Skip to content

fix(types): Page/App/Dashboard validate the spec's own fields instead of passing them through (#4115 C 组) - #3063

Merged
os-zhuang merged 1 commit into
mainfrom
claude/spec-debt-passthrough-groupc
Jul 30, 2026
Merged

fix(types): Page/App/Dashboard validate the spec's own fields instead of passing them through (#4115 C 组)#3063
os-zhuang merged 1 commit into
mainfrom
claude/spec-debt-passthrough-groupc

Conversation

@os-zhuang

Copy link
Copy Markdown
Contributor

承 objectstack#4115 分诊评论里划出的 C 组 —— 该组的选择理由是:它是 #4120 失效形态在 objectui 的等价物,且不需要任何重命名决策(A 组要改公开导出名,B 组要先定 type 判别式的命名约定)。

问题:.passthrough() 遇上 .strict()

AppSchema/DashboardSchema/PageSchemaextendBaseSchema,而后者是 .passthrough();spec 侧对应的三个是 strict。结果是 spec 独有的键完全不经校验穿过去:

节点 未校验的 spec 键 数量
App branding sharing embed objects apis requiredPermissions homePageId protection + _lock*/_package*/_provenance 整个包锁封套 23
Dashboard header refreshInterval performance aria protection + 包锁封套 10
Page interfaceConfig kind slots source requires aria 6

brading: {…}branding: {…} 在校验层面无从区分 —— 这正是 #4120 抓到的那类静默失效。

Page 还带一个活的后果:source 从未被声明,而 kind: 'html' | 'react' 的页面正是把正文放在 source 里的 —— 也就是说这类页面在这里根本无法表达

修法:不是 .strict(),是把 spec 的字段按引用引进来

.strict() 是错的 —— 这三个是组件节点,开放封套是有意为之(渲染器属性本就该穿透)。正解是让 spec 自己的字段按引用流入,也就是 zod/objectql.zod.tsListViewSchema 已经在用的范式。

新增 specFieldsExcept()(base.zod.ts)承载这个模式。它读 .shape 而不是调 SpecSchema.omit({…}).partial(),因为 zod 4 拒绝对带 refinement 的对象 .omit() —— spec 的 PageSchema 恰好有一个,惯用写法会在 import 期直接抛异常。这个坑记在 helper 的文档注释里(踩过一次就够了)。

每处 omit 都在原地写明理由:

  • name/label/description → 组件外壳,归 BaseSchema;
  • Page 的 type 是真冲突:spec 的 type 是页面种类(record|app|utility|list|home),objectui 的是组件判别式('page'),种类被放在 pageType。二者的调和是 B 组的重命名决策,本 PR 不动;
  • 各自的元素 schema(navigation/areas/contextSelectorswidgets/globalFilters/dateRangeregions)本身就是台账里独立的条目,保持本地、迁移另议。

.partial() 保证未来任何 spec 字段变成必填都不会让已存的 objectui 载荷失效

闸门与变异测试

新增 page-app-dashboard-spec-parity.test.ts(19 断言),三个方向:spec 长出未分诊字段 / spec 重命名被本地覆盖的锚点 / 有人加了未分诊的本地键。另有一组断言直接钉住「这些键现在真的被校验了」——例如 branding: 'blue'通过变成拒绝,kind: 'nonsense' 从通过变成拒绝,以及 kind:'html' + source 现在能正常表达。

变异测试(两个方向都会红):

  • 从 App 的派生里偷偷 omit 掉 branding3 个测试按名报红(expected [ 'branding' ] to deeply equal []'branding' is still undeclared、以及 branding 校验断言);
  • 给 Page 加一个未登记的本地键 → rogue-key 断言报红(expected [ 'myUntriagedField' ] to deeply equal [])。

验证

全仓 type-check 78/78 绿;@object-ui/types 271 断言绿;下游消费方(app-shell / plugin-dashboard / plugin-list / core)3626 断言绿 —— 确认收紧校验没有挡住任何现有渲染路径。另有一组断言专门守住「组件外壳仍然放行未知渲染器属性」,即这次收紧的只是 spec 拥有的那部分,节点本身没有被关上。

🤖 Generated with Claude Code

… of passing them through (objectstack#4115 group C)

These three renderer nodes extend BaseSchema, which is `.passthrough()`,
while their spec counterparts are strict. Every spec-only key therefore
rode through objectui completely unvalidated — 23 on App (`branding`,
`sharing`, `embed`, `objects`, `apis`, `requiredPermissions`,
`homePageId`, `protection`, the whole `_lock*`/`_package*`/`_provenance`
package envelope), 10 on Dashboard (`header`, `refreshInterval`,
`performance`, `aria`, `protection`, …) and 6 on Page (`interfaceConfig`,
`kind`, `slots`, `source`, `requires`, `aria`). A typo in any of them
(`brading: {…}`) was indistinguishable from the real key. This is the
objectstack#4120 silent-drop failure mode, objectui side.

Page carried a live consequence: `source` was never declared, so a
`kind: 'html' | 'react'` page — whose body lives in `source` — could not
be expressed at all.

The fix is NOT `.strict()`: these are component nodes and the open
envelope is deliberate. Spec fields now flow in **by reference**, the
pattern `zod/objectql.zod.ts`'s ListViewSchema already uses, via a new
`specFieldsExcept()` helper in base.zod.ts. The helper reads `.shape`
rather than calling `SpecSchema.omit({…}).partial()` because zod 4
refuses `.omit()` on an object carrying refinements — spec's PageSchema
has one, so the idiomatic form throws at import time.

Each omission is documented at its site: component-envelope keys go to
BaseSchema; Page's `type` genuinely collides (spec's is the page KIND,
objectui's is the component discriminator and the kind lives on
`pageType`); and the element schemas that are their own ledger entries
(navigation/areas/contextSelectors, widgets/globalFilters/dateRange,
regions) stay local with the migration deferred.

`.partial()` on the imported shape guarantees no future spec field can
become required and invalidate payloads already stored.

Mutation-tested: dropping a spec field from a derivation fails 3 tests by
name, and adding an untriaged objectui-only key fails the rogue-key
assertion. 78/78 type-check, 271 types + 3626 downstream assertions green.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@vercel

vercel Bot commented Jul 30, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated (UTC)
objectui Ignored Ignored Jul 30, 2026 3:06pm

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

Metric Value Budget
Main entry (gzip) 27.9 KB 350 KB
Entry file index-6r5mn9Wh.js
Status PASS

📦 Bundle Size Report

Package Size Gzipped
app-shell (index.js) 8.20KB 2.97KB
app-shell (runtime-config.js) 7.42KB 2.32KB
app-shell (types.js) 0.01KB 0.04KB
app-shell (urlParams.js) 7.57KB 2.97KB
auth (AuthContext.js) 0.31KB 0.24KB
auth (AuthGuard.js) 1.17KB 0.53KB
auth (AuthProvider.js) 22.10KB 4.37KB
auth (AuthShell.js) 3.49KB 1.40KB
auth (ForgotPasswordForm.js) 12.12KB 3.41KB
auth (LoginForm.js) 17.86KB 5.29KB
auth (PreviewBanner.js) 0.90KB 0.50KB
auth (RegisterForm.js) 6.43KB 2.09KB
auth (SocialSignInButtons.js) 9.60KB 3.89KB
auth (UserMenu.js) 3.40KB 1.22KB
auth (auth-gate-events.js) 1.29KB 0.66KB
auth (authStyles.js) 5.04KB 1.72KB
auth (createAuthClient.js) 35.76KB 9.11KB
auth (createAuthenticatedFetch.js) 4.37KB 1.69KB
auth (index.js) 2.35KB 1.07KB
auth (org-roles.js) 6.66KB 2.78KB
auth (phone-identifier.js) 1.11KB 0.66KB
auth (types.js) 0.59KB 0.35KB
auth (useAuth.js) 4.91KB 0.87KB
auth (useIsWorkspaceAdmin.js) 1.61KB 0.85KB
collaboration (CommentThread.js) 18.38KB 4.49KB
collaboration (LiveCursors.js) 3.17KB 1.27KB
collaboration (PresenceAvatars.js) 3.65KB 1.42KB
collaboration (PresenceProvider.js) 2.79KB 1.13KB
collaboration (index.js) 1.25KB 0.53KB
collaboration (useCommentSearch.js) 1.98KB 0.88KB
collaboration (useConflictResolution.js) 7.75KB 1.86KB
collaboration (useMentionNotifications.js) 1.81KB 0.68KB
collaboration (usePresence.js) 6.33KB 1.84KB
collaboration (useRealtimeSubscription.js) 7.91KB 2.01KB
components (index.js) 458.88KB 100.29KB
core (index.js) 2.16KB 0.78KB
create-plugin (index.js) 9.28KB 2.98KB
data-objectstack (index.js) 134.67KB 34.24KB
fields (index.js) 222.07KB 54.35KB
i18n (LocalizationContext.js) 1.76KB 0.96KB
i18n (currency.js) 1.22KB 0.64KB
i18n (i18n.js) 4.32KB 1.77KB
i18n (index.js) 2.46KB 0.96KB
i18n (pickLocalized.js) 1.70KB 0.83KB
i18n (provider.js) 5.37KB 1.72KB
i18n (useObjectLabel.js) 25.17KB 5.80KB
i18n (useSafeTranslation.js) 3.26KB 1.44KB
layout (index.js) 38.45KB 10.67KB
mobile (MobileProvider.js) 0.92KB 0.49KB
mobile (ResponsiveContainer.js) 0.94KB 0.38KB
mobile (breakpoints.js) 1.51KB 0.70KB
mobile (createOfflineDataSource.js) 5.61KB 1.74KB
mobile (index.js) 1.50KB 0.62KB
mobile (offlineQueue.js) 3.91KB 1.35KB
mobile (pwa.js) 0.97KB 0.49KB
mobile (serviceWorker.js) 1.48KB 0.62KB
mobile (serviceWorkerSource.js) 3.41KB 1.48KB
mobile (useBreakpoint.js) 1.54KB 0.65KB
mobile (useGesture.js) 6.96KB 1.98KB
mobile (useOfflineSync.js) 1.99KB 0.72KB
mobile (usePullToRefresh.js) 2.53KB 0.85KB
mobile (useResponsive.js) 0.71KB 0.42KB
mobile (useResponsiveConfig.js) 1.36KB 0.63KB
mobile (useSpecGesture.js) 4.05KB 1.53KB
mobile (useTouchTarget.js) 1.01KB 0.54KB
permissions (MePermissionsProvider.js) 8.76KB 3.06KB
permissions (PermissionContext.js) 0.31KB 0.25KB
permissions (PermissionGuard.js) 0.89KB 0.45KB
permissions (PermissionProvider.js) 3.67KB 1.12KB
permissions (evaluator.js) 4.41KB 1.44KB
permissions (index.js) 0.91KB 0.41KB
permissions (retry.js) 3.48KB 1.61KB
permissions (store.js) 0.91KB 0.42KB
permissions (useFieldPermissions.js) 1.28KB 0.52KB
permissions (usePermissions.js) 1.55KB 0.71KB
plugin-ai (index.js) 15.71KB 3.79KB
plugin-calendar (index.js) 44.90KB 12.35KB
plugin-charts (index.js) 60.52KB 17.11KB
plugin-chatbot (index.js) 180.09KB 42.72KB
plugin-dashboard (index.js) 111.59KB 28.74KB
plugin-designer (index.js) 210.51KB 42.50KB
plugin-detail (index.js) 221.81KB 54.28KB
plugin-editor (index.js) 2.46KB 1.10KB
plugin-form (index.js) 110.71KB 26.67KB
plugin-gantt (index.js) 162.26KB 39.53KB
plugin-grid (index.js) 183.80KB 48.21KB
plugin-kanban (index.js) 47.82KB 13.18KB
plugin-list (index.js) 103.56KB 24.66KB
plugin-map (index.js) 16.80KB 5.24KB
plugin-markdown (index.js) 13.65KB 4.67KB
plugin-report (index.js) 40.32KB 10.53KB
plugin-timeline (index.js) 25.75KB 7.32KB
plugin-tree (index.js) 8.36KB 2.81KB
plugin-view (index.js) 85.95KB 21.02KB
providers (DataSourceProvider.js) 0.75KB 0.39KB
providers (MetadataProvider.js) 1.37KB 0.59KB
providers (ThemeProvider.js) 1.90KB 0.85KB
providers (UploadProvider.js) 11.71KB 3.53KB
providers (index.js) 0.44KB 0.22KB
providers (types.js) 0.01KB 0.04KB
react-runtime (index.js) 5.67KB 2.37KB
react (LazyPluginLoader.js) 3.77KB 1.33KB
react (SchemaRenderer.js) 19.28KB 6.38KB
react (data-invalidation.js) 5.05KB 2.08KB
react (index.js) 1.02KB 0.55KB
sdui-parser (codegen.js) 4.09KB 1.74KB
sdui-parser (index.js) 3.47KB 1.54KB
sdui-parser (parse.js) 10.04KB 2.82KB
sdui-parser (types.js) 0.29KB 0.24KB
sdui-parser (validate.js) 4.69KB 1.48KB
types (ai.js) 0.20KB 0.17KB
types (api-types.js) 0.20KB 0.18KB
types (app.js) 2.87KB 0.99KB
types (base.js) 0.20KB 0.18KB
types (blocks.js) 0.20KB 0.18KB
types (complex.js) 0.20KB 0.18KB
types (crud.js) 0.20KB 0.18KB
types (data-display.js) 0.20KB 0.18KB
types (data-protocol.js) 0.20KB 0.19KB
types (data.js) 0.20KB 0.18KB
types (designer.js) 1.87KB 0.85KB
types (disclosure.js) 0.20KB 0.18KB
types (error-code.js) 1.54KB 0.88KB
types (feedback.js) 0.20KB 0.18KB
types (field-types.js) 0.20KB 0.18KB
types (form.js) 0.20KB 0.18KB
types (index.js) 2.07KB 0.99KB
types (layout.js) 0.20KB 0.18KB
types (managed-by.js) 0.19KB 0.18KB
types (mobile.js) 0.20KB 0.18KB
types (navigation.js) 0.20KB 0.18KB
types (objectql.js) 0.20KB 0.18KB
types (overlay.js) 0.20KB 0.18KB
types (permissions.js) 0.20KB 0.18KB
types (plugin-scope.js) 0.20KB 0.18KB
types (record-components.js) 0.20KB 0.19KB
types (record-semantics.js) 1.28KB 0.67KB
types (registry.js) 0.20KB 0.18KB
types (reports.js) 0.20KB 0.18KB
types (spec-report.js) 5.04KB 1.93KB
types (system-fields.js) 3.33KB 1.54KB
types (theme.js) 0.20KB 0.18KB
types (ui-action.js) 1.08KB 0.64KB
types (views.js) 0.20KB 0.18KB
types (widget.js) 0.20KB 0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-zhuang
os-zhuang merged commit 6b83a55 into main Jul 30, 2026
16 checks passed
@os-zhuang
os-zhuang deleted the claude/spec-debt-passthrough-groupc branch July 30, 2026 15:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant