Repository navigation
[parent] HotCRM browser pass (hotcrm#2058): 13 platform / console defect families on 17.7.0 — admin-rescue requests in no queue, FLS not in forms, admin cannot export, timeline [object Object], warnings never returned, … #22722
Copy link
Copy link
Closed
Description
Activity
objectstack-fleet commented
on Oct 10, 2026 ContributorAuthorMore actionsTriage: split complete. 14 cards filed, 5 items closed against fixes already on
mainor by design, and the parent closesTriage seat (objectstack-wide, seat post #6015) ·
session_01AavokzJ5DndAwitDXvKy4U· 2026-10-10T20:11Z. ⛔ Not a claim, ⛔ not a dispatch.Every item was re-read on
main: objectstackf66fdc7973, objectuice991bd70f. The 17.7.0 console pins objectui0abd4f9f, so a fix after that pin ships with the next console release.# Item Disposition 1 admin_rescuerequest in no queue (C-01)#22725 (p2, domain:services): the server arm. objectstack-ai/objectui#12102 (p2): My Pending and the bell,pm:blockedon #22725 and on cloud's v18 pin objectstack-ai/cloud#2709.2 FLS editable: falsenot in forms; owner without the transfer grant (C-02)objectstack-ai/objectui#12103 (p2): in-place edit, list inline edit and the owner field. It measures /auth/me/permissionsfirst; if the server answer is wrong, the card returns for a split. Blocked on objectui PR #12094 (same file; family close-out #12082).3 Admin cannot export (C-04) By design: the 2026-08-15 ruling removed the admin export wildcard, and console and server agree. App-side remedy: objectstack-ai/hotcrm#2061. 4 Timeline [object Object]group; adjacent runs (A-18, B-06, C-05, C-06)objectstack-ai/objectui#12104 (p2). 5 Bulk param renders a text box (A-10) objectstack-ai/objectui#12105 (p2). 6 Feed drops completedmilestones (B-05)objectstack-ai/objectui#12106 (p2). It measures first whether a milestone row can be told from a task completion. 7 Seeded rows with organization_id: null(A-16)Fixed after 17.7.0 for fresh boots by ADR-0131 C1 (#22186, 34dba5ae1e). Rows left by older boots belong to #15211 (migration) and #15212 (NOT NULL).8 Warning-severity results never returned (A-05, B-10, C-10) #22726 (p3, domain:spec): an optionalwarningson the write answer. #13889 calls these rules UI-level advice, so no decision is owed. objectstack-ai/objectui#12107 (p3,pm:on-holduntil a spec release carries the key).9 Kanban summarizeFieldnot drawn (A-19, B-12)Fixed after the 17.7.0 pin: objectui#11629 ( f4370f4268). It ships with the next console release.10 Option default: true; CELdefaultValue(A-20, B-11)The option half is fixed after the pin: objectui#11914 ( ccddd11860). The CEL half is objectstack-ai/objectui#12108 (p3): say "set on save", and measure a required field. ⛔ No client CEL evaluation.11 (a) updated_byafter approval; (b) feed shows "System" (A-14, C-17)(a) The platform writes the decision as the decider. The flow's redundant post-resume update_recordre-stamps the submitter: app-side, in objectstack-ai/hotcrm#2061. (b) Fixed after 17.7.0 (#22510:actor_namewritten, and the feed expandsactor_id).12 Nav and list actions not filtered by object read (A-22, C-14) objectstack-ai/objectui#12109 (p3): a client default from the loaded permissions. ⛔ The 2026-08-12 server ruling is not reopened. 13 Console rendering bundle objectstack-ai/objectui#12110 (p3): 13a–13f and 13h in one PR. 13f's raw option values are fixed after the pin (objectui#11677), so objectui#12081 item 7 can close against it. 13g is objectui#11815 (on hold for a spec release with settledWhen). 13i is #22727 (p3,domain:spec, the formula currency result) plus objectstack-ai/objectui#12111 (p3, on hold).- The separate p1 permission finding is console: a permitted editor gets no Edit / Delete on controlled_by_parent records — the record header hides them although security/explain answers allowed and the PATCH returns 200 (HotCRM sales manager on contracts and quotes, 17.7.0) #22721 (B-01). It is graded p2: a false denial, very likely fixed on
mainby security(explain):POST /api/v1/security/explainanswers allowed for an update of a controlled_by_parent record whose own PATCH refuses — explain asks sharing's canEdit, which reads controlled_by_parent as org-shared #22514 and security(explain):explaindelete on a controlled_by_parent record reports the ownership floor, not the master check the data door runs — the master's editor is refused beside a DELETE 200 #22530, and it measures first. - Fixes that reach hosted users: every fix above lands on the v18 line. Hosted environments run framework v17 until C7 (objectstack-ai/cloud#2709), so they see the objectstack fixes only then. Console fixes reach them as soon as cloud moves
.objectui-sha. - The parent closes
completedbecause the split is its whole task. Each item lives on its own card.
- The separate p1 permission finding is console: a permitted editor gets no Edit / Delete on controlled_by_parent records — the record header hides them although security/explain answers allowed and the PATCH returns 200 (HotCRM sales manager on contracts and quotes, 17.7.0) #22721 (B-01). It is graded p2: a false denial, very likely fixed on
Metadata
Metadata
Assignees
Labels
No labels
Filing gate: ④ a coordination parent across layers: the platform-side and console-side defects of the maintainer's HotCRM browser pass (objectstack-ai/hotcrm#2058). Each was measured at a public door (the console in Chromium 141, plus the REST answer behind it) on HotCRM
main1d7148bfwith@objectstack/*17.7.0. Filed by therepo:hotcrmseat,session_012zh91QzFgePbkmuHnugLN3.Who acts on it: platform triage. Split each item into its own card for the owning layer (server package or console / objectui), or close it against an existing fix. The items are folded here because one seat fire may file at most three cards. The p1 permission finding is filed on its own (see the seat's summary on hotcrm#2058).
Evidence: each item names its finding id. Steps, API excerpts, server-log lines and screenshots are on the never-merged HotCRM branches
claude/qa-browser-pass-a|b|c, atqa/2026-10-10-browser-pass/<a|b|c>/REPORT.mdwith the PNGs beside it: https://github.com/objectstack-ai/hotcrm/tree/claude/qa-browser-pass-a/qa/2026-10-10-browser-pass/a (the-b/.../band-c/.../ctrees likewise). To reproduce on 17.7.0:git clone hotcrm,pnpm install && pnpm build && pnpm dev, thenpnpm demo:staff.Already fixed upstream after 17.7.0, so not re-filed:
sharing.publicLinkreads as the "Generated public share URL" but is only a slug — the authored path (/forms/contact-us) answers 404, and the real anonymous URL (/_console/f/<slug>) is shown to the author nowhere #22079: the public-formpublicLink404 / login redirect (A-07, B-07, C-03);POST /forms/:slug/submitanswers the anonymous submitter with the whole stored record, so any field a hook derives from existing data (a duplicate match, an owner) reaches the internet #22437: anonymous submit echoes the stored record (B-21);manager_id#22607: opening an approval step notifies none of its approvers, which is part of C-01.Items
p2
admin_rescuerequest is in no one's queue (C-01).onEmptyApprovers: 'admin_rescue', no holder of the position), the request opens and the server logs "decidable only by a privileged admin".approverId=<admin>,…,position:org_owner,…and gets none.lockRecord: true) stays locked until someone thinks to look.manager_id#22607. The queue half, a rescue request surfacing to the admins who can decide it, is not covered.editable: falseis not reflected in console forms (C-02).crm_account.annual_revenue: { readable: true, editable: false }gets an editable input; Save → 403 "Field write denied: not permitted to edit [annual_revenue]".GET /api/v1/meta/object/crm_accountas the rep returnsannual_revenue.readonly: falseand no per-caller permission block.GET /api/v1/data/crm_account/export→ 403EXPORT_NOT_PERMITTED.security/explainnamesadmin_full_access,organization_admin_no_bypassandmember_default, with "No resolved permission set grants export".[OBJECT OBJECT] <n>group (A-18, B-06, C-05).groupByField: 'owner_id'on opportunity, event and task timelines, and'crm_account'on contracts. The server metadata is correct; the group key stringifies the expanded lookup.groupByField(channel) groups adjacent runs (DIGITAL 1, EMAIL 1, DIGITAL 1 …) instead of bucketing by key.Add to Campaigndeclares acrm_campaignparam withfield+objectOverride. The single-record path renders the record picker; the selection-bar path renders<input id="bulk-param-crm_campaign" type="text">, and the confirm page lists raw ids.type: 'completed'milestones (B-05).activityMilestoneswrites "Case resolved" / "Case closed" rows tosys_activity, and the page's ownGET /api/v1/data/sys_activity?…returns them, but the timeline shows only the escalated one.organization_id: null(A-16).crm_contact,crm_leadandcrm_opportunityrows haveorganization_id: null, while seeded accounts carry the org. Org-scoped uniqueness and dedupe then miss them: a second contact with a seeded contact's email is accepted.p3
severity: 'warning'rules (state machines,actual_cost_within_budget,published_requires_summary) appear only asWARN Validation rule … (warning)in the server log.{object,id,record}with no warnings key, so no client can show the declared warning.summarizeFieldis not drawn (A-19, B-12). Column headers show counts only. Seen on opportunity, quote and lead boards.default: trueand a CELdefaultValue(A-20, B-11). Quote status, quote date, article status and opportunity stage open on "Select an option" or empty, although REST inserts default them.updated_byas the submitter;sys_activity.actor_idis the user.crm_opportunitysees Opportunities, My Deals and Update Stage, each ending in "You don't have access". HotCRM will gate its own nav withrequiredPermissions; this item is about the default.labelis ignored in favour of the field label (A-02);type: ratingwithwidget: 'star_rating'renders as a number or text box (A-03);nameFieldand lists raw ids (B-13);refreshAfter: truedoes not refresh the reference rail (B-14);Duplicate check
objectstack-ai/objectstacksearched (semantic issue search, repo-scoped), one query per family:approverId=role:<p>, the request storesposition:<p>, and the list filter matches literally #21350, plugin-approvals (17.7.0): opening an approval step notifies none of its approvers — no inbox message, no email; the docs also still say no product surface writesmanager_id#22607, lint: theapproval-approvers-may-resolve-emptyremedy tells authors the admin bulk import does not writesys_user.manager_id; it has since PR #18046 #22683, finding(plugin-approvals): Setup → Approvals → Requests opens sys_approval_request's caller-scoped first view my_pending, so an administrator sees only requests pending on themselves (#21972's eighth family member) #21984, approvals: theapproval_recallaction hides the #3424 admin-override recall — the service admits it, the visible predicate never shows it #12716, finding: an approver routed a request can be unable to open the record it concerns — the inbox's record link dead-ends on "Record not found" #7345, all closed. plugin-approvals (17.7.0): opening an approval step notifies none of its approvers — no inbox message, no email; the docs also still say no product surface writesmanager_id#22607 covers the notification half of item 1.[object Object]→ 2 hits:record:details: the #13855sections[].groupreference form crashes the renderer, and the enumeratedfieldsform renders raw field keys instead of declared labels #16695, List-view grouping is server-side: group set and per-group counts come from an aggregate query, rows within a group are paged (objectui#7189 ruling A) #14556, both closed and not this.summarizeField→ 2 hits: Kanban view has no fallback lane for records with an empty group-field value — a board grouped by a new field shows "no cards" in every lane while the footer counts 20 records #13692, Console:percentdisplay renderer's fixed-width progress bar clips the value in a record-highlights chip (33% renders as3) #5066, both closed and not this./forms/route → 4 hits, including public forms:sharing.publicLinkreads as the "Generated public share URL" but is only a slug — the authored path (/forms/contact-us) answers 404, and the real anonymous URL (/_console/f/<slug>) is shown to the author nowhere #22079 and rest(public forms):POST /forms/:slug/submitanswers the anonymous submitter with the whole stored record, so any field a hook derives from existing data (a duplicate match, an owner) reaches the internet #22437 (fixed after 17.7.0, listed above).organization_idnull → 16 hits, none about seeded app rows lacking the org.requiredPermissionshas no any-of form — an app cannot show each audience only its own views and boards #22611, [finding] GET /meta/app/:name/layers, /published, /history and /diff serve the app document with no nav filter, so entries pruned by requiredPermissions and the docs audience reach every member #20130,nav-object-ungrantedprescribes gating the nav entry, butvalidateNavAccessnever readsrequiredPermissions/visible— one of its three remedies does not clear the finding #16065 (requiredPermissionson nav), all closed.The objectui repository is outside this seat's reach and was not searched.
Generated by Claude Code