Skip to content

fix(fields): emit the spec's $notContains, and keep secret out of inline edit (#2901) - #2940

Merged
os-zhuang merged 1 commit into
mainfrom
fix/2901-ncontains-secret-inline
Jul 28, 2026
Merged

fix(fields): emit the spec's $notContains, and keep secret out of inline edit (#2901)#2940
os-zhuang merged 1 commit into
mainfrom
fix/2901-ncontains-secret-inline

Conversation

@os-zhuang

Copy link
Copy Markdown
Contributor

The two defects from the #2901 audit that need no design decision. Audit doc is in #2937.

$ncontains was never a real operator

The sharing-rule criteria builder emitted { $ncontains: v } for "does not contain". That token appears zero times in @objectstack/spec, and objectui's own convertFiltersToAST throws on it — naming the correct spelling in its own error message:

Unknown filter operator '$ncontains' for field 'x'. Supported operators: …, $notContains, …

So every "does not contain" sharing rule authored in the UI validated at authoring time and was rejected downstream. Nothing caught it because the builder's operator list is hand-written and never compared against the spec vocabulary — the #2901 pattern exactly.

kvToCondition keeps accepting $ncontains on read, so criteria saved before this still load. Dropping it would turn stored rules into "criteria can't be represented" rather than migrating them.

secret was inline-editable as plaintext

secret was in neither EDIT_WIDGETS nor INLINE_EXCLUDED_FIELD_TYPES, so grid inline edit fell through to DataTable's plain text input — two lines below password, which is correctly excluded.

Both are masked on read, so that input renders the mask as if it were the value and writes it straight back. secret additionally round-trips through an encrypted store (ADR-0100, data/field.zod.ts), so the cell holds an opaque ref, not the secret.

The guard that blocked the fix

Adding secret tripped FieldEditWidget.test.ts's staleness check, which is itself mis-specified — and mis-specified in a way the audit predicted.

It treats FORM_FIELD_TYPES (Object.keys(fieldWidgetMap)) as the set of real field types. But spec spellings that reach a widget through the alias table are not keyssecretfield:password, autonumberfield:auto_number. index.tsx's own resolveFormWidgetType doc comment names secret as exactly such an alias. So the guard rejected a genuine spec field type as "stale".

Made the check alias-aware: an entry is real if it is a direct widget key or the alias table maps it explicitly. Still catches typos (secrett → falls back to field:text → fails), no longer rejects real types.

Verification

  • FieldEditWidget.test.ts, field-type-coverage.test.ts, and the new FilterConditionField.operators.test.ts119 tests pass.
  • New test pins every builder token to a FieldOperatorsSchema spelling, pins the round trip, and pins the $ncontains back-compat read.
  • Negative-checked: reverted the source to $ncontains and confirmed the new test fails with expected [ '$ncontains' ] to deeply equal [], then restored. A guard that cannot fail is worthless.
  • eslint: 0 errors. tsc: no new errors in the touched files.

🤖 Generated with Claude Code

… inline edit (#2901)

Two defects the #2901 audit turned up that need no design decision.

**`$ncontains` was never a real operator.** The sharing-rule criteria builder
emitted `{ $ncontains: v }` for "does not contain" — a token that appears zero
times in `@objectstack/spec`, and that objectui's own `convertFiltersToAST`
throws on while naming the correct spelling (`$notContains`) in its error
message. Every such rule validated in the UI and was rejected downstream.
`kvToCondition` keeps reading the old spelling so criteria saved before this
still load instead of failing as "can't be represented".

**`secret` was inline-editable as plaintext.** It sat in neither `EDIT_WIDGETS`
nor `INLINE_EXCLUDED_FIELD_TYPES`, so the grid fell back to a plain text input —
two lines below `password`, which is correctly excluded. Both are masked on
read, so that input renders the mask as the value and writes it back; `secret`
additionally round-trips through an encrypted store (ADR-0100), meaning the cell
holds an opaque ref, not the value.

Adding it tripped the exclusion-set staleness guard, which is itself
mis-specified: it treats `Object.keys(fieldWidgetMap)` as the set of real field
types, but spec spellings that reach a widget through the alias table
(`secret` → `field:password`, `autonumber` → `field:auto_number`, …) are not
keys — as index.tsx's own `resolveFormWidgetType` docs note. Made the check
alias-aware so it still catches typos without rejecting real types.

New `FilterConditionField.operators` test pins every builder token to a
`FieldOperatorsSchema` spelling and pins the round trip; verified it fails
against the old `$ncontains`.

Refs #2901

Co-Authored-By: Claude <noreply@anthropic.com>
@vercel

vercel Bot commented Jul 28, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated (UTC)
objectui Ignored Ignored Jul 28, 2026 5:22pm

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

Metric Value Budget
Main entry (gzip) 27.9 KB 350 KB
Entry file index-By-BOuKQ.js
Status PASS

📦 Bundle Size Report

Package Size Gzipped
app-shell (index.js) 8.20KB 2.97KB
app-shell (runtime-config.js) 7.42KB 2.32KB
app-shell (types.js) 0.01KB 0.04KB
app-shell (urlParams.js) 7.57KB 2.97KB
auth (AuthContext.js) 0.31KB 0.24KB
auth (AuthGuard.js) 1.17KB 0.53KB
auth (AuthProvider.js) 22.10KB 4.37KB
auth (AuthShell.js) 3.49KB 1.40KB
auth (ForgotPasswordForm.js) 12.12KB 3.41KB
auth (LoginForm.js) 17.86KB 5.29KB
auth (PreviewBanner.js) 0.90KB 0.50KB
auth (RegisterForm.js) 6.43KB 2.09KB
auth (SocialSignInButtons.js) 9.60KB 3.89KB
auth (UserMenu.js) 3.40KB 1.22KB
auth (auth-gate-events.js) 1.29KB 0.66KB
auth (authStyles.js) 5.04KB 1.72KB
auth (createAuthClient.js) 35.76KB 9.11KB
auth (createAuthenticatedFetch.js) 4.37KB 1.69KB
auth (index.js) 2.25KB 1.01KB
auth (org-roles.js) 6.72KB 2.85KB
auth (phone-identifier.js) 1.11KB 0.66KB
auth (types.js) 0.59KB 0.35KB
auth (useAuth.js) 4.91KB 0.87KB
auth (useIsWorkspaceAdmin.js) 1.61KB 0.85KB
collaboration (CommentThread.js) 18.38KB 4.49KB
collaboration (LiveCursors.js) 3.17KB 1.27KB
collaboration (PresenceAvatars.js) 3.65KB 1.42KB
collaboration (PresenceProvider.js) 2.79KB 1.13KB
collaboration (index.js) 1.25KB 0.53KB
collaboration (useCommentSearch.js) 1.98KB 0.88KB
collaboration (useConflictResolution.js) 7.75KB 1.86KB
collaboration (useMentionNotifications.js) 1.81KB 0.68KB
collaboration (usePresence.js) 6.33KB 1.84KB
collaboration (useRealtimeSubscription.js) 7.91KB 2.01KB
components (index.js) 450.13KB 97.92KB
core (index.js) 2.16KB 0.78KB
create-plugin (index.js) 9.28KB 2.98KB
data-objectstack (index.js) 127.78KB 32.15KB
fields (index.js) 220.19KB 53.95KB
i18n (LocalizationContext.js) 1.76KB 0.96KB
i18n (currency.js) 1.22KB 0.64KB
i18n (i18n.js) 4.32KB 1.77KB
i18n (index.js) 2.46KB 0.96KB
i18n (pickLocalized.js) 1.70KB 0.83KB
i18n (provider.js) 5.37KB 1.72KB
i18n (useObjectLabel.js) 25.17KB 5.80KB
i18n (useSafeTranslation.js) 3.26KB 1.44KB
layout (index.js) 38.45KB 10.67KB
mobile (MobileProvider.js) 0.92KB 0.49KB
mobile (ResponsiveContainer.js) 0.94KB 0.38KB
mobile (breakpoints.js) 1.51KB 0.70KB
mobile (createOfflineDataSource.js) 5.61KB 1.74KB
mobile (index.js) 1.50KB 0.62KB
mobile (offlineQueue.js) 3.91KB 1.35KB
mobile (pwa.js) 0.97KB 0.49KB
mobile (serviceWorker.js) 1.48KB 0.62KB
mobile (serviceWorkerSource.js) 3.41KB 1.48KB
mobile (useBreakpoint.js) 1.54KB 0.65KB
mobile (useGesture.js) 4.42KB 1.27KB
mobile (useOfflineSync.js) 1.99KB 0.72KB
mobile (usePullToRefresh.js) 2.53KB 0.85KB
mobile (useResponsive.js) 0.71KB 0.42KB
mobile (useResponsiveConfig.js) 1.36KB 0.63KB
mobile (useSpecGesture.js) 1.77KB 0.77KB
mobile (useTouchTarget.js) 1.01KB 0.54KB
permissions (MePermissionsProvider.js) 6.84KB 2.42KB
permissions (PermissionContext.js) 0.31KB 0.25KB
permissions (PermissionGuard.js) 0.89KB 0.45KB
