Skip to content

fix(chatbot): read the agent catalog in the declared envelope too (objectstack#4053) - #2992

Merged
os-zhuang merged 1 commit into
mainfrom
claude/envelope-drift-route-modules-v2zoky
Jul 30, 2026
Merged

fix(chatbot): read the agent catalog in the declared envelope too (objectstack#4053)#2992
os-zhuang merged 1 commit into
mainfrom
claude/envelope-drift-route-modules-v2zoky

Conversation

@os-zhuang

Copy link
Copy Markdown
Contributor

Defuses objectstack#4053 from the consumer side — single repo, no cross-repo coordination, safe to land before anything on the server moves.

Why this route is special

GET /api/v1/ai/agents is served by two producers (the framework dispatcher's degraded fallback when no AI service is registered, and cloud's service-ai) and is one of the last SDK-addressable routes still answering outside the declared { success: true, data } envelope. useAgents read only { agents } and a bare array, so the day either producer converts, the parse misses.

On most routes a missed parse is a visible bug. Here it is invisible, and that asymmetry is the whole argument for doing this first.

useAiSurfaceEnabled gates the entire AI surface on agents.length > 0 — deliberately, and its own header explains why: the route is access-filtered per caller, making it the only signal that is both edition- and user-aware (ADR-0068). A user without the ai_seat permission gets an empty catalog and the AI UI hides, instead of showing a button that 403s on click.

So an empty list is a correct, expected answer. Which means a parse miss and the legitimate hidden state are indistinguishable:

what the user sees
seat-less user (correct) no FAB, no top-bar link, no "Ask AI"
CE deployment, no service-ai (correct) same
parse missed the new envelope (bug) same

No error, no 403, no failed request, no log line. Nothing downstream would catch it.

The change

extractAgentList folds four shapes to one list:

[ … ]                                   bare array
{ agents: [ … ] }                       today, both producers
{ success: true, data: [ … ] }          the envelope, payload directly — the
                                        shape objectstack#3983 set as precedent
{ success: true, data: { agents: … } }  the envelope, payload relocated

The envelope is detected the way ObjectStackClient.unwrapResponse detects it — a boolean success — so the two readers can't disagree about what counts as one. Pure and exported, so the shapes are testable without standing up the hook.

No behaviour change against any server shipping today: the two shapes that worked before parse identically. This only removes the lockstep requirement, so the server can convert on its own schedule instead of having to land with a console release — the same consumer-first ordering I used for SharedRecordPage in objectstack#3983.

Correction to objectstack#4053

While verifying this I found the issue named the wrong exposure path, and I'll fix it there too. It said the risk sat in client.ai.agents.list()'s body?.agents compensation. That SDK method has zero callers in objectui and cloud — the only cloud hits are the route-ledger declaration and its conformance test. The real exposure is this file's own fetch.

Worth calling out because the error pointed the wrong way: someone following the issue would check the SDK, see nothing calls it, conclude "low risk", and skip exactly the path that matters.

Verification

gate result
vitest run agentListShapes 9 passed
agentAliases · agentCapabilities (neighbours) 29 passed total, no regressions
tests are load-bearing reverting to the two-shape read → 5 of 9 fail
turbo run type-check --filter=@object-ui/plugin-chatbot 9 tasks, clean
eslint 0 errors, 0 new warnings (2 remain, both pre-existing in the hook body)

Generated by Claude Code

…jectstack#4053)

`GET /api/v1/ai/agents` is served by two producers — the framework dispatcher's
degraded fallback when no AI service is registered, and cloud's service-ai — and
it is one of the last SDK-addressable routes still answering outside the declared
`{ success: true, data }` envelope. useAgents read only `{ agents }` and a bare
array, so the day either producer converts, the parse misses.

That miss is unusually dangerous here, which is why it is worth getting ahead of
rather than fixing after. The catalog is not just data: useAiSurfaceEnabled gates
the ENTIRE AI surface on `agents.length > 0`, because the route is access-filtered
per caller and is therefore the only signal that is both edition- and user-aware
(ADR-0068). An empty list is the correct answer for a seat-less user or a
Community-Edition deployment with no service-ai — so a parse miss and the
legitimate hidden state are indistinguishable: no error, no 403, no log, just the
FAB, the top-bar link and the designer's "Ask AI" quietly gone for every user.
Nothing downstream would catch it.

extractAgentList now folds all four shapes to the same list — bare array,
`{ agents }`, `{ success: true, data: [...] }`, `{ success: true, data: { agents } }`
— detecting the envelope the way ObjectStackClient.unwrapResponse does (a BOOLEAN
`success`), so the two readers cannot disagree about what counts as one. It is
exported and pure so the shapes are testable without standing up the hook.

