1111import {
1212 shouldDenyAnonymous , ANONYMOUS_DENY_STATUS , ANONYMOUS_DENY_CODE , ANONYMOUS_DENY_MESSAGE ,
1313} from '@objectstack/core' ;
14- // [commit 67ceb9aef ] `canonicalMetaUrlType` is the FOLD this transport was missing.
14+ // [#10503 ] `canonicalMetaUrlType` is the FOLD this transport was missing.
1515// See the two call sites below for what each one was deciding raw.
1616import { canonicalMetaUrlType , pluralToSingular } from '@objectstack/spec/shared' ;
1717import { CoreServiceName } from '@objectstack/spec/system' ;
@@ -100,7 +100,7 @@ import type { DomainHandlerDeps, DomainRoute } from '../domain-handler-registry.
100100 * ("real services with no written contract, so they keep today's `any` rather
101101 * than being given a shape here that nothing verifies"). The `any` is honest
102102 * about the SLOT. What it also did, silently, was hand every request literal
103- * downstream of it an unchecked call target: the end state of commit cccbe51bf's ruled pattern —
103+ * downstream of it an unchecked call target: the #11006 series' end state —
104104 * "an undeclared key in a request literal is a compile error" — stopped one
105105 * seam short here, so a misspelt or undeclared key in these literals compiled,
106106 * and so did a misspelt VERB.
@@ -113,7 +113,7 @@ import type { DomainHandlerDeps, DomainRoute } from '../domain-handler-registry.
113113 * probes below exist to deny — and it would have to answer for the three verbs
114114 * in the second group, which no contract declares at all. So the narrowing
115115 * happens at the consumer, once, exactly as `domains/packages.ts` (#13598) and
116- * `domains/mcp.ts` (commit e783e163d ) narrow the same slot for their own seams.
116+ * `domains/mcp.ts` (#8726 ) narrow the same slot for their own seams.
117117 *
118118 * ## ⛔ Every member is OPTIONAL, and the runtime probes STAY
119119 *
@@ -197,7 +197,7 @@ function mayReadPendingDrafts(caller: unknown): boolean {
197197}
198198
199199/**
200- * [commit 4fc4a3c0b ] The methods `/metadata/:type/:name` actually serves — the single
200+ * [#8848 ] The methods `/metadata/:type/:name` actually serves — the single
201201 * source for both the `Allow` header and the refusal message, so the two
202202 * cannot drift apart.
203203 *
@@ -816,19 +816,19 @@ async function answerMetaLayered(
816816}
817817
818818/**
819- * Percent-decode the `:name` path segment. [commit 7986d973f ]
819+ * Percent-decode the `:name` path segment. [#12195 ]
820820 *
821821 * This dispatcher splits the RAW path (`path.split('/')`) and, unlike the
822822 * `packages/rest` Hono routes, nothing decodes its parameters for it —
823823 * measured, not assumed: Hono's `c.req.path`, which the adapter's catch-all
824824 * hands to `dispatch()`, returns `/meta/lead/views%2Fall_leads` verbatim while
825825 * `c.req.param('name')` on the same request yields `views/all_leads`.
826826 *
827- * That difference is load-bearing here. Until commit 7986d973f the compound fold
827+ * That difference is load-bearing here. Until #12195 the compound fold
828828 * (`parts.slice(1).join('/')`) is what let a slash-bearing name be addressed
829829 * on this transport at all — unencoded, across segments. Retiring the fold
830830 * without decoding would leave a pre-grammar residue row addressable through
831- * `packages/rest` and NOT through the dispatcher, breaking the landed (commit 311433f6b)
831+ * `packages/rest` and NOT through the dispatcher, breaking #12194's landed
832832 * acceptance criterion that "reads and `deleteMetaItem` still answer for
833833 * pre-grammar residue rows, so any stored junk name remains listable and
834834 * clearable". Decoding makes ONE spelling — percent-encoded, the spelling the
@@ -1043,11 +1043,11 @@ export async function handleMetadataRequest(deps: DomainHandlerDeps, path: strin
10431043
10441044 // GET /metadata/:type/:name/published → get published version
10451045 //
1046- // [commit 7986d973f ] EXACTLY three segments, and no fold. This used to be
1046+ // [#12195 ] EXACTLY three segments, and no fold. This used to be
10471047 // `parts.length >= 3` with `parts.slice(1, -1).join('/')`, which re-joined
10481048 // every middle segment into one slash-bearing key so
10491049 // `lead/views/all_leads/published` resolved as name `views/all_leads`.
1050- // Stage 1 (commit 311433f6b ) refuses every slash-bearing name at the publish door,
1050+ // Stage 1 (#12194 ) refuses every slash-bearing name at the publish door,
10511051 // so that fold could only ever address a name that can no longer be
10521052 // written.
10531053 if ( parts . length === 3 && parts [ 2 ] === 'published' && ( ! method || method === 'GET' ) ) {
@@ -1140,7 +1140,7 @@ export async function handleMetadataRequest(deps: DomainHandlerDeps, path: strin
11401140
11411141 const metadataService = await deps . getService ( _context , CoreServiceName . enum . metadata ) ;
11421142 if ( metadataService && typeof ( metadataService as any ) . getPublished === 'function' ) {
1143- // [commit 67ceb9aef ] FOLDED — the smaller second site of the same class,
1143+ // [#10503 ] FOLDED — the smaller second site of the same class,
11441144 // dispatcher edition (the REST twin folds at the same point). The
11451145 // layered consult above folds internally at the protocol boundary;
11461146 // this fallback reads the code/package registry, which stores
@@ -1156,21 +1156,21 @@ export async function handleMetadataRequest(deps: DomainHandlerDeps, path: strin
11561156 if ( metaSvc && typeof ( metaSvc as any ) . getPublished === 'function' ) {
11571157 let fallbackData : unknown ;
11581158 try {
1159- // [commit 67ceb9aef ] Same fold — this slot reads the same canonical store.
1159+ // [#10503 ] Same fold — this slot reads the same canonical store.
11601160 fallbackData = await ( metaSvc as any ) . getPublished ( canonicalMetaUrlType ( type ) , name ) ;
11611161 } catch { /* fall through */ }
11621162 if ( fallbackData !== undefined ) return servePublished ( fallbackData ) ;
11631163 }
11641164 return { handled : true , response : deps . error ( 'Not found' , 404 ) } ;
11651165 }
11661166
1167- // /metadata/:type/:name — EXACTLY two segments. [commit 7986d973f ]
1167+ // /metadata/:type/:name — EXACTLY two segments. [#12195 ]
11681168 //
11691169 // This used to be `parts.length >= 2` with `parts.slice(1).join('/')`: every
11701170 // segment after the type was re-joined into one slash-bearing lookup key,
11711171 // so `/metadata/lead/views/all_leads` resolved as name `views/all_leads`.
11721172 // That fold WAS compound-name addressing on this transport, and stage 1
1173- // (commit 311433f6b ) made every name it could reach unwritable at the publish door.
1173+ // (#12194 ) made every name it could reach unwritable at the publish door.
11741174 //
11751175 // ⚠️ The `>=` also swallowed three-segment paths that were never compound
11761176 // names at all — `/metadata/object/foo/references` folded to name
@@ -1244,10 +1244,10 @@ export async function handleMetadataRequest(deps: DomainHandlerDeps, path: strin
12441244 // partition, never env-wide and never another org's. The active
12451245 // organization is resolved HERE, once, and reused by the write
12461246 // threading below — authorization and scope read one value (the
1247- // single-resolution shape the REST doors carry, commit b5378550e ). Resolving
1247+ // single-resolution shape the REST doors carry, #8919 ). Resolving
12481248 // it is a session read, not a protocol probe: the 403-vs-501
12491249 // discipline above is untouched.
1250- // [commit 67ceb9aef ] Folded at the boundary, once — the verdict and the
1250+ // [#10503 ] Folded at the boundary, once — the verdict and the
12511251 // scope decision below must read the same spelling.
12521252 const canonicalType = canonicalMetaUrlType ( type ) ;
12531253 // [#20408] The caller's VETTED organization — the `tenantId`
@@ -1305,8 +1305,8 @@ export async function handleMetadataRequest(deps: DomainHandlerDeps, path: strin
13051305 // capability gate above already made — scope and
13061306 // authorization read the same value by construction.
13071307 //
1308- // [commit 67ceb9aef ] The segment is FOLDED before the scope decision
1309- // — the correction commit 26f3588fb landed for the REST `/meta`
1308+ // [#10503 ] The segment is FOLDED before the scope decision
1309+ // — the correction #10340 landed for the REST `/meta`
13101310 // doors, arriving on the second transport. This branch read
13111311 // the RAW `parts[0]`, while `protocol.saveMetaItem` below
13121312 // folds the same string through `canonicalizeMetaRequestType`
@@ -1334,7 +1334,7 @@ export async function handleMetadataRequest(deps: DomainHandlerDeps, path: strin
13341334 const organizationId = organizationIdForMetaWrite (
13351335 canonicalType , activeOrganizationId ,
13361336 ) ;
1337- // [commit d806081dd ] Server-stated face: this branch answers through
1337+ // [#10888 ] Server-stated face: this branch answers through
13381338 // `deps.errorFromThrown`, which carries the refusal's
13391339 // `issues[]` in `details` (see the `details.issues` pin in
13401340 // `http-dispatcher.test.ts`), so `saveMetaItem`'s 422 renders
@@ -1395,7 +1395,7 @@ export async function handleMetadataRequest(deps: DomainHandlerDeps, path: strin
13951395 return { handled : true , response : deps . error ( 'Save not supported' , 501 ) } ;
13961396 }
13971397
1398- // [commit 4fc4a3c0b ] The read `try` below is this block's default answer, and it
1398+ // [#8848 ] The read `try` below is this block's default answer, and it
13991399 // used to carry NO method guard at all: every verb that is not `PUT`
14001400 // fell into it and was served the ordinary metadata READ.
14011401 //
@@ -1957,7 +1957,7 @@ export async function handleMetadataRequest(deps: DomainHandlerDeps, path: strin
19571957 return { handled : true , response : deps . success ( { types : [ 'object' , 'app' , 'plugin' ] } ) } ;
19581958 }
19591959
1960- // [commit 7986d973f ] A LOCATED refusal, not a bare `{ handled: false }`.
1960+ // [#12195 ] A LOCATED refusal, not a bare `{ handled: false }`.
19611961 //
19621962 // This tail was unreachable until this card: the branches above covered
19631963 // zero segments, one segment, and — through the compound fold — every path
0 commit comments