You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
fix(objectql): a driver error that leaves the engine no longer carries the failing statement or the caller's values
6
+
7
+
Clause-②: no
8
+
9
+
The engine has cut the bound statement out of its own log line for a failed driver call for a long time, but it rethrew the driver's raw error. Any in-process code that logged what it caught, such as an auth library's error logger, printed the statement and the row's values. The same cut now runs where the error leaves the engine, so no consumer needs a patch of its own.
10
+
11
+
-**Where.** Every engine operation that reaches a driver: `find`, `findOne`, `count`, `aggregate`, `insert` (batch included), `update` and `delete` (by id and by predicate), `execute`, `transaction`, `resolveSecretField` and `resolveInternalField`.
12
+
-**What is cut.** The statement and the caller's values, from the error's `message` and `stack`, from the properties drivers attach (mysql2's `sql` and `sqlMessage`; node-postgres' `detail`, `where` and `internalQuery`), and down the `cause` chain. A `DuplicateRecordError` keeps its own fields and carries a cut `cause`.
13
+
-**What stays.** The error's class (`instanceof` still holds), `name`, `code`, `errno`, `sqlState`, Postgres' identifier fields (`constraint`, `table`, `column`, …) and the database's own diagnostic. The message now reads as the statement's kind, a `[statement and bound values redacted]` marker and the diagnostic. A Postgres key-shaped `detail` keeps its column list. Every REST answer keeps its status, code and `field`.
14
+
-**What changes for a caller.** Code that read the statement or a value out of a driver error's message or properties now gets the marker instead. Branch on the class, `code` or `errno` instead. The driver error on a `DuplicateRecordError`'s `cause` is an equivalent copy, no longer the object the driver threw. An import's row report for a value-bearing database error no longer repeats the rejected value.
Copy file name to clipboardExpand all lines: docs/adr/0128-producer-discriminated-aad-for-cryptocontext.md
+1Lines changed: 1 addition & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -101,6 +101,7 @@ Any **one** of these turns the deferral over; none requires re-opening the direc
101
101
-**The hazard stops being hypothetical**: any intersection appears between the settings-namespace set and the set of object names carrying a `Field.secret()` field — in shipped platform metadata, in an example app, or in a reported customer deployment. §1.4's "no intersection" is the whole of the deferral's evidence, and it is a fact with a shelf life.
102
102
-**A fourth producer of `CryptoContext` is added**, or an existing one's vocabulary is widened to accept names it does not control. A fourth vocabulary in a flat space is the same defect with more surface, and the discriminant is far cheaper to introduce *with* the new producer than after it.
103
103
-**`ICryptoProvider` is opened for another breaking change.** The migration is the expensive half; the breaking-export half should be paid once. A queued breaking change to this interface should pull D1 in with it.
104
+
> **Note (2026-10-02).** This trigger was met by the keyed-digest break ([#21263](https://github.com/objectstack-ai/objectstack/issues/21263), PR [#21292](https://github.com/objectstack-ai/objectstack/pull/21292): a required `keyedDigest` member on `ICryptoProvider`), which landed without D1 by the maintainer's ruling A (comment [5945612493](https://github.com/objectstack-ai/objectstack/issues/21263#issuecomment-5945612493)) because the director's census (comment [5945420994](https://github.com/objectstack-ai/objectstack/issues/21263#issuecomment-5945420994)) measured zero out-of-repo `ICryptoProvider` implementations in the organisation's repositories, so pulling D1 in would have saved a second breaking-export change for no measured implementer population; D1 is scheduled on its own as [#21326](https://github.com/objectstack-ai/objectstack/issues/21326).
104
105
-**A compliance or customer requirement asks the platform to state its at-rest ciphertext binding.** The honest present-tense answer is §1's, and an organisation that needs a stronger one funds the work.
0 commit comments