Skip to content

fix(list,i18n): a 400 from the server no longer reads as "check your connection" - #3066

Merged
os-zhuang merged 1 commit into
mainfrom
claude/check-framework-followup
Jul 30, 2026
Merged

fix(list,i18n): a 400 from the server no longer reads as "check your connection"#3066
os-zhuang merged 1 commit into
mainfrom
claude/check-framework-followup

Conversation

@os-zhuang

Copy link
Copy Markdown
Contributor

The one objectui follow-up needed for this session's framework changes. Found by auditing each merged framework PR against objectui rather than assuming.

The defect

classifyLoadError (ListView.tsx) exists because a 403 used to render the same "check your connection and try again" panel as a genuine outage. Its own doc comment:

A 403 rendered as "check your connection" is indistinguishable from a real outage — users were told to debug their network when the server had (correctly) denied them access.

It made that distinction for 401 and 403, then sent everything else — 4xx included — to the network branch.

A 400 is the server saying it understood the request and will never accept it. Retrying resends the identical bad request, so the connection copy is advice that cannot work. Same mistake, one status code over.

Why now

objectstack-ai/objectstack#4121 made this reachable from ordinary stored metadata: a $filter array that is not a filter AST is now rejected at the protocol with 400 INVALID_FILTER. Previously it reached a driver — and for a lone ['and'] it silently returned every row.

So a view saved with such a filter now answers 400 on every load, and objectui was telling the user to check their network. The server change is right; this is the client half.

The change

A fourth classification, rejected, for status === 400 and for the server's 400-class codes (INVALID_FILTER, UNSUPPORTED_QUERY_PARAM, INVALID_QUERY). Its copy points at the filter rather than the network, and says who can fix it when the view is saved that way:

This view's query was rejected — The server could not process this view's filter or query options. Clearing the filters usually fixes it; if the view is saved this way, an administrator needs to correct it.

403/401 keep priority, so a permission denial can never read as a bad request. That ordering is pinned by a test rather than left to the reading order of the ifs.

All ten locale packs, not just en

The neighbouring panels are translated, and fallbackLng: 'en' would have rendered this one in English beside them — visible only to a non-English user, which is how the two failure modes all-locales-key-parity.test.ts describes stay invisible.

That gate caught a pack I missed: my first pass added nine, because the grep listing them was truncated by a head. The test named fr and the exact two keys.

Verification

  • 5 new tests: numeric httpStatus, an error code with no numeric status, a status embedded in the message text ("HTTP 400 Bad Request — {}"), and a 403/401 ordering guard.
  • Confirmed they have teeth: removing the 400 branch fails 4 of them.
  • plugin-list + i18n: 403 tests across 29 files, green. eslint: 0 errors.

What else was checked, and needed nothing

Framework change objectui impact
objectstack-ai/objectstack#4061 — three orphan vocabularies deleted none — 0 references to any deleted symbol
objectstack-ai/objectstack#4070combo, WidgetActionType = ActionType none — objectui already renders combo; the widget enum widening is what unblocks form, which its dispatcher already implements
objectstack-ai/objectstack#4107saveMeta persists canonical operators none — all three translation tables cover the full canonical vocabulary since #3022
objectstack-ai/objectstack#4153 / #4184 — analytics aggregate + measure fixes noneDatasetWidget already renders a failed query as an error panel, so the new throws surface as a visible message instead of a wrong number
objectstack-ai/objectstack#4135InlineActionSchema none blocking — the ElementButton renderer still forwards actionType/endpoint/navigate/description, which the schema does not declare; trimming them is a narrowing that belongs with the Stage C alias removal

Refs objectstack-ai/objectstack#4121, #2945

🤖 Generated with Claude Code

…connection"

classifyLoadError exists because a 403 rendered the same "check your
connection and try again" panel as a genuine outage — its own doc comment
says users "were told to debug their network when the server had (correctly)
denied them access." It made that distinction for 401 and 403, then sent
everything else, 4xx included, to the network branch.

A 400 is the server saying it understood the request and will never accept
it. Retrying resends the identical bad request, so the connection copy is
advice that cannot work — the same mistake the function exists to prevent,
one status code over.

Reachable from ordinary stored metadata since objectstack#4121: a `$filter`
array that is not a filter AST is now rejected at the protocol with
400 INVALID_FILTER, where it previously reached a driver (and, for a lone
['and'], silently returned every row). A view saved with such a filter now
answers 400 on every load.

Adds a fourth classification, `rejected`, for status 400 and the server's
400-class codes (INVALID_FILTER, UNSUPPORTED_QUERY_PARAM, INVALID_QUERY).
Its copy points at the filter rather than the network and says who can fix
it when the view is saved that way. 403/401 keep priority so a permission
denial can never read as a bad request — pinned by a test.

The two strings go into ALL TEN locale packs, not just en: the neighbouring
panels are translated and fallbackLng would have rendered this one in
English beside them. all-locales-key-parity.test.ts caught the pack I
missed.

5 new tests (numeric status, code without status, status in message text,
403/401 ordering); reverting the branch fails four. plugin-list + i18n:
403 tests / 29 files green.

Refs objectstack-ai/objectstack#4121, #2945

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@vercel

vercel Bot commented Jul 30, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated (UTC)
objectui Ignored Ignored Jul 30, 2026 3:27pm

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

Metric Value Budget
Main entry (gzip) 27.9 KB 350 KB
Entry file index-BuSBy84N.js
Status PASS

📦 Bundle Size Report

Package Size Gzipped
app-shell (index.js) 8.20KB 2.97KB
app-shell (runtime-config.js) 7.42KB 2.32KB
app-shell (types.js) 0.01KB 0.04KB
app-shell (urlParams.js) 7.57KB 2.97KB
auth (AuthContext.js) 0.31KB 0.24KB
auth (AuthGuard.js) 1.17KB 0.53KB
auth (AuthProvider.js) 22.10KB 4.37KB
auth (AuthShell.js) 3.49KB 1.40KB
auth (ForgotPasswordForm.js) 12.12KB 3.41KB
auth (LoginForm.js) 17.86KB 5.29KB
auth (PreviewBanner.js) 0.90KB 0.50KB
auth (RegisterForm.js) 6.43KB 2.09KB
auth (SocialSignInButtons.js) 9.60KB 3.89KB
auth (UserMenu.js) 3.40KB 1.22KB
auth (auth-gate-events.js) 1.29KB 0.66KB
auth (authStyles.js) 5.04KB 1.72KB
auth (createAuthClient.js) 35.76KB 9.11KB
auth (createAuthenticatedFetch.js) 4.37KB 1.69KB
auth (index.js) 2.35KB 1.07KB
auth (org-roles.js) 6.66KB 2.78KB
auth (phone-identifier.js) 1.11KB 0.66KB
auth (types.js) 0.59KB 0.35KB
auth (useAuth.js) 4.91KB 0.87KB
auth (useIsWorkspaceAdmin.js) 1.61KB 0.85KB
collaboration (CommentThread.js) 18.38KB 4.49KB
collaboration (LiveCursors.js) 3.17KB 1.27KB
collaboration (PresenceAvatars.js) 3.65KB 1.42KB
collaboration (PresenceProvider.js) 2.79KB 1.13KB
collaboration (index.js) 1.25KB 0.53KB
collaboration (useCommentSearch.js) 1.98KB 0.88KB
collaboration (useConflictResolution.js) 7.75KB 1.86KB
collaboration (useMentionNotifications.js) 1.81KB 0.68KB
collaboration (usePresence.js) 6.33KB 1.84KB
collaboration (useRealtimeSubscription.js) 7.91KB 2.01KB
components (index.js) 463.63KB 101.25KB
core (index.js) 2.16KB 0.78KB
create-plugin (index.js) 9.28KB 2.98KB
data-objectstack (index.js) 134.67KB 34.24KB
fields (index.js) 222.07KB 54.35KB
i18n (LocalizationContext.js) 1.76KB 0.96KB
i18n (currency.js) 1.22KB 0.64KB
i18n (i18n.js) 4.32KB 1.77KB
i18n (index.js) 2.46KB 0.96KB
i18n (pickLocalized.js) 1.70KB 0.83KB
i18n (provider.js) 5.37KB 1.72KB
i18n (useObjectLabel.js) 25.17KB 5.80KB
i18n (useSafeTranslation.js) 3.26KB 1.44KB
layout (index.js) 38.45KB 10.67KB
mobile (MobileProvider.js) 0.92KB 0.49KB
mobile (ResponsiveContainer.js) 0.94KB 0.38KB
mobile (breakpoints.js) 1.51KB 0.70KB
mobile (createOfflineDataSource.js) 5.61KB 1.74KB
mobile (index.js) 1.50KB 0.62KB
mobile (offlineQueue.js) 3.91KB 1.35KB
mobile (pwa.js) 0.97KB 0.49KB
mobile (serviceWorker.js) 1.48KB 0.62KB
mobile (serviceWorkerSource.js) 3.41KB 1.48KB
mobile (useBreakpoint.js) 1.54KB 0.65KB
mobile (useGesture.js) 6.96KB 1.98KB
mobile (useOfflineSync.js) 1.99KB 0.72KB
mobile (usePullToRefresh.js) 2.53KB 0.85KB
mobile (useResponsive.js) 0.71KB 0.42KB
mobile (useResponsiveConfig.js) 1.36KB 0.63KB
mobile (useSpecGesture.js) 4.05KB 1.53KB
mobile (useTouchTarget.js) 1.01KB 0.54KB
permissions (MePermissionsProvider.js) 8.76KB 3.06KB
permissions (PermissionContext.js) 0.31KB 0.25KB
permissions (PermissionGuard.js) 0.89KB 0.45KB
permissions (PermissionProvider.js) 3.67KB 1.12KB
permissions (evaluator.js) 4.41KB 1.44KB
permissions (index.js) 0.91KB 0.41KB
permissions (retry.js) 3.48KB 1.61KB
permissions (store.js) 0.91KB 0.42KB
permissions (useFieldPermissions.js) 1.28KB 0.52KB
permissions (usePermissions.js) 1.55KB 0.71KB
plugin-ai (index.js) 15.71KB 3.79KB
plugin-calendar (index.js) 44.90KB 12.35KB
plugin-charts (index.js) 60.52KB 17.11KB
plugin-chatbot (index.js) 180.09KB 42.72KB
plugin-dashboard (index.js) 111.59KB 28.74KB
plugin-designer (index.js) 210.51KB 42.50KB
plugin-detail (index.js) 221.81KB 54.28KB
plugin-editor (index.js) 2.46KB 1.10KB
plugin-form (index.js) 110.71KB 26.67KB
plugin-gantt (index.js) 162.26KB 39.53KB
plugin-grid (index.js) 183.94KB 48.25KB
plugin-kanban (index.js) 47.82KB 13.18KB
plugin-list (index.js) 104.07KB 24.88KB
plugin-map (index.js) 16.80KB 5.24KB
plugin-markdown (index.js) 13.65KB 4.67KB
plugin-report (index.js) 40.32KB 10.53KB
plugin-timeline (index.js) 25.75KB 7.32KB
plugin-tree (index.js) 8.36KB 2.81KB
plugin-view (index.js) 85.95KB 21.02KB
providers (DataSourceProvider.js) 0.75KB 0.39KB
providers (MetadataProvider.js) 1.37KB 0.59KB
providers (ThemeProvider.js) 1.90KB 0.85KB
providers (UploadProvider.js) 11.71KB 3.53KB
providers (index.js) 0.44KB 0.22KB
providers (types.js) 0.01KB 0.04KB
react-runtime (index.js) 5.67KB 2.37KB
react (LazyPluginLoader.js) 3.77KB 1.33KB
react (SchemaRenderer.js) 19.28KB 6.38KB
react (data-invalidation.js) 5.05KB 2.08KB
react (index.js) 1.02KB 0.55KB
sdui-parser (codegen.js) 4.09KB 1.74KB
sdui-parser (index.js) 3.47KB 1.54KB
sdui-parser (parse.js) 10.04KB 2.82KB
sdui-parser (types.js) 0.29KB 0.24KB
sdui-parser (validate.js) 4.69KB 1.48KB
types (ai.js) 0.20KB 0.17KB
types (api-types.js) 0.20KB 0.18KB
types (app.js) 2.87KB 0.99KB
types (base.js) 0.20KB 0.18KB
types (blocks.js) 0.20KB 0.18KB
types (complex.js) 0.20KB 0.18KB
types (crud.js) 0.20KB 0.18KB
types (data-display.js) 0.20KB 0.18KB
types (data-protocol.js) 0.20KB 0.19KB
types (data.js) 0.20KB 0.18KB
types (designer.js) 1.87KB 0.85KB
types (disclosure.js) 0.20KB 0.18KB
types (error-code.js) 1.54KB 0.88KB
types (feedback.js) 0.20KB 0.18KB
types (field-types.js) 0.20KB 0.18KB
types (form.js) 0.20KB 0.18KB
types (index.js) 2.07KB 0.99KB
types (layout.js) 0.20KB 0.18KB
types (managed-by.js) 0.19KB 0.18KB
types (mobile.js) 0.20KB 0.18KB
types (navigation.js) 0.20KB 0.18KB
types (objectql.js) 0.20KB 0.18KB
types (overlay.js) 0.20KB 0.18KB
types (permissions.js) 0.20KB 0.18KB
types (plugin-scope.js) 0.20KB 0.18KB
types (record-components.js) 0.20KB 0.19KB
types (record-semantics.js) 1.28KB 0.67KB
types (registry.js) 0.20KB 0.18KB
types (reports.js) 0.20KB 0.18KB
types (spec-report.js) 5.04KB 1.93KB
types (system-fields.js) 3.33KB 1.54KB
types (theme.js) 0.20KB 0.18KB
types (ui-action.js) 1.08KB 0.64KB
types (views.js) 0.20KB 0.18KB
types (widget.js) 0.20KB 0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-zhuang
os-zhuang merged commit d21794c into main Jul 30, 2026
16 checks passed
@os-zhuang
os-zhuang deleted the claude/check-framework-followup branch July 30, 2026 15:33
os-zhuang added a commit that referenced this pull request Jul 31, 2026
…ther the query expands a lookup (#3084)

#3072 single-sourced the ARRAY branch of the adapter's two `find()` routes. The
object branch was left as it was: `convertQueryParams` converted a MongoDB-style
filter to AST while `translateFilterToAST` returned it verbatim — so the same
`$filter` went out in two formats, decided by whether the query happened to
expand a lookup.

Measured across 21 operator shapes, four diverged. Most of the gap turned out to
be harmless, which is worth recording because it was not obvious: `{$and: […]}`
survives the plain route as a `['$and','=',[…]]` comparison that `parseFilterAST`
reads back as a real `$and`, and `$exists` vs `$null` is a difference the server
treats identically. Two were not harmless:

- THE UNKNOWN-OPERATOR GUARD ONLY RAN ON ONE ROUTE. `convertFiltersToAST` throws
  on an unrecognised operator, with a comment saying it does so "to avoid silent
  failure" — but the expanded route never called it, so a typo'd operator threw
  on a plain read and shipped silently whenever a lookup was expanded.

- `$regex` WAS SILENTLY REWRITTEN TO `contains`. The existing test's own example
  makes the case: `$regex: '^John'` means "starts with John", while
  `contains '^John'` looks for a literal caret — so "John Smith" does not match.
  A different question, not a weaker version of the same one, and neither result
  looks wrong on screen. The rewrite sat behind a `console.warn`, which is not
  an error channel in a deployed app, and the function's own unknown-operator
  message never listed `$regex` among the supported set. The spec has no
  `$regex` (`FILTER_OPERATORS`, data/filter.zod.ts), so there is nothing to
  translate it into: it is refused now, the same treatment the neighbouring
  unknown operator already got. Nothing in the repo depended on the conversion.

Both refusals throw `FilterOperatorError` carrying `code: 'INVALID_FILTER'` /
`httpStatus: 400`. The pre-existing unknown-operator throw was a bare `Error`,
which `classifyLoadError` reads as a network fault — so a malformed filter told
the user to check their connection (#3066), the one thing it was not.

`filter-converter.test.ts`'s `$regex` case asserted the old behaviour and is
rewritten to assert the refusal, keeping the `'^John'` example because it
demonstrates the harm better than any prose.

Verification: 9 new/changed tests; reverting the two source files fails 9 of
them. Full suite 762 files / 8875 tests green; tsc clean; eslint 0 errors.

Co-authored-by: Jack Zhuang <277994282+os-zhuang@users.noreply.github.com>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant