Repository navigation
Upgrade the @objectstack/* dependencies from 17.4.0 to 17.7.0, walking the official upgrade checklists of 17.5, 17.6 and 17.7 - #85
Merged
Conversation
…ale and page breadcrumb WIP on #82. All four @objectstack/* deps move together to ^17.7.0 and the lockfile resolves every @objectstack/* package to 17.7.0. 17.5 refuses `scale` on a currency field (the currency's ISO 4217 minor unit decides display) — `os validate` exited 1 on the six amount fields. 17.6 removed `page:header` `breadcrumb`; `os migrate meta --from 17` offers the same deletion (page-header-breadcrumb-removed). The better-auth fixture in pnpm-workspace.yaml is still in place at this commit; it is measured and removed separately. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HihZ11bQSqjCgjzHbpv4M1
…s to 1.7.3 The override named objectstack-ai/objectstack#16186 as its removal condition (closed completed). @objectstack/plugin-auth@17.7.0 now pins better-auth and every @better-auth/* member to exactly 1.7.3, which is what the 17.5 upgrade checklist asks for, and all eleven members resolve there without an override. Measured before removing it: 17.7.0 with the 1.7.2 pins still in place boots, but refuses the dev-admin seed ("Unknown field 'issuer' on object 'sys_account'"), so a fresh database has no account and sign-in answers 401. Keeping the fixture would have shipped an app nobody can log into. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HihZ11bQSqjCgjzHbpv4M1
Three comments and pnpm demo's printed operator note said the demo boot leaves every seeded owner_id NULL until the requester accounts exist. 17.5 (widened in 17.7, plugin-security CHANGELOG) also runs the first-admin ownership claim on every seed settle (`app:seeded`), so on 17.7.0 the demo boot ends with every ownerless row parked on the dev admin. Measured on a clean database: all 120 contracts owned by Dev Admin after the first `pnpm demo`; after the README's operator setup the next `pnpm demo` hands them over 43 / 43 / 34 as before. Only the sentences the bump made false move; the dated 17.3/17.4 measurements of legal_owner, owner and decided_by (still NULL on 17.7) are untouched. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HihZ11bQSqjCgjzHbpv4M1
…r 17.7's coverage walk `pnpm lint:i18n-gate` exited 1 on 17.7.0 with 36 zh-CN keys missing, none of them new strings: - 34 `flows.contract_intake.*` keys — the intake wizard's flow label, screen headings and field labels/placeholders. 17.7 (spec aead296) flipped the `flows` translation group to `live`, which switches on the coverage demand; on 17.4 the walk produced no flow keys at all, so a zh-CN user launched a contract through an English wizard and no gate could say so. - `pages.contract_detail.title` / `.subtitle` — 17.5 (4bbf766, #16772) made a slotted page's `slots.header` addressable. Both are record interpolation templates, the same string in every locale. The Chinese reuses the object bundle's words for the same columns; `en/flows.ts` mirrors the inline English so the two bundles carry the same keys. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HihZ11bQSqjCgjzHbpv4M1
…17.5
The dashboards' globalFilters comment said the bundle has no key for the filter
bar and listed `widgets.<id>.{title,description,subCaption}`; the record page's
said `walkAddressedPageComponents` addresses zero components on a slotted page.
17.5 (spec 4bbf766, #16772) added `globalFilters` keys and rooted the walk at
`slots` (the same call returns 14 on contract_detail on 17.7.0), and 17.7
retired `subCaption`. Each comment gains a dated note; the inline maps still
render and are left in place — adopting the new keys is a separate card, not
part of a dependency bump.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HihZ11bQSqjCgjzHbpv4M1
This was referenced Oct 9, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part of #82 — everything the card asks for is here except one product choice, which this PR deliberately does not make: whether
pnpm dev/pnpm demoturn 17.5's package-authored scheduled work back on (see Scheduled work — the decision this PR leaves open). Once that is decided, #82 can close.Clause-②: no
What changed
All four
@objectstack/*dependencies move together to^17.7.0, the lockfile is regenerated and committed, and the app is migrated through the 17.5, 17.6 and 17.7 upgrade checklists. Every source edit below was forced by a 17.5–17.7 refusal, a gate, or a comment the bump made false — no capability was adopted.d633b33package.json,pnpm-lock.yaml^17.0.0→^17.7.0as one set. Lockfile: 53 distinct@objectstack/*packages, all 17.7.0, zero17.4.0strings.zodresolves 4.6.5 (we pin none).d633b33contract.object.ts,payment-plan.object.ts,approval-rule.object.tsos validateexited 1 on 17.7:`scale` is not valid on a `currency` field — delete the keyon 6 currency fields (17.5 retired key). Deleted. Display now follows the currency's ISO 4217 minor unit (USD rendered139,500.00in the browser).d633b33contract_detail.page.tspage:headerbreadcrumbremoved in 17.6 (os migrate metaofferpage-header-breadcrumb-removed, plus a validate warning). The shell's breadcrumb still draws.d1551a2pnpm-workspace.yamloverrides:pinningbetter-auth+ ten@better-auth/*to 1.7.2) retired: its removal condition objectstack#16186 is closed, and@objectstack/plugin-auth@17.7.0pins the whole family to exactly 1.7.3. Measured, both ways — see Auth below.c4aa32cscripts/demo.mjs,src/data/contract.seed.ts,src/data/keys.tspnpm demo's printed operator note said the demo boot leaves every seededowner_idNULL. 17.5 (widened in 17.7) runs the first-admin ownership claim on every seed settle, so on 17.7 those rows end on the dev admin. Only the sentences the bump made false move.7fd37c5src/translations/{en,zh-CN}/flows.ts(new),{en,zh-CN}.ts,{en,zh-CN}/app.tspnpm lint:i18n-gateexited 1 on 17.7 with 36 zh-CN keys missing: 34flows.contract_intake.*(17.7 flipped theflowstranslation group live, which switches on the coverage demand — on 17.4 the walk produced no flow keys, so the intake wizard was English in zh-CN and nothing could say so) andpages.contract_detail.title/subtitle(17.5 made a slotted page'sslots.headeraddressable; both are record-interpolation templates).56c7501contract_detail.page.tsglobalFilterskeys; the walk now returns 14 on this page) andsubCaptionis retired in 17.7. A dated note each; the inline maps are left in place (adopting the new keys is its own card).Untouched on purpose:
engines.protocol: '^17'andobjectstack.manifest.jsonspecVersion: ^17.0.0(17.7.0 still implements protocol 17 —os doctor: Declared engines.protocol covers the installed platform), thepeerDependencyRulesblock (still true on 1.7.3 — see Install), and every governed file.Gates — on
56c7501, exit codes captured to a file before any pipeRun through this container's shared verify lock. For comparison,
main@14c899f(17.4.0): validate 44 rules ✓, lint21 warning(s), 5 suggestion(s), typecheck ✓, i18n gate ✓. The 21field-no-consumerswarnings are gone on 17.7 because 17.5 (c3a95d9) credits a field placed on the synthesized layout by its declared field group — every field here declares agroup. The 6 suggestions are the approval-approver advisories (one new onmanager_review, which names/api/v1/auth/admin/set-user-manager).os migrate meta --from 1756c7501scaleon 6 currency fields, all insrc/objects/schemaValid: true)page-header-breadcrumb-removed(applied) + 37flow-decision-mode-inclusive-explicitflow-decision-mode-inclusive-explicit— declined, each reviewedThe 37 decision offers. 17.5 made an edge-branched
decisiontake its first matching branch;migrate metaoffersmode: 'inclusive'to preserve the old every-true-branch behaviour. I dumped all 37 from the artifact with their out-edge conditions: every one is written as an explicit partition —Cbeside!C, or disjoint conjunctions (decision_rung2's four legal × finance cells,decision_party_given's resolved / inline / ask,decision_executed_file's four arms endingRvsX || !R). First-match and every-true-branch therefore take the same single edge in every state, so none needs the key — applying them blindly would makeos validatereportflow-decision-inclusive-overlapon all 37 (the checklist's own warning).Per-release checklist tables
DB (a) = fresh
.objectstack/databooted by 17.7. DB (b) = in-place: a database created bymain(17.4.0,pnpm demo+ the README operator setup), copied before the bump, then migrated and booted by 17.7. Every line marked not exercised on the release pages is recorded here with what it cost on this app.17.5.0
OS_PLATFORM_OWNER_EMAILTenancy: single; nogroup/isolatedposture authoredbound=False — disabled by deployment policy; see the decision section. Not decided in the diffos doctor✓ Package-authored scheduled work OFF (the default); with the variable set:ON — packaged time-triggered flows … are armedos migrate account-issuersys_account: 11 row(s) scanned, 11 distinct (provider_id, account_id) key(s). No key is held by more than one row — sys_account.issuer is safe to drop.apiflowconfig.secrettype: 'api'0 hits;/automation/_statuslists noapitrigger@better-auth/*to exactly 1.7.3;zod≥ 4.6.1 if pinnedzodnot pinned by usmigrate meta: this runtime implements protocol 17sys_accountdrop withos migrate apply --allow-destructive, then account-issuer expecting zeroapply --allow-destructive --yes→0 destructive,issuerstill present; account-issuer again → same safe to drop … run apply --allow-destructive; 17.7 boot logs[schema-drift] sys_account.issuer … orphaned — "os migrate apply --allow-destructive" to drop it. Harmless here (nullable; new accounts storeissuer NULLand sign in). Reported belowmode: 'inclusive';migrate meta --storedfor stored decisions--stored(DB b): Examined 0 stored metadata row(s)os compilebefore serving cubes--compile; no hand-written cubes; 19 analytics calls across 3 dashboards all200defineStack(...)export default defineStack({ … })checkdefaults tousingrls-predicate-*findings; all 8 policies areusing-only. 17.5's check defaults to using measured on both versions: identical results (admin403on anin_reviewcontract, legal owner200) — see Out of scopetype: 'page',undoable)page.assignedProfileswait, decision branchexpression/label, builtin keys,connector_action, region bodies)wait/connector nodes; validate passes at parse andregisterFlow(boot registered all 12)lookupscreen fieldreferencelookupscreen field (the twotype: 'lookup'hits are dataset dimensions)chartConfigstructure onto the widgetchartConfighits are comments; dashboards draw (browser)scaleon currency fields …)scalekeys deleted (d633b33); every other key listed: 0 hitsmanifest.idreverse-domain, no underscoresapp.objectstack.hotclmdateRangepreset dashboardsdateRangeauthored (3 hits are comments);compareTotile rendersApproved This Month 1 · 89% vs last monthNOT NULLfromrequiredalone; no column retypedclm_contract.amountfloaton 17.4-created, in-place and fresh DBs;planned_amountkeepsnotnull=1(authoredstorage.notNull)clm_*columnSqlDriver(better-sqlite3)file DBunbuildable_indexinos migrate plan0 change(s): 0 safe, 0 needs-confirm, 0 destructive, 1 additive column onsys_migrationkeyPrefixsys_notification_deliveryretention/dataanswers per caller: requester 43 / 43, counsel 120 / 120, admin 120 / 120401fromclient.auth.me()ctx.engine.findenvelopefindOne/update/ hook return shapestsc --noEmitexit 0beforeUpdatereading areadonlyfield fromctx.input.datainput[key] !== undefined ? input[key] : previous[key](contract.hook.ts:196,:375,:609), so a stripped key falls back to the stored value; the state machine ranin_review → in_approval → approvedin the browserregisterHookon find-one/count/aggregate eventsowner_iddiffers — see Boot)tsc --noEmitexit 0/diff,/history,/audit,/layersGET /api/v1/automation, export jobs,client.reports,spec/cloud,api-assembled,CONCURRENT_LIMIT_EXCEEDED)spec,/automation,/data,/identity,/security,/system,/uionlyenableOnInstall: trueconfirm17.6.0
authRequired: false)fallbackPermissionSet: nullembeddersobjectstack dev; every account holds a setmanage_platform_settingsfor datasource metadata/automation/_status12 flowsdatetimebefore year 1000datetimecolumnmode: 'local'besidesyncUrlpnpm update honoif a scanner flags the older copyhono@4.13.7remains under@objectstack/cli → @objectstack/mcp → @modelcontextprotocol/sdk(pnpm why); this repo runs no scanner, so not runmigrate meta --from 17, then--stored --apply--from 17: breadcrumb applied, 37 offers declined;--storedDB (b): 0 rows, so no--applymigrate audit-metadata-bodies, then--applysys_audit_log: 0 scanned, 0 to rewrite·sys_activity: 0 scanned·Nothing to rewritesql/ dataset memberfieldmust be a column; deleterefreshKeyrefreshKey0triggers/syncConfig/fieldMappingsdiv,requires,endpoint, subform columns,grouping,publicPicker,breadcrumb)breadcrumbdeleted (1 site); the rest 0 hitsField.selectpass validateos validate --strictfails on dead keys--strict; measured anyway: it fails only on the 7 existing advisories, noliveness-dead-property/unconsumed-widget-optiontimedefaults as a bare wall clocktimefields''/[]pending_archivefiltersarchive_no is_empty(text): 114 NULL, 0''in both DBs;legal_intakefilters a lookup200--visibility privateonos plugin publishinvalid_dateoverride needs_rangesiblingsstatus: 'obsolete'; subflows; flows named_…_(_daily-sweep.tsis a builder file); no subflowshttpnodesigningSecrethttpnodesstrictReadonlyWritesformula valuesspec/migrationsimports,--clone-from,os dev --no-watch,nextUtcCalendarDaydata.record.*events17.7.0
scaleis a key);migrate planDB (b) lists no orphaned app columnsys_metadatasharing.enabled: trueon public formsApprovalNodeConfigSchema; deprecated approver type over a position name{ type: 'position', value }and{ type: 'manager' };contract_approvalbound=True; one ladder step driven end to end (browser)sys_approval_request: 0 rows (the seed opens none — README says so)v2:ciphertext)LocalCryptoProvider; the app sets and rotates no secretmigrate meta --from 17,--stored --apply(agent lifecycle,heading/subheading,resizableColumns,sortField, pagerequires, widgetsubCaption)subCaptionhits are comments (corrected in56c7501);--storedDB (b): 0 rowsaudit-metadata-bodies(content hash)sys_flow_credentialsys_automation_runabsent before 17.7)os secret rewrap(optional)objectstack startselectwith no options, agent memory,requireson non-html page, joined reports, pie/donut/funnel with dimension and ≥ 2 values,subCaption, cube metric types,'*', hook bodies, approval configs)resultDialogkeys, JSON cube members,record:related_listaction ids, html literals)component-props-*advisories;resizable;sortField;element:textvariantglobalActions→objects._actionsformformViews, no.editreference404 RECORD_NOT_FOUNDfrom by-id writes on unreadable rows403, identical on 17.4)organization_idof another org on createinList(status)andowner == current_user.idSECRET_MASKacted_as;{{ body }}in approval templates409 METADATA_CONFLICTtokenX-Share-PasswordCORSisolated+ scheduled work:organizationon packaged jobsdefineJobos dev -a/--artifact/OS_ARTIFACT_PATHpnpm dev/demo.mjsuseobjectstack dev --compileonlyos package installhook / job bodiesICryptoProvider.keyedDigestcheckDashboardWidget…,AIChatWindowProps,StateMachineSchema)tscexit 0; installedspec-changes.jsonrelease 17.6.0 → 17.7.0: 50 added, 15 removed, 0 converted, 0 migratedorganizationId; new account signs in)sourceFieldMetafor a hand-builtAnalyticsServiceAuth — the fixture, measured both ways
better-auth+ 10@better-auth/*at 1.7.2WARN [auth] dev admin seed skipped: Unknown field 'issuer' on object 'sys_account'POST /api/v1/auth/sign-in/emailINVALID_EMAIL_OR_PASSWORD(sign-up 403, self-registration closed)GET /api/v1/auth/get-session200admin/create-user200; the new account signs in 200Keeping the fixture would have shipped an app no one can log into on a fresh database.
Install
pnpm installprinted no peer-dependency warning. BecausepeerDependencyRulessuppresses some, I resolved the same manifest twice in a scratch copy, with and without the block: without it pnpm reports exactly the five the block documents, now on 1.7.3 (four@better-auth/utils@0.4.2peers given 0.5.0, onebetter-sqlite3@^12given 13.0.3), and the two lockfiles are byte-identical. The block's comment still holds, so it stays.Boot-log diff against
main— same seed, clean.objectstack/data, read at seeder quiescenceBoth boots:
pnpm demoon an empty database, row counts perclm_*table polled every 5 s until 6 identical reads and 90 s of log silence (a 20 s window was too short: the background seed paused at 520 rows for ~30 s before resuming).main@14c899f(17.4.0)d1551a2)"inserted":820,"errored":404,"referencesDropped":0owner_id: NULL on all 820 rows on 17.4, the dev admin on all 820 on 17.7 (17.5/17.7 seed-settle claim; README procedure still hands contracts over 43 / 43 / 34)MigrationRecovery,PackageServicePlugin,TelemetryDatasource)12 flow(s) 9 bound12 flow(s) 3 bound— six schedule flows NOT bound — disabled by deployment policySystem started with degraded capabilities/ plugin failed to load[sql-driver] DATABASE_ERROR(_objectstack_sequences) andsys_oauth_resourceUNIQUE[Analytics] No admitObjectRead configured … at init,OAuth is served UNENCRYPTED(dev http), and the 6 scheduled-flow noticesThe new
[Analytics] … will NOT enforce the OBJECT-LEVEL read grantwarning is an init-order notice, not a leak: measured per caller above (#30 of 17.5).In-place upgrade — DB (b)
os migrate account-issuer→ clean ·os migrate plan→ 0 changes ·os migrate apply --allow-destructive --yes→ 1 additive column, 0 destructive ·os migrate meta --stored→ 0 rows ·os migrate audit-metadata-bodies→ 0 rows · thenpnpm devon 17.7:Server is ready, 41 plugins, 820clm_*rows intact, existing accounts sign in, new accounts can be created. First in-place boot additionally logs fivesys_permission_set … drifted from its metadata definition — re-projected(the shipped sets) and three[schema-drift]orphans (sys_account.issuer, its unique index, onesys_job_queueindex).Browser — Chromium at
/opt/pw-browsers/chromium-1194/chrome-linux/chrome, noplaywright install17.7.0 on
pnpm demo(fresh DB, README operator setup, re-run to hand rows over), driven with Playwright./_console/login/_console/apps/clm/clm_contract/view/my_contractsActive 18,Approved 2,Draft 2, …), amounts139,500.009, panel9 total · 9 notifications · 0 pending approvals, rows Instalment 2 overdue: Independent Contractor Agreement — Marcus Lindgren … — after one manual run of each job (scheduled work is off; see below)clm_admin)Send for Approvalwas correctly refused twice by the app's own gates (1 deviation(s) are still open…, thenAn approved legal review is required…); on a contract with neither:POST /api/v1/actions/clm_contract/send_for_approval → 200, request atmanager_reviewwaiting on the requester's manager; GM opened Waiting on Me, Approve → Confirm:POST /api/v1/approvals/requests/…/approve → 200, contractapprovedwithapproved_atstamped, and BR1 notified Contract approved: …Accept-Language: zh-CN)lang=zh-CN; nav 我的合同 / 法务工作台 / 管理层看板 / 财务看板; list and dashboard labels Chinese; record header still interpolates (ICA-2026-0001); the intake wizard now reads 发起合同 · 合同信息 · 标题 · 我方签约主体 … with Chinese placeholdersConsole / network, every pass: no page errors. Recurring and pre-existing: a
401onget-sessionbefore sign-in, an abortedorganization/list(the startup race PR #37 recorded), and for non-admin accounts403 PERMISSION_DENIEDonsys_activity,sys_comment,sys_attachmentandsys_approval_request(Discussion reads You don't have permission…). Those four 403s are identical on 17.4 — measured by bootingmainover the same database and replaying the calls — so they are not this bump's.Scheduled work — the decision this PR leaves open
Readings. On 17.7 the six daily jobs (F3, F4, F10–F13) register but do not arm:
bound=False — disabled by deployment policy,os doctorOFF (the default). They still run when triggered —POST /api/v1/automation/NAME/triggeranswered200for all six with the switch off and wrote 45 inbox rows across six recipients — so the reminder layer itself works; only the clock is off. WithOS_AUTOMATION_SCHEDULED_WORK_ENABLED=truethe same database binds 9 of 12 flows (17.4's count) and boot diagnostics drop from 9 warnings to 2.os devloads.env.development*(dotenv-flow), but.gitignoreexcludes.envand.env.*;os startdoes not read the development files.Why it is a choice, not a mechanical setting. The platform flipped the default deliberately (a clock-driven workload's cost is a fact about the deployment, not about the flow); these jobs mutate data at 06:00 / 07:00 UTC (mark overdue, expire contracts, draft renewals — PR #42 noted a re-run of
pnpm demothen drops two rows); and every mechanism touches run instructions or repo config.pnpm devandpnpm demopnpm demoonly.env.developmentplus a.gitignoreexception (or a wrapper script fordev)scripts/demo.mjspasses the variable to the demo boot; README note for deploymentspnpm devkeeps the six notices; two local commands differFour axes:
pnpm devis deliberately empty: the jobs have nothing to sweep there..env.development(A) is a place an agent later drops a secret..gitignoreexception.Recommendation: C, plus a README sentence for deployments. It restores the M3 showcase exactly as 17.4 ran it, keeps policy out of git, and leaves
pnpm dev— empty, nothing to remind about — on the platform default, whose notices are accurate there. B is coherent if the maintainer prefers zero repo policy. AGENTS.md's boot-warning rule is governed prose; listed below.#31's unlock probe on 17.7.0 — report only
Recipe from #80: a scratch
probe31_cycledataset withavgoversubmitted_at/activated_atand aderived: { op: 'difference' }. Never committed.pnpm validate0, renderspnpm validate1 andpnpm build1:measure-aggregate-field-type-refusedon both measures — applies aggregate "avg" to field "submitted_at", which object "clm_contract" declares asdatetime.pnpm typecheck0PUT /api/v1/meta/dataset/probe31_cycle→ 422INVALID_METADATA; nothing stored (GET→ 404)200,-0.8555…POST /api/v1/analytics/queryavg oversubmitted_at→ 400INVALID_FIELD…so the query was NOT run-0.86Outcome: it errors. #31's criterion 「本仓升到含该修复的版本后那条错路确实报错」 reads as met on 17.7.0. The metric itself is still uncomputable (refuse, not provide).⚠️ The first author-time run did not reach the question — it was refused on a new required dataset
label(datasets.4.label: Invalid input); I recorded it as a non-measurement and re-ran with onlylabel: 'Probe 31'added. Tree restored both times and proved by state:git status --porcelainempty,git diff HEAD0 bytes,git hash-object src/datasets/index.ts=git rev-parse HEAD:src/datasets/index.ts=14ce0601805306c73537a3b724ece7451ea7b67f, probe file absent.Platform findings — for the seat to file upstream (not patched here)
os migrate account-issuer/ the boot's[schema-drift]prescribe a command that cannot dropsys_account.issuer. 17.7.0, SQLite DB created by 17.4.0, app withrequires: ['auth'].os migrate plan/applycompose 0 plugins and examine 20 tables;sys_accountis reported only as an undeclared platform table.os migrate apply --allow-destructive --yes→0 destructive; the column stays;account-issuerand the next boot both prescribe the same command again. Harmless on SQLite here (nullable, NULLs pass the unique index), but the 17.5 checklist's expect zero never arrives.flowstranslation face has no key for a screen'sdescriptionor a screen field's select options. 17.7.0 zh-CN intake wizard: heading, labels and placeholders translate; the body text and options (Head office,USD — US Dollar) stay English. The schema's own guidance saysdescriptionis out of the face.pages.NAME.title/.subtitleholding only{contract_number}/{title}count as missing until a bundle repeats them verbatim.Acceptance notes
AGENTS.md:62cites the fixture inpnpm-workspace.yaml, which no longer exists.AGENTS.md:97andDESIGN.md§03 (line 98) require every number to declare its decimals; 17.5 refusesscaleon a currency field (decimals follow the currency).AGENTS.md's a boot that logs warnings is not a passing boot now meets six by-design scheduled-work notices on every default boot (see the decision). PR The two surfaces that merely restate the gate set should namepnpm verifyinstead of enumerating it — a restatement of a definition cannot be allowed to drift #81 holdsAGENTS.md.docs/backlog/02-contract-domain.mdand03-post-signature-domain.mdsay currency, scale 2.pageSizeand now page at 50 instead of 25 (ruled platform default); platformowner_idon seeded rows the fixture does not deal (obligations, instalments, …) is the dev admin instead of NULL.pages.NAME.components.ID.*on slotted pages anddashboards.NAME.globalFilters.*could replace the 22 inline{ en, 'zh-CN' }labels on the record page and the inline filter copy on the three dashboards.clm_adminholder cannot edit a contract pastsubmitted(PATCH /api/v1/data/clm_contract/ID→403), because every position also bindsclm_requester, whose using-onlycontract_requester_edit_windowis the only applicable update policy — while README saysclm_adminholds full reach over every CLM object. Also the foursys_*403s for non-admins listed under Browser.scripts/check-lint-i18n-gate.mjs's REACH list has noflowclass, so a regression that stops walking flows would not fail REACH (COVERAGE still counts them). Not changed: bump only.🤖 Generated with Claude Code
https://claude.ai/code/session_01HihZ11bQSqjCgjzHbpv4M1
Generated by Claude Code