Skip to content

inline-grid-receipt-cells c3: checklist clause predates ADR-0104 (opaque id, not a resolved object) #7669

Description

@huangyiirene

Symptom

The product works correctly: the grid derives one Receipt column with a real input[type=file] (objectui#2360 does not reproduce), picking a file runs a genuine presign → PUT → complete → thumbnail trace, and submit emits one atomic POST /api/v1/batch (atomic:true, {"$ref":0} parent reference), persisting both records. But checklist clause 3 reads partial because it expects a resolved stored-file object carrying receipt.name and an absolute http(s) URL, whereas the shipped payload is the bare opaque sys_file id.

Root cause

Located — checklist-vs-product drift, not a defect. Under ADR-0104 D3 (docs/adr/0104-field-runtime-value-shape-contract.md, "D3 — File-as-reference: field values point into sys_file"), a file field stores an opaque sys_file id as a field-ownership reference. The persisted value is a managed reference ({status:'committed', ref_object:'showcase_invoice_line', ref_id:…, ref_field:'receipt', acl:'private'}), not a data:/blob: placeholder, and is correctly gated (anon 401 / two members 403 / admin 200). storage-routes.ts documents the id as "the value a file field stores as a reference". The clause should be restated against ADR-0104 D3.

Reproduction

Run the inline-grid-receipt-cells item; inspect the submitted receipt value → it is the opaque sys_file id, not a resolved {name, url} object. Clause 3 as written expects the resolved shape and therefore reads partial.

Source

Extracted from the QA run #7635 (framework 92f26f7, console 6314e87f).

Activity

  1. claude commented on Aug 11, 2026

    @claude
    Contributor

    Dual-label resolution (queue+finding): promoted to pm:queue (finding stripped). Checklist restatement with a settled ruling behind it — ADR-0104 D3 ("File-as-reference: field values point into sys_file", docs/adr/0104-field-runtime-value-shape-contract.md:211, verified on origin/main @ 6a9dec6) already decides the stored shape; clause 3 just predates it. Nothing to ask the maintainer; the edit is mechanical. domain:devx stands (docs/qa/platform-checklist).

    本评论来自分诊座位 Routine(#5474 试点),不构成认领。


    Generated by Claude Code

  2. self-assigned this
    on Aug 11, 2026
  3. huangyiirene commented on Aug 11, 2026

    @huangyiirene
    CollaboratorAuthor

    Claim: PM loop round 3 (devx seat, 2026-08-11 term) — wave 3 unit D, packed with #7671 + #7670 (same attachments area file; full claim block on #7671). Branch claude/issue-7671-7669-7670-attachments-checklist; session session_01GZKbx4xyF7U5WXj6ch49BM; mode:cloud, model: opus. This card's half: restate clause 3 against ADR-0104 D3 (opaque sys_file id as the stored reference, correctly gated) — the checklist mirrors the shipped contract, no product change.


    Generated by Claude Code

  4. huangyiirene commented on Aug 11, 2026

    @huangyiirene
    CollaboratorAuthor

    Implemented as part of the packed unit — full os-dev report lives on #7671 (#7671, the os-dev-report comment). Draft PR: #7716, branch claude/issue-7671-7669-7670-attachments-checklist, first lines Fixes #7671 / Fixes #7669 / Fixes #7670.

    This card's half. inline-grid-receipt-cells acceptance clause 3 (0-indexed — the batch-payload clause) restated against ADR-0104 D3. Both citations re-verified at my ref (origin/main 21888ab), not taken from triage:

    • docs/adr/0104-field-runtime-value-shape-contract.md:211-224 — D3 "File-as-reference: field values point into sys_file": the stored form is "an opaque fileId string (array when multiple)"; "the inline {url, name, size} blob is retired from the write path"; the resolved { id, name, size, mimeType, url } FileValueSchema is the expanded form produced at read/expand time, whose url is "derived, never stored".
    • packages/services/service-storage/src/storage-routes.ts:250-252 — the /upload/complete fileId is documented as "the opaque sys_file id — the value a file field stores as a reference (ADR-0104 D3)".

    The old clause demanded a resolved stored-file object with receipt.name and an absolute http(s) URL, i.e. it asserted a contract the ADR had already retired — which is the whole reason run #7635 scored a correct product partial. The clause now asserts the bare opaque id together with the field-ownership stamp (ref_object / ref_id / ref_field / acl) that distinguishes a managed reference from a data:/blob: placeholder — the thing the run actually proved. Title, step text and source follow, and a new negative pins the drift itself so a future run cannot re-score the shipped shape as a defect.

    D3's parent-derived read gating is cross-referenced to download-authz-both-sides (which already carries the non-entitled personas) rather than duplicated here — the same discipline this item already applies to the ADR-0059 form-side guard. The product is correct and unchanged; only the checklist moved.


    Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions