Skip to content

fix(data-objectstack): validate the ADR-0010 protection envelope at the layered() boundary - #6061

Merged
yinlianghui merged 1 commit into
mainfrom
claude/issue-5676-layered-envelope-boundary-parse
Aug 24, 2026
Merged

fix(data-objectstack): validate the ADR-0010 protection envelope at the layered() boundary#6061
yinlianghui merged 1 commit into
mainfrom
claude/issue-5676-layered-envelope-boundary-parse

Conversation

@yinlianghui

Copy link
Copy Markdown
Collaborator

Fixes #5676

Carries triage's answer rather than re-opening the card's question: pass through and label, now validated at the boundary — extending to the whole ADR-0010 envelope the treatment #5672 already chose for lock.

What changed

MetadataClient.layered() now runs GetMetaItemLayeredResponseSchema.safeParse on the response body.

  • Conforming path — every value is the producer's schema output, and the ten as assertions that block carried are gone. (code / overlay / effective stay asserted: upstream declares them z.unknown() and T is the caller's own narrowing, which no schema here can check.)
  • Failure path — degrade and label. Values the schema rejects are still forwarded; dropping them would be the reject semantics the card refused, wearing different clothes. They are named in a new optional MetadataLayered._unrecognized, absent whenever everything parsed.
  • safeParse, never parse, and no try/catch anywhere near it.

The lock-banner consumer is untouched — its unrecognised-token title from #5672 already labels the value, and the boundary's job was to keep forwarding it. The labelling half did not demand an edit there.

PM mechanism assumptions — measured

1. Two days of drift. packages/data-objectstack/src/metadata-client.ts has had no commits since the card was filed (last touch 9e725e06a, unrelated). All three re-derivations hold on the merge-base: the cast sites (in fact ten, not seven — the card's seven are the vocabulary-bearing ones; lockReason / lockDocsUrl / packageId / packageVersion are the four free-string casts alongside them), the isLocked gate at ResourceEditPage.tsx:1547, and #5672's labelling mechanism (lockBannerTitle, tFormat('engine.edit.lockUnknown', …, { state: String(lock) })). #5672's pattern has not been generalised, so the fix is not smaller.

2. The spec schema. Installed spec is 17.2.0, not the 17.1.0 the card names — no impact, the schema is present and reachable. GetMetaItemLayeredResponseSchema is exported from @objectstack/spec/api and declares all seven ruled fields plus the four string ones. No split, nothing invented. Note the four resolved verdicts (lock / editable / deletable / resettable) are required on this path, tightened from the optional MetadataProtectionEnvelopeFields mixin.

3. The labelling convention. #5672's is "forward the raw token; the consumer names it". No second convention invented: the boundary's contribution is to keep that forwarding true and to make "this value is off-spec" machine-readable rather than re-derived per consumer. Only the banner ever re-derived it, and only for lock — the other six had no consumer-side check at all.

4. safeParse granularity — the important measurement. Measured on spec 17.2.0, not assumed: the whole-object safeParse is all-or-nothing. One unknown lock token returns success: false with data undefined, so the other six fields lose their types too. Leaning on it alone would degrade the entire envelope whenever a server spoke a newer dialect — the subtler version of this very bug. The failure branch therefore re-checks each key against that same schema's own shape[key], where only the offending field fails. Absence is never "unrecognised", so a pre-ADR-0010 backend (which sends no envelope, fails the object parse, and flags nothing) behaves exactly as before.

Verification

Both directions pinned, in metadata-client.layeredEnvelope.test.ts (22 tests):

  • (a) conforming envelope — all seven arrive with the server's values; _unrecognized absent, not empty.
  • (b) unknown lock token — resolves; the raw token is forwarded (the precondition lockBannerTitle consumes); _unrecognized is exactly ['lock']; the other six still arrive typed. Table-driven across all seven ruled fields.
  • (c) counter-probe — a structurally malformed envelope (lock: 42, lockSource: {}, editable: 'yes', overlayScope: []) resolves, names every malformed field, and still hands back the three layers. Plus non-object / null / array bodies.

Reverse verification, direction predicted before running. The test imports ./metadata-client — a relative same-package source import, no exports/dist hop and no alias, so no rebuild leg applies; both mutations were proved on disk by grepping injected and removed text separately, with the landing site printed and anchor uniqueness asserted first. Restored under trap … EXIT INT TERM; git diff HEAD --stat empty afterwards.

Ablation Predicted Observed
Labelling removed (unrecognizedEnvelopeKeys[]) (a) green, forwarding green, labelling red 9 red — every labelling assertion; (a) and the forwarding/resolves pins stayed green
Per-field → wholesale (flag every present key on object-parse failure) labelling red and the pre-ADR-0010 legacy case red 10 red, including sends no protection envelope, and nothing is flagged

The first ablation is the dispatch's point made concrete: (a) alone goes green on a client that has no labelling at all. The second is assumption 4 measured — a wholesale verdict degrades a legitimate older server's whole envelope.

One fix beyond the seven casts, named because it defeats the ruling

A 200 whose body was a bare JSON string or number rejected the promise with TypeError: Cannot use 'in' operator to search for 'code' in nonsense, from the envelope-detection guard's bare truthiness check (body && ('code' in body) || …). Pre-existing on origin/main (line 920-921 there), untouched by the seven-cast work, and confirmed by direct evaluation. "A malformed body must degrade, never throw" is the ruled shape, so this was in scope by the ruling rather than a drive-by; the counter-probe is what surfaced it. Guard is now typeof body === 'object' && body !== null && ….

Gates (exit codes captured before any pipe; verdicts quoted from the gate's own output)

Gate Result
pnpm --filter @object-ui/data-objectstack type-check exit 0> @object-ui/data-objectstack@17.6.0 type-check / > tsc --noEmit, script name echoed. First run was exit 2, the unbuilt-closure red (TS6305 Output file … has not been built), cleared by pnpm --filter '@object-ui/data-objectstack^...' build — not the missing-node_modules red.
pnpm exec vitest run packages/data-objectstack/src (root form) exit 0Test Files 43 passed (43), Tests 603 passed (603)
Downstream sweep, prefix form --filter '...@object-ui/data-objectstack' type-check exit 0Scope: 34 of 47, 33 packages ran a real type-check and printed Done; the 34th declares no such script. Prefix = downstream consumers, the correct direction: this change alters what the client returns.
pnpm --filter @object-ui/data-objectstack lint (plain eslint ., no --no-inline-config) exit 0✖ 370 problems (0 errors, 370 warnings); all warnings pre-existing no-explicit-any, none on the changed lines
Union at final head b0800a62c (data-objectstack + app-shell metadata-admin) exit 0Test Files 238 passed (238), Tests 2585 passed, 1 skipped (2586)

Changeset: .changeset/5676-layered-envelope-boundary-parse.md (minor) — Clause-② applies, this changes what a published client accepts and forwards.

Fork to report

None found. No consumer in this repo needs hard-reject semantics: layered() has one call path into the metadata-admin editor, which renders a banner from the value and has no branch that would prefer an exception. If one appears, the natural shape is a caller-side check on _unrecognized rather than a second boundary mode.


Generated by Claude Code

…he layered() boundary

`MetadataClient.layered()` cast ten wire fields of the metadata protection
envelope straight through — no parse, no allowlist, no default — over a raw
`res.json()` body. The consumer opens the lock banner on `lock !== 'none'`,
true for any non-`none` value, so a server sending an unknown lock state
opened the amber box, drew the padlock and rendered an empty title.

The boundary now runs `GetMetaItemLayeredResponseSchema.safeParse`. On the
conforming path the values are the producer's schema output and the ten
assertions are gone. `safeParse`, never `parse`: rejecting an unrecognised
dialect would answer a newer server with a blank page, which is worse than
the wrong render. Unrecognised values are still forwarded and are named in a
new optional `MetadataLayered._unrecognized` — "pass through and label",
extending to the whole envelope the treatment chosen for `lock` alone.

The check is per field, which is what makes it a degrade: the whole-object
`safeParse` is all-or-nothing (measured on spec 17.2.0 — one unknown `lock`
yields no `data` at all), so the failure branch re-checks each key against
that same schema's `shape[key]` and only the offending field loses its type.

Also fixed, because it defeats the same ruling: a 200 whose body was a bare
JSON string or number rejected the promise with a `TypeError: Cannot use 'in'
operator` from the envelope-detection guard's bare truthiness check.

Part of #5676

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CSoz9uGhaaSgiq3hshtN7L
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

Metric Value Budget
Eager closure (gzip, 52 chunks) 3220.5 KB 3990.2 KB
Main entry chunk (gzip) 153.6 KB 350 KB
Entry file index-Bg8iZcrI.js
Status PASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

Package Size Gzipped
app-shell (consoleActionDispatch.js) 0.20KB 0.19KB
app-shell (index.js) 10.38KB 3.90KB
app-shell (runtime-config.js) 18.10KB 6.51KB
app-shell (types.js) 0.01KB 0.04KB
app-shell (urlParams.js) 10.06KB 3.86KB
auth (ActiveOrganizationStorage.js) 25.05KB 9.16KB
auth (AuthContext.js) 0.31KB 0.24KB
auth (AuthGuard.js) 2.07KB 1.00KB
auth (AuthProvider.js) 40.18KB 10.59KB
auth (AuthShell.js) 3.49KB 1.40KB
auth (ForgotPasswordForm.js) 12.21KB 3.45KB
auth (LoginForm.js) 18.15KB 5.39KB
auth (PreviewBanner.js) 0.90KB 0.50KB
auth (RegisterForm.js) 6.65KB 2.22KB
auth (SocialSignInButtons.js) 9.61KB 3.89KB
auth (UserMenu.js) 3.41KB 1.23KB
auth (auth-gate-events.js) 1.29KB 0.66KB
auth (authStyles.js) 5.04KB 1.72KB
auth (createAuthClient.js) 40.21KB 10.80KB
auth (createAuthenticatedFetch.js) 8.46KB 3.43KB
auth (index.js) 3.19KB 1.44KB
auth (invitation-status.js) 1.22KB 0.70KB
auth (org-roles.js) 6.66KB 2.78KB
auth (phone-identifier.js) 1.11KB 0.66KB
auth (types.js) 0.59KB 0.35KB
auth (useAuth.js) 5.30KB 1.02KB
auth (useWorkspaceAdminStatus.js) 5.13KB 2.35KB
collaboration (CommentThread.js) 26.08KB 7.56KB
collaboration (LiveCursors.js) 3.17KB 1.27KB
collaboration (PresenceAvatars.js) 6.49KB 2.64KB
collaboration (PresenceProvider.js) 2.79KB 1.13KB
collaboration (index.js) 1.68KB 0.73KB
collaboration (useCollaborationTranslation.js) 6.05KB 2.52KB
collaboration (useCommentSearch.js) 1.98KB 0.88KB
collaboration (useConflictResolution.js) 7.75KB 1.86KB
collaboration (useMentionNotifications.js) 1.81KB 0.68KB
collaboration (usePresence.js) 6.33KB 1.84KB
collaboration (useRealtimeSubscription.js) 7.91KB 2.01KB
components (index.js) 505.15KB 114.53KB
core (index.js) 4.92KB 1.97KB
create-plugin (index.js) 10.08KB 3.26KB
data-objectstack (index.js) 166.86KB 46.08KB
fields (index.js) 238.40KB 59.89KB
i18n (LocalizationContext.js) 1.76KB 0.96KB
i18n (currency.js) 1.22KB 0.64KB
i18n (i18n.js) 4.28KB 1.75KB
i18n (index.js) 3.44KB 1.39KB
i18n (pickLocalized.js) 7.62KB 3.26KB
i18n (provider.js) 23.13KB 7.63KB
i18n (useDisplayLocale.js) 2.85KB 1.45KB
i18n (useObjectLabel.js) 33.40KB 8.71KB
i18n (useSafeTranslation.js) 7.77KB 3.13KB
layout (index.js) 38.95KB 10.97KB
mobile (MobileProvider.js) 0.92KB 0.49KB
mobile (ResponsiveContainer.js) 0.94KB 0.38KB
mobile (breakpoints.js) 1.51KB 0.70KB
mobile (createOfflineDataSource.js) 5.61KB 1.75KB
mobile (index.js) 1.55KB 0.62KB
mobile (offlineQueue.js) 3.91KB 1.35KB
mobile (pwa.js) 0.97KB 0.49KB
mobile (serviceWorker.js) 1.48KB 0.62KB
mobile (serviceWorkerSource.js) 3.41KB 1.48KB
mobile (useBreakpoint.js) 1.54KB 0.65KB
mobile (useGesture.js) 6.96KB 1.98KB
mobile (useOfflineSync.js) 1.99KB 0.72KB
mobile (usePullToRefresh.js) 2.53KB 0.85KB
mobile (useResponsive.js) 0.72KB 0.42KB
mobile (useResponsiveConfig.js) 1.37KB 0.63KB
mobile (useSpecGesture.js) 4.32KB 1.64KB
mobile (useTouchTarget.js) 1.01KB 0.54KB
permissions (MePermissionsProvider.js) 9.53KB 3.38KB
permissions (PermissionContext.js) 0.31KB 0.25KB
permissions (PermissionGuard.js) 0.89KB 0.45KB
permissions (PermissionProvider.js) 4.64KB 1.50KB
permissions (evaluator.js) 5.12KB 1.74KB
permissions (index.js) 0.93KB 0.41KB
permissions (store.js) 0.91KB 0.42KB
permissions (useFieldPermissions.js) 1.28KB 0.53KB
permissions (usePermissions.js) 1.93KB 0.88KB
plugin-ai (index.js) 15.75KB 3.80KB
plugin-calendar (index.js) 46.62KB 12.83KB
plugin-charts (index.js) 64.66KB 18.32KB
plugin-chatbot (index.js) 188.21KB 44.67KB
plugin-dashboard (index.js) 133.35KB 34.44KB
plugin-designer (index.js) 212.30KB 42.80KB
plugin-detail (index.js) 244.12KB 61.87KB
plugin-editor (index.js) 2.46KB 1.10KB
plugin-form (index.js) 125.63KB 30.64KB
plugin-gantt (index.js) 164.15KB 39.88KB
plugin-grid (index.js) 200.79KB 54.26KB
plugin-kanban (index.js) 52.93KB 14.60KB
plugin-list (index.js) 111.86KB 27.22KB
plugin-map (index.js) 20.11KB 6.64KB
plugin-markdown (index.js) 13.72KB 4.69KB
plugin-report (index.js) 43.49KB 11.93KB
plugin-timeline (index.js) 26.49KB 7.59KB
plugin-tree (index.js) 8.50KB 2.88KB
plugin-view (index.js) 84.57KB 20.74KB
providers (DataSourceProvider.js) 0.75KB 0.39KB
providers (MetadataProvider.js) 1.37KB 0.59KB
providers (ThemeProvider.js) 1.90KB 0.85KB
providers (UploadProvider.js) 11.66KB 3.50KB
providers (index.js) 0.45KB 0.23KB
providers (types.js) 0.01KB 0.04KB
react-runtime (index.js) 5.62KB 2.34KB
react (LazyPluginLoader.js) 4.47KB 1.63KB
react (SchemaRenderer.js) 52.40KB 17.45KB
react (data-invalidation.js) 5.05KB 2.08KB
react (index.js) 1.35KB 0.70KB
react (schema-input.js) 2.32KB 1.24KB
react (spec-input.js) 0.20KB 0.18KB
sdui-parser (codegen.js) 5.41KB 2.34KB
sdui-parser (dashboard-widget-options.js) 3.08KB 1.30KB
sdui-parser (index.js) 4.93KB 2.24KB
sdui-parser (input-type.js) 2.84KB 1.40KB
sdui-parser (parse.js) 12.13KB 3.65KB
sdui-parser (provenance.js) 3.66KB 1.82KB
sdui-parser (types.js) 0.28KB 0.23KB
sdui-parser (validate.js) 7.54KB 2.63KB
types (ai.js) 0.20KB 0.17KB
types (api-types.js) 0.20KB 0.18KB
types (app.js) 2.87KB 0.99KB
types (base.js) 0.20KB 0.18KB
types (blocks.js) 0.20KB 0.18KB
types (complex.js) 2.74KB 1.41KB
types (crud.js) 0.20KB 0.18KB
types (dashboard-filter-alias.js) 6.23KB 2.74KB
types (data-display.js) 0.20KB 0.18KB
types (data-protocol.js) 0.20KB 0.19KB
types (data.js) 0.20KB 0.18KB
types (designer.js) 1.87KB 0.85KB
types (disclosure.js) 0.20KB 0.18KB
types (error-code.js) 1.54KB 0.88KB
types (feedback.js) 0.20KB 0.18KB
types (field-types.js) 0.20KB 0.18KB
types (form.js) 0.20KB 0.18KB
types (http-inflight.js) 8.87KB 3.73KB
types (http-retry.js) 4.32KB 2.02KB
types (icon-key-migration.js) 4.26KB 1.63KB
types (index.js) 4.49KB 2.14KB
types (layout.js) 0.20KB 0.18KB
types (managed-by.js) 0.19KB 0.18KB
types (mobile.js) 2.59KB 1.31KB
types (navigation.js) 0.20KB 0.18KB
types (objectql.js) 0.20KB 0.18KB
types (overlay.js) 0.20KB 0.18KB
types (permissions.js) 0.20KB 0.18KB
types (plugin-scope.js) 0.20KB 0.18KB
types (record-components.js) 0.20KB 0.19KB
types (record-semantics.js) 1.28KB 0.67KB
types (registry.js) 0.20KB 0.18KB
types (reports.js) 0.20KB 0.18KB
types (spec-report.js) 5.05KB 1.93KB
types (spec-ui-namespace.js) 0.20KB 0.19KB
types (system-fields.js) 3.33KB 1.54KB
types (theme.js) 6.28KB 2.87KB
types (ui-action.js) 3.40KB 1.71KB
types (views.js) 0.20KB 0.18KB
types (widget.js) 0.20KB 0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

2 participants