Skip to content

ADR-0049 定去留:NotificationActionSchema / EmbedConfigSchema 实测没有授权门(#4001 批 14 改判的两个站点) #5015

Description

@xuyushun441-sys

与 #4988 同类。#4001 批 14 对 ui/ 六个文件逐个做门测量,11 个 strip 站点里 9 个是真门(已收紧)、2 个实测没有门。这两个不收紧 —— 「一个被精确校验的死槽位是更有说服力的谎言」(#4583)—— 但它们需要的判定是 ADR-0049 enforce-or-remove,不是棘轮。

两个站点

schema 文件
NotificationActionSchema packages/spec/src/ui/notification.zod.ts
EmbedConfigSchema packages/spec/src/ui/sharing.zod.ts

注意 sharing.zod.ts 是同文件内劈开的 —— 它的兄弟 SharingConfigSchema 是活门(FormViewSchema.sharing 承载,rest-server.ts 真的读 sharing.allowAnonymous / sharing.publicLink 来挂匿名表单路由,两个示例应用都在写),批 14 已收紧。这是账本第一次遇到一行两判,也是「per SCHEMA, not per file」这句话第一次真正生效。

三条独立测量(2026-08-03,均带阳性对照,同一次运行)

  1. 承载键 —— packages/spec/src 里除 ui/index.ts barrel 外无任何模块 import 这两个模块……
    • ui/notification.zod 的 importer 精确等于 ['ui/index.ts'];
    • ui/sharing.zod 的 importer 是 ['ui/index.ts', 'ui/view.zod.ts'],而 view.zod.ts 点名的是 SharingConfigSchema;全仓没有任何模块提到 EmbedConfigSchema。
    • (匹配器按 specifier 解析而非子串比对 —— 仓里有两个 sharing.zod,子串法会把 stack.zod.ts / security/index.ts 误记为 UI 那个的 importer。这一条是先证红发现的。)
  2. 图可达性 —— 从 24 个 metadata-type root 加 defineStack 的 ObjectStackSchema 做 BFS(build-schemas.ts 给 authorable-surface 的 tombstone 门禁可被手编基线绕过 —— 删掉基线行就删掉了证据(#4638 / #4643 已两次这样过绿) #4650 删除检查用的同一套闭包),6860 个节点,两个都走不到。同一次运行里四个阳性对照 PageSchema / ActionSchema / DashboardWidgetSchema / WebhookSchema 全部 root-graph;注入一个合成承载键后两个都翻成 root-graph。对照通过,所以「不可达」是关于图的事实。
  3. 调用点 —— framework / objectui 里除各自单测外没有任何 .parse()。

一个值得单独记的细节:objectui 消费的是 shape,不是 parse

NotificationActionSchema 并非无人问津 —— objectui 的 animation-notification-spec-parity.test.tsx 读 NotificationActionSchema.shape.variant,双向 pin 它自己手写的 NotificationActionButton 接口。但那是把 schema 当词汇表用,和 posture 完全无关:收紧它不会让那条 pin 更强一分。

这恰好说明「有消费者」不等于「有授权门」,也是这两个站点该走 ADR-0049 而不是走棘轮的原因。

需要的判定

批 14 已在两处 schema 的 JSDoc + 测试 pin + 账本行三处留痕,pin 是会红的:任何人给这两个形状接上承载键,那条断言立刻红并把人指回这里。

未指派。

Activity

  1. xuyushun441-sys commented on Aug 4, 2026

    @xuyushun441-sys
    CollaboratorAuthor

    分诊(PM,2026-08-04):按既定规范直接定退役,T2 档(空位填充,错过 v17 零悔)。同形状本周已三裁全 A(#4988/#4938/#4834——无门死面按 implementation-first 退役),切线规则 T2 明含此类;不再升级,维护者否决窗口有效。执行按 spec-property-retirement 套件,批 14 的 BFS/阳性对照证据(6860 节点、合成承载键翻转验证)即立案依据,dev 复核后照走。


    Generated by Claude Code

  2. self-assigned this
    on Aug 4, 2026
  3. os-zhuang commented on Aug 4, 2026

    @os-zhuang
    Contributor

    认领:PM 循环第 1 轮(spec 车道,维护者已提速至 batch:3,v17 优先)
    会话:session_01ErbEDVAg1No9gdg1pgDAGB
    分支:claude/issue-5015-notification-embed-retirement
    Worktree:objectstack-issue-5015
    域:domain:spec
    文件面:packages/spec/src/ui/notification.zod.ts(候补整文件退役)、packages/spec/src/ui/sharing.zod.ts(⚠️ 仅 EmbedConfigSchema,同文件 SharingConfigSchema 是活门不动)、packages/spec/src/ui/index.ts(barrel)、ADR-0087 conversion registry、spec 生成基线(与同批 #5021/#4938 在生成物上重叠,落地时按 os-regen 四步互保兄弟条目)、strictness 台账、.changeset/*.md

    执行依据:上方分诊裁决(2026-08-04,T2 退役,否决窗口已过)。注意:objectui animation-notification-spec-parity.test.tsx 把 NotificationActionSchema.shape 当词汇表消费,spec 侧摘除后 objectui 刷新依赖时会红 —— objectui 侧适配由 PM 在验收时单独立案挂 objectui 队列,本单 dev 不碰 objectui。


    Generated by Claude Code

  4. os-zhuang commented on Aug 4, 2026

    @os-zhuang
    Contributor

    验收:ACCEPT(PM 复核毕,PR #5300)

    复核依据(GitHub 实据):

    后续:CI 全绿后转 ready 入合并队列;objectui 侧适配单已立(3 个文件受影响,见下),Blocked-by 本 PR。


    Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions