Repository navigation
fix(spec): datasource read redaction resolves a driver's identity the way its sibling helper does - #21963
Conversation
… way its sibling helper does The per-driver half of `redactableConfigKeys` now looks a driver up through `resolveDriverId`, the resolver `passthroughSecretPaths` and the write door's contract lookup already use. Every spelling the write door judges against a builtin driver's contract is redacted as that driver, and a crafted driver id answers as a driver with no shipped contract instead of throwing. Claude-Session: https://claude.ai/code/session_01T9u38rswFp5Rw8DswRUReJ Co-authored-by: Claude <noreply@anthropic.com>
… credential migration hold under every accepted spelling of a builtin driver Lockstep pins for the spec redaction fix: the item read withholds the still-writable credential key under each accepted spelling, an untouched Save restores the stored value, a crafted driver id is read with its credentials withheld, and the migration planner reads the same list as under the canonical spelling. No source line in this package moves. Claude-Session: https://claude.ai/code/session_01T9u38rswFp5Rw8DswRUReJ Co-authored-by: Claude <noreply@anthropic.com>
…er identity Claude-Session: https://claude.ai/code/session_01T9u38rswFp5Rw8DswRUReJ Co-authored-by: Claude <noreply@anthropic.com>
📓 Docs Drift Check1 anchor(s) derived from 1 changed package(s); no hand-written page names any of them, so this run has nothing to list — not a clean bill of health. This check sees only pages that NAME a derived anchor: one that documents this change in prose, or enumerates it in an authoring dialect, names none and stays invisible to it on every run. What this run could not see
Coarse fallback — 138 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): Which tree this was computed onThis run read A worktree cut from an older # while this PR is open — GitHub drops the merge commit once it closes
git fetch origin 9c12aae5c41bf6212c21662baad61cf30fc6a747 && git checkout 9c12aae5c41bf6212c21662baad61cf30fc6a747
# afterwards, rebuild it from the two parents, which stay fetchable
git fetch origin 80f9f7e6ba5d2097a4cb32ca696908dcf9678102 cbea11408e36bb46b64f71d04cd367a442ef4777 && git checkout -B drift-repro 80f9f7e6ba5d2097a4cb32ca696908dcf9678102 && git merge --no-ff cbea11408e36bb46b64f71d04cd367a442ef4777
node scripts/docs-audit/affected-docs.mjs --json 80f9f7e6ba5d2097a4cb32ca696908dcf9678102 |
… decision in words instead of a tracker number (stage 25) (objectstack-ai#21975) Part of objectstack-ai#20749 Clause-②: no Stage 25 of this card: the next area of class (e), the test strings shipped under `packages/spec/src`, as ruled in `5902360492` on objectstack-ai#20513. This stage takes the second and last name-ordered `api/` group: the 13 id-bearing test files directly under `packages/spec/src/api/` from `plugin-rest-api.handler-status-retirement.test.ts` to `zod-issues-to-fields.test.ts`. Those files carried 89 messages and 95 tracker ids, citing 43 records. All 95 now either state what their record decided, in words (form D), or are dropped where the title already says it. No needle sits in this group. Text only: no assertion, identifier, test count or code comment changes, and no file is renamed. With this stage, `api/` carries no tracker id in a test string. ## Census at the base (`5a22eb5619`) Instruments: `census10.cjs` (md5 `9d08602ab972b4b8643c90d64d40fa41`), `census.cjs` (md5 `6e42a45a926d375013c32d62f16a296e`), `census-wide.cjs` (md5 `c98410a19529c439adb0afbfb00026a2`) and `dirtable.cjs` (md5 `dda605c54745b4a60cc14c9a686e4eff`), byte-identical to the copies stages 10 to 24 used. A literal counts as a test title when its folded message is argument 0 of a `describe` / `it` / `test` call, `.each` / `.skip` / `.only` chains included. Everything else is an "other" string. The worktree was cut from `origin/main` at `5a22eb5619`, the claim's base and stage 24's landing. Both instruments read **371 messages / 392 ids in 84 files**, the seat's reading and stage 24's head reading. | directory | files | messages / ids | titles | other | |:--|--:|--:|--:|--:| | `system/` | 34 | 154 / 167 | 128 / 138 | 26 / 29 | | (files directly in `src/`) | 30 | 118 / 120 | 117 / 119 | 1 / 1 | | `api/` (this PR: all 13 files) | 13 | 89 / 95 | 86 / 92 | 3 / 3 | | `ui/` | 5 | 7 / 7 | 0 | 7 / 7 | | `ai/` | 1 | 2 / 2 | 0 | 2 / 2 | | `contracts/` | 1 | 1 / 1 | 0 | 1 / 1 | | **total** | **84** | **371 / 392** | **331 / 349** | **40 / 43** | The group reads **89 messages / 95 ids in 13 files**, the seat's figures file for file: | file (under `api/`) | messages / ids | titles | other | |:--|--:|--:|--:| | `plugin-rest-api.handler-status-retirement.test.ts` | 4 / 4 | 3 / 3 | 1 / 1 | | `plugin-rest-api.schema-refs.test.ts` | 2 / 2 | 2 / 2 | 0 | | `plugin-rest-api.test.ts` | 2 / 2 | 2 / 2 | 0 | | `protocol.test.ts` | 46 / 50 | 46 / 50 | 0 | | `registry-retirement.test.ts` | 2 / 2 | 1 / 1 | 1 / 1 | | `rest-api-config-dead-keys-retirement.test.ts` | 2 / 2 | 2 / 2 | 0 | | `rest-server.test.ts` | 19 / 19 | 18 / 18 | 1 / 1 | | `router.test.ts` | 1 / 1 | 1 / 1 | 0 | | `sortability.test.ts` | 3 / 4 | 3 / 4 | 0 | | `storage.test.ts` | 2 / 2 | 2 / 2 | 0 | | `validate-data.test.ts` | 3 / 3 | 3 / 3 | 0 | | `websocket.test.ts` | 1 / 1 | 1 / 1 | 0 | | `zod-issues-to-fields.test.ts` | 2 / 3 | 2 / 3 | 0 | | **13 files** | **89 / 95** | **86 / 92** | **3 / 3** | Five more test files sit in the same name range and carry no id (`query-adapter.test.ts`, `realtime-shared.test.ts`, `realtime.test.ts`, `retired-error-codes.test.ts`, `versioning.test.ts`). The three "other" strings are expect failure messages, rewritten and declared to the text-only tool: `plugin-rest-api.handler-status-retirement.test.ts:179` and `rest-server.test.ts:768` (template literals) and `registry-retirement.test.ts:89` (one leaf of a `+` chain). - **Controls.** Lit: `ui/notification.test.ts` (1 id) and `system/book.test.ts` (2 ids), outside the group, read the same at the base and at the head. Dark: `protocol.test.ts` reads 0 at the head while 65 of its lines still carry a number, every one of them a comment. Planted in a scratch tree: an id put into a `storage.test.ts` title reads 1 / 1 (`title:it`), and an id put into a `sortability.test.ts` comment reads 0. - **A wider pattern** (any `#` plus digits) reads the same as the gate pattern in all 13 files at the base, and 0 in all 13 at the head. - **At the head:** 282 messages / 297 ids in 71 files. The 13 files read 0 / 0, `api/` leaves the table, and no other file moved. ## How the area was chosen `api/` has no subdirectory, so it is taken in name-ordered file groups near the ~100-id bound, the rule stages 20 to 24 used. Stage 24's cut named this group at 95 ids, and this census reads 95, so no re-cut was needed. `protocol.test.ts` (50 ids) fits one PR and one text-only proof, so it is not split. **Named for the next stages** (cut from the head census, 282 / 297): - **`system/`**, 167 ids in 34 files (one of them in `system/constants/`), two stages: - **first group:** `auth-config.test.ts` through `metadata-form-declared-rows.pin.test.ts`, 18 files, 91 messages / 97 ids (`i18n-resolver.test.ts` alone 53 / 56); - **second group:** `metadata-form-zod-reconciliation.test.ts` through `worker.test.ts`, 16 files, 63 / 70. Its first file carries 17 "other" strings, its ledger `why` entries. - The files directly in `src/`, 120, one stage. - The needles: the three docblock needles, the kept `ui/component-props-unknown-members.pin.test.ts:322` and stage 22's two. One stage, with an at-tier review. The four colour literals stay, as stage 21 decided. ## What each id became - **10 literals (11 ids)** now state a decision in words. - **12 literals (16 ids)** get their subject back in words, where the number stood for a thing. - **67 literals (68 ids)** drop a number the title already explains. Every cited record was fetched with all its comments through REST, and its decision was read from its ruling, ACCEPT and landing comments: a keyword digest of every record, and full reads wherever the new words carry a decision. 43 records are cited: 36 answer 200 and 7 answer 404. Two more were read for context: objectstack-ai#14478, whose ruling B objectstack-ai#15677 executes, and PR objectstack-ai#11426, objectstack-ai#11006's landing. The seven that answer 404 were read from what landed, through the commits endpoint (this checkout is shallow), each commit found through the CHANGELOG entry or the commit list of `protocol.test.ts`: - **objectstack-ai#6037**, from `18189983dd` (objectstack-ai#6474): `DataProtocol.validateData` asks the write path for its verdict and persists nothing, objectstack-ai#4633 ruling D; - **objectstack-ai#6239**, from `f549a0d4ad` (objectstack-ai#6526): `ViewProtocol`'s five viewId-addressed methods and ten schemas are retired; - **objectstack-ai#6361**, from `90bbf25107` (objectstack-ai#6866): the notification-list `cursor` is tombstoned on both halves (maintainer ruling 2026-08-07, option A); - **objectstack-ai#9740**, from `11b779e0f9` (objectstack-ai#9773): `MetadataProtocol.getMetaItemLayered` is declared, and the dead `'overlay'` `lockSource` arm is dropped; - **objectstack-ai#9741**, from `2a29caa532` (objectstack-ai#9804): `previewDrafts` / `state` are declared where the implementation enforces them, and `environmentId` is recorded as transport-level. Its changeset (`packages/spec/CHANGELOG.md:31798`) names it "maintainer ruling 2026-08-18", and `cccbe51bf7` cites "the objectstack-ai#9741 ruling"; - **objectstack-ai#11006**, from `cccbe51bf7` (objectstack-ai#11426): `publishMetaItem` is declared as an optional member with `PublishMetaItemRequest` (maintainer ruling 2026-08-22, option B); - **objectstack-ai#14691**, from `b3a63d32c9` (objectstack-ai#14868): the ten inert `RestServerConfig` keys the liveness ledger recorded as `dead` are retired. **The same-id titles stage 24 listed in this group:** - **`[objectstack-ai#5672]` x2** (`protocol.test.ts:508`, `:526`): objectstack-ai#5672's maintainer ruling A (`5199159328`): one closed capability vocabulary, emitted in full by both discovery producers, with an absent capability `enabled: false` rather than a missing key. `:508` now reads "strips a capability key outside the closed vocabulary". The old verb was "rejects", but the body pins the opposite: the parse stays green and the key does not survive it. `:526` now reads "… (ruled: an absent capability is `enabled: false`, not a missing key)". - **`(objectstack-ai#12038)` x5** (`:2575` to `:2686`): these five "declares the … body" describes are the describe-only transcriptions that the five-part ruling's implementation plan names (`5434804846`). None of them pins a lettered sub-ruling, so no letter is named; the title already says the decision, and only the number goes. - **`(objectstack-ai#12038 1C)`** (`:2710`): now "GetPublishedMetaItemResponseSchema stays opaque (ruled: no shape frozen against the current type registry)", ruling 1C's own reason. Its children pin the `unknown` body. - **`(objectstack-ai#19543, door ③)`** (`:2726`): door ③ is the AI-conversation list, which the schema name already names, and "declares the next-page signal" is that door's spec half (letter A, re-derivation `5825819437`). Only the number and the door label go. - **`(objectstack-ai#15677)`** in `plugin-rest-api.test.ts:694` and `websocket.test.ts:712`: now "… durations carry their unit in the key name", objectstack-ai#14478's ruling B (`5518649320`, population ruling `5548763981`), which objectstack-ai#15677 executes for `api/`. In `router.test.ts:565` the title already shows the rename (`RouteDefinition.timeout → timeoutMs`), so only the number goes. **Stated in words:** | record | literal (under `api/`) | now reads | the decision | |:--|:--|:--|:--| | objectstack-ai#14478 via objectstack-ai#15677 | `plugin-rest-api.test.ts:694`, `websocket.test.ts:712` | "… durations carry their unit in the key name" | Ruling B: a `z.number()` duration key carries its unit in its name; the old spellings are `retiredKey()` tombstones. | | objectstack-ai#5672 | `protocol.test.ts:508` | "strips a capability key outside the closed vocabulary" | Ruling A (2026-08-06): one closed vocabulary. | | objectstack-ai#5672 | `protocol.test.ts:526` | "rejects a capability map that is missing part of the vocabulary (ruled: an absent capability is `enabled: false`, not a missing key)" | Ruling A: both producers emit the whole vocabulary. | | objectstack-ai#9406 | `protocol.test.ts:1313` | "probes is opaque BY DECLARATION (ruled: modeled only once a consumer needs a field): …" | Maintainer ruling 2026-08-18 (`5322875103`): `probes` gets a deliberately opaque passthrough, upgraded to a modeled schema only when a consumer needs a field of it. | | objectstack-ai#9343 | `protocol.test.ts:1383` | "PublishPackageDraftsResponseSchema published[].advisories (ruled: advisory findings ride each published element)" | Maintainer ruling 2026-08-17 (`5321046016`): `advisories` rides each `published[]` element, with no parallel top-level map. | | objectstack-ai#9741 | `protocol.test.ts:1739` | "environmentId stays OUT of the meta-read request shape — transport-level by decision, not omission" | The 2026-08-18 ruling, as landed in `2a29caa532`: `environmentId` is the transport-level multi-kernel routing key. | | objectstack-ai#12038 | `protocol.test.ts:2710` | "GetPublishedMetaItemResponseSchema stays opaque (ruled: no shape frozen against the current type registry)" | Ruling 1C (`5434804846`): a thin envelope with the body opaque, no union frozen against today's type registry. | | objectstack-ai#6037 | `validate-data.test.ts:25` | "ValidateDataRequest — asks the write path for its verdict instead of predicting it" | What landed in `18189983dd`: the dry run stops predicting the write's verdict and asks for it. | | objectstack-ai#6037 | `validate-data.test.ts:57` | "ValidateDataResponse — the verdict the write path would reach, persisting nothing" | The same commit: `validateData` reports the write path's verdict on candidate rows and persists nothing. | **Subject back in words** (12 literals): - "zero holders after objectstack-ai#13823" becomes "zero holders after its retirement", and "[objectstack-ai#13823] ADR-0087 registration" becomes "handlerStatus retirement — ADR-0087 registration", the form of the repo's other retirement registration describes (objectstack-ai#13823 ruled remove, `5494755488`); - "the routes wired in objectstack-ai#3899" becomes "the routes wired to the request-schema gate", the gate the file's header names; - "(objectstack-ai#13155 — carries objectstack-ai#5745 to the third verb)" becomes "(carries the declared = returned discipline to the third verb)", the discipline objectstack-ai#7294 and objectstack-ai#13155 name objectstack-ai#5745 for; - "(objectstack-ai#4717 — objectstack-ai#4463 D3 on the response)" and "(objectstack-ai#9176 — objectstack-ai#4463 D3 on the publish door)" become "(advisory findings ride the 2xx response)" and "(advisory findings ride the 2xx on the publish door too)": objectstack-ai#4463's D3 sends gating findings to 422 and lets advisory findings ride the 2xx; - "the objectstack-ai#9612-gate class" becomes "the package-closure publish-gate class": objectstack-ai#9612's gate judges a publish against the written package's closure; - "objectstack-ai#10235 the objectstack-ai#7865 anchor category" becomes "the unprovisioned injected-anchor category", the platform anchors injected into an external object whose storage the platform does not provision (objectstack-ai#7865, ruling B); - the two "pre-objectstack-ai#3689" storage shapes become shapes "from before the shared success envelope"; - "the objectstack-ai#4052 non-repeat" becomes "the non-repeat of the retired `validateOnly` dry-run flag"; - "every objectstack-ai#8055-shaped fixture" becomes "every malformed-flow-body fixture". **Dropped where already stated** (67 literals, 68 ids). A number goes only where the title already says its decision. Examples: the two `[objectstack-ai#13823]` describes and the twelve `[objectstack-ai#14691]` / `(objectstack-ai#14691)` retirement titles ("REJECTS `patterns` with the retirement prescription — …", "the tombstones reject one key each, not the config — …"); `[objectstack-ai#11983]` x3, `[objectstack-ai#4579]` x2, `[objectstack-ai#4939]`, `[objectstack-ai#6361]`, `[objectstack-ai#20294]` and `objectstack-ai#3899 —`; the `objectstack-ai#10235` prefixes on "resolveObjectSortability — the closed category set" and "wire validity — …"; the five "transport-level by the objectstack-ai#9741 ruling" titles, which now read "transport-level by ruling"; the parenthesized `(objectstack-ai#5745 — …)`, `(objectstack-ai#7294 — …)`, `(objectstack-ai#9406 — …)`, `(objectstack-ai#10524 — …)` x2, `(objectstack-ai#9726 — …)`, `(objectstack-ai#9741 — …)` and `(objectstack-ai#4717 — …)` pairs, which keep their words; and the tails `(objectstack-ai#6239)`, `(objectstack-ai#4286)`, `(objectstack-ai#9740)`, `(objectstack-ai#11006)` x2, `(objectstack-ai#11678)` x3, `(objectstack-ai#9426)`, `(objectstack-ai#12005)` x3, `(objectstack-ai#11679)` x2, `(objectstack-ai#12004)` x2, `(objectstack-ai#3718)`, `(objectstack-ai#4572)`, `(objectstack-ai#4579)`, `(objectstack-ai#20294)`, `(objectstack-ai#8124/objectstack-ai#8055)`, the five `(objectstack-ai#12038)` and the `(objectstack-ai#4738, …)` aside in one expect message. The 404 numbers among them (objectstack-ai#6239, objectstack-ai#6361, objectstack-ai#9740, objectstack-ai#9741, objectstack-ai#11006, objectstack-ai#14691) go only where the title already states what landed. **No file is renamed.** ## Readers - **Needles:** none. The three declared strings are assertion failure messages (the second argument of `expect`), none is an expected value, and no title or message in the group is matched against a source docblock or another file's text. The one self-read in the group, `rest-api-config-dead-keys-retirement.test.ts:519`, reads its own file for the id-free describe title "tree-scoped absence", which this PR does not touch. - **Test-name filters:** none. No tracked script, workflow or package config passes `-t` / `--testNamePattern` to vitest; the one vitest `-t` hit is a README example under `packages/qa/dogfood` filtering its own fixture. - **Snapshots:** none. No `__snapshots__` directory is tracked under `packages/spec`, and none of the 13 files calls a snapshot matcher. - **Projects:** `rest-api-config-dead-keys-retirement.test.ts` is in the `repo` project (`packages/spec/vitest.repo-tests.json:31`); the other 12 run in `local`. The base-versus-head run below takes both projects. - **By substring:** every old literal, its id-bearing fragment and a window around each id (270 needles) was searched with `git grep` at the base, across the tracked tree outside its own file. No gate, doc, filter, snapshot, QA checklist entry or `scripts/check-*.mjs` self-test reads one. The 6 hits are sibling test titles: the two `(objectstack-ai#15677)` describes in this group hit each other (both rewritten here), `client/src/client.test.ts:1134` shares "query.distinct (objectstack-ai#4286)", and `metadata-protocol/src/protocol.validate-data.test.ts:102` shares "the objectstack-ai#4052 non-repeat". ## Text-only proof Stage 10's scratch tool (`textonly10.cjs`, md5 `d5e4801dbb4329ab1984da91e92fc47c`) compares base and head file by file on three legs: 1. **Skeleton:** the full AST, with string pieces masked. It must be identical. 2. **Comments:** every comment, byte-equal. 3. **Strings:** each changed string leaf must sit in a test-call title position or on a declared line, must carry a tracker id before, and must carry no `#` plus digits after. This stage declares the three expect-message lines named above. - **Result:** 13 of 13 files SAME on all three legs, with the per-file counts predicted in writing before any edit. - **Totals:** 89 changed string leaves in 89 literals: 86 titles and 3 declared. The diff's `+` and `-` lines are exactly the 89 planned lines as multisets, and every file keeps its line count. - **Controls (14 of 14 as predicted on the first run, on scratch copies, each anchor hit once):** identifier rename DIFF; numeric literal DIFF; comment edit COMMENT DIFF; a non-title string given an id VIOLATION; a rewritten title given a new id VIOLATION; a title that was id-free at base edited VIOLATION; one title reverted to base SAME; an `it.each` row given an id VIOLATION; an undeclared expect message changed VIOLATION; a title re-split into a `+` chain DIFF; a declared expect message reverted to base SAME; a declared template expect message given a new id VIOLATION; a declared `+`-chain leaf given a new id VIOLATION; a template-literal title given a new id VIOLATION. - **Templates and tables:** no `.each` title and no `$name` placeholder changes. The two template literals change only their text after the `${…}` span. **Test counts:** the 13 files were run at the base, in a separate base worktree, and at the head, with `--project local --project repo`. Both sides read 509 tests in 13 files, all passed, with the same count and status sequence per file in 13 of 13. 250 full test names change, and each changed name equals the base name with the planned replacements applied: 0 mismatches. No full name repeats on either side, and no head name carries `#` plus digits (250 base names did). `router.test.ts:565` writes its arrow as a `→` escape; the plan's anchor there starts after the escape, so the comparison tool, which reads escapes literally, met none, and vitest prints "RouteDefinition.timeout → timeoutMs …" on both sides. ## Changeset: `skip-changeset` Measured, not assumed: - `npm pack --dry-run` of `@objectstack/spec` lists 2068 files. 0 of the 13 touched files are in it, and no `*.test.ts` at all. The controls `src/api/protocol.zod.ts`, `src/api/rest-server.zod.ts` and `dist/index.mjs` are in it. - In the built `dist/`, two new phrases and an old one each read in 0 files. The control `Unrecognized key` reads in 42. So this PR publishes nothing, and no changeset is added. ## Verification (at `c63eba0adf`) - `pnpm turbo run build` over all packages: 71 / 71, through the shared verify lock (`VERDICT command-exit 0`). - `@objectstack/spec`: - `vitest run --project local`: 619 files, 18480 passed, 1 todo. - `typecheck`: exit 0, including `check:test-typecheck` (52 files / 246 errors / 135 pinned signatures held). Its program holds all 13 group files, counted by path with `tsc --listFilesOnly -p tsconfig.test.json`. - `check:generated`: all 15 generated artifacts up to date, against the `dist/` the build above wrote. - **Gates:** `dispatch-gates --commands` derived 79 families: stage 24's 80 without `check:error-code-casing`, whose named sources this diff does not touch. All 79 exit 0. `--ran` reconciles: 79 derived, 79 run, 0 NOT-MEASURED, 0 UNRUN, every family with its exit code recorded. The same 79 derive from `origin/main` `230e4944b0` with this diff applied. The five roster families marked as sharing a directory with this diff (`check:meta-url-spelling`, `check:spec-changes`, `check:authz-resolver`, `check:error-code-casing`, `check:filter-alias-parity`) each exit 0. - **ESLint, a proven narrowing:** `--no-inline-config` over the 13 files reads 0 errors and 0 warnings. The population comes from ESLint's own config: 13 configured, 0 ignored. No file sets `parserOptions.project` or `projectService`, so no untouched file's verdict can move. - `check-governed-merges --test`: NOT governed, 178 changed lines (+89 / -89). - A control-byte scan over the 13 changed files finds none. ## `main` since the base Re-fetched just before this PR opened, `origin/main` was six commits past the base (`c9761cd2fb`: objectstack-ai#21966, objectstack-ai#21951, objectstack-ai#21963, objectstack-ai#21969, objectstack-ai#21965, objectstack-ai#21962). They touch 28 files, none of the 13 and none under `packages/spec/src/api/`, so `main` was not merged. The two `packages/spec/src` files they change (`data/datasource-credential-redaction.ts` and its test) read 0 / 0 in the census at `c9761cd2fb`: the one id they add is a code comment. `git merge-tree` onto `c9761cd2fb` is clean, and none of the 4 open PRs touches any of the 13 files. ## Acceptance notes - **Same-id test titles in this card's later stages** go with those stages: `system/book.test.ts:413` (`(objectstack-ai#12038)`). - **Same-id test titles in other packages** stay: 97 lines in 15 packages (`runtime` 25, `objectql` 13, `lint` 12, `metadata-protocol` 12, `rest` 12, `client` 8, `metadata-core` 4, `qa/dogfood` 2, `service-automation` 2, `service-storage` 2, and one each in `examples/app-crm`, `examples/app-showcase`, `driver-sql`, `plugin-sharing` and `types`), each package's share under the objectstack-ai#20513 lane children. - **Code comments with live ids** remain in these files and their sources, among them the `* objectstack-ai#3899 —` header in `plugin-rest-api.schema-refs.test.ts`, the `* objectstack-ai#8124 —` header in `zod-issues-to-fields.test.ts`, the `// [objectstack-ai#5672] This fixture used to lead with …` comment above `protocol.test.ts:508`, and the `/** [objectstack-ai#20294] … */` docblock in `rest-api-config-dead-keys-retirement.test.ts`. Code comments are not this card's share. --- _Generated by [Claude Code](https://claude.ai/code/session_01T9u38rswFp5Rw8DswRUReJ)_ Co-authored-by: Claude <noreply@anthropic.com>
Fixes #21955
Clause-②: no
What changed
The per-driver half of
redactableConfigKeysinpackages/spec/src/data/datasource-credential-redaction.tsnow resolves a driver's identity throughresolveDriverId. That is the resolver its sibling helperpassthroughSecretPathsalready uses, and the one the write door's contract lookup (getDriverConfigSchema) uses. There is no second identity resolver: the fix replaces one lookup line with the sibling's two-line shape.redactedConfigKeysnames it.service-datasourcesource line moves.getDatasource(),restoreRedactedConfigand the credential migration all reach the fix through the spec export (measured below).Measured reach, before the fix (BASE
76fec88b16, spec dist built from BASE)A unit-level harness of
service-datasource'sDatasourceAdminService, with an in-memory record store, ran every spelling the alias table and the resolver's folding accept. The harness is scratch and is not committed.DatasourceSchema.safeParseand bycreateDatasource, and was judged against the builtin contract (validateDriverConfig(...).known === true).getDatasource, behindGET /api/v1/datasources/:name): for each accepted spelling other than the canonical one, the still-writable credential key came back inconfigandredactedConfigKeyswas[]. The canonical spelling withheld it.datasourceredactor, used by the/metaitem and list reads): the same answer as the item read for every spelling.listDatasources): it serves noconfigat all, by its contract (DatasourceSummary), so it carries no exposure for any spelling.getDatasource, the metadata redactor,restoreRedactedConfigandplanCredentialMigrationeach threw an unhandledTypeError. So the item read failed, an edit with a config patch failed, and the migration planner failed.listDatasourceswas unaffected.After the fix, the same harness reads every accepted spelling as withheld and named, and every crafted id as read without a throw.
Exposure stays admin-only: the datasource read doors require the admin capability.
Pins
packages/spec/src/data/datasource-credential-redaction.test.ts, a new block. Every spelling is derived fromDRIVER_ID_ALIASESplus the resolver's own folding (as-is, upper, capitalised, padded), never listed by hand.service-datasource(declared on [PM seat] domain:services — ⏳ vacant #6021):datasource-config-redaction.test.ts: the admin item read withholds the key under each accepted spelling. An untouched Save restores the stored value under each accepted spelling, so redaction never turns a save into deletion. A crafted id is read with its credentials withheld, and an untouched Save keeps them.datasource-credential-migration.test.ts: the planner reads the same list under each accepted spelling. A bindable row names the still-writable key as residue, byte-equal to the canonical spelling's plan. A row holding only that key is refused with it named.Reverse verification (fix committed first, then reverted with
scripts/ablation-replace.mjs, then restored)src, so no build leg applies. Predicted three red, with the premise and the control staying green. ObservedTests 3 failed | 41 passed (44): the byte-equal set, the withheld key, and the crafted id. Restore proof: blobb543590328efequals HEAD, andgit diff HEADis empty.service-datasourcepins. These resolve@objectstack/spec/datathroughdist, so each leg rebuilt spec.ablation-dist-preflightfound the reverted line in 8 built files. Predicted five red. ObservedTests 5 failed | 61 passed (66).--absentreported the marker absent from all 228 built files and the tree clean against HEAD. ThenTests 66 passed (66).Clause-② (measured)
no. The fix narrows what the read path serves, not what@objectstack/specaccepts.DatasourceSchema.safeParsegave the same answer before and after for every spelling and every crafted id in the harness.check:api-surface:public API surface + factory signatures unchanged.check:authorable-surfaceandcheck:export-originsare green.The changeset is
@objectstack/specpatch.service-datasourcetakes none, because no source line in it moved.Tests and gates (at HEAD
cbea11408e)pnpm --filter @objectstack/spec exec vitest run --project local --maxWorkers=2:Test Files 619 passed (619),Tests 18476 passed | 1 todo.pnpm --filter @objectstack/service-datasource exec vitest run --maxWorkers=2:Test Files 41 passed (41),Tests 748 passed (748).@objectstack/metadata-protocol, which reaches the datasource redactor:protocol.metadata-redaction.test.tsandstored-metadata-body-family.pin.test.tsgaveTests 56 passed (56).pnpm --filter @objectstack/service-datasource typecheckandpnpm --filter @objectstack/spec typecheck(includingcheck:test-typecheck) both exit 0.tsc --listFilesconfirms that both editedservice-datasourcetest files are in the program.node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstack: 87 derived, 86 run with exit 0, 1 NOT MEASURED, 0 unrun (--ranreconciliation).pnpm check:dual-build-cjs-loads, reason: PREREQUISITE NOT MET (exit 3). It reads every package's builtdist/, and this worktree built only the closure it needed. Declared to CI..tsfiles. Each resolves to a config undereslint --print-config, so none is ignored.eslint --no-inline-config --format jsonlinted 4 files with 0 errors and 0 warnings.eslint.config.mjsenables no type-aware linting (zeroproject/projectServiceentries, and none in the resolvedparserOptions). So this diff cannot move any untouched file's verdict.pnpm lintstays CI's.origin/mainwas re-fetched before this PR opened (80f9f7e6ba). Nothing that landed since BASE touches these files, so there was no merge.Acceptance notes
STILL_WRITABLE_CREDENTIAL_KEYSandPASSTHROUGH_SECRET_PATHSare typed as string-keyed records. Typing them by the builtin id union would make a raw-string index a compile error, closing this defect class attsc. That is not done here, to keep the fix to the sibling's shape. Carrier: the at-tier contract review of this PR.Generated by Claude Code