Skip to content

Commit 63af2cb

Browse files
committed
Merge remote-tracking branch 'origin/main' into claude/issue-20574-conversions-merge-clean
2 parents d316f45 + 9a4b2bb commit 63af2cb

154 files changed

Lines changed: 836 additions & 811 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,21 @@
1+
---
2+
'@objectstack/spec': minor
3+
---
4+
5+
feat(spec): the stored-filter conversion rewrites a filter on a block whose rows are inline, as it does on any other block
6+
7+
The ADR-0087 D2 conversion `page-component-filter-record-to-rule-array` no longer leaves every filter of a page component whose rows are inline (`data: { provider: 'value', … }`, a `data` array, or `staticData`) as stored. Such a filter, the binding's `dataSource.filter` included, is now rewritten to the `[{ field, operator, value }, ...]` rule array exactly as it is on a block that queries an object. What still stays as stored, and is still reported as a TODO, is only a filter with a part that has no lossless rule spelling: a combinator, a null value, or an operator the rule vocabulary does not spell. That holds on any block.
8+
9+
Why the conversion declined, and why it no longer needs to: the `object-map`, `object-tree`, `object-calendar` and `object-gantt` blocks match that filter against their own rows in objectui's in-memory data source (`ValueDataSource.find`). The conversion was written against an objectui version whose `find` excluded every row for a rule array, so it left those filters alone and said so in the TODO. The objectui version this repository pins (`.objectui-sha`, the same pin the previous release shipped) lowers a rule array before it matches, and it selects the rows the stored form selected. That was measured over every operator the conversion maps: 114 filters on eight rows, null and missing values included. The same filters select no row on the objectui build just before that fix. So the decline was already protecting nothing: it only left convertible filters unconverted and reported TODOs that no longer needed to exist.
10+
11+
What an operator sees:
12+
13+
- `os migrate meta --stored` now lists such a page as a pending rewrite. It used to list it as a `skipped` row with a TODO. A preview over a database whose only legacy filters sat on inline-row blocks therefore exits 1 until `os migrate meta --stored --apply` rewrites them.
14+
- Until then, every stored-row read replays the same rewrite, so the block reads the rule array and shows the same rows.
15+
- Nothing an author writes is accepted or refused differently. The conversion stays retired from the authoring path, and no schema changes.
16+
17+
The migration entries `element-data-source-and-object-block-filter-rule-array` and `object-grid-default-filters-rule-array`, and the protocol-18 step rationale, no longer say that inline-row filters are left as stored.
18+
19+
ADR-0087 disposition: already registered. This changes the behaviour of the registered D2 conversion `page-component-filter-record-to-rule-array` and edits its two D3 entries. There is nothing new to register.
20+
21+
Clause-②: no
Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
---
2+
'@objectstack/plugin-security': patch
3+
---
4+
5+
Provenance comments in `plugin-security` were re-anchored
6+
7+
Comment and docblock lines under `src/` that cited tracker numbers which no
8+
longer resolve on GitHub now cite the record in this repository that decided
9+
the matter (an ADR where one exists, otherwise the commit in this repository's
10+
history), and say in their own words what was decided. Comments only: no type,
11+
schema, export, log or refusal text, or runtime behaviour changes.
Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
---
2+
'@objectstack/cli': patch
3+
---
4+
5+
Provenance comments in `@objectstack/cli` were re-anchored
6+
7+
Comment and docblock lines under `src/` that cited tracker numbers which no
8+
longer resolve on GitHub now cite the commit in this repository's history that
9+
decided the matter, and say in their own words what was decided. Two strings
10+
move with them: the `os i18n extract --source-hashes` help text now says what
11+
the provenance companion records instead of citing a number, and the header
12+
that flag writes into each `<locale>.source-hashes.generated.ts` cites the
13+
commit that introduced the companion. No command, flag, exit code, error code,
14+
type, export or runtime behaviour changes.

‎content/docs/automation/connectors.mdx‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -114,6 +114,8 @@ Materializes a single **`request`** action accepting
114114
payload per call. Use it when the upstream is "just HTTP" and you don't have a
115115
spec document.
116116

117+
Do not put a credential in `headers` or `defaultHeaders`: both are stored in metadata and served with it. Declare it as `auth.credentialRef` instead — the resolved `auth` is applied to every request — as the `Authorization` header, or for `api-key` as `headerName` (default `X-API-Key`) or the `paramName` query parameter.
118+
117119
### `provider: 'openapi'` — one action per operation
118120

119121
Config: **`spec`** (required) and **`baseUrl`** (optional — overrides the

‎content/docs/automation/flows.mdx‎

Lines changed: 7 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -261,15 +261,19 @@ nothing is assigned or written in its place.
261261
{
262262
id: 'notify_slack',
263263
type: 'http',
264-
label: 'Send Slack Notification',
264+
label: 'Post Order Event',
265265
config: {
266-
url: 'https://hooks.slack.com/services/...',
266+
url: 'https://api.example.com/v1/order-events',
267267
method: 'POST',
268-
body: { text: 'New order: {record.name}' },
268+
body: { event: 'order.created', name: '{record.name}' },
269269
},
270270
}
271271
```
272272

273+
<Callout type="warn" title="Do not put a secret in an http node's url or headers">
274+
A flow definition, including an `http` node's `url` and `headers`, is served to every member who can read flows. A token, API key or signed webhook url written there is readable by all of them. Route an outbound credential to a declarative connector's `auth.credentialRef` and call it with a `connector_action` node instead — see [Connectors](/docs/automation/connectors#authentication). Only `signingSecret` (and a start node's `secret`) is withheld when a definition is served; `url` and `headers` are served as written.
275+
</Callout>
276+
273277
**Script:**
274278

275279
The built-in `script` executor never evaluates an arbitrary JavaScript string —

‎packages/cli/src/commands/cloud/login.ts‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@
1212
* ## `--json` here is NDJSON — a declared exception, same as `os login` (#6730)
1313
*
1414
* Everywhere else in this CLI `--json` means "stdout is exactly one JSON
15-
* document" (#6217). Both device-flow login commands are declared exceptions to
15+
* document" (commit 2b641ddd4). Both device-flow login commands are declared exceptions to
1616
* that, and they are the SAME exception: one compact JSON document per line.
1717
*
1818
* ### What was broken

‎packages/cli/src/commands/compile.ts‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -228,7 +228,7 @@ export default class Compile extends Command {
228228
// one. See `printAuthoringAdvisories` for the measurement.
229229
printAuthoringAdvisories(ruleAdvisories);
230230
};
231-
// [#12125] The ADR-0087 D2 conversion notices, hoisted for the SAME reason
231+
// [commit 79cf692b0] The ADR-0087 D2 conversion notices, hoisted for the SAME reason
232232
// and under the SAME ruling as the four lists above — one field over. The
233233
// notices were computed at step 2 (below) and reached the terminal SUCCESS
234234
// payload alone, so all nine failure exits dropped a list already in hand.

‎packages/cli/src/commands/create.ts‎

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -38,7 +38,7 @@
3838
* ObjectStack is a developer tool, so a documented developer-facing command has
3939
* to work for the developer who follows the docs. This command is documented on
4040
* four public doc pages (`deployment/cli`, `plugins/index`, the two
41-
* `protocol/kernel` pages) and, until #14824, every one of those readers got a
41+
* `protocol/kernel` pages) and, until commit cf6b67164, every one of those readers got a
4242
* project that CANNOT INSTALL:
4343
*
4444
* - the emitted `package.json` declared `@objectstack/spec` and
@@ -81,7 +81,7 @@
8181
*
8282
* ## The emitted package NAME follows the placement too (#15530)
8383
*
84-
* The audience decides the name, and #14824 moved the audience without moving
84+
* The audience decides the name, and commit cf6b67164 moved the audience without moving
8585
* the name: the standalone default kept stamping `@objectstack/plugin-<name>`
8686
* — a scope the developer it now scaffolds for cannot publish to — onto every
8787
* project, with the emitted README telling them to install it from there. The
@@ -321,9 +321,9 @@ function pluginDirName(name: string): string {
321321
* ## Why the standalone name is unscoped
322322
*
323323
* `@objectstack` is a scope the developer this command scaffolds FOR cannot
324-
* publish to. Until #14824 that was arguably fine, because the default output
324+
* publish to. Until commit cf6b67164 that was arguably fine, because the default output
325325
* landed inside this monorepo, where every sibling really does carry the scope.
326-
* That ruling pointed the default at the developer's own directory and the name
326+
* That commit pointed the default at the developer's own directory and the name
327327
* did not move with the audience — so the standalone emission stamped a scope
328328
* its owner does not own onto every project generated from it. ⚠️ Nothing in
329329
* this repository can see that: the name is never resolved from a registry

‎packages/cli/src/commands/database-driver-allowlist.pin.test.ts‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -36,10 +36,10 @@
3636
* `start.ts` and once in `dev.ts`, and that duplication is exactly how the two
3737
* can drift apart from each other as well as from the resolver.
3838
*
39-
* SCOPE (#6860 vs #6345): this pins the CANONICAL kinds — the `driverId` values
39+
* SCOPE (#6860 vs commit e2798fab7): this pins the CANONICAL kinds — the `driverId` values
4040
* the resolver produces. The resolver also accepts aliases (`pg`, `mysql2`,
4141
* `libsql`, `mingo`, `wasm`, …) which the flag deliberately does not offer;
42-
* converging that vocabulary is #6345's job, and this pin is written so it does
42+
* converging that vocabulary was commit e2798fab7's job, and this pin is written so it does
4343
* not prejudge it — an alias collapses to its canonical id and is not demanded
4444
* of the flag.
4545
*/
@@ -101,7 +101,7 @@ function candidateTokens(): string[] {
101101
* is supplied so it resolves normally; the catch is kept so the derivation
102102
* survives another kind growing the same "recognized but unusable" shape.
103103
*
104-
* `err.recognized` is what keeps that catch honest (#6345). The resolver now
104+
* `err.recognized` is what keeps that catch honest (commit e2798fab7). The resolver now
105105
* ALSO throws `UnsupportedDriverError` for a spelling nothing claims — the CLI
106106
* half of "both hosts refuse the same input", which replaced a silent fall-through
107107
* to the dev SQLite default. Reading `driverType` off that error would report the

‎packages/cli/src/commands/database-driver-flag-derivation.test.ts‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@
2424
* Deriving the flag from the CONFIG-CONTRACT face (`DRIVER_ID_ALIASES` /
2525
* `resolveDriverId`) instead of the SELECTION face would offer `sqlite3`,
2626
* `better-sqlite3`, `mariadb` and `inmemory` — spellings neither boot host has
27-
* ever accepted as a selection (#6345 fixes the selection face as the union of
27+
* ever accepted as a selection (commit e2798fab7 fixes the selection face as the union of
2828
* what the two hosts accepted the day the ruling was written). The last case here
2929
* drives oclif's real parser to prove they are still refused at parse time.
3030
*/

0 commit comments

Comments
 (0)