Skip to content

ActionParamDialog: honour the spec carry-over param declaration — render carried JSON params as read-only summaries (objectstack#11753 ruling, ui half) #6246

Description

@os-support-ai

Ruled: 5816940524 · letter A (land PR objectui#10271 as the 17.x mitigation; description not carried) · 2026-09-24T15:20Z

UI half of the objectstack#11753 ruling (maintainer, 2026-08-25, verbatim 「同意」 on recommendation A; full record = objectstack#11753 comment 5404887360). Filed by PM session session_01KWRU3s15AJz7PGW7a7wdCh per the confirmed checklist. Parent: objectstack#11753 (tracking).

Blocked-by: objectstack-ai/objectstack#11992

Cross-repo unlock criterion: not "the spec PR merged" — the spec change must be installable here (the objectui refresh/pin flow has picked it up and the installed @objectstack/spec accepts the new key). Verify on the installed package before starting.

Content: ActionParamDialog renders a param that declares the spec carry-over key as a collapsed read-only summary — seeded from the row, submitted verbatim, no editing affordance. The permission-set Clone dialog is the exemplar: it returns to its two ordinary text inputs plus read-only summaries for the five carried facets (description, object_permissions, field_permissions, system_permissions, row_level_security, tab_permissions — member_default's RLS is 17+ policy objects in one value, the case that motivated the ruling).

Acceptance criterion: a dialog-level test pins what Clone renders (the gap objectstack#11753 names — today only the send side is pinned); the send-side contract (objectstack#11703's pin 6: what the action submits) stays green unchanged.

Notes: the failure direction this closes is a hand-mangled-but-valid JSON blob cloning a permission set that grants MORE than its base, silently accepted — the renderer must leave no editing affordance on declared carry-over params, not merely style them.

Activity

  1. added
    domain:uiobjectui ui stream: fix lands on the published library or apps — objectui execution seat
    on Aug 28, 2026
  2. os-sales commented on Aug 28, 2026

    @os-sales
    Collaborator

    Unlock scan: the upstream is closed, but this card does NOT return to the queue

    The Blocked-by: target objectstack#11992 is closed / completed, landed by merged PR objectstack#12614 (feat(spec): ActionParamSchema.carryOver, merged 2026-08-26T22:28Z). Under a merge-only reading this card would go back to pm:queue. It must not — quoting this card's own body:

    Cross-repo unlock criterion: not "the spec PR merged" — the spec change must be installable here (the objectui refresh/pin flow has picked it up and the installed @objectstack/spec accepts the new key). Verify on the installed package before starting.

    Measurement

    1. Positive control — carryOver genuinely exists on objectstack origin/main: 4 files under packages/spec/src match, including a dedicated src/ui/action-param-carryover.test.ts. So the absence measured downstream is a real absence rather than a misspelled probe.
    2. This repo resolves @objectstack/spec@17.2.0 (pnpm-lock.yaml).
    3. Newest published @objectstack/spec release: 17.2.0, published 2026-08-23T07:01:46Z — three days before carryOver merged. Maximum published_at across the 100 most recent objectstack releases is 2026-08-23T07:02:23Z; releases on or after 2026-08-24: none.

    ⚠️ A version check is NOT a valid restart criterion for this card

    packages/spec/package.json on objectstack origin/main still reads 17.2.0 — the same version string as the release published on 2026-08-23, which does not contain carryOver. The version number therefore does not distinguish "spec with carryOver" from "spec without it". Any restart criterion phrased as a version comparison would fire a false unlock and send a dev to build against a key the installed package does not accept — the exact premise-false dispatch this discipline exists to prevent.

    The criterion below probes for the symbol on the installed package instead.

    State change

    pm:blocked is replaced by pm:on-hold. The body's Blocked-by: line is superseded by the criterion below and left in place only as history.

    Restart-when: in this repo, after a spec pin bump / refresh, grep -rl carryOver node_modules/@objectstack/spec/dist returns at least one file — i.e. the installed @objectstack/spec actually declares the key. ⛔ Do not substitute a version comparison; see the hazard above.

    Restart-touch: pnpm-lock.yaml — unlike a runtime-plugin dependency, this repo does install @objectstack/spec, so the pin move is visible in-repo.

    On restart the dispatch shape is unchanged from the body, and the dev's first action stays the body's own instruction: verify the key on the installed package before writing anything.


    Generated by Claude Code

  3. objectstack-fleet commented on Sep 24, 2026

    @objectstack-fleet
    Contributor

    解除挂起 → pm:queue · 定级 priority:p2 —— 重开条件已满足;克隆权限集时,被带过去的权限 JSON 今天仍可手改

    分诊席(session_01Tw7jnJinGHvoGSi8aFkhPJ,objectstack 座位贴 #6015),2026-09-24T01:39Z。objectui 清理第一批:本席逐张读完卡面与全部评论,把结论与理由报给维护者,维护者答复后执行。 维护者答:「其他同意」。

    读数

    • 本仓安装的 spec 17.4.0:dist/ui 里已声明 carryOver(index.js / index.mjs / index.d.mts)。⇒ 卡面 5450626564 的 Restart-when:(grep -rl carryOver node_modules/@objectstack/spec/dist 有结果)已满足。
    • packages/app-shell/src/views/ActionParamDialog.tsx 在 origin/main 上 carryOver 0 处。⇒ 对话框还没有按声明把带过去的参数渲染成只读摘要。

    定级 p2

    业务后果:管理员克隆一个权限集时,对象权限、字段权限、行级安全这些被原样带过去的数据,今天在对话框里是可编辑的 JSON。手滑改出一段合法但更宽的 JSON,就会克隆出一个比原来权限更大的权限集,而且没有任何提示。⛔ 不定 p1:要管理员本人误改,⛔ 不是越权。

    交付(照卡面)

    声明了 carryOver 的参数渲染成折叠的只读摘要:从行数据取值,原样提交,⛔ 不留任何编辑入口,不只是改样式。加一个对话框级的测试,钉住 Clone 渲染出什么;发送侧的现有测试保持不变。


    Generated by Claude Code

  4. objectstack-fleet commented on Sep 24, 2026

    @objectstack-fleet
    Contributor

    Claim: PM loop round 1 — domain:ui execution seat
    Session: session_01BA3nKVUwKQJf8DBxrSVtNC
    Branch: claude/issue-6246-action-param-carryover
    Worktree: objectui-issue-6246
    Domain: domain:ui
    Seat: domain:ui#1
    File surface: packages/app-shell/src/views/ActionParamDialog.tsx and its tests, the param type it reads if carryOver must be added to it, one .changeset/6246-…md (stop on breach; explain in the report)
    Container & model: M, mode:subagent, model: opus (default judgement tier) — dispatch-gates.mjs refuses for this repo from the objectstack checkout ⇒ no path-derived mandate; tier is this seat's judgement: the failure direction is a clone that grants more than its base.
    Clause-②: yes
    Thread-read: 5805914175
    Serial constraints cleared: every open PR's file list read 2026-09-24T13:51Z (objectui#10256, #10255, #10253, #10252, #10251, #10249, #10248, #10246, #10169, #9488, #9391, #8941) ⇒ none touches ActionParamDialog.tsx. The unlock was read by triage at 5805914175: installed spec 17.4.0 declares carryOver, and ActionParamDialog.tsx has 0 reads of it.

    Scope

    The card body as ruled (objectstack#11753, recommendation A, 「同意」): a param that declares carryOver renders as a collapsed read-only summary, seeded from the row and submitted verbatim, with no editing affordance. Add a dialog-level pin on what Clone renders. The send-side pin stays green unchanged. ⇒ Fixes #6246.

    Why Clause-②: yes

    Honouring the key may add carryOver to objectui's own param shape, which widens what that shape accepts. ⇒ a contract review is owed before enqueue.

    domain:ui seat #1 · session_01BA3nKVUwKQJf8DBxrSVtNC · claim · 2026-09-24T13:53Z

  5. objectstack-fleet commented on Sep 24, 2026

    @objectstack-fleet
    Contributor

    os-dev-report

    {
      "issue": 6246,
      "status": "done",
      "branch": "claude/issue-6246-action-param-carryover",
      "pr": "https://github.com/objectstack-ai/objectui/pull/10271",
      "session": "session_01BA3nKVUwKQJf8DBxrSVtNC — harness-stamped (container CLAUDE_CODE_REMOTE_SESSION_ID cse_01BA3nKVUwKQJf8DBxrSVtNC; mode:subagent, so it is the parent PM session's id)",
      "premise_still_valid": true,
      "summary": "ActionParamDialog now honours the spec's ActionParamSchema.carryOver. A declared carry-over param renders as a collapsed read-only summary: a Shadcn Collapsible that is closed by default and shows the value verbatim in a pre when expanded. No field widget is built for it, and its row-seeded value is submitted verbatim. The key never reached the dialog before, because resolveActionParam() builds its output key by key and dropped it. The key now rides all three resolver branches onto @object-ui/core ActionParamDef.carryOver. serializeParamValues exempts carry-over values from the upload id reduction. One i18n key, actionDialog.carryOverHint, was added to all 10 packs. The action designer's ActionPreview dialog mock draws a read-only line instead of the declared widget, because this change would otherwise have made its 'the widget ActionParamDialog will render' claim false. Premise verified on the installed package: @objectstack/spec 17.4.0 declares carryOver as an optional boolean. The published @objectstack/plugin-security 17.4.0 declares carryOver: true on the five clone_permission_set facets, so there is a live producer. Its description param is deliberately left editable, so Clone shows three ordinary inputs plus five summaries, not the card's 'two' (see open_questions). The assignee on the card was os-bill (the PM's) and was left untouched.",
      "tests": "HEAD c11f8d5d (final commit; worktree clean). NEW PIN packages/app-shell/src/views/ActionParamDialog.carryOver-6246.test.tsx has 11 tests over legs A resolver, B render, C submit and D designer. The fixture is the transcribed clone_permission_set params, each parsed through the INSTALLED ActionParamSchema, with a refusal control proving the parse can fail. RED BEFORE FIX (base d7de5348 plus the test file only): 'Tests 6 failed | 4 passed (10)'. Leg C submit was already green pre-fix, as expected: an untouched seeded textarea was always sent verbatim. ABLATIONS via objectstack scripts/ablation-replace.mjs, WRAP mode. For each one the anchor hit as declared, the blob moved, and the restore was proven by blob == HEAD plus an empty git diff HEAD. (1) dialog render branch 'if (rawParam.carryOver) {' changed to 'if (false && ...)': 'Tests 2 failed | 8 passed'. The two failures are exactly leg B read-only and leg B expand; every CONTROL, leg A and leg C stayed green. (2) serializeParamValues skip line deleted: 1 failed (carried upload) | 9 passed. (3) resolver 'carryOver: param.carryOver,' deleted, 3 hits: 4 failed (leg A x2, leg B x2) | 6 passed. (4) ActionPreview 'if (p.carryOver) {' changed to false: 1 failed (leg D) | 10 passed. REVERSE TYPE CHECK: planting carryOverX beside carryOver in an ActionParamDef literal made tsc -p packages/app-shell/tsconfig.test.json red with 'TS2561 ... carryOverX does not exist in type ActionParamDef. Did you mean to write carryOver?'. That program has 4604 files in --listFiles, includes the test file (1 hit), and resolves core via the rebuilt packages/core/dist/actions/ActionRunner.d.ts (2 carryOver hits). UNION AT c11f8d5d, all from the repo root under os-verify-lock: 'pnpm exec vitest run packages/app-shell/ --maxWorkers=2' gave 'Test Files 754 passed (754) / Tests 7461 passed | 1 skipped (7462)'. 'pnpm exec vitest run packages/core/ packages/i18n/ --maxWorkers=2' gave 'Test Files 232 passed (232) / Tests 4541 passed (4541)'. TYPE-CHECK: 'turbo run type-check --filter=@object-ui/app-shell --filter=@object-ui/core --filter=@object-ui/i18n --concurrency=2' gave 'Tasks: 32 successful, 32 total' (dependency closure built by ^build) at the core/i18n final state. After the last app-shell edit, 'pnpm --filter @object-ui/app-shell type-check' echoed 'tsc --noEmit && tsc -p tsconfig.test.json' with VERDICT command-exit 0 at c11f8d5d. GATES (exit 0 at c11f8d5d): check:control-bytes 'OK (scanned 8264 ...)'; check:new-line-citations 'VERDICT ... 0 new citation(s)'; check:i18n-keys; check:i18n-drift ('1 key(s) added', 'No en value changed'); check:i18n-dead-keys; check:changeset-claims; check:pending-changeset-literals; check:designer-field-key-parity 'OK'; check:action-forward-parity; check:unreferenced-sources 'OK'; check:handler-key-reads 'OK'; check:test-path-roots 'OK'; node scripts/check-changeset-presence.mjs ('15 source file(s) of 3 released package(s) changed, and this change declares 1 changeset(s)'). LINT, a proven narrowing: (1) the population comes from eslint.config.js, whose TS block is files '**/*.{ts,tsx}' (the 2 changed .md files are outside it); (2) --format json reports 15 files, 0 errors, and no new warnings vs base on the files compared; (3) invariance: the config uses tseslint.configs.recommended with no parserOptions.project/projectService, so linting is not type-aware, and no eslint-rules/ rule reads the disk, so no untouched file's verdict can move. NOT MEASURED: check:readme-exports, check:doc-examples and check:doc-snippets, reason: PREREQUISITE NOT MET (the whole workspace is unbuilt in this worktree; the gates' own 'run the build first' refusal). The README addition is a JSON fence with no import binding. NOT MEASURED: the send-side pin objectstack#11703 pin 6 (packaged-permission-set-lock.test.ts in @objectstack/plugin-security), reason: it lives in objectstack, reads only objectstack's action definition, and this diff changes no objectstack file. CI on c11f8d5d at report time: in_progress (14 success, 3 skipped, 25 in progress, 0 failed).",
      "mcp_calls": "0 — no MCP tool used",
      "api_writes": "2 REST writes, both through the scripts/pm fleet relay (objectstack-fleet[bot]). (1) POST /repos/objectstack-ai/objectui/pulls (draft; relay dispatch POST /repos/objectstack-ai/objectstack/dispatches, run 36016362436, conclusion success), which opened #10271. (2) POST /repos/objectstack-ai/objectui/issues/6246/comments (this os-dev-report, via post-stamped.mjs). Not counted as REST: 4 git pushes of the branch (empty probe, then 3 content pushes). Zero label writes, zero PATCHes.",
      "deviations": [
        "File surface is wider than the claim names. The claim names the dialog, its tests, 'the param type it reads' (= @object-ui/core ActionParamDef in packages/core/src/actions/ActionRunner.ts) and one changeset. This PR also touches: packages/app-shell/src/utils/resolveActionParams.ts (the RawActionParam mirror plus a one-key pass-through on its 3 output branches; the declaration cannot reach the dialog without it; this is dispatch Zone 2 #4's 'a mirror must gain carryOver' case); packages/i18n/src/locales/*.ts x10 (one new key, as the dispatch anticipated); packages/app-shell/README.md (AGENTS.md #2 docs); packages/app-shell/src/views/metadata-admin/previews/ActionPreview.tsx (this change made its declared 'the widget ActionParamDialog will render' false for carry-over params, so it was fixed in the same PR). No open PR's file list touches any of them: read 2026-09-24T14:35Z across the 14 open non-release PRs. None of them is fenced.",
        "The PR body's not-filed note sits under '## Scope notes', not '## Acceptance notes'. The body is write-once; if the heading matters, the seat can rename it.",
        "Conflict surfaced, not resolved: on the parent objectstack#11753, comment 5536466144 (hotlong, 2026-09-04) re-aims the card to ADR-0131 C9 ('the fix is not a new contract key on the old one'). The spec key had already shipped (objectstack#12614, 2026-08-26), and the triage unlock 5805914175 (2026-09-24, maintainer 「其他同意」) postdates that comment without citing it. This PR honours the already-published key in 17.x. It adds no new contract surface."
      ],
      "open_questions": [
        {
          "question": "The ruling and the card say the Clone dialog 'returns to two ordinary text inputs' and list description among the carried facets. The producer (clone_permission_set in @objectstack/plugin-security, objectstack#12614) deliberately leaves description editable, and that PR says the objectui leg may revisit it. This renderer follows the declaration, so Clone now shows three inputs (display name, API name, description) plus five read-only summaries. Should description also be carried?",
          "options": [
            "A: keep it as shipped. description is prose, not a permission facet, and editing it cannot widen a grant, which is the fail direction the ruling closes. No change.",
            "B: declare carryOver: true on the description param in plugin-security (an objectstack producer change, patch). No objectui change is needed, because this renderer honours it automatically."
          ],
          "recommendation": "A. Axes: business need: the ruling's harm is grant widening, and description carries no grant. Long-term: the key stays a per-param declaration, and the producer already made this call on the record. AI-error: either way nothing silent, since both states are declared and enforced. Startup focus: A is zero work."
        }
      ],
      "out_of_scope_findings": [
        "Not a filing class (a missing designer affordance: zero pull, no runtime refusal or silent drop). The action designer's param inspector (ActionDefaultInspector, 'Pre-fill from row' checkbox) offers no carryOver toggle, so an author sets the key only by editing the JSON source. Its patchParam spreads the param, so an authored carryOver survives other edits. Dedupe words: carryOver inspector toggle, ActionDefaultInspector carry-over, designer param read-only. carrier: 承接者:无 · noted, not filed (also recorded in the PR body's Scope notes)."
      ]
    }

    Generated by Claude Code

  6. objectstack-fleet commented on Sep 24, 2026

    @objectstack-fleet
    Contributor

    需裁决 → needs-user-decision:PR objectui#10271 实现已复核通过,但与父卡的一条改道评论冲突,落地前请维护者定

    domain:ui seat #1, session_01BA3nKVUwKQJf8DBxrSVtNC. ⛔ 本席不代裁:两条在案的授权读数给出相反方向,按「两条细则冲突 ⇒ 按更严的一条行动并立卡」,PR 暂不入队。

    Governing text: objectstack#11753 ruling 5404887360(A,maintainer 「同意」)· objectstack#11753 5536466144(ADR-0131 C9 改道)· 本卡解锁 5805914175(maintainer 「其他同意」)· ADR-0131 D3/D6/§4

    维护者速读

    • 改了什么:PR objectui#10271 让克隆权限集对话框把声明了 carryOver 的参数(对象权限、字段权限、系统权限、行级安全、Tab 权限这五项)渲染成折叠的只读摘要,原样提交,不留任何编辑入口。
      • 实现与 11 个 pin 已通过契约复审(PASS,5816814050),CI 全绿。
      • 它不新增 spec 键,只消费 17.4.0 里已发布的 ActionParamSchema.carryOver。plugin-security 17.4.0 已在这五项上声明了这个键。
    • 为什么要你定:两条授权读数方向相反。
      • 父卡 objectstack#11753 的 5536466144(2026-09-04):这个对话框在 ADR-0131 里会被删除重建(C9,objectui#7611),所以「答案是重建页上真正的矩阵编辑器 —— ⛔ 不是一个把 textarea 变只读的 flag」。父卡因此是 pm:blocked + target:v18。
      • 本卡的解锁 5805914175(2026-09-24,你答「其他同意」)批准的恰是「声明了 carryOver 的参数渲染成折叠的只读摘要」。它没有引用 5536466144。
    • 风险与代价(含回滚):
      • 落地:17.x 的越权克隆口子立即关上。这段代码在 v18 随对话框一起被 C9 删掉。回滚就是 revert 一个 PR,不涉及任何契约变更。
      • 不落地:5536466144 自己写明「17.x 不修这个暴露」,手改出一段合法但更宽的 JSON 仍会克隆出权限更大的权限集。同时 spec 已发布、生产方已声明的键在渲染端继续不兑现。
    • 席位意见:荐 A,理由见下方四轴。
    • 你要做的(一个动作):回 A 或 B。附带子问题:description 要不要也声明 carryOver(荐「不」)。

    选项

    子问题 —— description:

    • 不声明(荐):它是散文,不是权限 facet,改它扩大不了授权。生产方 PR #12614 已明确这样选。
    • 声明:只改 plugin-security 一行,objectui 零改动。

    四轴分析

    • 实际业务需求:
      • 暴露是实测的:5536466144 自己承认「hazard is real」「17.x 不修」。
      • 生产方 plugin-security 17.4.0 已在五个 facet 上声明 carryOver,消费面是活的,不是投机。
      • ⇒ 利 A。
    • 项目长远合理性(权重 ≥50%):
      • 长远答案两边一致,都是 C9 的矩阵编辑器。
      • A 不新增任何契约面,只兑现已发布的键;代价是给一个 v18 要删的对话框加约 535 行(含测试与 10 个语言包),随 C9 一起消失。
      • B 保持「spec 已声明、生产方已声明、渲染端不兑现」的状态直到 v18;要么留着这个悬空的键,要么另开卡退役它。
      • ⇒ A 的长期代价是可回收的一次性代码。B 的长期代价是一个悬空声明,外加一张额外的退役或缓解卡。
    • 防 AI 写错:
      • 「声明即强制」:一个 spec 已发布、元数据已声明的键,在运行时不兑现,正是 AI 最容易被骗的形状 —— 读 schema 以为只读,实际可编辑。
      • A 让声明与行为一致;B 延续 declared ≠ enforced。
      • ⇒ 利 A。
    • 创业阶段不扩散:
      • A 不加新概念、新键、新门,只消费已有的。
      • B 若要 17.x 缓解,需要另立一张 objectstack 卡。
      • ⇒ 两者都不扩散契约;A 少一张卡。

    四轴同向 A。唯一的反向力是 5536466144 的「⛔ 不是只读 flag」—— 它写于这个键已发布之后,却没有提及这个键已经存在。这正是本席不能代你判断的地方。

    本次状态变更

    pm:dispatched → needs-user-decision(同一笔 replace)。assignee 保留:PR 已由本席交付,裁 A 后由本席落地;裁 B 则由本席关闭 PR 并按 B 转态。

    domain:ui seat #1 · 决策落卡 · 2026-09-24T15:12Z

  7. objectstack-fleet commented on Sep 24, 2026

    @objectstack-fleet
    Contributor

    Ruling A · ✅ ACCEPT — PR objectui#10271 at c11f8d5d · needs-user-decision → pm:dispatched, entering the merge queue

    domain:ui seat #1, session_01BA3nKVUwKQJf8DBxrSVtNC. The maintainer answered the decision 5816834213 in this seat's live session on 2026-09-24 at about 15:17Z. The option chosen, verbatim: 「A 落地(推荐)」. Its text: land as the 17.x mitigation; ADR-0131 C9 stays the v18 answer, and this code goes with the dialog when C9 deletes it; description stays editable. The thread was re-read to its tip 5816834213 in the act that wrote this.

    Implemented-by:  claude/issue-6246-action-param-carryover
    Reviewed-by:     session_01BA3nKVUwKQJf8DBxrSVtNC
    
    item reading
    shape draft · base main · Fixes #6246 · Clause-②: yes at line start
    the fix A param that declares carryOver renders as a collapsed read-only summary. It is seeded from the row, submitted as the same reference, and no widget is built for it. The resolver carries the key on all three branches. The upload-id reduction skips it. The designer mock draws a read-only line. One i18n key goes into all 10 packs
    fail direction No edit path remains. A missing seed omits the param, and the server fills an empty facet, which is fail-closed
    surface wider than the claim: resolveActionParams.ts, the 10 locales, the README and ActionPreview.tsx, each required. Accepted
    review-tier record PASS at c11f8d5d (5816814050)
    CI 43 terminal: 40 success, 3 skipped by design · governed-queue guard ⇒ NOT GOVERNED

    The dev's open question

    description stays editable, as ruling A states. No producer change is needed.

    Out of scope

    • Acceptance notes (from the PR's Scope notes): the action designer's param inspector offers no carryOver toggle, so an author sets the key only in the JSON source. There is zero pull today; noted, not filed.

    domain:ui seat #1 · ruling + review · 2026-09-24T15:18Z

  8. objectstack-fleet commented on Sep 24, 2026

    @objectstack-fleet
    Contributor

    Ruling: batch #222 item 1 · letter A (land PR objectui#10271 as the 17.x mitigation) · sub-question: description NOT carried · maintainer 「同意」 (chat, director seat summon #29, session_01EcrTi7s5oDYPHS4Pi7h31d) 2026-09-24T15:18Z

    Director seat, summon #29. Presented with recommendation A (fallback B), plus the sub-question recommendation "do not carry description"; the maintainer agreed. Thread re-read to its last comment (5816834213) in this act.

    Ruled: A. PR objectui#10271 lands as the 17.x mitigation. It honours the already-published ActionParamSchema.carryOver (spec 17.4.0; declared by @objectstack/plugin-security 17.4.0 on the five facets) and adds no contract surface. This settles the conflict the seat surfaced:

    • objectstack#11753 5536466144 (ADR-0131 C9: the matrix editor on the rebuilt page) stays the v18 answer. It is not overturned. This code is deleted with the dialog when C9 lands.
    • Until v18, a declared key is enforced rather than left dangling, and the grant-widening clone path is closed now instead of "not fixed in 17.x".

    Sub-question: description is not carried. It is prose, not a permission facet; editing it cannot widen a grant. The producer's choice in objectstack#12614 stands. ⛔ No plugin-security change.

    Execution: needs-user-decision → pm:dispatched in this stroke. The delivering seat (domain:ui seat #1, session_01BA3nKVUwKQJf8DBxrSVtNC) keeps it and enqueues PR objectui#10271 on its own green (contract review PASS 5816814050). The PR text should cite this ruling and C9 as the v18 successor. priority:p2 and domain:ui stand.


    Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    domain:uiobjectui ui stream: fix lands on the published library or apps — objectui execution seatpriority:p2

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions