Skip to content

Commit 676d44d

Browse files
committed
chore(spec): changeset + regenerated artifacts for the field-security pair
`gen:api-surface-declarations` and `gen:docs`, as `check:generated` proved stale; `authorable-surface/ui.json` is the build's own regeneration. Six additions in the authorable surface and nothing else — the two keys on the three record blocks. The changeset is `minor` and carries `Clause-②: yes (widening)`: the three keys were refused at parse before this change, so declaring two of them widens the accept set on a published authoring surface. Claude-Session: https://claude.ai/code/session_01JbZnqu8bt6YqfJsr9vaFb3 Co-authored-by: Claude <noreply@anthropic.com>
1 parent 1a0bc61 commit 676d44d

4 files changed

Lines changed: 41 additions & 0 deletions

File tree

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
---
2+
"@objectstack/spec": minor
3+
---
4+
5+
`record:details`, `record:highlights` and `record:related_list` accept `enforceFieldSecurity` and `redactFields` — the two field-security keys objectui's detail renderers have been honouring on documents this contract refused by name (#18159).
6+
7+
Clause-②: yes (widening)
8+
9+
All three blocks are `strictObject`s that declared neither key, while `@object-ui/plugin-detail` reads both off each of the three. An author who wrote either was refused at publish, and the same document was honoured on the raw-node path — a contract that could not be satisfied by writing it down. Both keys are declared here, optional, with no schema default, so an absent key stays absent rather than becoming "the author asked for off".
10+
11+
- **`enforceFieldSecurity`** (boolean) folds the block's field list — the detail body's fields and sections, the highlight chips, the related list's `columns` — through the caller's field-read permissions before rendering, so a field the permission set denies leaves no empty row behind.
12+
- **`redactFields`** (string array) drops the names it lists outright. On `record:related_list` it also reaches the columns the list derives for itself when none are authored.
13+
- **The claim is held to what the render path does.** Both are presentation filters, applied in the browser after the record is fetched: the values are in the page either way, so neither is a data-access control and neither is the object's `publicSharing.redactFields`, which removes them server-side. Each `describe()` says that in the text an author reads, rather than leaving the key names to imply it (Prime Directive #10). The gates that do keep a value from a caller are the field's own `requiredPermissions` / `maskingRule` (ADR-0066 D3) and the permission set.
14+
- **⚠️ On `record:details`, `redactFields` neighbours the already-declared `hideFields`** and on a well-formed field list the two remove the same rows: `hideFields` is the dedupe channel the renderer also writes to (live `record:highlights` registrations, the page-title field), `redactFields` is the author's deliberate omission and the arm that participates in the renderer's fail-closed fold. Converging them is a contract question this change did not open.
15+
- **⚠️ The third key the same three renderers read — `requiredPermissions` — is deliberately NOT declared**, and stays refused by name on all three. Its read is `perms.can(objectName, name)`, whose second parameter is this package's own closed `PermissionActionSchema` enum, not the ADR-0066 capability set that name means on `action`, `app`, `field` and `bulkAction`. Measured on both shipped permission providers: under the backend-backed one an unmapped name falls through to the object's `allowRead` bit, so a capability the caller does not hold passes for every reader; under the role-based one the same name is denied for everyone whenever the object carries a permission config. Declaring it would mint the ADR-0049 fail-open access gate retired from `app.areas[].requiredPermissions` in 17.0.0. The exit is a ruling, not an omission.
16+
17+
⚠️ **Not measured here**: the runtime behaviour of either declared key in a browser, and whether any authored document anywhere writes them. "The schema refused it" is not "nobody writes it"; only the first is measured.

‎content/docs/references/ui/component.mdx‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1091,6 +1091,8 @@ View filter rule
10911091
| **hideFields** | `string[]` | optional | Field names to omit from the body — applied to `fields` and to every section's `fields` (used to dedupe fields already shown in `record:highlights` or as the page title) |
10921092
| **inlineEdit** | `boolean` | optional | Allow inline field editing in the detail body (renderer default: on, where the object itself is editable — set `false` to force it off). |
10931093
| **showHeader** | `boolean` | optional | Render the detail body's own heading (renderer default: off). |
1094+
| **enforceFieldSecurity** | `boolean` | optional | Fold this block's field list through the caller's FIELD-read permissions before rendering, so a field the permission set denies leaves no empty row behind (renderer default: off). Presentation only: it re-applies the same field-read answer the server already enforced (ADR-0066 D3) and never widens access — with it off a denied field still arrives masked or stripped, and with it on the server still decides every value. |
1095+
| **redactFields** | `string[]` | optional | Field names this block never renders, whatever the permission answer (renderer default: render everything authored). Presentation only, evaluated in the browser after the record is fetched — the values are still in the page, so this is NOT a data-access control and NOT the object's `publicSharing.redactFields`, which removes them server-side. To keep a value from the caller, gate the field itself (`requiredPermissions` / `maskingRule`, ADR-0066 D3) or the permission set. Neighbours `hideFields`, which is the dedupe channel the renderer also writes to. |
10941096
| **aria** | `{ ariaLabel?: string \| Record<string, string>; ariaDescribedBy?: string; role?: string }` | optional | ARIA accessibility attributes |
10951097

10961098
### Nested Shape: `RecordDetailsProps.sections[number]`
@@ -1159,6 +1161,8 @@ Type: `string`
11591161
| :--- | :--- | :--- | :--- |
11601162
| **fields** | `(string \| { name: string; label?: string; type?: string; readonly?: boolean })[]` | ✅ | Key fields to highlight (1-7 fields max, typically displayed as prominent cards). Each item may be a bare field name or `{name, label?, type?, readonly?}` for inline overrides. |
11611163
| **layout** | `Enum<'horizontal' \| 'vertical'>` | optional (default: `"horizontal"`) | Layout orientation for highlight fields |
1164+
| **enforceFieldSecurity** | `boolean` | optional | Fold this block's highlight chips through the caller's FIELD-read permissions before rendering, so a field the permission set denies leaves no empty chip behind (renderer default: off). Presentation only: it re-applies the same field-read answer the server already enforced (ADR-0066 D3) and never widens access — the record is fetched either way and the server still decides every value. |
1165+
| **redactFields** | `string[]` | optional | Field names this block never renders as a chip, whatever the permission answer (renderer default: render every field authored). Presentation only, evaluated in the browser after the record is fetched — the values are still in the page, so this is NOT a data-access control and NOT the object's `publicSharing.redactFields`, which removes them server-side. To keep a value from the caller, gate the field itself (`requiredPermissions` / `maskingRule`, ADR-0066 D3) or the permission set. |
11621166
| **aria** | `{ ariaLabel?: string \| Record<string, string>; ariaDescribedBy?: string; role?: string }` | optional | ARIA accessibility attributes |
11631167

11641168
### Nested Shape: `RecordHighlightsProps.fields[number]`
@@ -1279,6 +1283,8 @@ Type: `string`
12791283
| **showViewAll** | `boolean` | optional (default: `true`) | Show "View All" link to see all related records |
12801284
| **actions** | `string[]` | optional | Action IDs available for related records |
12811285
| **add** | `{ picker: object; linkField?: string; label?: string \| Record<string, string> }` | optional | Add-existing-via-picker config (generic m2m/junction assignment). |
1286+
| **enforceFieldSecurity** | `boolean` | optional | Fold this list's `columns` through the caller's FIELD-read permissions on the RELATED object before rendering (renderer default: off). Presentation only: it re-applies the same field-read answer the server already enforced (ADR-0066 D3) and never widens access — the rows are fetched either way and the server still decides every value. |
1287+
| **redactFields** | `string[]` | optional | Field names this list never renders, whatever the permission answer (renderer default: render every column authored or derived). Applies to the authored `columns` AND to the columns the list derives for itself when none are authored. Presentation only, evaluated in the browser after the rows are fetched — the values are still in the page, so this is NOT a data-access control and NOT the object's `publicSharing.redactFields`, which removes them server-side. To keep a value from the caller, gate the field itself (`requiredPermissions` / `maskingRule`, ADR-0066 D3) or the permission set. |
12821288
| **aria** | `{ ariaLabel?: string \| Record<string, string>; ariaDescribedBy?: string; role?: string }` | optional | ARIA accessibility attributes |
12831289

12841290
### Nested Shape: `RecordRelatedListProps.filter[number]`

‎packages/spec/api-surface-declarations/ui.txt‎

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3073,6 +3073,8 @@ declare const ComponentPropsMap: {
30733073
hideFields: z.ZodOptional<z.ZodArray<z.ZodString>>;
30743074
inlineEdit: z.ZodOptional<z.ZodBoolean>;
30753075
showHeader: z.ZodOptional<z.ZodBoolean>;
3076+
enforceFieldSecurity: z.ZodOptional<z.ZodBoolean>;
3077+
redactFields: z.ZodOptional<z.ZodArray<z.ZodString>>;
30763078
aria: z.ZodOptional<z.ZodObject<{
30773079
ariaLabel: z.ZodOptional<z.ZodUnion<readonly [z.ZodString, z.ZodType<Record<string, string> & {
30783080
key?: never;
@@ -3192,6 +3194,8 @@ declare const ComponentPropsMap: {
31923194
defaultValue?: never;
31933195
}>>]>>;
31943196
}, z.core.$strict>>;
3197+
enforceFieldSecurity: z.ZodOptional<z.ZodBoolean>;
3198+
redactFields: z.ZodOptional<z.ZodArray<z.ZodString>>;
31953199
aria: z.ZodOptional<z.ZodObject<{
31963200
ariaLabel: z.ZodOptional<z.ZodUnion<readonly [z.ZodString, z.ZodType<Record<string, string> & {
31973201
key?: never;
@@ -3221,6 +3225,8 @@ declare const ComponentPropsMap: {
32213225
vertical: "vertical";
32223226
horizontal: "horizontal";
32233227
}>>;
3228+
enforceFieldSecurity: z.ZodOptional<z.ZodBoolean>;
3229+
redactFields: z.ZodOptional<z.ZodArray<z.ZodString>>;
32243230
aria: z.ZodOptional<z.ZodObject<{
32253231
ariaLabel: z.ZodOptional<z.ZodUnion<readonly [z.ZodString, z.ZodType<Record<string, string> & {
32263232
key?: never;
@@ -18753,6 +18759,8 @@ declare const RecordDetailsProps: z.ZodObject<{
1875318759
hideFields: z.ZodOptional<z.ZodArray<z.ZodString>>;
1875418760
inlineEdit: z.ZodOptional<z.ZodBoolean>;
1875518761
showHeader: z.ZodOptional<z.ZodBoolean>;
18762+
enforceFieldSecurity: z.ZodOptional<z.ZodBoolean>;
18763+
redactFields: z.ZodOptional<z.ZodArray<z.ZodString>>;
1875618764
aria: z.ZodOptional<z.ZodObject<{
1875718765
ariaLabel: z.ZodOptional<z.ZodUnion<readonly [z.ZodString, z.ZodType<Record<string, string> & {
1875818766
key?: never;
@@ -18795,6 +18803,8 @@ declare const RecordHighlightsProps: z.ZodObject<{
1879518803
vertical: "vertical";
1879618804
horizontal: "horizontal";
1879718805
}>>;
18806+
enforceFieldSecurity: z.ZodOptional<z.ZodBoolean>;
18807+
redactFields: z.ZodOptional<z.ZodArray<z.ZodString>>;
1879818808
aria: z.ZodOptional<z.ZodObject<{
1879918809
ariaLabel: z.ZodOptional<z.ZodUnion<readonly [z.ZodString, z.ZodType<Record<string, string> & {
1880018810
key?: never;
@@ -19023,6 +19033,8 @@ declare const RecordRelatedListProps: z.ZodObject<{
1902319033
defaultValue?: never;
1902419034
}>>]>>;
1902519035
}, z.core.$strict>>;
19036+
enforceFieldSecurity: z.ZodOptional<z.ZodBoolean>;
19037+
redactFields: z.ZodOptional<z.ZodArray<z.ZodString>>;
1902619038
aria: z.ZodOptional<z.ZodObject<{
1902719039
ariaLabel: z.ZodOptional<z.ZodUnion<readonly [z.ZodString, z.ZodType<Record<string, string> & {
1902819040
key?: never;

‎packages/spec/authorable-surface/ui.json‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1039,15 +1039,19 @@
10391039
"ui/RecordChatterProps:width",
10401040
"ui/RecordDetailsProps:aria",
10411041
"ui/RecordDetailsProps:columns",
1042+
"ui/RecordDetailsProps:enforceFieldSecurity",
10421043
"ui/RecordDetailsProps:fields",
10431044
"ui/RecordDetailsProps:hideFields",
10441045
"ui/RecordDetailsProps:inlineEdit",
10451046
"ui/RecordDetailsProps:layout [RETIRED]",
1047+
"ui/RecordDetailsProps:redactFields",
10461048
"ui/RecordDetailsProps:sections",
10471049
"ui/RecordDetailsProps:showHeader",
10481050
"ui/RecordHighlightsProps:aria",
1051+
"ui/RecordHighlightsProps:enforceFieldSecurity",
10491052
"ui/RecordHighlightsProps:fields",
10501053
"ui/RecordHighlightsProps:layout",
1054+
"ui/RecordHighlightsProps:redactFields",
10511055
"ui/RecordHistoryProps:emptyText",
10521056
"ui/RecordHistoryProps:limit",
10531057
"ui/RecordHistoryProps:unknownUserText",
@@ -1067,9 +1071,11 @@
10671071
"ui/RecordRelatedListProps:add",
10681072
"ui/RecordRelatedListProps:aria",
10691073
"ui/RecordRelatedListProps:columns",
1074+
"ui/RecordRelatedListProps:enforceFieldSecurity",
10701075
"ui/RecordRelatedListProps:filter",
10711076
"ui/RecordRelatedListProps:limit",
10721077
"ui/RecordRelatedListProps:objectName",
1078+
"ui/RecordRelatedListProps:redactFields",
10731079
"ui/RecordRelatedListProps:relationshipField",
10741080
"ui/RecordRelatedListProps:relationshipValueField",
10751081
"ui/RecordRelatedListProps:showViewAll",

0 commit comments

Comments
 (0)