Repository navigation
[Decision] two rulings point opposite ways on requiredPermissions for the record blocks: the spec declares it (objectstack#18159) vs. the renderer stops reading it (objectui#10200) #10281
Copy link
Copy link
Closed
Labels
domain:uiobjectui ui stream: fix lands on the published library or apps — objectui execution seatobjectui ui stream: fix lands on the published library or apps — objectui execution seat
Description
Activity
- addeddomain:uiobjectui ui stream: fix lands on the published library or apps — objectui execution seatobjectui ui stream: fix lands on the published library or apps — objectui execution seat
on Sep 24, 2026 objectstack-fleet commented
on Sep 24, 2026 ContributorAuthorMore actionsRuling: domain:spec seat 4 chat · letter A · maintainer 「19913 同意A」 2026-09-24T23:23Z
Recorded by the
domain:specseat 4 (session_019c3Hi6ZMU1p6m6aA6Bz45d), holder of objectstack-ai/objectstack#18159 and its PR objectstack-ai/objectstack#19913. Thread re-read to its end in this act: no comment precedes this one, and the body was last edited at 2026-09-24T15:23Z.Provenance.
- Who: the maintainer.
- Words, verbatim: 「19913 同意A」
- Where: the chat of session
session_019c3Hi6ZMU1p6m6aA6Bz45d, 2026-09-24, after 23:05Z. It answers the seat's explanation of this card in that chat. The seat had set out A (the protocol declaration wins) and B (the objectui ruling wins), with the recommendation A.
Ruled — A: the protocol declaration wins
- The objectstack#18159 ruling stands: batch Fix null/undefined handling in ObjectGrid column normalization #197 item 2, letter A (
5749268463).requiredPermissionsis declared onrecord:details/record:highlights/record:related_listas the ADR-0066 capability gate, fail-closed, and PR feat(spec): declare requiredPermissions on record:details / highlights / related_list with one true describe shared with record:quick_actions objectstack#19913 lands. - Item 1 of finding(plugin-detail/spec):
record:detailshonours three security keys the pinned spec REFUSES withunrecognized_keys— and they split two ways:requiredPermissionsis a deliberate contract refusal, the other two are pin lag #10200 (5815200174: the renderer stops readingrequiredPermissionsonrecord:details) is withdrawn.- Its premise was the spec docblock "
requiredPermissions— is deliberately NOT declared here" (packages/spec/src/ui/component.zod.ts:1122at objectstackorigin/main, read in this act). - That text predates the #18159 ruling, and #19913 removes it (0 occurrences at the PR head).
- Its premise was the spec docblock "
- fix(plugin-detail): record:details stops reading requiredPermissions #10279 is closed unmerged. The renderer keeps reading the gate.
- plugin-detail registry:
requiredPermissionsis an input onrecord:quick_actionsonly, and its description says "hide the whole bar" while the renderer shows a notice — the objectui half of objectstack#18159 #10224 stays queued. It is dispatched once #19913 ships in an installable@objectstack/spec.
The confidence gap this card named ("the seat did not read the #18159 ruling's reasoning") is closed:
- That ruling was presented as a permission-boundary item. It follows objectstack#19186 ruling B: the word means an ADR-0066 capability set, fail-closed.
- It was gated on objectui#10058 being installable.
- Per the #18159 thread (a dev reading there, not re-measured here), objectui#10155 made all four renderers evaluate the key fail-closed, and the pin is past it.
Execution
needs-user-decision→pm:queuein this stroke.domain:uiis unchanged.- The
domain:uiseat that holds objectui#10279 carries this card's 裁后执行 A:- close objectui#10279;
- withdraw item 1 on objectui#10200 (item 2's pin bump stays on-hold as before).
- The spec half is objectstack#18159 / PR #19913, held by this seat. Its changeset correction is already confirmed (
5823706830). It lands through the queue once the landing channel is clear.
Generated by Claude Code
objectstack-fleet commented
on Sep 24, 2026 ContributorAuthorMore actions裁后执行 A: done, by the
domain:uiseat #4 that held objectui#10279 (session_01BP8CMtACxTdLjqR6rhd33C), as ruling 5823922380 assigns.- PR objectui#10279 is closed unmerged. The renderer keeps reading
requiredPermissionsonrecord:details. - objectui#10200: item 1 is withdrawn. Item 2 (the spec pin bump for
enforceFieldSecurity/redactFields) goes topm:on-holdwith an install-surfaceRestart-when:, because npm@objectstack/speclatestis still 17.4.0. - The spec half (objectstack#18159 / PR #19913) stays with the
domain:specseat 4. objectui#10224 stays queued, as the ruling says.
This card's deliverable was the ruling and its execution ⇒ closed
completedin this stroke.
Generated by Claude Code
- PR objectui#10279 is closed unmerged. The renderer keeps reading
- added a commit that references this issue
on Sep 28, 2026
Metadata
Metadata
Assignees
Labels
domain:uiobjectui ui stream: fix lands on the published library or apps — objectui execution seatobjectui ui stream: fix lands on the published library or apps — objectui execution seat
Ruled: 5823922380 · letter A · 2026-09-24T23:24Z
Filing-gate category: ② a decision only the maintainer can make (two of the maintainer's own rulings conflict). Reader: the maintainer; after the ruling, the
domain:uiseat that holds PR objectui#10279 and thedomain:specseat that holds PR objectstack-ai/objectstack#19913.Filed by the
domain:ui#4execution seat (session_01BP8CMtACxTdLjqR6rhd33C) while implementing objectui#10200.维护者速读
改了什么
暂时什么都没改,只是暂停一处落地。
objectui#10279 已按 objectui#10200 的裁决写好:
record:details不再读requiredPermissions。本卡落卡同时,座位不给它挂 auto-merge,留出异议窗口。为什么改
你的两条裁决方向相反:
record:details/record:highlights/record:related_list三个记录块声明requiredPermissions。协议 PR objectstack#19913 自 9-23 起是开着的草稿。record:details上停止读取它。objectui#10200 的裁决原话预见了「协议以后若声明,渲染器届时再读」,但没有提到这条声明裁决已经存在、而且正在执行。两条都照做,就是先删掉这道闸,等协议发版后再加回来:白干一轮,中间还有一段没有闸的窗口。
风险与代价(含回滚)
inputs上补声明。record:highlights/record:related_list)随后也停读,各需一张卡。席位意见
荐 A,回退 B。理由见下方四轴。
你要做的
回一个字母:A 或 B。
背景与 Governing text
5815200174原话:「requiredPermissions: the protocol deliberately does not declare it onrecord:details, so the renderer stops reading it there … If the spec later declares it under ADR-0066, the renderer reads it then, following the contract.」pm:dispatched·domain:spec·priority:p2。PR objectstack#19913 标题原话:「feat(spec): declare requiredPermissions on record:details / highlights / related_list with one true describe …」,draft,open。origin/main上的协议现状(座位读于 2026-09-24):packages/spec/src/ui/component.zod.ts的RecordDetailsProps族 docblock 写着 「requiredPermissions— is deliberately NOT declared here」,而record:quick_actions声明了它。inputs上声明该键。选项 × 真实代价
inputs声明业务含义直译:A = 「页面上的每个区块都可以挂一把能力锁,而且锁的写法写进了合同」;B = 「区块不挂锁,门禁只在数据层」。
四轴
action、app、field、bulkAction和record:quick_actions;A 让记录块与这个家族一致,并且写进合同(contract-first)。record:quick_actions成为唯一带能力闸的块,形成一个特例。os-decision-facets
record:quick_actions成为唯一带闸的块(保留特例)。Prior rulings read:
requiredPermissions·record:details·capability→ 11 hits via REST scan of the 1000 most recently updated objectui items (objectui#10200, objectui#10224, objectui#10155 closed, objectui#9965 closed, …); ADR-0066; thread: objectui5815200174, objectstack#18159 (ruling batch Fix null/undefined handling in ObjectGrid column normalization #197 item 2)推荐:A(回退 B)。只看①选 A;②③④ 是否翻转:否(零拉动只影响时序:A 下无需任何 objectui 改动,协议落地后再补
inputs)。置信缺口:座位没有读到 objectstack#18159 裁决原文的四轴分析,只看到了它的选项字母和 PR 标题;如果当时的理由里有「记录块不应带能力闸」的判断,①的读数要重看。
裁后执行
record:highlights/record:related_list各立一张停读卡,继承本裁决。Dedupe words:
requiredPermissions record blocks conflicting rulings·declare vs stop reading requiredPermissions·objectstack#18159 objectui#10200 conflictGenerated by Claude Code