Repository navigation
v17: retire the overloaded managedBy: 'system' bucket — move the 8 admin/user-writable objects to a dedicated bucket #3355
Description
Activity
裁决(维护者 2026-08-02 委托,按四轴评估:长远合理性 / 防 AI 静默犯错 / 实际业务 / 不扩边界):选项 1 —— 新增
platform-data枚举值,退役system。- 长远:
config语义不匹配——sys_user_preference是用户自有数据而非 admin-authored,且config抑制 CSV 导入。留一个语义含混的桶,是给未来每个新对象的归类制造二义。 - 防 AI 犯错:枚举值语义精确、affordance 默认清晰,作者(尤其 AI)才能选对;闭合 union 移除
'system'让存量声明在编译期就红,不会静默 fall through 到platform。 - 边界:这不是新功能,是完成 v16 已出货的 split 的收尾;一个枚举值 + 一行默认,不扩大产品面。
附带决策(正文标 TBD 的 affordance 默认):
platform-data默认可写(create/edit/delete: true),与桶名语义一致,8 个对象大多可删掉重复的userActions;需要更窄的用userActions收窄。授权继续由 DelegatedAdminGate / RLS / permission sets 承担,不变。v17 内落地,blast radius 按正文 framework/objectui 清单执行。
Generated by Claude Code
- 长远:
裁决修订(2026-08-02,维护者质询后,替代上一条评论的命名部分):新值定名
system-data,不用platform-data。维护者点名了上一条裁决的一个真实缺陷:枚举里已经有
platform(用户业务数据、完整 CRUD、且是缺省值,object.zod.ts:849/CRUD_AFFORDANCE_DEFAULTS),再添一个语义不相干的platform-data是在同一个闭合枚举里制造相邻混淆——恰恰违反「防 AI 作者犯错」这条权重最高的评估轴。且这 8 个对象全部在sys_*命名空间,桶名归入 "system" 词族与命名现实一致。system-data语义定义- schema 归系统:平台/插件定义、随版本演进,租户不可改 —— 与
platform(租户业务建模)的分界; - 数据归 admin/用户:经治理路径写入,authz = DelegatedAdminGate / RLS / permission sets,不变 —— 与
engine-owned(数据也归引擎、零用户写)的分界; - 默认 affordance 可写(create/edit/delete/import/exportCsv: true),8 个对象大多可删掉重复的
userActions;需更窄用userActions收窄(RBAC 关联表等的实际写入权仍由授权层把守,affordance 只是 UI 呈现)。
收官叙事:v16 把过载的
system拆出engine-owned(加法);v17 把剩余一半改名system-data、退役裸system(减法,major)。因 v16 已抽干引擎侧,存量'system'→'system-data'是一对一机械替换——升级处方零判断成本,suggestKey别名表加system → system-data,报错即给出正确拼法。考虑并放弃的备选
platform-data(上条裁决)—— 与既有platform相邻混淆,否;- 复用
config—— 语义错位 + 抑制 CSV 导入(上条评论已述),否; - 保留
system仅改文档(零破坏)—— 名不副实继续教坏作者,"system vs engine-owned" 的选择歧义留存,且 ADR-0103 附录已把退役记为 v17 目标,错过要等 v18,否。
其余(blast radius 清单、跨仓拆分、v17 major 窗口)维持上一条裁决不变。
Generated by Claude Code
- schema 归系统:平台/插件定义、随版本演进,租户不可改 —— 与
🔒 CLAIM — pm-dispatch round 8(v17 协议优先批)
branch:claude/issue-3355-retire-managedby-system
worktree:objectstack-issue-3355维护者已指示 v17 发布在即、协议变更类优先。本条是 ADR-0103 附录白纸黑字记为 v17-only 的 breaking 改名(把 8 个可写平台对象移出语义被掏空的
managedBy: 'system'),错过这个 major 窗口就要再等一个大版本,故排在 v17 协议清单首位。
Generated by Claude Code
- added 8 commits that reference this issue
on Aug 2, 2026 - added a commit that references this issue
on Aug 2, 2026
Deferred breaking cleanup from the ADR-0103 addendum (v16 enum split, merged in #3352 / objectui#2739). Not urgent — this is a v17 major-only change.
Background
ADR-0103 (v16) split the overloaded
managedBy: 'system'bucket additively: the 20 engine-owned objects moved to the new explicitengine-ownedvalue, while the 8 admin/user-writable objects keptmanagedBy: 'system'— which now means "engine-managed schema, writable viauserActions". That leavessystemas a residual, still-overloaded value: its name says "system" but it now specifically labels writable platform DATA.The addendum recorded the end state as a v17 change:
Scope — the 8 objects still on
managedBy: 'system'All declare
userActions: { create: true, edit: true, delete: true }(or a subset). Authz is theDelegatedAdminGate/ RLS / permission sets — theuserActionsis an affordance declaration only.sys_user_preferenceplatform-objects/identitysys_approval_delegationplugin-approvalssys_user_positionplugin-securitysys_position_permission_setplugin-securitysys_user_permission_setplugin-securitysys_notification_subscriptionservice-messagingsys_notification_templateservice-messagingsys_notification_preferenceservice-messagingThe design decision (resolve first)
What bucket do these move to? Two candidates:
platform-datavalue — "platform-defined schema holding admin/user-writable data; authz via delegated administration / RLS." Cleanest fit; keeps them distinct from admin-authoredconfigand from user-ownedplatform. The affordance default would be writable (create/edit/delete: true, so most drop theiruserActions), or stay locked-by-default withuserActions— TBD.config— reuse the existing admin-authored bucket. Simpler (no new value) but semantically loose: several of these are user-owned (sys_user_preference) or governed by delegated admin / RLS, not "admin authored," andconfigsuppresses CSV import which some may want.Recommend option 1 (a dedicated value) unless the affordance semantics of
configprove an exact match.Blast radius (mirrors the v16 split)
CRUD_AFFORDANCE_DEFAULTS(packages/spec/src/data/object.zod.ts); remove'system'and its default row; guard sets (ENGINE_OWNED_BUCKETS,GUARDED_WRITE_BUCKETS) if the new bucket needs listing; the 8 object declarations; tests; ADR update;objects.mdx+ regenerated references.ManagedByBucketunion +MANAGED_BY_BUCKETS(@object-ui/types);resolveCrudAffordancesDEFAULTS (@object-ui/core);ManagedByBadgevariant +resolveManagedByEmptyState(@object-ui/app-shell).Why v17 (breaking)
system) — any downstream app or package declaringmanagedBy: 'system'becomes invalid (a type error against the closed union, and unknown at runtime →platformfallthrough).Not in scope / already handled
resolveCrudAffordances+ the engine write guard drive the policy off resolved affordances, not the bucket literal (verified: no code branches on=== 'system'). This is purely a taxonomy/self-documentation cleanup.userActionsde-dup are done (feat(spec): explicitengine-ownedmanagedBy bucket (ADR-0103 addendum, #3343) #3352, objectui#2739, objectui#2724).Related
#3343 (parent tracking issue) · #3352 · objectui#2739 · objectui#2724 · ADR-0103 (+ its v16 addendum)