Repository navigation
Commit 6dd99b8
fix(rest): one anonymous-intake rule honours every declared public-form withdrawal (#21566)
Fixes #21475
Clause-②: yes (widening) — five new exports on
`@objectstack/metadata-core`'s index (the shared anonymous-intake rule);
graded `minor`.
## What
A second declared means of withdrawing a public form from anonymous
intake is now honoured by every anonymous door; pinned both sides.
Which forms a `view` opens to anonymous intake is now **one rule**,
defined once in `@objectstack/metadata-core`
(`anonymousFormIntakeCandidates`, with `anonymousFormIntakeSlugs` /
`anonymousFormIntakeSlug` / `publicFormSlug`), and read by:
- both anonymous form doors in `@objectstack/rest`
(`registerFormEndpoints` → `findPublicFormView`), and
- the organization-scoped `view` write check in
`@objectstack/metadata-protocol` (`anonymousFormIntakeOrgScopeRefusal`),
whose local projection (`src/anonymous-form-intake.ts`) is deleted in
favour of the shared one.
So no door reads one declared means and not the other, there is no
second per-door check, and the write-time judgement cannot drift from
what the doors serve. The rule follows `SharingConfigSchema` as
declared, including its defaults, so a raw stored body and its parse get
the same answer.
## Pins (both sides)
- `packages/metadata-core/src/anonymous-form-intake.test.ts` — the rule
itself, every closed shape, raw-vs-parse parity, the three candidate
shapes.
- `packages/rest/src/public-form-withdrawal.test.ts` — new block:
withdrawn by either declared means ⇒ both doors `404 FORM_NOT_FOUND`,
`createData` never called; published ⇒ `200` / `201` (control); with
tenancy resolving an organization and with tenancy unregistered.
Existing fixtures that never declared public sharing per the schema now
declare it.
-
`packages/metadata-protocol/src/protocol.org-scoped-write-refused.test.ts`
— an org-scoped walled write that withdraws through the second means now
counts as a change and is refused `403 NOT_OVERRIDABLE`, nothing saved.
- Dogfood, single posture
(`showcase-public-form-withdrawal.dogfood.test.ts`, real showcase boot):
withdrawn env-wide by the second means ⇒ both doors 404 `FORM_NOT_FOUND`
and no row lands; republished ⇒ 200/201 and the row lands. The existing
`allowAnonymous` pins stay green.
- Dogfood, walled posture
(`public-form-withdrawal-walled.dogfood.test.ts`): the same withdrawal
org-scoped is refused 403; env-wide closes both doors; republish
restores.
## Ablation (one-shot, not kept)
Deleted the second-means check from the shared rule via `node
scripts/ablation-replace.mjs` (anchor 1 → 0, blob `bf5a099a` →
`ad331202`), rebuilt `@objectstack/metadata-core`,
`ablation-dist-preflight --absent` confirmed the guard gone from all 12
built files. Result: rest 4 failed / 12 passed (exactly the four
second-means cases), metadata-protocol 1 failed / 22 passed, dogfood 2
failed / 9 passed, metadata-core 5 failed / 8 passed; every
`allowAnonymous` pin and every control stayed green. Restore: blob ==
HEAD, `git diff HEAD` empty; rebuilt and the preflight found the guard
back in dist; `git status --porcelain` empty.
## Tests (at `0164be245`)
- `@objectstack/metadata-core` vitest: 17 files / 311 passed.
- `@objectstack/rest` vitest: 262 files / 5044 passed, 327 skipped.
- `@objectstack/metadata-protocol` vitest: 206 passed, 3 skipped files /
3177 passed, 19 skipped.
- `@objectstack/dogfood` (the four public-form files): 4 files / 17
passed.
- `typecheck` for metadata-core, metadata-protocol, rest, dogfood: all
`Done`.
- `node scripts/pm/dispatch-gates.mjs --commands`: 114 derived commands
run; 113 exit 0; `check:dual-build-cjs-loads` answered PREREQUISITE NOT
MET (needs a full workspace build): NOT MEASURED, left to CI. `--ran`
reconciliation: 114 of 114 accounted for.
- `@objectstack/spec` `check:generated`: all 15 artifacts current after
`gen:docs` (the regenerated `content/docs/references/ui/sharing.mdx`
carries the corrected module header).
- eslint, narrowed to the 12 changed `.ts` files (`--no-inline-config
--format json`): 12 files, 0 errors, 0 warnings. Narrowing is sound:
`eslint.config.mjs` enables no type-aware linting (no
`parserOptions.project`), so this diff cannot move any untouched file's
verdict. The full `pnpm lint` is CI's.
## Acceptance notes
- `content/docs/ui/forms.mdx` and the `sharing.zod.ts` module header are
corrected to state the rule as enforced.
- A published skill's description of the public-form opt-in now
under-states it. `skills/**` is a Tier H surface, so it is left out of
this PR to keep this one ungoverned; it needs its own follow-up
(carrier: none yet).
- Upgrade note: a form whose sharing never declared public sharing as
the schema defines it stops being served anonymously after this lands.
The changeset says so in class-level terms and points at the public
forms guide.
---
_Generated by [Claude
Code](https://claude.ai/code/session_018zT8d8NpiQ1ExhuNd5TxY6)_
---------
Co-authored-by: Claude <noreply@anthropic.com>1 parent a387354 commit 6dd99b8
16 files changed
Lines changed: 320 additions & 95 deletions
File tree
- .changeset
- content/docs
- references/ui
- ui
- packages
- metadata-core/src
- metadata-protocol/src
- qa/dogfood/test
- rest/src
- spec/src/ui
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
17 | 17 | | |
18 | 18 | | |
19 | 19 | | |
20 | | - | |
21 | | - | |
22 | | - | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
23 | 24 | | |
24 | 25 | | |
25 | 26 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
20 | 20 | | |
21 | 21 | | |
22 | 22 | | |
23 | | - | |
| 23 | + | |
24 | 24 | | |
25 | 25 | | |
26 | 26 | | |
| |||
86 | 86 | | |
87 | 87 | | |
88 | 88 | | |
89 | | - | |
| 89 | + | |
90 | 90 | | |
91 | 91 | | |
92 | 92 | | |
| |||
99 | 99 | | |
100 | 100 | | |
101 | 101 | | |
102 | | - | |
| 102 | + | |
103 | 103 | | |
104 | 104 | | |
105 | 105 | | |
| |||
230 | 230 | | |
231 | 231 | | |
232 | 232 | | |
233 | | - | |
| 233 | + | |
234 | 234 | | |
235 | 235 | | |
236 | 236 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
137 | 137 | | |
138 | 138 | | |
139 | 139 | | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
This file was deleted.
Lines changed: 12 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
604 | 604 | | |
605 | 605 | | |
606 | 606 | | |
| 607 | + | |
| 608 | + | |
| 609 | + | |
| 610 | + | |
| 611 | + | |
| 612 | + | |
| 613 | + | |
| 614 | + | |
| 615 | + | |
| 616 | + | |
| 617 | + | |
| 618 | + | |
607 | 619 | | |
608 | 620 | | |
609 | 621 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
38 | 38 | | |
39 | 39 | | |
40 | 40 | | |
41 | | - | |
42 | 41 | | |
43 | 42 | | |
44 | 43 | | |
| |||
90 | 89 | | |
91 | 90 | | |
92 | 91 | | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
93 | 95 | | |
94 | 96 | | |
95 | 97 | | |
| |||
Lines changed: 26 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
203 | 203 | | |
204 | 204 | | |
205 | 205 | | |
| 206 | + | |
| 207 | + | |
| 208 | + | |
| 209 | + | |
| 210 | + | |
| 211 | + | |
| 212 | + | |
| 213 | + | |
| 214 | + | |
| 215 | + | |
| 216 | + | |
| 217 | + | |
| 218 | + | |
| 219 | + | |
| 220 | + | |
| 221 | + | |
| 222 | + | |
| 223 | + | |
| 224 | + | |
| 225 | + | |
| 226 | + | |
| 227 | + | |
| 228 | + | |
| 229 | + | |
| 230 | + | |
| 231 | + | |
206 | 232 | | |
0 commit comments