Skip to content

fix(app-shell): package-door permission save carries every editor-authorable facet (#4302) - #4534

Merged
yinlianghui merged 1 commit into
mainfrom
claude/issue-4302-package-door-slice
Aug 13, 2026
Merged

fix(app-shell): package-door permission save carries every editor-authorable facet (#4302)#4534
yinlianghui merged 1 commit into
mainfrom
claude/issue-4302-package-door-slice

Conversation

@yinlianghui

Copy link
Copy Markdown
Collaborator

Fixes #4302

An RLS policy authored in Studio's package door was silently discarded: Save returned 200 with a success toast, and the PUT body carried no rowLevelSecurity key at all. Tab visibility and delegated-admin scope were reverted the same way.

What was measured, before writing any code

(a) Why the slice exists — is the hold-back deliberate? mergePermissionSlice arrived in 4f77044 (#2222, ADR-0086 P0) for one stated reason: objects and fields accumulate authorization rows contributed by many packages, so a package-door Save must not clobber another package's rows. The load path applies that scoping to exactly two mapsresetDraftBaseline({ ...full, objects: sliced.objects, fields: sliced.fields }) — and hands every other facet to the editors unscoped. ADR-0086 agrees (§P0 "this package's own object slice"; the facet table lists tabPermissions and adminScope as set-level metadata, not per-package slices). So holding the advanced facets back protected no one: the author edits what the panel showed them in full, and the merge discarded it. The deliberate part — other packages' rows — is preserved by the row-level merge loops, which this PR does not touch.

(b) Does the server accept the dropped facets on the package door? Read-only in the objectstack sibling. client.save(..., { mode: 'draft', packageId }) reaches saveMetaItem (metadata-protocol/src/protocol.ts:8777), whose spec-conformance gate runs for draft and publish alike — it is not conditioned on mode — and resolves permission to PermissionSetSchema (spec/src/kernel/metadata-type-schemas.ts:156). That schema declares rowLevelSecurity, tabPermissions and adminScope as first-class optional keys (spec/src/security/permission.zod.ts:462/487/508). Inside saveMetaItem the packageId decides only writability and row attribution (:9239, :9288) — there is no per-package narrowing of the body. The server accepts all three on this door, so widening the client cannot convert a silent drop into a 422. Premise holds; no server card.

(c) Companion seed defect (ruling item 3) — measured NOT necessary. PermissionAdvancedFacets.tsx:368 no longer seeds the retired priority key: commit 5419f55 (#4057) removed it and added stripRetiredRlsKeys for already-poisoned stored policies, closing objectstack#7130 (closed). The current seed is { name: '', object: '*', operation: 'all', using: '', enabled: true }. Nothing folded in; PermissionAdvancedFacets.retiredKeys.test.tsx stays green.

The fix — the drift is inverted, not extended

A facet the editor can author comes from edited; the freshly-read base supplies only what the editor cannot author. objects / fields are authored too, but per-row — they keep going through the same scope merge, so other packages' contributions survive byte-for-byte.

A key absent from edited still comes from base: absence means "this caller does not model the facet", never "the author cleared it". Clearing still persists as clearing, because the facet editors always write a value — an emptied policy list is [], a present key.

Structural guard is a test, not UI copy (ruling item 2): permission-slice.authoredKeys.test.ts scans the two draft-owning sources for the keys their setDraft(...) updaters write, and fails when one is not carried by the slice. It carries its own anti-empty-green assertions — a scanner self-test on a fixture, plus a floor of keys the scan must find — so a scanner that goes blind reds instead of passing on an empty set. No runtime message, no i18n rows (i18n.ts untouched).

Red-first evidence

Prediction written before running. Against unfixed code:

× persists an RLS policy authored in the editor instead of reverting to the stored list
    AssertionError: expected [ { name: 'stored_policy', ...(4) } ] to have a length of 2 but got 1
× persists authored tab visibility
    AssertionError: expected { a_account: 'visible', ...(1) } to deeply equal { a_account: 'hidden', ...(1) }
× persists an authored delegated-admin scope
    AssertionError: expected { businessUnit: 'stored_bu', ...(1) } to deeply equal { businessUnit: 'authored_bu', ...(1) }
× carries every facet the editor can author — no silent drop on the package door
    AssertionError: expected [ 'adminScope', 'fields', ...(6) ] to deeply equal []
× PUTs the authored RLS policy, tab visibility and admin scope
    AssertionError: expected undefined to deeply equal [ { name: 'qa_st2_rls', ...(4) } ]

That last one is the card's own wire evidence reproduced: the key is not merely wrong, it is absent.

Two prediction deviations, declared rather than smoothed over:

  1. I predicted the structural-guard file would red with an ESM link error on the missing export. It did not — vite left EDITOR_AUTHORED_KEYS as undefined, new Set(undefined) is empty, and the failure came out as an assertion naming all 8 dropped keys. Sharper than predicted, same direction.
  2. I predicted the "absent key falls back to base" case would be green both ways. Its facet assertions were, but its label assertion was red: the old code did label: edited.label unconditionally, so a partial edited nulled a stored label. The presence rule fixes that too.

Reverse verification (git diff to a patch file + git checkout --, never git stash — shared stack): removing only the source fix reproduced exactly those 9 failures, with the environment-door guard and the ADR-0086 P0 preservation case staying green. Restored with git apply; sha256 verified byte-identical (f66c8497...OK).

Pins

Verification

  • pnpm exec vitest run --maxWorkers=2 over the permission family: 18 files, 137 tests passed
  • pnpm --filter @object-ui/app-shell run type-check (both passes: tsc --noEmit and tsc -p tsconfig.test.json): green
  • eslint on changed files: 0 errors; the 2 modified files carry 0 warnings (unchanged from origin/main); the new harness carries 5 no-explicit-any warnings, the same pattern in the same roles as the sibling PermissionMatrixEditor.scope.test.tsx on main (6)
  • check-control-bytes OK (plus a direct self-scan of the new files), changeset:check OK, check-phantom-dependencies OK
  • .d.ts diff measured both ways (clean dist/ + tsconfig.tsbuildinfo between builds): 415 files each way, exactly one differsviews/metadata-admin/permission-slice.d.ts. index.d.ts is byte-identical and the package exports map publishes only ., so the new symbol is not entry-reachable ⇒ patch (precedent fix(app-shell): organization & invitation UI translates its six English holdouts (#4474) #4496)

Out of scope, filed


Generated by Claude Code

…horable facet (#4302)

An RLS policy authored in Studio's package door was silently discarded: Save
returned 200 with a success toast and the PUT body carried no `rowLevelSecurity`
key at all, so no row filter was ever persisted while the surface still showed
the permission set as configured. Tab visibility and the delegated-admin scope
were reverted the same way.

`mergePermissionSlice` returned `{...base, name, label, isDefault, objects,
fields}` — five keys from the edited draft and every other facet from a fresh
server read. That whitelist had drifted behind the editor. It is now inverted:
a facet the editor can author comes from `edited`, and `base` supplies only what
the editor cannot author. The package scoping ADR-0086 P0 actually needs is
`objects` / `fields`, which still go through the same row-level merge, so other
packages' contributed rows are preserved byte-for-byte.

A structural guard scans the editor sources for the keys their `setDraft(...)`
updaters write and fails when the slice does not carry one, so the next facet
added to the editor cannot silently drop on this door.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017Qqyix2QcnpUC9XeYVDzx3
@vercel

vercel Bot commented Aug 13, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated (UTC)
objectui Ignored Ignored Aug 13, 2026 5:25am

Request Review

@github-actions github-actions Bot added the tests label Aug 13, 2026
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

Metric Value Budget
Main entry (gzip) 24.7 KB 350 KB
Entry file index-BcOGXu8v.js
Status PASS

📦 Bundle Size Report

Package Size Gzipped
app-shell (index.js) 9.56KB 3.59KB
app-shell (runtime-config.js) 7.42KB 2.32KB
app-shell (types.js) 0.01KB 0.04KB
app-shell (urlParams.js) 8.92KB 3.41KB
auth (AuthContext.js) 0.31KB 0.24KB
auth (AuthGuard.js) 1.17KB 0.53KB
auth (AuthProvider.js) 25.13KB 5.40KB
auth (AuthShell.js) 3.49KB 1.40KB
auth (ForgotPasswordForm.js) 12.21KB 3.45KB
auth (LoginForm.js) 18.13KB 5.39KB
auth (PreviewBanner.js) 0.90KB 0.50KB
auth (RegisterForm.js) 6.64KB 2.21KB
auth (SocialSignInButtons.js) 9.60KB 3.89KB
auth (UserMenu.js) 3.40KB 1.22KB
auth (auth-gate-events.js) 1.29KB 0.66KB
auth (authStyles.js) 5.04KB 1.72KB
auth (createAuthClient.js) 38.46KB 10.17KB
auth (createAuthenticatedFetch.js) 6.34KB 2.43KB
auth (index.js) 2.35KB 1.07KB
auth (org-roles.js) 6.66KB 2.78KB
auth (phone-identifier.js) 1.11KB 0.66KB
auth (types.js) 0.59KB 0.35KB
auth (useAuth.js) 5.02KB 0.88KB
auth (useIsWorkspaceAdmin.js) 1.61KB 0.85KB
collaboration (CommentThread.js) 26.07KB 7.56KB
collaboration (LiveCursors.js) 3.17KB 1.27KB
collaboration (PresenceAvatars.js) 6.49KB 2.64KB
collaboration (PresenceProvider.js) 2.79KB 1.13KB
collaboration (index.js) 1.65KB 0.73KB
collaboration (useCollaborationTranslation.js) 6.05KB 2.52KB
collaboration (useCommentSearch.js) 1.98KB 0.88KB
collaboration (useConflictResolution.js) 7.75KB 1.86KB
collaboration (useMentionNotifications.js) 1.81KB 0.68KB
collaboration (usePresence.js) 6.33KB 1.84KB
collaboration (useRealtimeSubscription.js) 7.91KB 2.01KB
components (index.js) 489.32KB 108.45KB
core (index.js) 3.37KB 1.34KB
create-plugin (index.js) 10.08KB 3.26KB
data-objectstack (index.js) 156.23KB 42.29KB
fields (index.js) 230.14KB 57.12KB
i18n (LocalizationContext.js) 1.76KB 0.96KB
i18n (currency.js) 1.22KB 0.64KB
i18n (i18n.js) 4.32KB 1.77KB
i18n (index.js) 3.35KB 1.38KB
i18n (pickLocalized.js) 3.69KB 1.73KB
i18n (provider.js) 23.12KB 7.62KB
i18n (useDisplayLocale.js) 2.84KB 1.45KB
i18n (useObjectLabel.js) 27.59KB 6.63KB
i18n (useSafeTranslation.js) 7.77KB 3.13KB
layout (index.js) 38.98KB 10.85KB
mobile (MobileProvider.js) 0.92KB 0.49KB
mobile (ResponsiveContainer.js) 0.94KB 0.38KB
mobile (breakpoints.js) 1.51KB 0.70KB
mobile (createOfflineDataSource.js) 5.61KB 1.74KB
mobile (index.js) 1.50KB 0.62KB
mobile (offlineQueue.js) 3.91KB 1.35KB
mobile (pwa.js) 0.97KB 0.49KB
mobile (serviceWorker.js) 1.48KB 0.62KB
mobile (serviceWorkerSource.js) 3.41KB 1.48KB
mobile (useBreakpoint.js) 1.54KB 0.65KB
mobile (useGesture.js) 6.96KB 1.98KB
mobile (useOfflineSync.js) 1.99KB 0.72KB
mobile (usePullToRefresh.js) 2.53KB 0.85KB
mobile (useResponsive.js) 0.71KB 0.42KB
mobile (useResponsiveConfig.js) 1.36KB 0.63KB
mobile (useSpecGesture.js) 4.32KB 1.64KB
mobile (useTouchTarget.js) 1.01KB 0.54KB
permissions (MePermissionsProvider.js) 8.75KB 3.06KB
permissions (PermissionContext.js) 0.31KB 0.25KB
permissions (PermissionGuard.js) 0.89KB 0.45KB
permissions (PermissionProvider.js) 3.67KB 1.12KB
permissions (evaluator.js) 4.41KB 1.44KB
permissions (index.js) 0.91KB 0.41KB
permissions (store.js) 0.91KB 0.42KB
permissions (useFieldPermissions.js) 1.28KB 0.52KB
permissions (usePermissions.js) 1.55KB 0.71KB
plugin-ai (index.js) 15.75KB 3.80KB
plugin-calendar (index.js) 46.86KB 12.91KB
plugin-charts (index.js) 62.07KB 17.65KB
plugin-chatbot (index.js) 181.21KB 43.14KB
plugin-dashboard (index.js) 120.95KB 31.53KB
plugin-designer (index.js) 212.58KB 42.83KB
plugin-detail (index.js) 239.88KB 59.99KB
plugin-editor (index.js) 2.46KB 1.10KB
plugin-form (index.js) 114.58KB 27.68KB
plugin-gantt (index.js) 164.14KB 39.98KB
plugin-grid (index.js) 189.28KB 50.29KB
plugin-kanban (index.js) 48.62KB 13.42KB
plugin-list (index.js) 111.13KB 27.12KB
plugin-map (index.js) 18.16KB 5.81KB
plugin-markdown (index.js) 13.72KB 4.69KB
plugin-report (index.js) 41.16KB 10.96KB
plugin-timeline (index.js) 26.25KB 7.53KB
plugin-tree (index.js) 8.50KB 2.88KB
plugin-view (index.js) 84.08KB 20.55KB
providers (DataSourceProvider.js) 0.75KB 0.39KB
providers (MetadataProvider.js) 1.37KB 0.59KB
providers (ThemeProvider.js) 1.90KB 0.85KB
providers (UploadProvider.js) 11.71KB 3.53KB
providers (index.js) 0.44KB 0.22KB
providers (types.js) 0.01KB 0.04KB
react-runtime (index.js) 5.67KB 2.37KB
react (LazyPluginLoader.js) 3.77KB 1.33KB
react (SchemaRenderer.js) 23.73KB 7.96KB
react (data-invalidation.js) 5.05KB 2.08KB
react (index.js) 1.23KB 0.66KB
react (spec-input.js) 0.20KB 0.18KB
sdui-parser (codegen.js) 4.09KB 1.74KB
sdui-parser (index.js) 4.47KB 2.03KB
sdui-parser (parse.js) 10.04KB 2.82KB
sdui-parser (types.js) 0.29KB 0.24KB
sdui-parser (validate.js) 4.69KB 1.48KB
types (ai.js) 0.20KB 0.17KB
types (api-types.js) 0.20KB 0.18KB
types (app.js) 2.87KB 0.99KB
types (base.js) 0.20KB 0.18KB
types (blocks.js) 0.20KB 0.18KB
types (complex.js) 0.20KB 0.18KB
types (crud.js) 0.20KB 0.18KB
types (dashboard-filter-alias.js) 6.23KB 2.74KB
types (data-display.js) 0.20KB 0.18KB
types (data-protocol.js) 0.20KB 0.19KB
types (data.js) 0.20KB 0.18KB
types (designer.js) 1.87KB 0.85KB
types (disclosure.js) 0.20KB 0.18KB
types (error-code.js) 1.54KB 0.88KB
types (feedback.js) 0.20KB 0.18KB
types (field-types.js) 0.20KB 0.18KB
types (form.js) 0.20KB 0.18KB
types (http-retry.js) 4.32KB 2.02KB
types (index.js) 3.05KB 1.52KB
types (layout.js) 0.20KB 0.18KB
types (managed-by.js) 0.19KB 0.18KB
types (mobile.js) 2.59KB 1.31KB
types (navigation.js) 0.20KB 0.18KB
types (objectql.js) 0.20KB 0.18KB
types (overlay.js) 0.20KB 0.18KB
types (permissions.js) 0.20KB 0.18KB
types (plugin-scope.js) 0.20KB 0.18KB
types (record-components.js) 0.20KB 0.19KB
types (record-semantics.js) 1.28KB 0.67KB
types (registry.js) 0.20KB 0.18KB
types (reports.js) 0.20KB 0.18KB
types (spec-report.js) 5.05KB 1.93KB
types (system-fields.js) 3.33KB 1.54KB
types (theme.js) 0.20KB 0.18KB
types (ui-action.js) 3.40KB 1.71KB
types (views.js) 0.20KB 0.18KB
types (widget.js) 0.20KB 0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

Copy link
Copy Markdown
Collaborator Author

PM step-7 复核 — ACCEPT (session_017Qqyix2QcnpUC9XeYVDzx3)

Auto-merge armed (squash).


Generated by Claude Code


Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[security] An RLS policy authored in Studio's package door is silently discarded — Save succeeds, no row filter is ever persisted

2 participants