Filing-gate category: ① a product defect with a named site and a reproduction (class a). It is the objectui#8440 disclosure class on the grid surface. Reader: triage first (route and grade), then the domain:ui execution seat that claims it.
Filed by the domain:ui execution seat (seat 1, session session_01BA3nKVUwKQJf8DBxrSVtNC) from the os-dev-report of objectui#8686 (PR objectui#10568). ⛔ Not graded and not routed.
Site (read by the seat on objectui origin/main a50600166)
packages/components/src/renderers/complex/data-table.tsx handleCellKeyDown: on Ctrl+C / Cmd+C, when not editing, it copies String(row[columnKey]) for EVERY cell. Each td is focusable (tabIndex 0), and there is no masked-type check. The cell DRAWS the mask (MaskedCellRenderer), while the keyboard copy writes the raw value.
Reproduction (the dev's throwaway probe, deleted, ⛔ not re-run by the seat)
ObjectGrid inside a SchemaRendererProvider, schema field api_key of type password, value RAW-PROBE-CREDENTIAL, window width 1280. keyDown c with ctrlKey on the masked td, then on the name td as the control:
cellFound: true;
rawInDom: false: the value is not in the DOM, so the mask holds visually;
- clipboard payloads
['RAW-PROBE-CREDENTIAL', 'Row one']: the masked cell copied the raw credential.
Reach and grade notes (for triage, not a grade)
- Defence in depth, like objectui#10434's family: ObjectStack's read mask (
collectMaskedReadFields) already replaces secret and generic password values with SECRET_MASK server-side. So on an ObjectStack backend the clipboard gets the mask string, and the raw value needs a backend that does not mask. The UI still promises "hidden" and hands out whatever it holds.
- The shape of the fix: the natural second consumer of objectui#8686's
isMaskedFieldType(). components cannot import fields, so plugin-grid would pass a per-column masked flag (or a copy-refusal) into the data table, and the table refuses to copy a masked cell, as the detail page does since objectui#8440. It lands after objectui#8686 (PR objectui#10568).
- Also noted:
plugin-grid exports useCellClipboard, which copies String(row[field]) with no masked check but has 0 in-repo callers (zero pull). It is listed in PR objectui#10568's Acceptance notes, not filed separately.
Dedupe
REST page walk over the 1000 most recently updated objectui items (oldest updated_at 2026-09-18). handleCellKeyDown, ctrl+c, clipboard near password / mask / secret, and useCellClipboard ⇒ only PR objectui#10568 (and PR objectui#10529 on the mask renderer, closed). Must-hit control isMaskedFieldType ⇒ PR objectui#10568.
Dedupe words: grid ctrl+c password raw · DataTable handleCellKeyDown clipboard · masked cell copy grid · 8440 grid
Generated by Claude Code
Filing-gate category: ① a product defect with a named site and a reproduction (class a). It is the objectui#8440 disclosure class on the grid surface. Reader: triage first (route and grade), then the
domain:uiexecution seat that claims it.Filed by the
domain:uiexecution seat (seat 1, sessionsession_01BA3nKVUwKQJf8DBxrSVtNC) from theos-dev-reportof objectui#8686 (PR objectui#10568). ⛔ Not graded and not routed.Site (read by the seat on objectui
origin/maina50600166)packages/components/src/renderers/complex/data-table.tsxhandleCellKeyDown: on Ctrl+C / Cmd+C, when not editing, it copiesString(row[columnKey])for EVERY cell. Eachtdis focusable (tabIndex 0), and there is no masked-type check. The cell DRAWS the mask (MaskedCellRenderer), while the keyboard copy writes the raw value.Reproduction (the dev's throwaway probe, deleted, ⛔ not re-run by the seat)
ObjectGridinside aSchemaRendererProvider, schema fieldapi_keyof typepassword, valueRAW-PROBE-CREDENTIAL, window width 1280.keyDowncwithctrlKeyon the maskedtd, then on thenametdas the control:cellFound: true;rawInDom: false: the value is not in the DOM, so the mask holds visually;['RAW-PROBE-CREDENTIAL', 'Row one']: the masked cell copied the raw credential.Reach and grade notes (for triage, not a grade)
collectMaskedReadFields) already replacessecretand genericpasswordvalues withSECRET_MASKserver-side. So on an ObjectStack backend the clipboard gets the mask string, and the raw value needs a backend that does not mask. The UI still promises "hidden" and hands out whatever it holds.isMaskedFieldType().componentscannot importfields, soplugin-gridwould pass a per-column masked flag (or a copy-refusal) into the data table, and the table refuses to copy a masked cell, as the detail page does since objectui#8440. It lands after objectui#8686 (PR objectui#10568).plugin-gridexportsuseCellClipboard, which copiesString(row[field])with no masked check but has 0 in-repo callers (zero pull). It is listed in PR objectui#10568's Acceptance notes, not filed separately.Dedupe
REST page walk over the 1000 most recently updated objectui items (oldest
updated_at2026-09-18).handleCellKeyDown,ctrl+c, clipboard near password / mask / secret, anduseCellClipboard⇒ only PR objectui#10568 (and PR objectui#10529 on the mask renderer, closed). Must-hit controlisMaskedFieldType⇒ PR objectui#10568.Dedupe words:
grid ctrl+c password raw·DataTable handleCellKeyDown clipboard·masked cell copy grid·8440 gridGenerated by Claude Code