No behaviour change against any server shipping today: the shapes that worked
before parse identically. This only removes the lockstep requirement, so the
server side can convert on its own schedule instead of having to land with a
console release — the same consumer-first ordering used for SharedRecordPage in
objectstack#3983.

Nine tests; reverting to the previous two-shape read fails five of them.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CYbS3kS8xzsHNXFTzp4e2z
@vercel

vercel Bot commented Jul 30, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated (UTC)
objectui Ignored Ignored Jul 30, 2026 7:47am

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

Metric Value Budget
Main entry (gzip) 27.9 KB 350 KB
Entry file index-bW6VnhSl.js
Status PASS

📦 Bundle Size Report

Package Size Gzipped
app-shell (index.js) 8.20KB 2.97KB
app-shell (runtime-config.js) 7.42KB 2.32KB
app-shell (types.js) 0.01KB 0.04KB
app-shell (urlParams.js) 7.57KB 2.97KB
auth (AuthContext.js) 0.31KB 0.24KB
auth (AuthGuard.js) 1.17KB 0.53KB
auth (AuthProvider.js) 22.10KB 4.37KB
auth (AuthShell.js) 3.49KB 1.40KB
auth (ForgotPasswordForm.js) 12.12KB 3.41KB
auth (LoginForm.js) 17.86KB 5.29KB
auth (PreviewBanner.js) 0.90KB 0.50KB
auth (RegisterForm.js) 6.43KB 2.09KB
auth (SocialSignInButtons.js) 9.60KB 3.89KB
auth (UserMenu.js) 3.40KB 1.22KB
auth (auth-gate-events.js) 1.29KB 0.66KB
auth (authStyles.js) 5.04KB 1.72KB
auth (createAuthClient.js) 35.76KB 9.11KB
auth (createAuthenticatedFetch.js) 4.37KB 1.69KB
auth (index.js) 2.25KB 1.01KB
auth (org-roles.js) 6.72KB 2.85KB
auth (phone-identifier.js) 1.11KB 0.66KB
auth (types.js) 0.59KB 0.35KB
auth (useAuth.js) 4.91KB 0.87KB
auth (useIsWorkspaceAdmin.js) 1.61KB 0.85KB
collaboration (CommentThread.js) 18.38KB 4.49KB
collaboration (LiveCursors.js) 3.17KB 1.27KB
collaboration (PresenceAvatars.js) 3.65KB 1.42KB
collaboration (PresenceProvider.js) 2.79KB 1.13KB
collaboration (index.js) 1.25KB 0.53KB
collaboration (useCommentSearch.js) 1.98KB 0.88KB
collaboration (useConflictResolution.js) 7.75KB 1.86KB
collaboration (useMentionNotifications.js) 1.81KB 0.68KB
collaboration (usePresence.js) 6.33KB 1.84KB
collaboration (useRealtimeSubscription.js) 7.91KB 2.01KB
components (index.js) 450.83KB 98.17KB
core (index.js) 2.16KB 0.78KB
create-plugin (index.js) 9.28KB 2.98KB
data-objectstack (index.js) 134.67KB 34.24KB
fields (index.js) 221.10KB 54.18KB
i18n (LocalizationContext.js) 1.76KB 0.96KB
i18n (currency.js) 1.22KB 0.64KB
i18n (i18n.js) 4.32KB 1.77KB
i18n (index.js) 2.46KB 0.96KB
i18n (pickLocalized.js) 1.70KB 0.83KB
i18n (provider.js) 5.37KB 1.72KB
i18n (useObjectLabel.js) 25.17KB 5.80KB
i18n (useSafeTranslation.js) 3.26KB 1.44KB
layout (index.js) 38.45KB 10.67KB
mobile (MobileProvider.js) 0.92KB 0.49KB
mobile (ResponsiveContainer.js) 0.94KB 0.38KB
mobile (breakpoints.js) 1.51KB 0.70KB
mobile (createOfflineDataSource.js) 5.61KB 1.74KB
mobile (index.js) 1.50KB 0.62KB
mobile (offlineQueue.js) 3.91KB 1.35KB
mobile (pwa.js) 0.97KB 0.49KB
mobile (serviceWorker.js) 1.48KB 0.62KB
mobile (serviceWorkerSource.js) 3.41KB 1.48KB
mobile (useBreakpoint.js) 1.54KB 0.65KB
mobile (useGesture.js) 4.42KB 1.27KB
mobile (useOfflineSync.js) 1.99KB 0.72KB
mobile (usePullToRefresh.js) 2.53KB 0.85KB
mobile (useResponsive.js) 0.71KB 0.42KB
mobile (useResponsiveConfig.js) 1.36KB 0.63KB
mobile (useSpecGesture.js) 1.77KB 0.77KB
mobile (useTouchTarget.js) 1.01KB 0.54KB
permissions (MePermissionsProvider.js) 6.84KB 2.42KB
permissions (PermissionContext.js) 0.31KB 0.25KB
permissions (PermissionGuard.js) 0.89KB 0.45KB
permissions (PermissionProvider.js) 3.67KB 1.12KB
permissions (evaluator.js) 4.41KB 1.44KB
permissions (index.js) 0.91KB 0.41KB
permissions (store.js) 0.91KB 0.42KB
permissions (useFieldPermissions.js) 1.28KB 0.52KB
permissions (usePermissions.js) 1.55KB 0.71KB
plugin-ai (index.js) 15.71KB 3.79KB
plugin-calendar (index.js) 44.90KB 12.35KB
plugin-charts (index.js) 57.26KB 16.24KB
plugin-chatbot (index.js) 180.09KB 42.72KB
plugin-dashboard (index.js) 109.60KB 28.33KB
plugin-designer (index.js) 210.56KB 42.56KB
plugin-detail (index.js) 216.52KB 53.02KB
plugin-editor (index.js) 2.46KB 1.10KB
plugin-form (index.js) 103.45KB 25.12KB
plugin-gantt (index.js) 162.26KB 39.53KB
plugin-grid (index.js) 179.45KB 47.03KB
plugin-kanban (index.js) 47.82KB 13.18KB
plugin-list (index.js) 98.30KB 23.23KB
plugin-map (index.js) 16.80KB 5.24KB
plugin-markdown (index.js) 13.65KB 4.67KB
plugin-report (index.js) 37.77KB 10.00KB
plugin-timeline (index.js) 25.03KB 7.11KB
plugin-tree (index.js) 8.36KB 2.81KB
plugin-view (index.js) 85.47KB 20.82KB
providers (DataSourceProvider.js) 0.75KB 0.39KB
providers (MetadataProvider.js) 1.37KB 0.59KB
providers (ThemeProvider.js) 1.55KB 0.67KB
providers (UploadProvider.js) 11.71KB 3.53KB
providers (index.js) 0.44KB 0.22KB
providers (types.js) 0.01KB 0.04KB
react-runtime (index.js) 5.67KB 2.37KB
react (LazyPluginLoader.js) 3.77KB 1.33KB
react (SchemaRenderer.js) 19.28KB 6.38KB
react (data-invalidation.js) 5.05KB 2.08KB
react (index.js) 1.02KB 0.55KB
sdui-parser (codegen.js) 4.09KB 1.74KB
sdui-parser (index.js) 3.47KB 1.54KB
sdui-parser (parse.js) 10.04KB 2.82KB
sdui-parser (types.js) 0.29KB 0.24KB
sdui-parser (validate.js) 4.69KB 1.48KB
types (ai.js) 0.20KB 0.17KB
types (api-types.js) 0.20KB 0.18KB
types (app.js) 2.87KB 0.99KB
types (base.js) 0.20KB 0.18KB
types (blocks.js) 0.20KB 0.18KB
types (complex.js) 0.20KB 0.18KB
types (crud.js) 0.20KB 0.18KB
types (data-display.js) 0.20KB 0.18KB
types (data-protocol.js) 0.20KB 0.19KB
types (data.js) 0.20KB 0.18KB
types (designer.js) 0.77KB 0.41KB
types (disclosure.js) 0.20KB 0.18KB
types (error-code.js) 1.54KB 0.88KB
types (feedback.js) 0.20KB 0.18KB
types (field-types.js) 0.20KB 0.18KB
types (form.js) 0.20KB 0.18KB
types (index.js) 1.92KB 0.93KB
types (layout.js) 0.20KB 0.18KB
types (managed-by.js) 0.19KB 0.18KB
types (mobile.js) 0.20KB 0.18KB
types (navigation.js) 0.20KB 0.18KB
types (objectql.js) 0.20KB 0.18KB
types (overlay.js) 0.20KB 0.18KB
types (permissions.js) 0.20KB 0.18KB
types (plugin-scope.js) 0.20KB 0.18KB
types (record-components.js) 0.20KB 0.19KB
types (record-semantics.js) 1.28KB 0.67KB
types (registry.js) 0.20KB 0.18KB
types (reports.js) 0.20KB 0.18KB
types (spec-report.js) 5.04KB 1.93KB
types (system-fields.js) 2.39KB 1.17KB
types (theme.js) 0.20KB 0.18KB
types (ui-action.js) 0.75KB 0.46KB
types (views.js) 0.20KB 0.18KB
types (widget.js) 0.20KB 0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-zhuang
os-zhuang marked this pull request as ready for review July 30, 2026 07:56
@os-zhuang
os-zhuang merged commit 9a13622 into main Jul 30, 2026
16 checks passed
@os-zhuang
os-zhuang deleted the claude/envelope-drift-route-modules-v2zoky branch July 30, 2026 07:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants