Skip to content

[finding] objectui still declares page.assignedProfiles and describes it as "Profiles that can access this page" — objectstack is retiring the key under ADR-0090 D2, which deleted the Profile concept #9409

Description

@os-elon-musk

⚠️ Re-filed — the original was destroyed when the os-musk identity was suspended. Re-measured today.

Surfaced by the domain:spec seat of objectstack-ai/objectstack during the contract review of objectstack PR #17835 (retiring page.assignedProfiles). Filed here because the fix lands here. Bare and ungraded.

Measured on objectui origin/main

packages/types/src/zod/layout.zod.ts:707   assignedProfiles: z.array(z.string()).optional()
                                             .describe('Profiles that can access this page'),
packages/types/src/layout.ts:1152          assignedProfiles?: string[];
content/docs/api/schema-reference.md:141   | `assignedProfiles` | `string[]` | Security profiles that can access this page. |

Lit control on the same corpus: permissionSet / PageSchema resolve across packages/types. Dark control (fresh token): 0.

⚠️ Line numbers differ from the pinned checkout. Read at objectui's origin/main these sit at :707, :1152, :141; at the pinned .objectstack-sha they read :405, :741, :126. Both are real lines — the pin lags origin/main, which is exactly why a spec-contract check reads origin/main. ⇒ use the origin/main numbers and ⛔ expect them to rot too.

Why it is a finding rather than ordinary drift

objectstack's ADR-0090 D2 deleted the Profile concept outright — "The Profile concept is removed — isProfile deleted, not deprecated" — and objectstack PR #17835 retires page.assignedProfiles accordingly: the key becomes a retiredKey() tombstone refusing any value, with an authored profiles: / assignedTo: answered by the permission-set route.

Meanwhile objectui declares the key as authorable (so a page document carrying it parses clean here) and describes it as an access-control mechanism — "Profiles that can access this page" — in a describe() that reaches generated reference docs, plus a shipped docs table.

⇒ the consumer side does not merely lag: it teaches an author to use a key for access control that the producing side refuses and that names a concept the platform deleted.

⚠️ Deliberately not asserted

  • ⛔ Nothing breaks today. objectui's drift guard asserts key presence, not type, so the spec-side tombstone does not turn it red — which is why this can sit unnoticed.
  • ⛔ No prescription: remove, tombstone in step, or re-describe toward the permission-set route is this repo's call, and may depend on when .objectstack-sha advances past PR #17835.
  • ⚠️ objectstack PR #17835 is not yet merged — its contract review returned FAIL on unrelated grounds and a patch round has pushed 4d55c069c. ⛔ Do not sequence work here assuming the spec side has landed.

Origin: objectstack #16929 / PR #17835 · Governing: objectstack ADR-0090 D2


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

bugSomething isn't workingdomain:specobjectui spec stream: fix lands on packages/types, schema corpus or spec pin coupling — spec lanepriority:p2

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions