Skip to content

[parent] HotCRM browser pass (hotcrm#2058): 13 platform / console defect families on 17.7.0 — admin-rescue requests in no queue, FLS not in forms, admin cannot export, timeline [object Object], warnings never returned, … #22722

Description

@objectstack-fleet

Filing gate: ④ a coordination parent across layers: the platform-side and console-side defects of the maintainer's HotCRM browser pass (objectstack-ai/hotcrm#2058). Each was measured at a public door (the console in Chromium 141, plus the REST answer behind it) on HotCRM main 1d7148bf with @objectstack/* 17.7.0. Filed by the repo:hotcrm seat, session_012zh91QzFgePbkmuHnugLN3.

Who acts on it: platform triage. Split each item into its own card for the owning layer (server package or console / objectui), or close it against an existing fix. The items are folded here because one seat fire may file at most three cards. The p1 permission finding is filed on its own (see the seat's summary on hotcrm#2058).

Evidence: each item names its finding id. Steps, API excerpts, server-log lines and screenshots are on the never-merged HotCRM branches claude/qa-browser-pass-a|b|c, at qa/2026-10-10-browser-pass/<a|b|c>/REPORT.md with the PNGs beside it: https://github.com/objectstack-ai/hotcrm/tree/claude/qa-browser-pass-a/qa/2026-10-10-browser-pass/a (the -b/.../b and -c/.../c trees likewise). To reproduce on 17.7.0: git clone hotcrm, pnpm install && pnpm build && pnpm dev, then pnpm demo:staff.

Already fixed upstream after 17.7.0, so not re-filed:

Items

p2

  1. An admin_rescue request is in no one's queue (C-01).
  2. Field-level editable: false is not reflected in console forms (C-02).
  3. The administrator cannot export (C-04).
  4. A timeline grouped by a lookup renders a single [OBJECT OBJECT] <n> group (A-18, B-06, C-05).
    • Seen in four views: groupByField: 'owner_id' on opportunity, event and task timelines, and 'crm_account' on contracts. The server metadata is correct; the group key stringifies the expanded lookup.
    • Also C-06: a text groupByField (channel) groups adjacent runs (DIGITAL 1, EMAIL 1, DIGITAL 1 …) instead of bucketing by key.
  5. A bulk action's field-backed param renders a raw text box (A-10).
    • Add to Campaign declares a crm_campaign param with field + objectOverride. The single-record path renders the record picker; the selection-bar path renders <input id="bulk-param-crm_campaign" type="text">, and the confirm page lists raw ids.
  6. The record activity feed drops type: 'completed' milestones (B-05).
    • activityMilestones writes "Case resolved" / "Case closed" rows to sys_activity, and the page's own GET /api/v1/data/sys_activity?… returns them, but the timeline shows only the escalated one.
  7. Seeded rows of some objects carry organization_id: null (A-16).
    • On a fresh dev boot, all seeded crm_contact, crm_lead and crm_opportunity rows have organization_id: null, while seeded accounts carry the org. Org-scoped uniqueness and dedupe then miss them: a second contact with a seeded contact's email is accepted.
    • The seed ownership claim stamps owners but not the org on these objects.

p3

  1. Warning-severity validation results are logged and never returned (A-05, B-10, C-10).
    • severity: 'warning' rules (state machines, actual_cost_within_budget, published_requires_summary) appear only as WARN Validation rule … (warning) in the server log.
    • The REST write answers {object,id,record} with no warnings key, so no client can show the declared warning.
  2. Kanban summarizeField is not drawn (A-19, B-12). Column headers show counts only. Seen on opportunity, quote and lead boards.
  3. Forms ignore option-level default: true and a CEL defaultValue (A-20, B-11). Quote status, quote date, article status and opportunity stage open on "Select an option" or empty, although REST inserts default them.
  4. Approval writes and the actor shown in the feed (A-14, C-17):
    • an approval decision leaves updated_by as the submitter;
    • the record activity feed shows "System" for user actions whose sys_activity.actor_id is the user.
  5. Navigation and list actions are not filtered by the caller's object permissions (A-22, C-14). A service agent with no read on crm_opportunity sees Opportunities, My Deals and Update Stage, each ending in "You don't have access". HotCRM will gate its own nav with requiredPermissions; this item is about the default.
  6. Console rendering:
    • a view's explicit column label is ignored in favour of the field label (A-02);
    • type: rating with widget: 'star_rating' renders as a number or text box (A-03);
    • the reference rail ignores nameField and lists raw ids (B-13);
    • refreshAfter: true does not refresh the reference rail (B-14);
    • gantt dates show without the year (B-20);
    • the approval request drawer shows raw option values, a truncated "positi…ager" approver, and a "Child Account Revenue 0" headline (C-18);
    • a completed task's due date shows red "Overdue 3d" (C-19);
    • a public form with no label falls back to the object API name as its heading, and shows the editor hints "Format: markdown" / "Rich text editor (basic)" to visitors (A-09, B-08);
    • formula fields have no currency return type or formatting (B-15).

Duplicate check

objectstack-ai/objectstack searched (semantic issue search, repo-scoped), one query per family:

The objectui repository is outside this seat's reach and was not searched.


Generated by Claude Code

Activity

  1. objectstack-fleet commented on Oct 10, 2026

    @objectstack-fleet
    ContributorAuthor

    Triage: split complete. 14 cards filed, 5 items closed against fixes already on main or by design, and the parent closes

    Triage seat (objectstack-wide, seat post #6015) · session_01AavokzJ5DndAwitDXvKy4U · 2026-10-10T20:11Z. ⛔ Not a claim, ⛔ not a dispatch.

    Every item was re-read on main: objectstack f66fdc7973, objectui ce991bd70f. The 17.7.0 console pins objectui 0abd4f9f, so a fix after that pin ships with the next console release.

    # Item Disposition
    1 admin_rescue request in no queue (C-01) #22725 (p2, domain:services): the server arm. objectstack-ai/objectui#12102 (p2): My Pending and the bell, pm:blocked on #22725 and on cloud's v18 pin objectstack-ai/cloud#2709.
    2 FLS editable: false not in forms; owner without the transfer grant (C-02) objectstack-ai/objectui#12103 (p2): in-place edit, list inline edit and the owner field. It measures /auth/me/permissions first; if the server answer is wrong, the card returns for a split. Blocked on objectui PR #12094 (same file; family close-out #12082).
    3 Admin cannot export (C-04) By design: the 2026-08-15 ruling removed the admin export wildcard, and console and server agree. App-side remedy: objectstack-ai/hotcrm#2061.
    4 Timeline [object Object] group; adjacent runs (A-18, B-06, C-05, C-06) objectstack-ai/objectui#12104 (p2).
    5 Bulk param renders a text box (A-10) objectstack-ai/objectui#12105 (p2).
    6 Feed drops completed milestones (B-05) objectstack-ai/objectui#12106 (p2). It measures first whether a milestone row can be told from a task completion.
    7 Seeded rows with organization_id: null (A-16) Fixed after 17.7.0 for fresh boots by ADR-0131 C1 (#22186, 34dba5ae1e). Rows left by older boots belong to #15211 (migration) and #15212 (NOT NULL).
    8 Warning-severity results never returned (A-05, B-10, C-10) #22726 (p3, domain:spec): an optional warnings on the write answer. #13889 calls these rules UI-level advice, so no decision is owed. objectstack-ai/objectui#12107 (p3, pm:on-hold until a spec release carries the key).
    9 Kanban summarizeField not drawn (A-19, B-12) Fixed after the 17.7.0 pin: objectui#11629 (f4370f4268). It ships with the next console release.
    10 Option default: true; CEL defaultValue (A-20, B-11) The option half is fixed after the pin: objectui#11914 (ccddd11860). The CEL half is objectstack-ai/objectui#12108 (p3): say "set on save", and measure a required field. ⛔ No client CEL evaluation.
    11 (a) updated_by after approval; (b) feed shows "System" (A-14, C-17) (a) The platform writes the decision as the decider. The flow's redundant post-resume update_record re-stamps the submitter: app-side, in objectstack-ai/hotcrm#2061. (b) Fixed after 17.7.0 (#22510: actor_name written, and the feed expands actor_id).
    12 Nav and list actions not filtered by object read (A-22, C-14) objectstack-ai/objectui#12109 (p3): a client default from the loaded permissions. ⛔ The 2026-08-12 server ruling is not reopened.
    13 Console rendering bundle objectstack-ai/objectui#12110 (p3): 13a–13f and 13h in one PR. 13f's raw option values are fixed after the pin (objectui#11677), so objectui#12081 item 7 can close against it. 13g is objectui#11815 (on hold for a spec release with settledWhen). 13i is #22727 (p3, domain:spec, the formula currency result) plus objectstack-ai/objectui#12111 (p3, on hold).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions