You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
[finding] The metadata door saves an edit to a code-defined datasource (PUT /api/v1/meta/datasource/:name answers 200) and the metadata read then serves it, while the datasource admin door refuses the same edit as read-only #21899
Filing gate: ① a product defect with reach measured (class b). Two doors onto one code-defined datasource give opposite answers to the same edit. The one that accepts it breaks the published read-only contract.
reach, on objectstack start with the showcase at origin/main607463d7, against its code-defined showcase_external (examples/app-showcase/src/system/datasources/showcase-external.datasource.ts):
PUT /api/v1/meta/datasource/showcase_external with a changed label answers 200 with "Saved datasource 'showcase_external' (env-wide, state=active) [seq=2]".
GET /api/v1/meta/datasource/showcase_external then serves label: 'Meta Renamed 21889' and _packageId: null.
GET /api/v1/datasources (the admin list) still answers the code definition's label, "External Analytics (SQLite)".
The admin door refuses the same edit: PATCH /api/v1/datasources/showcase_external answers 400 DATASOURCE_ADMIN_ERROR "… is code-defined and cannot be edited at runtime.".
DELETE /api/v1/meta/datasource/showcase_external answered 200 on the @objectstack/verifybootStack harness.
Filed by the domain:cli seat (seat post #6024, session_01RWZbGvPFcRKvUqASZtunCU). ⛔ Not a claim. Triage sets the grade and the lane.
Contract
packages/spec/src/data/datasource.zod.ts:665-666 (DatasourceSchema.origin, published in @objectstack/spec): code-defined datasources are "code — authored as *.datasource.ts, GitOps-owned, read-only in the UI".
packages/services/service-datasource/src/datasource-admin-service.ts:15-17: "Code-defined datasources (origin: 'code') are read-only — update/remove reject them", and "A runtime datasource never shadows a code one (code wins on collision)". After the meta save, the metadata read serves the saved row over the code definition.
packages/runtime/src/app-plugin.ts (the comment above :752): code-defined datasources are "registered IN MEMORY ONLY — never persisted to the runtime DB store". The meta save persisted a row (seq=2).
Not measured: whether the saved row survives a restart and shadows the code definition at boot. Also not measured: whether the external-import or validate doors read the edited row.
Reader who acts
Triage grades it and picks the answer. For example: the metadata door refuses writes to an origin: 'code' datasource with the admin door's answer, or the metadata door's overlay of a code datasource is ruled intended and the two doors' texts are reconciled.
Dedupe: MCP search_issues, repo-scoped, open and closed:
None is this. #21124 (closed) is a capability gate on a datasource write path, not the read-only posture of origin: 'code'. #21058 is the admin doors' cross-field refinements. The overlay hits concern other types' serving and dispatch.
Filing gate: ① a product defect with reach measured (class b). Two doors onto one code-defined datasource give opposite answers to the same edit. The one that accepts it breaks the published read-only contract.
objectstack startwith the showcase atorigin/main607463d7, against its code-definedshowcase_external(examples/app-showcase/src/system/datasources/showcase-external.datasource.ts):PUT /api/v1/meta/datasource/showcase_externalwith a changedlabelanswers200with "Saved datasource 'showcase_external' (env-wide, state=active) [seq=2]".GET /api/v1/meta/datasource/showcase_externalthen serveslabel: 'Meta Renamed 21889'and_packageId: null.GET /api/v1/datasources(the admin list) still answers the code definition's label, "External Analytics (SQLite)".PATCH /api/v1/datasources/showcase_externalanswers400 DATASOURCE_ADMIN_ERROR"… is code-defined and cannot be edited at runtime.".DELETE /api/v1/meta/datasource/showcase_externalanswered200on the@objectstack/verifybootStackharness.out_of_scope_findings[0]of itsos-dev-report5998901936). The answers above are that report's. The seat read the contract texts below onorigin/mainand did not re-run the boot.Filed by the
domain:cliseat (seat post #6024,session_01RWZbGvPFcRKvUqASZtunCU). ⛔ Not a claim. Triage sets the grade and the lane.Contract
packages/spec/src/data/datasource.zod.ts:665-666(DatasourceSchema.origin, published in@objectstack/spec): code-defined datasources are "code— authored as*.datasource.ts, GitOps-owned, read-only in the UI".packages/services/service-datasource/src/datasource-admin-service.ts:15-17: "Code-defined datasources (origin: 'code') are read-only — update/remove reject them", and "A runtime datasource never shadows a code one (code wins on collision)". After the meta save, the metadata read serves the saved row over the code definition.packages/runtime/src/app-plugin.ts(the comment above:752): code-defined datasources are "registered IN MEMORY ONLY — never persisted to the runtime DB store". The meta save persisted a row (seq=2)._packageId. Any fix for [finding] A code-defined datasource is registered without its package's provenance, so the external import never applies the ADR-0028 namespace rule to it — an import names an unprefixed object and is accepted #21889 that resolves a datasource's namespace from its_packageIdwould be switched off again, for that datasource, by one meta-door save.Reader who acts
Triage grades it and picks the answer. For example: the metadata door refuses writes to an
origin: 'code'datasource with the admin door's answer, or the metadata door's overlay of a code datasource is ruled intended and the two doors' texts are reconciled.Dedupe: MCP
search_issues, repo-scoped, open and closed:POST /external/validatedoes not see a federated object saved at runtime (throughPUT /meta/objector the import) until the next restart #21842, feat(metadata-core,metadata-protocol,objectql,plugin-security): thesys_metadatafamily goes tenant-less; the per-organization overlay axis retires; managed content is sealed (ADR-0131 D6/D7/D13) #15206, [security] A datasource write path admits callers below the capability the datasource admin door requires for create/update — detail withheld pending maintainer #21124, [finding]POST /api/v1/datasources(and the PATCH door) never runDatasourceSchema's cross-field refinements — a mongocredentialsRefpairing thatos buildandPUT /metarefuse is accepted 201, and the bound secret is silently unused #21058, [security] Stored datasource credentials are served unredacted to an admin through a read path outside the two datasource read doors — detail withheld pending maintainer #21086, [security] A datasource read path serves connection topology to signed-in members below the capability the datasource admin door requires — detail withheld pending maintainer #21087, [security] datasource credential in a nested config position is served in cleartext on read — redaction is top-level-key-only #13405, service-datasource: a re-import the metadata door refuses as DESTRUCTIVE_CHANGE prescribes?force=true, which the import route never reads — a third face of #11095's class (reachable once #21788 lands) #21841, [security] Family closeout: stored metadata bodies (stored datasource credential material included) are still reachable outside the redacting doors at several further positions — detail withheld pending maintainer #21120.None is this. #21124 (closed) is a capability gate on a datasource write path, not the read-only posture of
origin: 'code'. #21058 is the admin doors' cross-field refinements. The overlay hits concern other types' serving and dispatch.