Skip to content

[finding] the published content/docs/api/client-sdk.mdx:337 install example is REFUSED on two counts when copied verbatim — the sibling of #18607, on the SDK docs page an integrator reads first #18776

Description

@os-support-ai

Surfaced by the dev delivering #18607 (PR #18771) as an out-of-scope finding, then re-derived by the dispatching seat before filing — ⛔ the instance is the dev's reading; the dedupe and the framing are the seat's. ⛔ Filed bare: finding only; grading and domain:* are triage's.

The instance

content/docs/api/client-sdk.mdx:337 calls

await client.packages.install({ id: 'com.objectstack.plugin-auth', version: '1.0.0' })

Parsed against the contract its own call site declares (PackageInstallRequestSchema, whose manifest is ManifestSchema), it is REFUSED on two counts:

  • invalid_value at [manifest, type]
  • invalid_type at [manifest, name]

⇒ it fails when copied verbatim, on a hand-written page (it is in scripts/docs-audit/handwritten-docs.json).

Why this is class (a) and not a docs nit

Identical in kind to #18607, which this seat has just landed: the lane's boundary is 「不完整 vs 错误」 and an example that fails when copied is 错误. This one is on the published SDK docs page, which is what an integrator reads before the README.

⚠️ No gate sees it, and that is measured

  • check:skill-examples — the block carries no os-check marker, so it is never type-checked, although that page IS in its SDK_DOCS_PAGES population.
  • scripts/measure-markdown-ts-blocks.mjs — LIT but blind here: it reports live TS2307 / TS18046 / TS18004 on other blocks, so it is not dark; it cannot see this class because install declares its first parameter any.
  • check:published-readme-exports reads fenced blocks for imported symbols only.

⇒ the payload of a documented example is parsed by nothing.

⛔ What is NOT asserted

That a general gate should be built. The measurement above strengthens the case, but wiring a census into a required gate is a maintainer's floor decision, ⛔ not a finding. Recorded on #18607's PR as an open question.

Dedupe words: client-sdk docs packages.install example · manifest type name missing · ManifestSchema refuses docs example · published docs example fails verbatim · api client-sdk mdx install.

Dedupe run before filing, ⛔ not from memory: complete repo-scoped enumeration of 517 open issues (⚠️ REST /search/* answers 403 for this seat — «sessions are bound to their configured repositories» — so enumeration + local match is the only instrument). client-sdk → 3, packages.install → 2, ManifestSchema → 8, none of them this. Negative control → 0. Nearest and ⛔ NOT this: #18417 (plugin-spec.mdx pins @objectstack/ui in a peerDependencies example — a different defect in a docs example) and #18715 (fenced blocks in no population — the gate-coverage question, not a broken example).


Generated by Claude Code

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions