You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
**Runtime Boundary** — runtime metadata is file/artifact-backed and read-only at boot. Database-backed metadata persistence exists for explicitly configured control-plane services, not as an automatic runtime project-DB bridge.
Metadata API (list types, list items, get item) is fully functional
Metadata is loaded from config files or dist/objectstack.json at startup and held in memory
MetadataPlugin no longer registers sys_metadata / sys_metadata_history into the runtime or auto-bridges ObjectQL to DatabaseLoader
Future: production Artifact API loader and durable local artifact cache
System Services
Protocol
Implementation Package
Status
Notes
Logging
@objectstack/core
✅
Cross-platform logger (browser + server)
API Registry
@objectstack/core
✅
Central endpoint registry
Metrics
@objectstack/observability
✅
Metrics exporters shipped (metrics-exporters.ts)
Tracing
@objectstack/observability
⚠️
Error/exporter pipeline shipped (error-exporters.ts); full distributed tracing in progress
Audit
@objectstack/plugin-audit
✅
Audit writers + audit objects shipped
Job
@objectstack/service-job
✅
Job service with cron/db/interval adapters
Cache
⚠️
⚠️
HTTP caching implemented, in-memory cache partial
Translation
@objectstack/service-i18n
✅
i18n/translation service with file adapter
Feature Flags
❌
📋
Planned
Encryption
❌
📋
Planned
Compliance
❌
📋
Planned
Masking
❌
📋
Planned
Notification
@objectstack/service-messaging
🟡
Framework pipeline shipped; objectui bell cut-over remains
Change Management
❌
📋
Planned
Collaboration
❌
📋
Planned
Data Layer (ObjectQL)
Core Data Modeling
Protocol
@objectstack/spec
@objectstack/objectql
@objectstack/client
Status
Field
✅
✅
✅
✅ Full
Object
✅
✅
✅
✅ Full
Validation
✅
⚠️
❌
⚠️ Partial
Hook
✅
✅
❌
✅ Full
Dataset
✅
❌
❌
❌ Not Impl
Mapping
✅
❌
❌
❌ Not Impl
Document
✅
❌
❌
❌ Not Impl
External Lookup
✅
❌
❌
❌ Not Impl
Field Type Support:
Field Type
Implementation
Notes
text, textarea, email, url, phone
✅
Full support
number, currency, percent
✅
Full support
boolean, checkbox
✅
Full support
date, datetime, time
✅
Full support
select, multiselect
✅
Full support
lookup, master_detail
✅
Full support in spec, partial in memory driver
formula
✅
CEL-backed formula fields are implemented
summary
✅
Server-side rollups for count/sum/min/max/avg on child records
json, array
✅
Full support
file, image
📋
Protocol defined, not implemented
Query Engine
Protocol
@objectstack/objectql
@objectstack/client
@objectstack/driver-memory
Status
Query AST
✅
✅
⚠️
✅ Full
Query Builder
❌
✅
❌
✅ Client
Filter Operators
✅
✅
⚠️
⚠️ Partial
Aggregations
✅
✅
✅
✅ Full
Joins
✅
✅
❌
⚠️ Spec only
Sorting
✅
✅
❌
⚠️ Spec only
Pagination
✅
✅
✅
✅ Full
Window Functions
✅
❌
❌
❌ Spec only
Subqueries
✅
❌
❌
❌ Spec only
Notes:
Full query protocol is defined and implemented in ObjectQL engine
Actual query capability depends on driver implementation
Memory driver supports basic queries only
Client SDK provides query builder utilities
API Layer (Transport)
HTTP & REST
Protocol
@objectstack/rest
@objectstack/runtime
@objectstack/plugin-hono-server
@objectstack/client
Status
REST Server
✅
✅ (re-export)
✅
❌
✅ Full
HTTP Server
❌
✅
✅
❌
✅ Full
Endpoint
✅
❌
✅
❌
✅ Full
Router
✅
✅
✅
❌
✅ Full
Discovery
❌
✅
✅
✅
✅ Full
Contract
✅
✅
❌
❌
⚠️ Partial
Protocol
❌
✅
❌
✅
✅ Full
Errors
✅
✅
✅
✅
✅ Full
HTTP Cache
✅
✅
✅
✅
✅ Full
Batch
✅
✅
✅
✅
✅ Full
The data (/data), metadata (/meta), and batch endpoints are implemented in @objectstack/rest (rest-server.ts); @objectstack/runtime re-exports RestServer from that package and provides the underlying HTTP server/dispatcher.
REST Endpoints Implemented:
Endpoint Pattern
Method
Purpose
Status
/api/v1
GET
API discovery
✅
/meta
GET
List metadata types
✅
/meta/{type}
GET
List items of type
✅
/meta/{type}/{name}
GET
Get specific metadata item
✅
/data/{object}
GET
List records
✅
/data/{object}/{id}
GET
Get single record
✅
/data/{object}
POST
Create record
✅
/data/{object}/{id}
PATCH
Update record
✅
/data/{object}/{id}
DELETE
Delete record
✅
/data/{object}/createMany
POST
Batch create
✅
/data/{object}/updateMany
POST
Batch update
✅
/data/{object}/deleteMany
POST
Batch delete
✅
/data/{object}/{id}/clone
POST
Clone a record (gated by enable.clone)
✅
/data/{object}/batch
POST
Atomic batch operations
✅
/batch
POST
Cross-object atomic batch (parent + children in one transaction, $ref)
✅
Advanced Protocols
Protocol
Implementation
Status
Notes
Analytics
✅
✅
ObjectQL aggregation plus @objectstack/service-analytics dataset execution; analytics read scope auto-bridges to security.getReadFilter for RLS-aware dashboards/reports
OData
❌
📋
Protocol defined, not implemented
GraphQL
❌
📋
Protocol defined, not implemented
Realtime
@objectstack/service-realtime
⚠️
Realtime service with in-memory adapter shipped; production adapters in progress
WebSocket
@objectstack/service-realtime
⚠️
Transport provided via the realtime service in-memory adapter
UI Layer (ObjectUI)
View System
Protocol
@objectstack/spec
Implementation
Status
View
✅
🟡
🟡 Studio/ObjectUI renders authored metadata surfaces; general-purpose renderer coverage is still incomplete
ListView
✅
🟡
🟡 ObjectUI grid/list surfaces support per-view persistence, filters, row actions, density, galleries, and permission-aware affordances; full protocol parity is ongoing
FormView
✅
🟡
🟡 ObjectUI forms support live field rules (visibleWhen / readonlyWhen / requiredWhen), inline-grid row rules, and server-aligned required enforcement
Page
✅
🟡
🟡 Record-page authoring, page create flows, block canvas editing, slotted record pages, and selected page blocks are implemented in ObjectUI; full component catalogue remains in progress
App
✅
🟡
🟡 Navigation metadata is consumed by the console/app shell; full renderer parity remains in progress
Dashboard
✅
🟡
🟡 ObjectUI renders metric/chart/list/pivot/funnel/table widgets, drill-downs (group → records → record chain), type-aware cells, and dataset-bound widgets; Studio can author per-widget dataset bindings (dataset / dimensions / values)
🟡 Selected page/record components render in ObjectUI (record:alert, related lists, highlights, page blocks); catalogue parity remains in progress
Theme
✅
❌
❌ Spec only
Widget
✅
🟡
🟡 Dashboard/report/list/form widgets render in ObjectUI; custom widget manifest/runtime parity remains in progress
Chart
✅
🟡
🟡 Recharts-backed dashboard/report charts cover bar/line/pie/area/scatter/funnel/gauge/treemap/sankey with formatting and field-coverage guards
Notes:
All UI protocols are fully defined in spec
Metadata API can retrieve UI definitions (views, apps, pages, dashboards,
reports, actions)
Active Studio/ObjectUI source lives in the sibling ../objectui repo and is
bundled into packages/console via the objectui refresh workflow
Metadata-admin curated forms now merge server-only fields back into the save
payload, so a Studio form that exposes only part of a metadata type should
not strip newer protocol properties
The 2026-05-08 → 2026-06-08 ObjectUI scan covered 910 non-merge frontend
commits. The largest functional clusters were metadata-admin/Studio,
master-detail forms, reports/dashboards, record detail/related lists,
action transport, flow designer, developer/API pages, AI draft publishing,
and i18n.
React SDK provides data hooks; the cross-surface renderer is still being
completed in ObjectUI rather than in this backend repo
Automation Layer
**Plugin-Provided Service** — The kernel does NOT include an automation engine. Flow, workflow, and approval services are provided by plugins — the flow engine ships in `@objectstack/service-automation`, with approval nodes in `@objectstack/plugin-approvals`.
Protocol
@objectstack/spec
Kernel
Plugin Required
Status
Flow
✅
❌
✅
✅ @objectstack/service-automation
Workflow
✅
❌
✅
✅ @objectstack/service-automation
Approval
✅
❌
✅
✅ @objectstack/plugin-approvals
Webhook
✅
❌
✅
✅ @objectstack/plugin-webhooks
ETL
✅
❌
✅
📋 Plugin
Sync
✅
❌
✅
📋 Plugin
Trigger Registry
✅
❌
✅
✅ trigger-record-change / trigger-schedule
Notes:
Hook system is implemented in ObjectQL (beforeFind, afterInsert, etc.) — this is data-layer eventing, not workflow automation
The flow/workflow engine ships in @objectstack/service-automation (engine.ts, builtin nodes, plugin.ts); approvals, webhooks, and triggers ship as plugin-approvals, plugin-webhooks, trigger-record-change, and trigger-schedule
ETL and Sync protocols are defined but not yet implemented as plugins
Discovery API reports automation service as unavailable until a plugin is registered
Security Layer
**Plugin-Provided Service** — The kernel does NOT handle authentication or authorization. Security services must be provided by plugins (e.g., `@objectstack/plugin-auth`). The Discovery API reports auth as `unavailable` until a plugin is registered.
Auth Service (plugin-auth)
The auth service in CoreServiceName covers both authentication (identity) and authorization (permissions). There is no separate permission service — it is part of auth.
Protocol
Area
@objectstack/spec
Kernel
Plugin Required
Status
Identity
Authentication
✅
❌
✅
📋 Plugin
Auth Config
Authentication
✅
❌
✅
📋 Plugin
Role
Authentication
✅
❌
✅
📋 Plugin
Organization
Authentication
✅
❌
✅
📋 Plugin
Policy
Authentication
✅
❌
✅
📋 Plugin
SCIM
Authentication
✅
❌
✅
📋 Plugin
Permission
Authorization
✅
✅ Phase-1
✅
✅ plugin-security
Sharing
Authorization
✅
❌
✅
📋 Plugin
RLS
Authorization
✅
✅ Phase-1 (tenant + owner)
✅
✅ plugin-security
Territory
Authorization
✅
❌
✅
📋 Plugin
Notes:
All security protocols (identity + permission) are delivered by a single auth plugin — matching CoreServiceName
Client SDK supports bearer token header — but token validation requires the auth plugin
Auth route (/auth/*) only appears in Discovery when the auth plugin is registered
Fine-grained authorization (RLS, sharing, territory) is internal to the auth plugin
Phase-1 RBAC enforcement is live end-to-end: REST → ObjectQL → SecurityPlugin middleware now receives a populated ExecutionContext (userId, tenantId, positions, permissions). Tenant isolation is enforced as a Layer 0 tenant wall (plugin-security/tenant-layer.ts, ADR-0095 D1) that AND-composes organization_id == current_user.organization_id ahead of and independently of business RLS — the earlier wildcard tenant_isolation RLS policy on member_default was retired (an OR-merged business policy could widen it). The default member_default set still ships per-object overrides sys_organization_self (id == current_user.organization_id) and sys_user_self (id == current_user.id) for the global tables that lack an organization_id column. The earlier tenantField indirection (RLS expressions written against an abstract tenant_id column then rewritten to the configured physical column at compile time) was removed — the placeholder, the column name, and RLSUserContext.organization_id are now the same name end-to-end. The legacy objectql.registerTenantMiddleware (hardcoded where.tenant_id injection that pre-dated SecurityPlugin) has been removed; SecurityPlugin is the sole authority for tenant isolation. Analytics now uses the same reusable read scope via security.getReadFilter, so dataset-bound dashboards/reports do not bypass RLS. Verified cross-organization isolation on pnpm dev:crm across sys_organization, sys_member, sys_user, sys_user_permission_set, sys_position_permission_set. Anonymous traffic is denied by default (the ADR-0056 D2 default-deny flip landed: requireAuth defaults to true); an explicit requireAuth: false opt-out logs a boot-time warning, and public forms do not depend on any fall-open — they carry a declaration-derived publicFormGrant (ADR-0056 Option A).
OWD / sharing-model enforcement is live and proven end-to-end (ADR-0056): private, public_read, public_read_write, and controlled_by_parent are enforced through plugin-sharing + plugin-security and verified by dogfood proofs over the real HTTP stack. object.sharingModel accepts the canonical OWD vocabulary only (private / public_read / public_read_write / controlled_by_parent) — the legacy read / read_write / full aliases were removed from the enum (ADR-0090 D4), and an unset sharingModel on a custom object resolves to private (ADR-0090 D1). RLS owner policies resolve current_user.email in addition to id / organization_id / positions (#2054). Permission sets may declare isDefault: true as the install-time suggestion to bind the set to the built-in everyone position (ADR-0090 D5, superseding the ADR-0056 D7 fallback-profile mechanism).
AI Layer
The in-UI AI **runtime** below ships in **ObjectOS**, not in the
open-source framework. The agent / skill / tool **schemas** stay open in
`@objectstack/spec/ai`; the **open-source framework** exposes AI via
[`@objectstack/mcp`](/docs/ai) (BYO-AI). The Implementation / Status columns
describe that separate runtime.
Protocol
@objectstack/spec
Implementation
Status
Agent
✅
ObjectOS runtime
✅ Agent runtime
Model Registry
✅
ObjectOS runtime
✅ Model registry
RAG Pipeline
✅
@objectstack/service-knowledge
⚠️ Knowledge service + knowledge-memory / knowledge-ragflow / embedder-openai plugins
NLQ
✅
ObjectOS runtime
⚠️ Data-query tools
Conversation
✅
ObjectOS runtime
✅ In-memory + ObjectQL conversation services
Agent Action
✅
ObjectOS runtime
⚠️ Action/data/knowledge tools
Cost
✅
❌
❌ Spec only
Predictive
✅
❌
❌ Spec only
Orchestration
✅
ObjectOS runtime
⚠️ Agent tool orchestration
Feedback Loop
✅
ObjectOS runtime
⚠️ Eval harness
DevOps Agent
✅
❌
❌ Spec only
Notes:
Complete AI protocol suite defined
The ObjectOS runtime ships agents, model registry, conversation, tools, skills, and an eval harness
RAG/embedding is provided by @objectstack/service-knowledge plus the knowledge-memory, knowledge-ragflow, and embedder-openai plugins (all open)
Cost tracking, predictive, and the DevOps agent protocols remain spec-only
⚠️ Slack connector shipped; broader SaaS catalogue in progress
Database Connector
✅
@objectstack/driver-sql, driver-mongodb
✅ Delivered via the database drivers
File Storage
✅
@objectstack/service-storage
✅ File storage service with local + S3 adapters and storage routes
Message Queue
✅
@objectstack/service-queue
⚠️ Queue service shipped
GitHub Connector
✅
❌
❌ Spec only
Vercel Connector
✅
❌
❌ Spec only
QA & Testing
Protocol
@objectstack/spec
@objectstack/core
@objectstack/verify
Status
Testing
✅
✅
✅
✅ Full
Features Implemented:
TestSuite, TestScenario, TestStep schemas ✅
HTTP adapter for testing ✅
MSW integration for browser mocking ✅
QA runner in core ✅
Implementation Roadmap
Phase 1: Core Infrastructure ✅ COMPLETE
[x] Microkernel & Plugin System
[x] Logging System
[x] Service Registry
[x] Event Bus
[x] API Registry
Phase 2: Data Layer ✅ COMPLETE
[x] ObjectQL Engine
[x] Schema Registry
[x] Protocol Implementation
[x] Basic Query Support
[x] CRUD Operations
[x] Hook System
Phase 3: API Layer ✅ COMPLETE
[x] REST Server
[x] HTTP Server (Hono)
[x] Endpoint Generation
[x] Discovery API
[x] Metadata API
[x] Batch Operations
[x] HTTP Caching
Phase 4: Client SDKs ✅ COMPLETE
[x] TypeScript Client
[x] React Hooks
[x] Query Builder
[x] Error Handling
Phase 5: Developer Tools ✅ COMPLETE
[x] CLI Tools
[x] Config Validation
[x] Development Server
[x] Metadata Management
Phase 6: Advanced Features 🚧 IN PROGRESS
[x] Production Database Drivers — @objectstack/driver-sql (PostgreSQL/MySQL dialects), @objectstack/driver-mongodb, and @objectstack/driver-sqlite-wasm ship; additional dialect coverage ongoing
[ ] GraphQL API
[ ] OData Support
[ ] Realtime Subscriptions
[ ] WebSocket Support
Phase 7: UI Layer 🟡 IN PROGRESS
[ ] UI Renderer
[x] Studio metadata-admin engine — generic metadata list/detail/edit surfaces, live preview, draft/publish/rollback, create-mode forms, server-side diagnostics, package scoping, and skew-safe curated inspectors
[x] Form conditional rules — ObjectUI supports visibleWhen, readonlyWhen, requiredWhen, row-scoped inline-grid rules, and required-on-submit enforcement
[x] Master-detail forms — inline subforms, spreadsheet-style line items, atomic batch create/edit, lookup auto-fill, line ordering, duplicate/reorder, and subtotal/tax/total stack
[x] Record detail + related lists — derived related lists, record-page assignment, action slots, system/audit sections, and opt-in reference rail
[x] Authorization Plugin — @objectstack/plugin-security enforces CRUD/FLS/RLS in the ObjectQL middleware chain; REST → ObjectQL now propagates ExecutionContext end-to-end (Phase-1)
[x] Row-Level Security — tenant isolation is a Layer 0 tenant wall (plugin-security/tenant-layer.ts, ADR-0095 D1) that AND-composes organization_id == current_user.organization_id independently of business RLS (the earlier wildcard tenant_isolation policy on member_default was retired); member_default still applies per-object overrides sys_organization_self / sys_user_self. The earlier tenantField rewrite indirection was removed: RLS column, placeholder, and RLSUserContext.organization_id use the same canonical name end-to-end
[x] Analytics RLS bridge — @objectstack/service-analytics auto-bridges to security.getReadFilter(object, context) and fails closed when read-scope resolution cannot be safely applied
[x] Multi-tenancy — verified cross-organization isolation on pnpm dev:crm (Alice@OrgAlpha vs. Bob@OrgBeta only see their own records across sys_organization, sys_member, sys_user, and sys_*_permission_set link tables)
[x] Legacy objectql.registerTenantMiddleware removed — SecurityPlugin is now the sole tenant-isolation authority
[x] Organization-Wide Defaults / sharing model — private, public_read, public_read_write, and controlled_by_parent enforced via plugin-sharing + plugin-security, proven by dogfood over the real HTTP stack (ADR-0056). Canonical vocabulary only — legacy aliases removed from the enum (ADR-0090 D4); unset custom-object OWD resolves to private (ADR-0090 D1)
[x] Sharing Rule evaluator — criteria rules re-evaluated on afterInsert / afterUpdate (plugin-sharing/rule-hooks.ts); enforced recipients are user / position / unit_and_subordinates (business-unit-subtree widening, ADR-0057 D5 / ADR-0090 D3); owner-type rules and group/guest recipients remain [experimental — not enforced]
[x] Everyone-baseline suggestion — a permission set may set isDefault: true as the install-time suggestion to bind it to the built-in everyone position; resolved per-request as an additive baseline, no fallback cliff (ADR-0090 D5)
[x] Default-deny for anonymous traffic — the global default-deny flip landed (ADR-0056 D2): requireAuth defaults to true, explicit requireAuth: false opt-outs warn at boot, and public forms self-authorize via publicFormGrant (Option A)
[ ] Studio RLS visual editor
[ ] Per-user×org permission cache
[ ] Audit UI / denied-access logging
Phase 10: AI Integration 📋 PLANNED
[ ] Agent Framework
[ ] RAG Pipeline
[ ] NLQ Engine
[ ] Model Registry
Summary Statistics
Overall Implementation Status
Category
Total Protocols
Status
Data
16
Core modeling, hooks, and query engine fully implemented; document/mapping/external-lookup still pending
UI
10
Studio/ObjectUI render most authored surfaces (🟡); full cross-surface renderer parity in progress
Permission + RLS live (plugin-security); identity/sharing/territory still plugin-pending
Automation (plugin)
7
Flow, workflow, approval, webhook, and triggers implemented; ETL/Sync pending
AI
12
Agents, model registry, conversation, tools, RAG implemented (ObjectOS runtime + open knowledge plugins); cost/predictive/DevOps-agent pending
Integration
7
REST/OpenAPI/MCP/Slack connectors, file storage, and queue implemented; GitHub/Vercel connectors pending
QA
1
Fully implemented
Implementation Coverage
Implementation spans every layer of the platform. Core infrastructure, data modeling, the REST API, client SDKs, security (Phase-1), automation, AI, and integration all have shipping implementations. Remaining gaps are concentrated in specific protocols (OData/GraphQL, cross-surface UI renderer parity, sharing/territory authorization, ETL/Sync, and a handful of governance and AI-cost services) rather than entire layers. Refer to the per-layer tables above for protocol-level status.
Core Functionality Status
Feature Area
Status
Production Ready
Kernel & Plugins
✅
Yes
Data Modeling
✅
Yes
Query Engine
⚠️
Partial (depends on driver)
REST API
✅
Yes
Client SDKs
✅
Yes
Metadata System
⚠️
Partial (in-memory only, DB persistence pending)
HTTP Caching
✅
Yes
Testing Tools
✅
Yes
UI Rendering
❌
No
Workflows
✅
Yes (plugin: service-automation)
Security
⚠️
Partial (Phase-1 RBAC/RLS via plugin-security)
AI Features
⚠️
Partial (ObjectOS runtime + open knowledge plugins)
Package Feature Matrix
Feature
spec
core
objectql
runtime
client
client-react
cli
metadata
hono
memory
msw
Protocol Definitions
✅
❌
❌
❌
❌
❌
❌
❌
❌
❌
❌
Microkernel
❌
✅
❌
❌
❌
❌
❌
❌
❌
❌
❌
Plugin System
❌
✅
❌
✅
❌
❌
❌
❌
❌
❌
❌
Service Registry
❌
✅
❌
❌
❌
❌
❌
❌
❌
❌
❌
Event Bus
❌
✅
❌
❌
❌
❌
❌
❌
❌
❌
❌
Logging
❌
✅
❌
❌
❌
❌
❌
❌
❌
❌
❌
Schema Registry
❌
❌
✅
❌
❌
❌
❌
❌
❌
❌
❌
ObjectQL Engine
❌
❌
✅
❌
❌
❌
❌
❌
❌
❌
❌
Protocol Implementation
❌
❌
✅
❌
❌
❌
❌
❌
❌
❌
❌
REST Server
❌
❌
❌
✅
❌
❌
❌
❌
❌
❌
❌
Endpoint Generation
❌
❌
❌
✅
❌
❌
❌
❌
❌
❌
❌
HTTP Server
❌
❌
❌
✅
❌
❌
❌
❌
✅
❌
❌
Client SDK
❌
❌
❌
❌
✅
❌
❌
❌
❌
❌
❌
Query Builder
❌
❌
❌
❌
✅
❌
❌
❌
❌
❌
❌
React Hooks
❌
❌
❌
❌
❌
✅
❌
❌
❌
❌
❌
CLI Commands
❌
❌
❌
❌
❌
❌
✅
❌
❌
❌
❌
Config Validation
❌
❌
❌
❌
❌
❌
✅
❌
❌
❌
❌
Metadata Loading
❌
❌
❌
❌
❌
❌
❌
✅
❌
❌
❌
File Watching
❌
❌
❌
❌
❌
❌
❌
✅
❌
❌
❌
Database Driver
❌
❌
❌
❌
❌
❌
❌
❌
❌
⚠️
❌
API Mocking
❌
❌
❌
❌
❌
❌
❌
❌
❌
❌
✅
The REST server, endpoint generation, and data/meta/batch endpoints are implemented in the @objectstack/rest package (not shown as a column above); @objectstack/runtime re-exports RestServer from it.