You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 5444bb1
Browse filesBrowse the repository at this point in the historyBrowse files
feat(spec): the stored-filter conversion rewrites a filter on a block whose rows are inline, as it does on any other block
6
+
7
+
The ADR-0087 D2 conversion `page-component-filter-record-to-rule-array` no longer leaves every filter of a page component whose rows are inline (`data: { provider: 'value', … }`, a `data` array, or `staticData`) as stored. Such a filter, the binding's `dataSource.filter` included, is now rewritten to the `[{ field, operator, value }, ...]` rule array exactly as it is on a block that queries an object. What still stays as stored, and is still reported as a TODO, is only a filter with a part that has no lossless rule spelling: a combinator, a null value, or an operator the rule vocabulary does not spell. That holds on any block.
8
+
9
+
Why the conversion declined, and why it no longer needs to: the `object-map`, `object-tree`, `object-calendar` and `object-gantt` blocks match that filter against their own rows in objectui's in-memory data source (`ValueDataSource.find`). The conversion was written against an objectui version whose `find` excluded every row for a rule array, so it left those filters alone and said so in the TODO. The objectui version this repository pins (`.objectui-sha`, the same pin the previous release shipped) lowers a rule array before it matches, and it selects the rows the stored form selected. That was measured over every operator the conversion maps: 114 filters on eight rows, null and missing values included. The same filters select no row on the objectui build just before that fix. So the decline was already protecting nothing: it only left convertible filters unconverted and reported TODOs that no longer needed to exist.
10
+
11
+
What an operator sees:
12
+
13
+
-`os migrate meta --stored` now lists such a page as a pending rewrite. It used to list it as a `skipped` row with a TODO. A preview over a database whose only legacy filters sat on inline-row blocks therefore exits 1 until `os migrate meta --stored --apply` rewrites them.
14
+
- Until then, every stored-row read replays the same rewrite, so the block reads the rule array and shows the same rows.
15
+
- Nothing an author writes is accepted or refused differently. The conversion stays retired from the authoring path, and no schema changes.
16
+
17
+
The migration entries `element-data-source-and-object-block-filter-rule-array` and `object-grid-default-filters-rule-array`, and the protocol-18 step rationale, no longer say that inline-row filters are left as stored.
18
+
19
+
ADR-0087 disposition: already registered. This changes the behaviour of the registered D2 conversion `page-component-filter-record-to-rule-array` and edits its two D3 entries. There is nothing new to register.
Copy file name to clipboardExpand all lines: content/docs/automation/connectors.mdx
+2Lines changed: 2 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -114,6 +114,8 @@ Materializes a single **`request`** action accepting
114
114
payload per call. Use it when the upstream is "just HTTP" and you don't have a
115
115
spec document.
116
116
117
+
Do not put a credential in `headers` or `defaultHeaders`: both are stored in metadata and served with it. Declare it as `auth.credentialRef` instead — the resolved `auth` is applied to every request — as the `Authorization` header, or for `api-key` as `headerName` (default `X-API-Key`) or the `paramName` query parameter.
118
+
117
119
### `provider: 'openapi'` — one action per operation
118
120
119
121
Config: **`spec`** (required) and **`baseUrl`** (optional — overrides the
<Callouttype="warn"title="Do not put a secret in an http node's url or headers">
274
+
A flow definition, including an `http` node's `url` and `headers`, is served to every member who can read flows. A token, API key or signed webhook url written there is readable by all of them. Route an outbound credential to a declarative connector's `auth.credentialRef` and call it with a `connector_action` node instead — see [Connectors](/docs/automation/connectors#authentication). Only `signingSecret` (and a start node's `secret`) is withheld when a definition is served; `url` and `headers` are served as written.
275
+
</Callout>
276
+
273
277
**Script:**
274
278
275
279
The built-in `script` executor never evaluates an arbitrary JavaScript string —
0 commit comments