Repository navigation
fix(data): record-change payloads apply the write-response credential mask and internal-field omission - #21866
Conversation
… mask and internal-field omission Claude-Session: https://claude.ai/code/session_018zT8d8NpiQ1ExhuNd5TxY6 Co-Authored-By: Claude <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018zT8d8NpiQ1ExhuNd5TxY6 Co-Authored-By: Claude <noreply@anthropic.com>
…al boot Claude-Session: https://claude.ai/code/session_018zT8d8NpiQ1ExhuNd5TxY6 Co-Authored-By: Claude <noreply@anthropic.com>
…riven through Claude-Session: https://claude.ai/code/session_018zT8d8NpiQ1ExhuNd5TxY6 Co-Authored-By: Claude <noreply@anthropic.com>
Co-Authored-By: Claude <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018zT8d8NpiQ1ExhuNd5TxY6
📓 Docs Drift CheckThis PR changes 4 package(s): 5 hand-written doc(s) NAME something this change touched and may need an implementation-accuracy re-verification:
⛔ 1 release-owned page(s) also name something this change touched. These are read-only:
What this run could not see
Coarse fallback — 22 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): Which tree this was computed onThis run read A worktree cut from an older # while this PR is open — GitHub drops the merge commit once it closes
git fetch origin dcb3d872ea9f236c41019902ece3e94046cf63f3 && git checkout dcb3d872ea9f236c41019902ece3e94046cf63f3
# afterwards, rebuild it from the two parents, which stay fetchable
git fetch origin 9f9510f25e6aa65aa61ce3effb42706fabcab92e c87404e8c43e7787353d6b79b014896a5dbc0cee && git checkout -B drift-repro 9f9510f25e6aa65aa61ce3effb42706fabcab92e && git merge --no-ff c87404e8c43e7787353d6b79b014896a5dbc0cee
node scripts/docs-audit/affected-docs.mjs --json 9f9510f25e6aa65aa61ce3effb42706fabcab92e
|
…idening Co-Authored-By: Claude <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018zT8d8NpiQ1ExhuNd5TxY6
Contract reviewServed-tier: ① Derived judgments
② Semver level
③ Boundary flags
Implemented-by: VERDICT: PASS |
Fixes #21830
Clause-②: yes (widening)
Record-change payloads apply the same credential mask and internal-field omission as write responses.
What changed
One rule, one helper:
omitInternalFieldsFromWriteResponse(@objectstack/core, the helper PR #21816 landed for write responses). No second copy of the rule anywhere.packages/objectql/src/engine.ts,publishDataEvent). Theafterandchangesbodies ofdata.record.created/data.record.updatedare projected through the helper on a fresh shallow copy: credential-class fields carrySECRET_MASK(ornullwhen unset),internal: truefields are omitted. The engine's own write result is untouched, so privileged in-process callers are unchanged.plugin-approvals,payload_jsonwhen the request is opened);plugin-webhooksauto-enqueuer,afterandchanges);service-knowledgerecordToDocumenttakes the object definition as an optional fourth argument and skips credential-class andinternalfields, under'*'and when named explicitly)..changeset/record-change-payload-credential-mask.md(minor for@objectstack/service-knowledge, patch for the other three).Verification (head d6e0eae, after merging origin/main)
VERDICT command-exit 0.@objectstack/objectqlfull suite:Test Files 376 passed (376),Tests 7486 passed (7486).@objectstack/plugin-approvals: 60 files / 895 tests passed.@objectstack/plugin-webhooks: 14 / 163 passed.@objectstack/service-knowledge: 4 / 49 passed.typecheckfor objectql, plugin-approvals, plugin-webhooks: green (check:test-typecheck: OK). service-knowledge has no typecheck script.test/approval-snapshot-credential-field.dogfood.test.ts1 passed, after a build of the dogfood dependency closure.node scripts/pm/dispatch-gates.mjs --commandsderived 75 families; all 75 run, all exit 0 (pluscheck-nul-bytes);--ranreconciliation: 75 run, 0 NOT-MEASURED, a derived zero with exit codes recorded.scripts/ablation-replace.mjs, from the committed state): removing the helper call in the engine's event-body projection turnssrc/engine-realtime-credential-mask.test.tsred (3 failed, 1 passed); restore proven by blob hash equal to HEAD (48b8210911cc) and an emptygit diff HEAD.Acceptance notes
getSchema(or an unregistered object) projects nothing, matching the helper's own posture; the engine-side projection still applies upstream.Generated by Claude Code
Review round 1 (PM seat)
@objectstack/service-knowledgeis nowminor:recordToDocument, a published export, gains an optional fourth argument (the object definition); three-argument calls behave as before.before(no producer fills it today).c87404e8c4:@objectstack/plugin-webhooks163/163; the changeset gates green againstorigin/main.