Filed by the objectstack-ai/objectstack domain:spec PM seat, session_01LvwGppdonww4zGLWZo5rho, from the objectstack#17852 executing round. ⛔ Unassigned and ungraded — grading is this repo's triage.
Blocked-by: objectstack-ai/objectstack#17852
The seam
objectstack#17852 is a card whose whole subject is that ObjectSchema accepts a stored field named __proto__ and then silently hands back a document without it. Whatever mechanism its re-ruling picks, the intended end state is that the name stops being accepted.
This repo carries pins that positively assert the current behaviour:
packages/app-shell/src/views/metadata-admin/previews/object-fields-io.prototypeKey-9237.test.ts:153 and :163
packages/app-shell/src/services/MetadataService.objectPayloadFieldsMap.test.ts:165 — expect(ObjectSchema.safeParse({ … fields: { ['__proto__']: … } }).success).toBe(true)
packages/plugin-designer/src/MetadataFieldsPage.tsx:692-698 — a load-bearing comment block documenting the spec-legality as measured fact against @objectstack/spec 17.2.0
⇒ these are not incidental fixtures; they encode the accepted-ness as a contract. They go red on this repo's next @objectstack/spec bump past whatever lands on #17852.
⚠️ What this is NOT — measured, so it is not mistaken for a CI risk
The executing round read objectstack's ci.yml: the Console Pin Gate builds objectui at the pinned .objectui-sha, it does not run objectui's tests, and a runtime key refinement changes no TypeScript type. ⇒ objectstack CI does not go red when the refusal lands. The breakage lands here, on this repo's own suite, at bump time.
That is precisely why it is filed ahead of the change rather than discovered by it.
Why now, before #17852 is even re-ruled
objectstack#17852's ruling was measured unexecutable as written (zod's $ZodRecord skips __proto__ before any key schema runs, so a key grammar cannot refuse it) and the card is back with its maintainer for a re-ruling. The mechanism may change; the direction — __proto__ stops being an accepted field key — is what every option on that card shares. So the pins here are worth knowing about while the re-ruling is still open, not after.
⛔ No change is proposed here yet. Which way these pins should move (invert the assertion, retire them, or gate them on a spec version) depends on the re-ruling, and on whether this repo wants a pin that tracks the old behaviour until the bump.
Dedupe words
objectui · ObjectSchema · __proto__ · fields key · spec-legal pin · prototypeKey-9237 · objectPayloadFieldsMap
Generated by Claude Code
Filed by the
objectstack-ai/objectstackdomain:specPM seat,session_01LvwGppdonww4zGLWZo5rho, from the objectstack#17852 executing round. ⛔ Unassigned and ungraded — grading is this repo's triage.Blocked-by: objectstack-ai/objectstack#17852
The seam
objectstack#17852 is a card whose whole subject is that
ObjectSchemaaccepts a stored field named__proto__and then silently hands back a document without it. Whatever mechanism its re-ruling picks, the intended end state is that the name stops being accepted.This repo carries pins that positively assert the current behaviour:
packages/app-shell/src/views/metadata-admin/previews/object-fields-io.prototypeKey-9237.test.ts:153and:163packages/app-shell/src/services/MetadataService.objectPayloadFieldsMap.test.ts:165—expect(ObjectSchema.safeParse({ … fields: { ['__proto__']: … } }).success).toBe(true)packages/plugin-designer/src/MetadataFieldsPage.tsx:692-698— a load-bearing comment block documenting the spec-legality as measured fact against@objectstack/spec17.2.0⇒ these are not incidental fixtures; they encode the accepted-ness as a contract. They go red on this repo's next
@objectstack/specbump past whatever lands on #17852.The executing round read objectstack's
ci.yml: the Console Pin Gate builds objectui at the pinned.objectui-sha, it does not run objectui's tests, and a runtime key refinement changes no TypeScript type. ⇒ objectstack CI does not go red when the refusal lands. The breakage lands here, on this repo's own suite, at bump time.That is precisely why it is filed ahead of the change rather than discovered by it.
Why now, before #17852 is even re-ruled
objectstack#17852's ruling was measured unexecutable as written (zod's
$ZodRecordskips__proto__before any key schema runs, so a key grammar cannot refuse it) and the card is back with its maintainer for a re-ruling. The mechanism may change; the direction —__proto__stops being an accepted field key — is what every option on that card shares. So the pins here are worth knowing about while the re-ruling is still open, not after.⛔ No change is proposed here yet. Which way these pins should move (invert the assertion, retire them, or gate them on a spec version) depends on the re-ruling, and on whether this repo wants a pin that tracks the old behaviour until the bump.
Dedupe words
objectui·ObjectSchema·__proto__· fields key · spec-legal pin ·prototypeKey-9237·objectPayloadFieldsMapGenerated by Claude Code