permissions (PermissionProvider.js) 3.67KB 1.12KB
permissions (evaluator.js) 4.41KB 1.44KB
permissions (index.js) 0.91KB 0.41KB
permissions (store.js) 0.91KB 0.42KB
permissions (useFieldPermissions.js) 1.28KB 0.52KB
permissions (usePermissions.js) 1.55KB 0.71KB
plugin-ai (index.js) 15.71KB 3.79KB
plugin-calendar (index.js) 44.90KB 12.35KB
plugin-charts (index.js) 57.26KB 16.24KB
plugin-chatbot (index.js) 179.93KB 42.67KB
plugin-dashboard (index.js) 109.60KB 28.33KB
plugin-designer (index.js) 210.56KB 42.56KB
plugin-detail (index.js) 216.77KB 53.01KB
plugin-editor (index.js) 2.46KB 1.10KB
plugin-form (index.js) 103.51KB 25.12KB
plugin-gantt (index.js) 162.26KB 39.53KB
plugin-grid (index.js) 179.35KB 46.97KB
plugin-kanban (index.js) 47.82KB 13.18KB
plugin-list (index.js) 98.55KB 23.28KB
plugin-map (index.js) 16.80KB 5.24KB
plugin-markdown (index.js) 13.65KB 4.67KB
plugin-report (index.js) 37.07KB 9.81KB
plugin-timeline (index.js) 25.03KB 7.11KB
plugin-tree (index.js) 8.36KB 2.81KB
plugin-view (index.js) 85.68KB 20.85KB
providers (DataSourceProvider.js) 0.75KB 0.39KB
providers (MetadataProvider.js) 1.37KB 0.59KB
providers (ThemeProvider.js) 1.55KB 0.67KB
providers (UploadProvider.js) 11.71KB 3.53KB
providers (index.js) 0.44KB 0.22KB
providers (types.js) 0.01KB 0.04KB
react-runtime (index.js) 3.19KB 1.38KB
react (LazyPluginLoader.js) 3.77KB 1.33KB
react (SchemaRenderer.js) 18.70KB 6.09KB
react (data-invalidation.js) 5.05KB 2.08KB
react (index.js) 1.00KB 0.55KB
sdui-parser (codegen.js) 4.09KB 1.74KB
sdui-parser (index.js) 2.16KB 0.94KB
sdui-parser (parse.js) 10.04KB 2.82KB
sdui-parser (types.js) 0.29KB 0.24KB
sdui-parser (validate.js) 4.69KB 1.48KB
types (ai.js) 0.20KB 0.17KB
types (api-types.js) 0.20KB 0.18KB
types (app.js) 2.87KB 0.99KB
types (base.js) 0.20KB 0.18KB
types (blocks.js) 0.20KB 0.18KB
types (complex.js) 0.20KB 0.18KB
types (crud.js) 0.20KB 0.18KB
types (data-display.js) 0.20KB 0.18KB
types (data-protocol.js) 0.20KB 0.19KB
types (data.js) 0.20KB 0.18KB
types (designer.js) 0.77KB 0.41KB
types (disclosure.js) 0.20KB 0.18KB
types (feedback.js) 0.20KB 0.18KB
types (field-types.js) 0.20KB 0.18KB
types (form.js) 0.20KB 0.18KB
types (index.js) 1.86KB 0.91KB
types (layout.js) 0.20KB 0.18KB
types (managed-by.js) 0.19KB 0.18KB
types (mobile.js) 0.20KB 0.18KB
types (navigation.js) 0.20KB 0.18KB
types (objectql.js) 0.20KB 0.18KB
types (overlay.js) 0.20KB 0.18KB
types (permissions.js) 0.20KB 0.18KB
types (plugin-scope.js) 0.20KB 0.18KB
types (record-components.js) 0.20KB 0.19KB
types (record-semantics.js) 1.28KB 0.67KB
types (registry.js) 0.20KB 0.18KB
types (reports.js) 0.20KB 0.18KB
types (spec-report.js) 5.04KB 1.93KB
types (system-fields.js) 2.39KB 1.17KB
types (theme.js) 0.20KB 0.18KB
types (ui-action.js) 0.75KB 0.46KB
types (views.js) 0.20KB 0.18KB
types (widget.js) 0.20KB 0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-zhuang
os-zhuang merged commit b9aae51 into main Jul 28, 2026
16 checks passed
@os-zhuang
os-zhuang deleted the fix/2901-ncontains-secret-inline branch July 28, 2026 17:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant