Skip to content

feat(studio): render the runtime authoring gate's advisory findings after a save - #4236

Merged
yinlianghui merged 1 commit into
mainfrom
claude/issue-4133-advisory-findings
Aug 11, 2026
Merged

feat(studio): render the runtime authoring gate's advisory findings after a save#4236
yinlianghui merged 1 commit into
mainfrom
claude/issue-4133-advisory-findings

Conversation

@yinlianghui

Copy link
Copy Markdown
Collaborator

Fixes #4133

The gate's advisories ride a 200 — the save succeeded, the row persisted, the version bumped — and objectui discarded them one layer further out than the server used to: MetadataClient.save parsed the response body, returned it as an opaque T, and every call site awaited it for its side effect and dropped the value. objectstack#7435 (89d7b35a7) put them on the wire; this renders them.

Premise check

Verified against the installed rc.6 dist rather than assumed (a runtime safeParse, not a type read):

spec version: 17.0.0-rc.6
SaveMetaItemResponseSchema exported: true
RuntimeAuthoringIssueSchema exported: true
parse WITH advisories -> true
parse WITHOUT advisories -> true   advisories key present: false
reverse probe: partial finding REJECTED -> true  advisories.0.path | advisories.0.where | …

rulesRun is absent from the response and nothing here expects it.

The call-site map

Every app-shell write path takes its client from useMetadataClient, so that hook — not the ~20 client.save(...) call sites — is where this lifts. Measured, with the save mode each site uses:

call site mode advisories today
ResourceEditPage.tsx:1100 — the main authoring editor draft none (D1, below)
StudioDesignSurface.tsx — 8 sites, all pillars draft none (D1)
ObjectHooksPanel.tsx, PackageOwdOverviewPanel.tsx draft none (D1)
views/runtime-metadata-persistence.ts draft none (D1)
EmbeddedItemEditor.tsx:102 active rendered
datasource/DatasourceResourcePage.tsx:427 active rendered
plugin-designer object / field / app pages active rendered (via MetadataClientConfig)

MetadataProvider's client is read-only and never receives one, so it is not wired.

Flow coverage — stated honestly, and pinned

A draft-then-publish flow surfaces nothing today, at both of its doors, for two different reasons — and the first is not the one the card assumed:

  • The save door. Drafts are never gated. The framework returns before running a single rule, at metadata-protocol/src/runtime-authoring-gate.ts:388:
    // D1 — drafts are never gated. Publishing one runs this same function.
    if (args.state !== 'active') return null;
    
    So a draft save produces no findings at all, rather than producing some that are withheld. The client is not what suppresses this; there is nothing to suppress.
  • The publish door. It does run the gate, but PublishMetaItemResponseSchema carries no advisories field until objectstack#7294.

Since Studio's designer saves as draft on every edit, that is the whole designer. a draft save carries no findings — the gate never ran (D1) is the control test asserting the publish path is unchanged.

Shape

Mirrors ObjectStackAdapter.onWriteWarning (#3431/#3455) — the repo's existing seam for exactly this problem: a successful write whose response carries something the author must be told, emitted as an event so the data layer never imports a toaster. Rendering mirrors writeWarningToast.ts (pure builder, caller-owned sink) and the 10s multi-finding toast of preview/usePublishAllDrafts.ts.

Warning tier, never error — the title says "Saved" first, because a successful save that reads as a failure is the defect this surface must not ship. Each finding renders rule + message + hint, with where as secondary context; path is a machine pointer and is omitted. message/hint are server prose, rendered verbatim — only the frame is translated (console.saveAdvisoryTitle, all ten packs). The finding type is re-exported from @objectstack/spec (RuntimeAuthoringIssue), not restated, so it cannot fork from the 422 issues[] it shares a declaration with.

Malformed findings are dropped rather than printed as blanks, and a throwing renderer cannot turn a committed save into an error.

Reverse verification

Direction predicted before running: removing the emit restores "parse and discard", so the pins asserting an event arrives go red and the absence-asserting ones cannot see it.

Measured, exactly as predicted — 5 red / 20 green:

× emits the findings a successful save returned
× carries rule, message and hint through verbatim — they are server prose
× labels the mode when a draft save does somehow advise
× survives the withEnvironment clone — console clients are all env-scoped
× survives the withPreviewDrafts clone
 Tests  5 failed | 20 passed (25)

Worth recording: saveAdvisoryToast.test.ts stayed fully green through the revert. It exercises the pure builder, not the wiring — those tests alone would not catch this regression, which is what the data-layer emit pins carry. The clone pins are there because useMetadataClient routes every console client through withEnvironment; dropping the sink there would have disabled the channel silently.

Tests

packages/data-objectstack                     28 files, 408 tests   PASS
app-shell providers + metadata-admin + ratchet 147 files, 1488 tests PASS
i18n all-locales-key-parity                    20 tests             PASS
check:i18n-keys / check:i18n-drift / check:control-bytes             PASS
eslint (7 touched files)                       0 errors

Pre-existing reds, confirmed not mine

Both comparison-worktreed against clean origin/main (6314e87f2):

  • check:spec-symbols — identical failure set on clean main (5 symbols in @object-ui/types, incl. complex.zod.ts). My RuntimeAuthoringIssue re-export passes the gate.
  • data-objectstack type-check — spec-symbol-batch6.test.ts(208) reproduces with my changes fully reverted via git checkout origin/main --. Cause: rc.6 added a third DroppedFieldsEvent.reason member (primary_key) and the typetest pins two.
  • app-shell type-check — the resolveActionParams.test.ts reds. No error in any file this PR touches.

All belong to the #4169 rc.6 train / PR #4208, not to this change.


Generated by Claude Code

…fter a save

The gate's advisories ride a 200 — the save succeeded, the row persisted — and
objectui discarded them client-side: `MetadataClient.save` parsed the response
body, returned it as an opaque `T`, and every call site awaited it for its side
effect and dropped the value. objectstack#7435 put them on the wire; this
renders them.

`MetadataClient` gains an `onSaveAdvisory` sink, invoked after a save whose
response carried a non-empty `advisories[]`. The console wires it in
`useMetadataClient` — the one hook every app-shell write path takes its client
from — so a single wiring covers ResourceEditPage, StudioDesignSurface,
EmbeddedItemEditor, DatasourceResourcePage and ObjectHooksPanel rather than a
toast copied into twenty call sites. The finding shape is re-exported from
`@objectstack/spec` (`RuntimeAuthoringIssue`) rather than restated, so it cannot
fork from the 422 `issues[]` it shares a declaration with.

The affordance is the warning tier and says "Saved" first: a successful save
that reads as a failure is the defect this surface must not ship. `message` and
`hint` are server prose and render verbatim; only the frame is translated.

Coverage is stated honestly and pinned: drafts are never gated (the framework
returns at its D1 early-return before running a rule), so Studio's designer —
which saves as draft on every edit — surfaces nothing today, and the publish
door returns no advisories until objectstack#7294.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017Qqyix2QcnpUC9XeYVDzx3
@vercel

vercel Bot commented Aug 11, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated (UTC)
objectui Ignored Ignored Aug 11, 2026 5:27am

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

Metric Value Budget
Main entry (gzip) 28.3 KB 350 KB
Entry file index-Bhdq1r6j.js
Status PASS

📦 Bundle Size Report

Package Size Gzipped
app-shell (index.js) 8.88KB 3.25KB
app-shell (runtime-config.js) 7.42KB 2.32KB
app-shell (types.js) 0.01KB 0.04KB
app-shell (urlParams.js) 7.57KB 2.97KB
auth (AuthContext.js) 0.31KB 0.24KB
auth (AuthGuard.js) 1.17KB 0.53KB
auth (AuthProvider.js) 22.10KB 4.37KB
auth (AuthShell.js) 3.49KB 1.40KB
auth (ForgotPasswordForm.js) 12.21KB 3.45KB
auth (LoginForm.js) 18.13KB 5.39KB
auth (PreviewBanner.js) 0.90KB 0.50KB
auth (RegisterForm.js) 6.64KB 2.21KB
auth (SocialSignInButtons.js) 9.60KB 3.89KB
auth (UserMenu.js) 3.40KB 1.22KB
auth (auth-gate-events.js) 1.29KB 0.66KB
auth (authStyles.js) 5.04KB 1.72KB
auth (createAuthClient.js) 35.76KB 9.11KB
auth (createAuthenticatedFetch.js) 4.37KB 1.69KB
auth (index.js) 2.35KB 1.07KB
auth (org-roles.js) 6.66KB 2.78KB
auth (phone-identifier.js) 1.11KB 0.66KB
auth (types.js) 0.59KB 0.35KB
auth (useAuth.js) 4.91KB 0.87KB
auth (useIsWorkspaceAdmin.js) 1.61KB 0.85KB
collaboration (CommentThread.js) 26.07KB 7.56KB
collaboration (LiveCursors.js) 3.17KB 1.27KB
collaboration (PresenceAvatars.js) 6.49KB 2.64KB
collaboration (PresenceProvider.js) 2.79KB 1.13KB
collaboration (index.js) 1.65KB 0.73KB
collaboration (useCollaborationTranslation.js) 6.05KB 2.52KB
collaboration (useCommentSearch.js) 1.98KB 0.88KB
collaboration (useConflictResolution.js) 7.75KB 1.86KB
collaboration (useMentionNotifications.js) 1.81KB 0.68KB
collaboration (usePresence.js) 6.33KB 1.84KB
collaboration (useRealtimeSubscription.js) 7.91KB 2.01KB
components (index.js) 488.60KB 108.25KB
core (index.js) 3.04KB 1.15KB
create-plugin (index.js) 10.08KB 3.26KB
data-objectstack (index.js) 145.46KB 37.89KB
fields (index.js) 228.33KB 56.58KB
i18n (LocalizationContext.js) 1.76KB 0.96KB
i18n (currency.js) 1.22KB 0.64KB
i18n (i18n.js) 4.32KB 1.77KB
i18n (index.js) 2.65KB 1.06KB
i18n (pickLocalized.js) 1.70KB 0.83KB
i18n (provider.js) 9.48KB 3.27KB
i18n (useObjectLabel.js) 27.59KB 6.63KB
i18n (useSafeTranslation.js) 4.52KB 1.96KB
layout (index.js) 38.98KB 10.85KB
mobile (MobileProvider.js) 0.92KB 0.49KB
mobile (ResponsiveContainer.js) 0.94KB 0.38KB
mobile (breakpoints.js) 1.51KB 0.70KB
mobile (createOfflineDataSource.js) 5.61KB 1.74KB
mobile (index.js) 1.50KB 0.62KB
mobile (offlineQueue.js) 3.91KB 1.35KB
mobile (pwa.js) 0.97KB 0.49KB
mobile (serviceWorker.js) 1.48KB 0.62KB
mobile (serviceWorkerSource.js) 3.41KB 1.48KB
mobile (useBreakpoint.js) 1.54KB 0.65KB
mobile (useGesture.js) 6.96KB 1.98KB
mobile (useOfflineSync.js) 1.99KB 0.72KB
mobile (usePullToRefresh.js) 2.53KB 0.85KB
mobile (useResponsive.js) 0.71KB 0.42KB
mobile (useResponsiveConfig.js) 1.36KB 0.63KB
mobile (useSpecGesture.js) 4.32KB 1.64KB
mobile (useTouchTarget.js) 1.01KB 0.54KB
permissions (MePermissionsProvider.js) 8.75KB 3.06KB
permissions (PermissionContext.js) 0.31KB 0.25KB
permissions (PermissionGuard.js) 0.89KB 0.45KB
permissions (PermissionProvider.js) 3.67KB 1.12KB
permissions (evaluator.js) 4.41KB 1.44KB
permissions (index.js) 0.91KB 0.41KB
permissions (store.js) 0.91KB 0.42KB
permissions (useFieldPermissions.js) 1.28KB 0.52KB
permissions (usePermissions.js) 1.55KB 0.71KB
plugin-ai (index.js) 15.71KB 3.79KB
plugin-calendar (index.js) 45.23KB 12.45KB
plugin-charts (index.js) 61.52KB 17.49KB
plugin-chatbot (index.js) 180.33KB 42.79KB
plugin-dashboard (index.js) 118.58KB 30.71KB
plugin-designer (index.js) 210.85KB 42.64KB
plugin-detail (index.js) 238.21KB 59.54KB
plugin-editor (index.js) 2.46KB 1.10KB
plugin-form (index.js) 114.58KB 27.68KB
plugin-gantt (index.js) 164.14KB 39.98KB
plugin-grid (index.js) 187.97KB 49.90KB
plugin-kanban (index.js) 48.60KB 13.41KB
plugin-list (index.js) 110.31KB 26.76KB
plugin-map (index.js) 17.00KB 5.32KB
plugin-markdown (index.js) 13.72KB 4.69KB
plugin-report (index.js) 40.58KB 10.58KB
plugin-timeline (index.js) 26.21KB 7.52KB
plugin-tree (index.js) 8.50KB 2.88KB
plugin-view (index.js) 84.03KB 20.55KB
providers (DataSourceProvider.js) 0.75KB 0.39KB
providers (MetadataProvider.js) 1.37KB 0.59KB
providers (ThemeProvider.js) 1.90KB 0.85KB
providers (UploadProvider.js) 11.71KB 3.53KB
providers (index.js) 0.44KB 0.22KB
providers (types.js) 0.01KB 0.04KB
react-runtime (index.js) 5.67KB 2.37KB
react (LazyPluginLoader.js) 3.77KB 1.33KB
react (SchemaRenderer.js) 23.71KB 7.96KB
react (data-invalidation.js) 5.05KB 2.08KB
react (index.js) 1.23KB 0.66KB
react (spec-input.js) 0.20KB 0.18KB
sdui-parser (codegen.js) 4.09KB 1.74KB
sdui-parser (index.js) 4.47KB 2.03KB
sdui-parser (parse.js) 10.04KB 2.82KB
sdui-parser (types.js) 0.29KB 0.24KB
sdui-parser (validate.js) 4.69KB 1.48KB
types (ai.js) 0.20KB 0.17KB
types (api-types.js) 0.20KB 0.18KB
types (app.js) 2.87KB 0.99KB
types (base.js) 0.20KB 0.18KB
types (blocks.js) 0.20KB 0.18KB
types (complex.js) 0.20KB 0.18KB
types (crud.js) 0.20KB 0.18KB
types (data-display.js) 0.20KB 0.18KB
types (data-protocol.js) 0.20KB 0.19KB
types (data.js) 0.20KB 0.18KB
types (designer.js) 1.87KB 0.85KB
types (disclosure.js) 0.20KB 0.18KB
types (error-code.js) 1.54KB 0.88KB
types (feedback.js) 0.20KB 0.18KB
types (field-types.js) 0.20KB 0.18KB
types (form.js) 0.20KB 0.18KB
types (http-retry.js) 4.32KB 2.02KB
types (index.js) 2.71KB 1.34KB
types (layout.js) 0.20KB 0.18KB
types (managed-by.js) 0.19KB 0.18KB
types (mobile.js) 2.59KB 1.31KB
types (navigation.js) 0.20KB 0.18KB
types (objectql.js) 0.20KB 0.18KB
types (overlay.js) 0.20KB 0.18KB
types (permissions.js) 0.20KB 0.18KB
types (plugin-scope.js) 0.20KB 0.18KB
types (record-components.js) 0.20KB 0.19KB
types (record-semantics.js) 1.28KB 0.67KB
types (registry.js) 0.20KB 0.18KB
types (reports.js) 0.20KB 0.18KB
types (spec-report.js) 5.05KB 1.93KB
types (system-fields.js) 3.33KB 1.54KB
types (theme.js) 0.20KB 0.18KB
types (ui-action.js) 3.40KB 1.71KB
types (views.js) 0.20KB 0.18KB
types (widget.js) 0.20KB 0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@yinlianghui
yinlianghui marked this pull request as ready for review August 11, 2026 05:43
@yinlianghui
yinlianghui added this pull request to the merge queue Aug 11, 2026
Merged via the queue into main with commit c0f9a4b Aug 11, 2026
21 checks passed
@yinlianghui
yinlianghui deleted the claude/issue-4133-advisory-findings branch August 11, 2026 05:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Studio: render the runtime authoring gate's advisory findings returned by saveMetaItem

2 participants