Skip to content

fix(data-objectstack,core): an object filter no longer depends on whether the query expands a lookup - #3084

Merged
os-zhuang merged 1 commit into
mainfrom
claude/object-filter-single-route
Jul 31, 2026
Merged

fix(data-objectstack,core): an object filter no longer depends on whether the query expands a lookup#3084
os-zhuang merged 1 commit into
mainfrom
claude/object-filter-single-route

Conversation

@os-zhuang

Copy link
Copy Markdown
Contributor

The last untouched half of the adapter's two find() routes. #3072 single-sourced the array branch; the object branch still had convertQueryParams converting a MongoDB-style filter to AST while translateFilterToAST returned it verbatim — so the same $filter went out in two formats, decided by whether the query happened to expand a lookup.

Sizing it before fixing it

I measured all 21 operator shapes through both routes, comparing the server-side predicate each ends at. Four diverged — and most of the gap was harmless, which was not obvious beforehand and is worth recording:

shape verdict
{$and: […]} (dashboard scope filters, via mergeFilters) benign — survives the plain route as ['$and','=',[…]], which parseFilterAST reads back as a real $and. I expected this to be a third bug; it isn't.
$exists vs $null benign — the plain route inverts to $null, the server treats them identically
unknown operator real
$regex real

The two that mattered

The unknown-operator guard only ran on one route. convertFiltersToAST throws on an unrecognised operator, with a comment stating it does so "to avoid silent failure". The expanded route never called it — so a typo'd operator threw on a plain read and shipped silently whenever a lookup was expanded. The guard was bypassed by exactly the condition it should have been indifferent to.

$regex was silently rewritten to contains. The existing test's own example makes the case better than prose could:

{ name: { $regex: '^John' } }   // "starts with John"
// became
['name', 'contains', '^John']   // looks for a literal caret — "John Smith" does NOT match

A different question, not a weaker version of the same one, and neither result looks wrong on screen. The rewrite sat behind a console.warn — not an error channel in a deployed app — and the function's own unknown-operator error message never listed $regex among the supported operators, so the code disagreed with itself. The spec has no $regex (FILTER_OPERATORS, data/filter.zod.ts), so there is nothing to translate it into. It is refused now, the same treatment the neighbouring unknown operator already got. Nothing in the repo depended on the conversion.

Bonus: the refusals stopped blaming the network

Both now throw FilterOperatorError with code: 'INVALID_FILTER' / httpStatus: 400. The pre-existing unknown-operator throw was a bare Error, which classifyLoadError classifies as a network fault — so a malformed filter told the user to check their connection (#3066). That was latent before this PR.

A test that asserted the old behaviour

filter-converter.test.ts pinned $regex → contains including the console.warn. Rewritten to assert the refusal, keeping the '^John' example — it documents the harm better than any comment.

Verification

9 new/changed tests. Reverting the two source files fails 9 of them. Both routes are driven for every case rather than the helper being called directly. Full suite 762 files / 8875 tests green; tsc clean; eslint 0 errors.

Refs #3072, #3081, #3066

🤖 Generated with Claude Code

…ther the query expands a lookup

#3072 single-sourced the ARRAY branch of the adapter's two `find()` routes. The
object branch was left as it was: `convertQueryParams` converted a MongoDB-style
filter to AST while `translateFilterToAST` returned it verbatim — so the same
`$filter` went out in two formats, decided by whether the query happened to
expand a lookup.

Measured across 21 operator shapes, four diverged. Most of the gap turned out to
be harmless, which is worth recording because it was not obvious: `{$and: […]}`
survives the plain route as a `['$and','=',[…]]` comparison that `parseFilterAST`
reads back as a real `$and`, and `$exists` vs `$null` is a difference the server
treats identically. Two were not harmless:

- THE UNKNOWN-OPERATOR GUARD ONLY RAN ON ONE ROUTE. `convertFiltersToAST` throws
  on an unrecognised operator, with a comment saying it does so "to avoid silent
  failure" — but the expanded route never called it, so a typo'd operator threw
  on a plain read and shipped silently whenever a lookup was expanded.

- `$regex` WAS SILENTLY REWRITTEN TO `contains`. The existing test's own example
  makes the case: `$regex: '^John'` means "starts with John", while
  `contains '^John'` looks for a literal caret — so "John Smith" does not match.
  A different question, not a weaker version of the same one, and neither result
  looks wrong on screen. The rewrite sat behind a `console.warn`, which is not
  an error channel in a deployed app, and the function's own unknown-operator
  message never listed `$regex` among the supported set. The spec has no
  `$regex` (`FILTER_OPERATORS`, data/filter.zod.ts), so there is nothing to
  translate it into: it is refused now, the same treatment the neighbouring
  unknown operator already got. Nothing in the repo depended on the conversion.

Both refusals throw `FilterOperatorError` carrying `code: 'INVALID_FILTER'` /
`httpStatus: 400`. The pre-existing unknown-operator throw was a bare `Error`,
which `classifyLoadError` reads as a network fault — so a malformed filter told
the user to check their connection (#3066), the one thing it was not.

`filter-converter.test.ts`'s `$regex` case asserted the old behaviour and is
rewritten to assert the refusal, keeping the `'^John'` example because it
demonstrates the harm better than any prose.

Verification: 9 new/changed tests; reverting the two source files fails 9 of
them. Full suite 762 files / 8875 tests green; tsc clean; eslint 0 errors.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@vercel

vercel Bot commented Jul 31, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated (UTC)
objectui Ignored Ignored Jul 31, 2026 1:21am

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

Metric Value Budget
Main entry (gzip) 27.9 KB 350 KB
Entry file index-DVwDskhx.js
Status PASS

📦 Bundle Size Report

Package Size Gzipped
app-shell (index.js) 8.26KB 2.99KB
app-shell (runtime-config.js) 7.42KB 2.32KB
app-shell (types.js) 0.01KB 0.04KB
app-shell (urlParams.js) 7.57KB 2.97KB
auth (AuthContext.js) 0.31KB 0.24KB
auth (AuthGuard.js) 1.17KB 0.53KB
auth (AuthProvider.js) 22.10KB 4.37KB
auth (AuthShell.js) 3.49KB 1.40KB
auth (ForgotPasswordForm.js) 12.12KB 3.41KB
auth (LoginForm.js) 17.86KB 5.29KB
auth (PreviewBanner.js) 0.90KB 0.50KB
auth (RegisterForm.js) 6.43KB 2.09KB
auth (SocialSignInButtons.js) 9.60KB 3.89KB
auth (UserMenu.js) 3.40KB 1.22KB
auth (auth-gate-events.js) 1.29KB 0.66KB
auth (authStyles.js) 5.04KB 1.72KB
auth (createAuthClient.js) 35.76KB 9.11KB
auth (createAuthenticatedFetch.js) 4.37KB 1.69KB
auth (index.js) 2.35KB 1.07KB
auth (org-roles.js) 6.66KB 2.78KB
auth (phone-identifier.js) 1.11KB 0.66KB
auth (types.js) 0.59KB 0.35KB
auth (useAuth.js) 4.91KB 0.87KB
auth (useIsWorkspaceAdmin.js) 1.61KB 0.85KB
collaboration (CommentThread.js) 18.38KB 4.49KB
collaboration (LiveCursors.js) 3.17KB 1.27KB
collaboration (PresenceAvatars.js) 3.65KB 1.42KB
collaboration (PresenceProvider.js) 2.79KB 1.13KB
collaboration (index.js) 1.25KB 0.53KB
collaboration (useCommentSearch.js) 1.98KB 0.88KB
collaboration (useConflictResolution.js) 7.75KB 1.86KB
collaboration (useMentionNotifications.js) 1.81KB 0.68KB
collaboration (usePresence.js) 6.33KB 1.84KB
collaboration (useRealtimeSubscription.js) 7.91KB 2.01KB
components (index.js) 471.25KB 102.82KB
core (index.js) 2.16KB 0.78KB
create-plugin (index.js) 9.28KB 2.98KB
data-objectstack (index.js) 136.34KB 34.64KB
fields (index.js) 222.07KB 54.35KB
i18n (LocalizationContext.js) 1.76KB 0.96KB
i18n (currency.js) 1.22KB 0.64KB
i18n (i18n.js) 4.32KB 1.77KB
i18n (index.js) 2.46KB 0.96KB
i18n (pickLocalized.js) 1.70KB 0.83KB
i18n (provider.js) 5.37KB 1.72KB
i18n (useObjectLabel.js) 25.17KB 5.80KB
i18n (useSafeTranslation.js) 3.26KB 1.44KB
layout (index.js) 38.45KB 10.67KB
mobile (MobileProvider.js) 0.92KB 0.49KB
mobile (ResponsiveContainer.js) 0.94KB 0.38KB
mobile (breakpoints.js) 1.51KB 0.70KB
mobile (createOfflineDataSource.js) 5.61KB 1.74KB
mobile (index.js) 1.50KB 0.62KB
mobile (offlineQueue.js) 3.91KB 1.35KB
mobile (pwa.js) 0.97KB 0.49KB
mobile (serviceWorker.js) 1.48KB 0.62KB
mobile (serviceWorkerSource.js) 3.41KB 1.48KB
mobile (useBreakpoint.js) 1.54KB 0.65KB
mobile (useGesture.js) 6.96KB 1.98KB
mobile (useOfflineSync.js) 1.99KB 0.72KB
mobile (usePullToRefresh.js) 2.53KB 0.85KB
mobile (useResponsive.js) 0.71KB 0.42KB
mobile (useResponsiveConfig.js) 1.36KB 0.63KB
mobile (useSpecGesture.js) 4.05KB 1.53KB
mobile (useTouchTarget.js) 1.01KB 0.54KB
permissions (MePermissionsProvider.js) 8.76KB 3.06KB
permissions (PermissionContext.js) 0.31KB 0.25KB
permissions (PermissionGuard.js) 0.89KB 0.45KB
permissions (PermissionProvider.js) 3.67KB 1.12KB
permissions (evaluator.js) 4.41KB 1.44KB
permissions (index.js) 0.91KB 0.41KB
permissions (retry.js) 3.48KB 1.61KB
permissions (store.js) 0.91KB 0.42KB
permissions (useFieldPermissions.js) 1.28KB 0.52KB
permissions (usePermissions.js) 1.55KB 0.71KB
plugin-ai (index.js) 15.71KB 3.79KB
plugin-calendar (index.js) 44.90KB 12.35KB
plugin-charts (index.js) 60.52KB 17.11KB
plugin-chatbot (index.js) 180.09KB 42.72KB
plugin-dashboard (index.js) 111.59KB 28.74KB
plugin-designer (index.js) 210.51KB 42.50KB
plugin-detail (index.js) 221.81KB 54.28KB
plugin-editor (index.js) 2.46KB 1.10KB
plugin-form (index.js) 110.71KB 26.67KB
plugin-gantt (index.js) 162.26KB 39.53KB
plugin-grid (index.js) 182.21KB 48.24KB
plugin-kanban (index.js) 47.82KB 13.18KB
plugin-list (index.js) 103.85KB 24.80KB
plugin-map (index.js) 16.80KB 5.24KB
plugin-markdown (index.js) 13.65KB 4.67KB
plugin-report (index.js) 40.32KB 10.53KB
plugin-timeline (index.js) 25.75KB 7.32KB
plugin-tree (index.js) 8.36KB 2.81KB
plugin-view (index.js) 85.79KB 20.99KB
providers (DataSourceProvider.js) 0.75KB 0.39KB
providers (MetadataProvider.js) 1.37KB 0.59KB
providers (ThemeProvider.js) 1.90KB 0.85KB
providers (UploadProvider.js) 11.71KB 3.53KB
providers (index.js) 0.44KB 0.22KB
providers (types.js) 0.01KB 0.04KB
react-runtime (index.js) 5.67KB 2.37KB
react (LazyPluginLoader.js) 3.77KB 1.33KB
react (SchemaRenderer.js) 19.28KB 6.38KB
react (data-invalidation.js) 5.05KB 2.08KB
react (index.js) 1.02KB 0.55KB
sdui-parser (codegen.js) 4.09KB 1.74KB
sdui-parser (index.js) 3.47KB 1.54KB
sdui-parser (parse.js) 10.04KB 2.82KB
sdui-parser (types.js) 0.29KB 0.24KB
sdui-parser (validate.js) 4.69KB 1.48KB
types (ai.js) 0.20KB 0.17KB
types (api-types.js) 0.20KB 0.18KB
types (app.js) 2.87KB 0.99KB
types (base.js) 0.20KB 0.18KB
types (blocks.js) 0.20KB 0.18KB
types (complex.js) 0.20KB 0.18KB
types (crud.js) 0.20KB 0.18KB
types (data-display.js) 0.20KB 0.18KB
types (data-protocol.js) 0.20KB 0.19KB
types (data.js) 0.20KB 0.18KB
types (designer.js) 1.87KB 0.85KB
types (disclosure.js) 0.20KB 0.18KB
types (error-code.js) 1.54KB 0.88KB
types (feedback.js) 0.20KB 0.18KB
types (field-types.js) 0.20KB 0.18KB
types (form.js) 0.20KB 0.18KB
types (index.js) 2.07KB 0.99KB
types (layout.js) 0.20KB 0.18KB
types (managed-by.js) 0.19KB 0.18KB
types (mobile.js) 0.20KB 0.18KB
types (navigation.js) 0.20KB 0.18KB
types (objectql.js) 0.20KB 0.18KB
types (overlay.js) 0.20KB 0.18KB
types (permissions.js) 0.20KB 0.18KB
types (plugin-scope.js) 0.20KB 0.18KB
types (record-components.js) 0.20KB 0.19KB
types (record-semantics.js) 1.28KB 0.67KB
types (registry.js) 0.20KB 0.18KB
types (reports.js) 0.20KB 0.18KB
types (spec-report.js) 5.05KB 1.93KB
types (system-fields.js) 3.33KB 1.54KB
types (theme.js) 0.20KB 0.18KB
types (ui-action.js) 1.08KB 0.64KB
types (views.js) 0.20KB 0.18KB
types (widget.js) 0.20KB 0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-zhuang
os-zhuang merged commit ad0183a into main Jul 31, 2026
16 checks passed
@os-zhuang
os-zhuang deleted the claude/object-filter-single-route branch July 31, 2026 01:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant