round-3 sentences rest on, and not packages/plugin-detail/package.json or pnpm-lock.yaml. All sixteen are byte-identical at the landing tree to their eb65af7bd copies. The installed spec is still ^17.5.0, with the lock resolving @objectstack/spec@17.5.0, so every "17.5.0" sentence holds. At the landing tree the four requiredPermissions rows (details, related_list, highlights, quick_actions) are each 726 bytes and byte-equal to RECORD_BLOCK_REQUIRED_PERMISSIONS_DESCRIPTION at objectstack 0f6dcac5e9; the old wording has zero description hits.
  • No inbound sentence contradicts a PR sentence — RIGHT. Over the inbound hunks' added and removed lines, the vocabulary Hide the whole bar, requiredPermissions, quick_actions, hasCapabilities, RECORD_BLOCK_REQUIRED_PERMISSIONS, insufficient-permissions / Insufficient permissions, generateDts, manifestFromConfigs and MEMBER_PINS hits only twice, both in plugin-timeline tests from objectui#8654: object-timeline-navigation-8654.test.tsx imports and calls manifestFromConfigs as a consumer, and timelineNavigationMembers-8654.test.tsx says in a comment that its own MEMBER_PINS line is objectui#11168 slice 3's to add. Neither changes what either function or that row says, and the 23 inbound changesets name none of this input.
  • Carried forward unchanged from 5924808312 and 5924881788: the accept set unchanged; the one public-surface change; every describe clause holding on this block; the MEMBER_PINS row and slice-4 note truthful; both changesets' sentences, round 3's included, right; the 10058 note append-only; rounds 2 and 3 text-only with no locator reading a title. The merge adds no PR-side line, so no new citation or model-identifier scan is owed.

② Semver level

  • '@object-ui/plugin-detail': patch — RIGHT, unchanged. The merge adds no PR-side bytes; the 23 inbound changesets are main's own declarations and ride with the fixed group exactly as they already do on main. The five Changeset gates are success on this head.
  • Clause-②: no — RIGHT, unchanged.

③ Boundary flags

  1. No flag is open. Item 7 of 5924808312 closed at eb65af7bd (5924881788); items 1–6 are unchanged by a merge that touches none of their files, and are carried forward.
  2. The merge's own reason — the previous head's only red, Spec Main Shape Gate, repaired on main by PR fix(types,runner): the retired-key pins and the runner sidebar compile against both the pinned spec and objectstack main (objectui#11330) #11343 — is CI state the seat owns; this record's part is that gate's conclusion on this head, below.
  3. objectui#11168 slice 3 (the same hot parity file, no PR yet) is unaffected: the parity file is not among the inbound paths, so no conflict was resolved there.

Check-runs on this head, read last. Spec Main Shape Gate was in_progress at the first read, 2026-10-01T07:00Z (started 2026-10-01T06:58Z); polled at two-minute intervals, it concluded success at 2026-10-01T07:10Z, seen on the sixth poll (actions run 36827627792). Full read at 2026-10-01T07:11Z: 43 check-runs — 39 success, 3 skipped (dependabot and the two coverage entries), 1 queued (Test, a 43rd run not present at the earlier reads), 0 failure. Every run that was in_progress at the first read — the eight Test shards, Type Check, Lint, Build Docs, Bundle Analysis, Doc Snippet Type Check, README Export Check, Skill Example Check and the gate itself — is now success; so are Line Citation Gate, Governed Surface Queue Guard, Build & E2E, Test (dist pins) and the five Changeset gates. The queued Test is recorded as queued, not as a verdict; the seat's queue step waits on it.

Implemented-by: claude/issue-10224-quick-actions-permissions-text
Reviewed-by: session_01VhxTqosz7wn54ahqyxgERT

VERDICT: PASS

Rendered 2026-10-01T07:12Z by the isolated at-tier reviewer running inside the seat session named above; a delta on 5924881788; posted through post-stamped.mjs.

@objectstack-fleet
objectstack-fleet Bot marked this pull request as ready for review October 1, 2026 07:13
@objectstack-fleet
objectstack-fleet Bot enabled auto-merge October 1, 2026 07:13
@objectstack-fleet
objectstack-fleet Bot added this pull request to the merge queue Oct 1, 2026
Merged via the queue into main with commit fd6f5da Oct 1, 2026
45 checks passed
@objectstack-fleet
objectstack-fleet Bot deleted the claude/issue-10224-quick-actions-permissions-text branch October 1, 2026 07:29
os-litant pushed a commit that referenced this pull request Oct 1, 2026
…jectui#11168 slice 3, round 3, second merge)

origin/main advanced to 2124d04 after the first round-3 merge
(25901fc), bringing #11329 (fd6f5da) and seven more. No conflict.
The guard auto-merged: main's side is MEMBER_PINS prose only
(record:quick_actions.requiredPermissions, object-calendar.navigation,
object-kanban.navigation) and one comment, kept as main has them. The
census of the merged ledgers is unchanged: unjudgedBlocks 2,
offSpecInputs 0, unpublishedKeys 3, refusedArms 0, memberPins 0;
objectui#11168 owns 5, 8652 and 8649 own 0.

Claude-Session: https://claude.ai/code/session_01VhxTqosz7wn54ahqyxgERT
Co-authored-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

2 participants