Skip to content

Commit 151a8ce

Browse files
committed
fix(spec): the error-code waiver reasons and the auth-feature registry notes state each decision in words instead of a tracker number (stage 7)
Class (f) of the spec lane's runtime-string share: 17 registry rationales (33 tracker ids) in STANDARD_SYNONYM_WAIVERS / PROVENANCE_WAIVERS and PUBLIC_AUTH_FEATURES. Each now states the cited decision in words, or drops a citation its sentence already explained. Text only; one patch changeset. Claude-Session: https://claude.ai/code/session_01T9u38rswFp5Rw8DswRUReJ Co-authored-by: Claude <noreply@anthropic.com>
1 parent 045b946 commit 151a8ce

3 files changed

Lines changed: 85 additions & 54 deletions

File tree

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
---
2+
'@objectstack/spec': patch
3+
---
4+
5+
The error-code waiver reasons and the public auth-feature registry's notes no longer cite tracker numbers; each one states the decision behind it in words
6+
7+
Clause-②: no
8+
9+
Two registries in `@objectstack/spec` carry a written reason beside each entry. In `@objectstack/spec/api`, every `STANDARD_SYNONYM_WAIVERS` and `PROVENANCE_WAIVERS` entry records why a registered error code is kept or placed where it is. In `@objectstack/spec/kernel`, `PUBLIC_AUTH_FEATURES` records how each public auth flag is consumed. Seventeen of those reasons pointed at an issue-tracker number for the decision behind them. The number goes; where the sentence did not already say what was decided, it now does. For example:
10+
11+
- The five grandfathered synonyms (`CONFLICT`, `FORBIDDEN`, `INTERNAL`, `NOT_FOUND`, `UNAUTHORIZED`) say their consolidation onto the standard member is deferred until a code has a measured victim.
12+
- The `FLOW_DISABLED` waiver says every door that dispatches a flow answers from one status table. The `TENANT_SCOPE_REQUIRED` waiver says an uninstall across every organization must be declared, never inferred from a missing one.
13+
- The `phoneNumber` note names the fix the registry generalizes: create-user's phone field follows the opt-in phoneNumber plugin.
14+
15+
One reason also corrects a stale fact. The `deviceAuthorization` exemption described a known gap in objectui's `DeviceAuthPage`. That gap was closed in objectui on 2026-07-15: the page reads the flag and says device authorization is not enabled, rather than calling the device-auth endpoints. The text now says so.
16+
17+
Text only: no waiver's code, package, shadowed member or registration, no flag's surface, semantics or gated inputs, and no export, type, schema, order or count moves. Each reason still parses under its schema's non-empty rule. A tool that matches one of these reasons by its old text (for example by a tracker-number substring) needs the new spelling.

‎packages/spec/src/api/error-code-ledger.zod.ts‎

Lines changed: 59 additions & 48 deletions
Original file line numberDiff line numberDiff line change
@@ -1615,36 +1615,39 @@ export const STANDARD_SYNONYM_WAIVERS: readonly StandardSynonymWaiver[] = [
16151615
{
16161616
code: 'CONFLICT',
16171617
shadows: 'RESOURCE_CONFLICT',
1618-
reason: 'Pre-gate synonym on the wire (respondSharingError 409 arm; registered by #8111). ' +
1619-
'Wire value kept; consolidation deferred per #8211.',
1618+
reason: 'Pre-gate synonym on the wire (respondSharingError 409 arm), registered as it stood ' +
1619+
'when the record-sharing errors moved onto the ADR-0112 envelope, so the wire stayed ' +
1620+
'byte-identical. Wire value kept; consolidation deferred until it has a measured victim.',
16201621
},
16211622
{
16221623
code: 'FORBIDDEN',
16231624
shadows: 'PERMISSION_DENIED',
16241625
reason: 'Pre-gate synonym on the wire from @objectstack/rest, plugin-sharing and ' +
1625-
'plugin-approvals; #13353 added the cloud-connection provenance row for the same ' +
1626-
'pre-existing wire value (its marketplace-install plugin-route 403). ' +
1627-
'Wire value kept; consolidation deferred per #8211.',
1626+
'plugin-approvals; cloud-connection lists the same pre-existing wire value under its own ' +
1627+
'provenance row (its marketplace-install plugin-route 403). ' +
1628+
'Wire value kept; consolidation deferred until it has a measured victim.',
16281629
},
16291630
{
16301631
code: 'INTERNAL',
16311632
shadows: 'INTERNAL_ERROR',
16321633
reason: 'Pre-gate synonym on the wire from five packages. Wire value kept; ' +
1633-
'consolidation deferred per #8211.',
1634+
'consolidation deferred until it has a measured victim.',
16341635
},
16351636
{
16361637
code: 'NOT_FOUND',
16371638
shadows: 'RESOURCE_NOT_FOUND',
16381639
reason: 'Pre-gate synonym on the wire from @objectstack/rest and plugin-sharing; ' +
1639-
'#19441 added the plugin-security provenance row for the same pre-existing wire value ' +
1640-
'(its permission-set overlay-discard 404). Wire value kept; consolidation deferred per #8211.',
1640+
'plugin-security lists the same pre-existing wire value under its own provenance row ' +
1641+
'(its permission-set overlay-discard 404). Wire value kept; consolidation deferred until ' +
1642+
'it has a measured victim.',
16411643
},
16421644
{
16431645
code: 'UNAUTHORIZED',
16441646
shadows: 'UNAUTHENTICATED',
16451647
reason: 'Pre-gate synonym (401 reason phrase) on the wire from @objectstack/rest — ' +
1646-
'surfaced by the detector when the #8211 gate landed, beyond the four the card named; ' +
1647-
'same class, same grandfather rationale. Wire value kept; consolidation deferred per #8211.',
1648+
'surfaced by the synonym detector when it landed, beyond the four first reported; ' +
1649+
'same class, same grandfather rationale. Wire value kept; consolidation deferred until ' +
1650+
'it has a measured victim.',
16481651
},
16491652
];
16501653

@@ -1749,52 +1752,57 @@ export const PROVENANCE_WAIVERS: readonly ProvenanceWaiver[] = [
17491752
reason: 'Shared constructor one package over: metadata-core\'s ' +
17501753
'`engineUpdateDispatchRejectError` spells the string, but the throw ships in ' +
17511754
'production from `ObjectQL.update` (engine.ts) — the objectql row\'s own comment ' +
1752-
'records "hence registered here" (#11142/#11230).',
1755+
'records "hence registered here".',
17531756
},
17541757
{
17551758
package: '@objectstack/service-automation',
17561759
code: 'FLOW_DISABLED',
17571760
registeredUnder: '@objectstack/runtime',
17581761
reason: 'The trigger door, not the producer, names the wire vocabulary: the engine ' +
1759-
'returns `AutomationResult.code` and runtime\'s doors read it and answer 409 ' +
1760-
'(#9415/#9446; the runtime row\'s comment records the decision).',
1762+
'returns `AutomationResult.code` and runtime\'s doors read it and answer 409 — every ' +
1763+
'door that dispatches a flow answers from one status table, by ruling (the runtime ' +
1764+
'row\'s comment records the decision).',
17611765
},
17621766
{
17631767
package: '@objectstack/service-automation',
17641768
code: 'FLOW_NO_START_NODE',
17651769
registeredUnder: '@objectstack/runtime',
1766-
reason: 'Same decision as FLOW_DISABLED, 422 arm (#9415/#9446): the trigger door ' +
1770+
reason: 'Same decision as FLOW_DISABLED, its 422 arm: the trigger door ' +
17671771
'names the wire vocabulary; the engine result carries the classification.',
17681772
},
17691773
{
17701774
package: '@objectstack/service-automation',
17711775
code: 'FLOW_INPUT_SCHEMA_INVALID',
17721776
registeredUnder: '@objectstack/runtime',
1773-
reason: 'Registered ahead of its producer by design (#10025 → #11504, the #10413 → ' +
1774-
'#10576 split shape): the engine\'s `execute()` catch classifies the refusal, the ' +
1775-
'trigger door serves it — the runtime row\'s comment records "registered HERE and ' +
1776-
'not under the engine\'s package" with its three FLOW_* siblings.',
1777+
reason: 'Registered ahead of its producer by design: the ruling that a definition-level ' +
1778+
'input-schema refusal is non-retryable and never dispatched split into a contract ' +
1779+
'half, which minted this code, and a services half that emits it, the contract half ' +
1780+
'landing first. The engine\'s `execute()` catch classifies the refusal, the trigger ' +
1781+
'door serves it — the runtime row\'s comment records "registered HERE and not under ' +
1782+
'the engine\'s package" with its three FLOW_* siblings.',
17771783
},
17781784
{
17791785
package: '@objectstack/service-datasource',
17801786
code: 'EXTERNAL_IMPORT_ERROR',
17811787
registeredUnder: '@objectstack/rest',
1782-
reason: 'Adjudicated on #13353: the only door for `importObject` is rest\'s ' +
1783-
'`POST …/tables/:remote/import` (external-datasource-routes.ts), whose catch stamps ' +
1784-
'this code itself for EVERY importObject throw and never reads the producer\'s ' +
1785-
'declaration — the door names the wire vocabulary. The producer\'s `err.code` ' +
1786-
'(`importNameRefusedError`) is the #8016 declaration shape, agreeing with the door ' +
1787-
'by construction, not a second wire emitter.',
1788+
reason: 'Adjudicated when the provenance gate landed: the only door for `importObject` ' +
1789+
'is rest\'s `POST …/tables/:remote/import` (external-datasource-routes.ts), whose ' +
1790+
'catch stamps this code itself for EVERY importObject throw and never reads the ' +
1791+
'producer\'s declaration — the door names the wire vocabulary. The producer\'s ' +
1792+
'`err.code` (`importNameRefusedError`) declares its own `status` and `code`, the ' +
1793+
'shape the shared thrown-error resolver honours, agreeing with the door by ' +
1794+
'construction, not a second wire emitter.',
17881795
},
17891796
{
17901797
package: '@objectstack/client',
17911798
code: 'UPLOAD_SESSION_EXPIRED',
17921799
registeredUnder: '@objectstack/service-storage',
1793-
reason: 'Client-side synthesis (#7870): `resumeUpload` mirrors the server\'s 410 pair ' +
1794-
'when the progress poll reports `expired`, so caller branches fire identically. The ' +
1795-
'ledger\'s scope prose covers the SERVING side; whether a client-synthesised code ' +
1796-
'belongs in the ledger at all is the open scope question #13353 recorded — ' +
1797-
'deliberately a waiver, not a row, until that question is ruled.',
1800+
reason: 'Client-side synthesis: `resumeUpload` mirrors the server\'s 410 pair when the ' +
1801+
'progress poll reports `expired`, so caller branches fire identically. The ledger\'s ' +
1802+
'scope prose covers the SERVING side; whether a client-synthesised code belongs in ' +
1803+
'the ledger at all is an open scope question, recorded when the provenance gate ' +
1804+
'landed and left unruled for want of pull — deliberately a waiver, not a row, until ' +
1805+
'that question is ruled.',
17981806
},
17991807
{
18001808
package: '@objectstack/spec',
@@ -1809,35 +1817,38 @@ export const PROVENANCE_WAIVERS: readonly ProvenanceWaiver[] = [
18091817
package: '@objectstack/types',
18101818
code: 'VALIDATION_FAILED',
18111819
registeredUnder: '@objectstack/runtime',
1812-
reason: 'Shared constructor by design (#8016/#3918): `validationFailure()` lives in ' +
1813-
'the dependency-light package so BOTH doors recognise one shape; the throws are ' +
1814-
'served under the emitting doors\' own registrations (runtime\'s dispatcher exits, ' +
1815-
'rest\'s `mapDataError` — both packages list the code).',
1820+
reason: 'Shared constructor by design: `validationFailure()` lives in the ' +
1821+
'dependency-light package beside the one thrown-error mapping both doors share, so ' +
1822+
'BOTH doors recognise one shape and answer it 400 with its `fields[]`, never 500; the ' +
1823+
'throws are served under the emitting doors\' own registrations (runtime\'s ' +
1824+
'dispatcher exits, rest\'s `mapDataError` — both packages list the code).',
18161825
},
18171826
{
18181827
package: '@objectstack/core',
18191828
code: 'ANALYTICS_DATE_RANGE_UNRECOGNIZED',
18201829
registeredUnder: '@objectstack/runtime',
1821-
reason: 'Shared constructor one package over, the #8016 shape (#16322): ' +
1822-
'`analyticsDateRangeUnrecognizedError` (utils/analytics-date-range.ts) spells the ' +
1823-
'string ONCE so driver-memory\'s cube face and BOTH service-analytics strategies ' +
1824-
'refuse identically — which is the property the card\'s shared conformance fixture ' +
1825-
'exists to hold, and which two independent refusals could not give. Core ships no ' +
1826-
'HTTP door; the wire emission stays runtime\'s, whose row names this exact second ' +
1827-
'moment. ⛔ Deliberately ONE waiver rather than a row per driver: with one ' +
1828-
'constructor there is one stamp site, and rows for packages that stamp nothing ' +
1829-
'would be the dead weight this file\'s gate refuses.',
1830+
reason: 'Shared constructor one package over: `analyticsDateRangeUnrecognizedError` ' +
1831+
'(utils/analytics-date-range.ts) spells the string ONCE so driver-memory\'s cube face ' +
1832+
'and BOTH service-analytics strategies refuse an unrecognised `dateRange` identically ' +
1833+
'— which is the property the shared date-range conformance fixture exists to hold, ' +
1834+
'and which two independent refusals could not give. Core ships no HTTP door; the wire ' +
1835+
'emission stays runtime\'s, whose row names this exact second moment. ⛔ Deliberately ' +
1836+
'ONE waiver rather than a row per driver: with one constructor there is one stamp ' +
1837+
'site, and rows for packages that stamp nothing would be the dead weight this file\'s ' +
1838+
'gate refuses.',
18301839
},
18311840
{
18321841
package: '@objectstack/runtime',
18331842
code: 'TENANT_SCOPE_REQUIRED',
18341843
registeredUnder: '@objectstack/metadata-protocol',
18351844
reason: 'The door mirrors the producer\'s refusal; it is not a second emitter. ' +
1836-
'`DELETE /packages/:id` (domains/packages.ts, `requireUninstallOrganizationScope`) asks ' +
1837-
'`deletePackage`\'s organization-scope question BEFORE `registry.uninstallPackage`, and ' +
1838-
'answers with the code `deletePackage` refuses with (#7780), so a refused uninstall ' +
1839-
'changes nothing (#20492). The door never sends `allTenants`, so its condition is exactly ' +
1840-
'the producer\'s "no organization"; the protocol keeps its own refusal as the second line ' +
1841-
'and stays the registered emitter.',
1845+
'`DELETE /packages/:id` (domains/packages.ts, `requireUninstallOrganizationScope`) ' +
1846+
'asks `deletePackage`\'s organization-scope question BEFORE ' +
1847+
'`registry.uninstallPackage`, and answers with the code `deletePackage` refuses a ' +
1848+
'scope-less uninstall with (an uninstall across every organization must be declared, ' +
1849+
'never inferred from a missing one), so a refused uninstall changes nothing. The door ' +
1850+
'never sends `allTenants`, so its condition is exactly the producer\'s "no ' +
1851+
'organization"; the protocol keeps its own refusal as the second line and stays the ' +
1852+
'registered emitter.',
18421853
},
18431854
];

‎packages/spec/src/kernel/public-auth-features.ts‎

Lines changed: 9 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -191,10 +191,10 @@ export const PUBLIC_AUTH_FEATURES = {
191191
semantics: 'opt-in',
192192
exempt: {
193193
reason:
194-
'No spec input (sys_device_code declares no actions). Known gap: ' +
195-
'objectui DeviceAuthPage hits the device-auth endpoints without ' +
196-
'checking this flag (absent from its client type) — tracked in ' +
197-
'objectui#2513 (#2874 P2②).',
194+
'No spec input (sys_device_code declares no actions). Login ' +
195+
'consumption verified: objectui DeviceAuthPage reads this flag and, ' +
196+
'when it is off, says device authorization is not enabled instead ' +
197+
'of calling the device-auth endpoints.',
198198
},
199199
},
200200
admin: {
@@ -217,7 +217,9 @@ export const PUBLIC_AUTH_FEATURES = {
217217
semantics: 'opt-in',
218218
gatedInputs: ['sys_user.actions.create_user.params.phoneNumber'],
219219
notes:
220-
'The original #2871 fix. Also read by objectui LoginForm for the ' +
220+
'The fix this registry generalizes: create-user\'s phone field ' +
221+
'follows the opt-in phoneNumber plugin instead of offering a field ' +
222+
'the backend refuses. Also read by objectui LoginForm for the ' +
221223
'phone+password sign-in mode.',
222224
},
223225
phoneNumberOtp: {
@@ -227,7 +229,8 @@ export const PUBLIC_AUTH_FEATURES = {
227229
reason:
228230
'Login-surface only: gates the "sign in with verification code" link ' +
229231
'(LoginForm) and the phone branch of forgot-password. Only advertised ' +
230-
'when SMS is actually deliverable (#2780).',
232+
'when an SMS service can actually deliver the code; a log-only ' +
233+
'transport in production keeps it off.',
231234
},
232235
},
233236
} as const satisfies Record<string, PublicAuthFeatureEntry>;

0 commit comments

Comments
 (0)