Skip to content

Commit 8dea55d

Browse files
docs(adr): ADR-0061 D5 — dated note: the anonymous publicPicker search model is retired by ruling E (#21180) (#21223)
Refs #21180 Docs-only. Adds one dated note to ADR-0061 under its D5 entry (`docs/adr/0061-record-search-architecture.md:54`). The original sentence says anonymous search "keeps the existing `publicPicker` model". The note records that this model is retired by the maintainer's ruling E on #21079 (record `5933054144`, 「同意E」, 2026-10-01), which reverses the #7467 model. The original text is not rewritten: the diff is exactly two added lines, a blank line and the note. **Tier H.** `docs/adr/**` is a governed surface, so this PR lands only on the maintainer's approval. No seat merges, queues or arms it. The code half (the retirement itself) is the separate PR #21222; this PR carries no closing keyword, so merging it does not close the card. ## The note (its links shown as plain references) > **Note (2026-10-01) — anonymous search retired.** The `publicPicker` model the sentence above keeps is retired by the maintainer's ruling E on #21079 (comment 5933054144, 2026-10-01), which reverses the #7467 model (declare `publicPicker`). Anonymous public forms no longer take lookup, `master_detail` or `user` fields: the public-form resolve route leaves them off the anonymous rendering unconditionally, the anonymous record-search route `GET /forms/:slug/lookup/:field` is deleted, and `publicPicker` is a `retiredKey()` tombstone under ADR-0087 D2 (immediate retirement). So there is no public/anonymous record search; the rest of D5 stands. The retirement is #21180. ## Gates (derived from this diff, head `6b16db083`) `dispatch-gates --commands` derives 19 families. All 19 ran to exit 0, among them `check-adr-links` (695 links resolve), `check-adr-symbol-anchors`, `check:adr-anchors`, `check:pm-governed-merges`, `check:doc-authoring`, `check:nul-bytes` and `check:closing-keyword-parity`. One, `check:doc-formula-expressions`, first refused with exit 3 because `formula` and `lint` were not built in this fresh worktree. It ran to exit 0 after the build its refusal prescribed. `skip-changeset` applies: the diff publishes nothing. ## 维护者速读(草稿) **改了什么**:只在 ADR-0061 的 D5 条目(`:54`)下追加一条注明日期(2026-10-01)的说明,原文一字不改;差异只有新增的两行。 **为什么改**:D5 原文写着匿名搜索"沿用现有的 `publicPicker` 模型"。裁决 E(#21079,「同意E」)已退役该模型,推翻 #7467 的"声明 `publicPicker`"。不加这条说明,ADR 会继续声明一个已被删除的匿名记录搜索口,下一个读者会据此重建它。 **风险与代价(含回滚)**:纯文档,不改任何代码或行为,不发布任何包。回滚就是删掉这两行。代码那一半(墓碑、删路由、迁移登记)在 #21222,与本 PR 互不依赖,哪个先落都可以。 **席位意见**: **你要做的**:读一遍这条说明,确认措辞准确地记下了裁决 E,然后批准合并;本 PR 属 Tier H,只能由你点。 --- _Generated by [Claude Code](https://claude.ai/code/session_017VaLJnYwhPsanVCe9dMCJU)_ Co-authored-by: Claude <noreply@anthropic.com>
1 parent 434c6c7 commit 8dea55d

1 file changed

Lines changed: 2 additions & 0 deletions

File tree

‎docs/adr/0061-record-search-architecture.md‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -53,6 +53,8 @@ The default contract is `$search: string` (plus existing `$filter`/scope). **Fie
5353
### D5 — Security: search is a thin layer over the gated `find()`
5454
Search runs through the **same query pipeline as `find()`** — RLS, field-level security, and row filters apply automatically; **no separate unguarded search path**. Results respect the **ADR-0045 materialization/visibility gate** (draft vs published). The `$searchFields` override is subset-validated (D1). **Secret / encrypted / PII fields are never searchable** (excluded from default, rejected from override). Public/anonymous search keeps the existing `publicPicker` model (projection + `maxResults` ≤ 50, no enumeration). LIKE wildcards are escaped (driver-sql already does).
5555

56+
> **Note (2026-10-01) — anonymous search retired.** The `publicPicker` model the sentence above keeps is retired by the maintainer's ruling E on [#21079](https://github.com/objectstack-ai/objectstack/issues/21079) ([comment 5933054144](https://github.com/objectstack-ai/objectstack/issues/21079#issuecomment-5933054144), 2026-10-01), which reverses the [#7467](https://github.com/objectstack-ai/objectstack/issues/7467) model (declare `publicPicker`). Anonymous public forms no longer take lookup, `master_detail` or `user` fields: the public-form resolve route leaves them off the anonymous rendering unconditionally, the anonymous record-search route `GET /forms/:slug/lookup/:field` is deleted, and `publicPicker` is a `retiredKey()` tombstone under ADR-0087 D2 (immediate retirement). So there is no public/anonymous record search; the rest of D5 stands. The retirement is [#21180](https://github.com/objectstack-ai/objectstack/issues/21180).
57+
5658
### D6 — Global search: fan-out now, unified `searchAll` is Tier 2
5759
Global search this phase = **client fan-out over the per-object Tier-1 resolver** (CommandPalette already fans out; it only needs per-object search to actually filter) — zero new server surface. The unified server `searchAll` with cross-object relevance is **Tier 2** (it needs a unified index to rank well). **Knowledge/vector stays a separate subsystem**; "blended" record+knowledge search is future and out of scope, but API-compatible.
5860

0 commit comments

Comments
 (0)