Skip to content

fix(app-shell): the External Datasource panel unwraps the { success, data } envelope its routes answer (objectui#11628) - #11640

Merged
objectstack-fleet[bot] merged 3 commits into
mainfrom
claude/issue-11628-external-envelope
Oct 5, 2026
Merged

objectstack-fleet[bot] merged 3 commits into
mainfrom
claude/issue-11628-external-envelope

Conversation

@objectstack-fleet

Copy link
Copy Markdown
Contributor

Fixes #11628

Clause-②: no

What changed

packages/app-shell/src/views/metadata-admin/external/api.ts read the External Datasource routes as if they answered bare payloads. Every /datasources/:name/external/* route answers through the shared sendOk, so the payload sits under data. The client read tables, draft, catalog and { ok, results } from the top of the body. As a result the panel listed no remote tables (tables ?? [] turned the miss into an empty list), showed no catalog timestamp, crashed Validation on results.length, and the import dialog could not be reached.

  • A new readExternalData unwraps data once, for all four /external/* calls. Each caller then reads its own payload key from data. A 2xx body without the { success: true, data } envelope is now an error that names the route, instead of being read as an empty answer.
  • The same reader's failure arm called String(body.error) on the ADR-0112 nested envelope, so every refusal read [object Object]. The 503 arm compared that same string with external_service_unavailable, a code the server no longer sends, so the "federation not enabled" hint could never show. Refusals now go through app-shell's existing readEnvelopeFailureText. The 503 is now recognised by the envelope's own code, SERVICE_UNAVAILABLE. This is the PM's mechanism assumption 2: measured below, it was the same envelope in the same function, so it is fixed in this PR.
  • importObjectDraft keeps its own reader, because it calls the /meta door, not an /external/* route. That door's success body is the save result, with no data. Its refusals come in two dialects, both measured: nested { error: { code, message } } from the capability gate, and flat { error: 'SENTENCE', code } from spec validation. The old reader handled only the flat one, and printed a non-admin's 403 as [object Object]. It now reads both.
  • api.test.ts uses the measured wire shapes. It covers all five calls, the 503 arm on each of the four routes, and both /meta refusal dialects.
  • No panel component changed. With the client fixed, the four consumers (SchemaBrowser, ExternalDatasourcePanel, ValidationPanel, ImportObjectDialog) render correctly as they are.

Wire shapes, measured live (objectstack main at 0a348031, stock showcase, --fresh)

Call Route Success body on the wire Refusal body on the wire Old client read
listRemoteTables GET /external/tables {success:true,data:{tables:[customers,orders]}} {success:false,error:{code,message}} (401 UNAUTHENTICATED, 403 PERMISSION_DENIED) body.tables, missing, so []
generateObjectDraft POST /external/tables/:remote/draft {success:true,data:{draft:{...}}} 400 EXTERNAL_DATASOURCE_ERROR nested body.draft, so undefined
refreshCatalog POST /external/refresh-catalog {success:true,data:{catalog:{snapshotAt,...}}} 400 EXTERNAL_DATASOURCE_ERROR nested body.catalog, so undefined
validateDatasource POST /external/validate {success:true,data:{ok:true,results:[2 rows]}} 403 PERMISSION_DENIED nested the whole envelope as {ok,results}, so results was undefined
importObjectDraft PUT /meta/object/:name {success:true,version,seq,state,message} (no data, not read) 403 {error:{code:'FORBIDDEN',message}} nested; 422 INVALID_METADATA and 400 VALIDATION_ERROR flat {error:'SENTENCE',code} String(body.error): right for flat, [object Object] for nested

The 503 SERVICE_UNAVAILABLE arm cannot be reached on the showcase, because it wires the external-datasource service. Its shape comes from the server's unavailable writer in registerExternalDatasourceRoutes (sendError(res, 503, 'SERVICE_UNAVAILABLE', …)) and is covered by the unit test. Live: NOT MEASURED.

Live panel, before and after (same backend, console from this worktree)

The console ran from this worktree under vite, proxied to the backend, at /apps/setup/metadata/datasource/showcase_external. "Before" is api.ts temporarily restored to the base 1c2e2c4 from the committed fix; restoring HEAD was confirmed by blob hash. Both runs blocked the dev-only /api/v1/dev/metadata-events stream; see Acceptance notes.

Step Before (1c2e2c4) After (this branch)
Tables tab 0 rows, "No remote tables found (check the datasource's allowedSchemas)." 2 rows: customers 7, orders 7
Refresh catalog 200 with data.catalog.snapshotAt; no timestamp rendered snapshot 10/5/2026, 2:51:36 AM rendered
Import dialog, up to the draft read unreachable (no row) opens; POST …/tables/customers/draft 200; shows object name customers and the generated source
Validation, Run validation "Preview failed to render", Cannot read properties of undefined (reading 'length') "All 2 objects match the remote schema." with showcase_ext_customer and showcase_ext_order

The real api.ts was also called inside the page against the same backend, as the admin and as the non-admin auditor.demo@example.com persona:

Call Before After
admin generateObjectDraft(showcase_external, no_such_table) Error: [object Object] Remote table 'no_such_table' not found on datasource 'showcase_external'. (EXTERNAL_DATASOURCE_ERROR)
admin refreshCatalog(no_such_ds) Error: [object Object] [ObjectQL] Datasource 'no_such_ds' has no registered driver to introspect. (EXTERNAL_DATASOURCE_ERROR)
auditor listRemoteTables / validateDatasource Error: [object Object] Introspecting an external datasource requires the manage_platform_settings capability. (PERMISSION_DENIED) (the server wraps the capability name in backticks; dropped here)
auditor importObjectDraft Error: [object Object] Saving a metadata item requires the manage_metadata capability. (FORBIDDEN)
admin importObjectDraft (name mismatch, flat 400) the server's sentence the same sentence (unchanged)

PM mechanism assumptions

  1. Confirmed, and extended to the fifth call. The table above lists every call in the file and the shape each one read.
  2. Confirmed as a misread, live. Every refusal on these routes printed [object Object], and the 503 hint never fired. The fix is in this PR, in the same reader.
  3. For refusals there was already a helper, and this PR reuses it: readEnvelopeFailureText (packages/app-shell/src/utils/apiErrorEnvelope.ts, same package, no new export). For success bodies app-shell has no shared unwrap helper. @object-ui/data-objectstack's unwrapDispatcherEnvelope is module-private. It is also deliberately lenient (it returns the body as-is when there is no data), and that is the tolerance this card's defect hid behind. Reusing it would need a new package export, which the Clause-② fence rules out. So the strict unwrap lives in this module.
  4. The backend ran from this worker's own objectstack worktree at main 0a348031, built with OS_SKIP_DTS=1 under the verify lock. The shared checkout was not touched.

Tests

All gates below ran on the merged head 4779053: this branch plus one merge of origin/main at 22ddcd5. Each exit code was written to a file as it ran.

  • Unit tests for this module, red before and green after. pnpm exec vitest run packages/app-shell/src/views/metadata-admin/external/api.test.ts
    • Fix committed (790b3b1), then api.ts restored to base 1c2e2c4: Tests 12 failed | 4 passed (16), exit 1. The failures were expected [] to deeply equal [customers, orders], Cannot read properties of undefined (reading 'name'), expected undefined to deeply equal the catalog, the envelope returned as {ok,results}, Error: [object Object] where ExternalServiceUnavailableError was expected, and '[object Object]' in the message.
    • git checkout HEAD -- api.ts put the fix back; the blob hash matched HEAD and git diff HEAD was empty. Re-run: Tests 16 passed (16), exit 0.
    • The four tests that pass on the old client are the ?schema passthrough, the HTTP-status fallback, the /meta 2xx, and the flat /meta refusal. The old client already handled each of these.
  • pnpm exec vitest run packages/app-shell/ --maxWorkers=2 (root form, under the verify lock): Test Files 1000 passed | 1 skipped (1001), Tests 9940 passed | 9 skipped (9949), exit 0.
  • pnpm --filter @object-ui/app-shell type-check (tsc --noEmit && tsc -p tsconfig.test.json; the second config includes src/**/*.test.ts), after turbo run build --filter='@object-ui/app-shell^...': exit 0.
  • pnpm --filter @object-ui/app-shell lint: exit 0, 0 errors. The warnings are pre-existing, and none is in external/api.ts or api.test.ts.
  • Root checks whose subject this diff touches: all exit 0.
    • check:metadata-write-doors reads importObjectDraft as a raw-PUT door and prints OK 17 metadata write door(s) derived (3 raw PUT, 14 SDK) … 3 reach assertObjectMetadataWritable.
    • check:new-line-citations prints 0 new citation(s).
    • The rest: check:control-bytes, check:test-path-roots, check:vi-mock-specifiers, check:vi-mock-inherit, check:vi-mock-override-shape, check:changeset-claims, check:pending-changeset-literals, check:self-import, check:esm-specifiers, check:shell-escape-residue, check:unreferenced-sources, check:phantom-deps, check:unused-deps, check:comment-mask-corpus, scripts/check-changeset-presence.mjs and scripts/check-changeset-no-major.mjs.
  • node scripts/check-governed-queue-guard.mjs --test on the three paths reports NOT GOVERNED.
  • The repo-wide pnpm lint and the full test farm are left to CI.

Acceptance notes

  • Dev-only reload after "Refresh catalog" (observation, not filed). With the console under vite dev and the backend under objectstack dev, "Refresh catalog" writes the catalog snapshot. The backend then emits a metadata-change event on /api/v1/dev/metadata-events, and apps/console's MetadataHmrReloader reloads the page about 0.6 s later. That wipes the panel state, timestamp included. The reloader is enabled by import.meta.env.DEV, so by its own default the published console (/_console) does not run it (read from source; not measured on /_console). The live measurement blocked that stream to see the panel as the published console behaves. Owner: none.
  • listRemoteTables no longer applies ?? []. With the envelope checked first, that fallback could only hide a data without tables, and the server always sends tables.
  • objectui's import dialog saves through PUT /meta/object/:name, not the server's POST /external/tables/:remote/import. service-datasource: importing an external table under a name that differs from its remoteName creates an object that answers 500 "no such table" — and the import does not survive a restart objectstack#21788 (the server-side twin) is about that POST route and stays open; this PR does not touch it.
  • Behaviour change in importObjectDraft: a 2xx no longer parses the body, because nothing reads it. A 2xx with an unparseable body used to reject.

Generated by Claude Code

claude added 3 commits October 5, 2026 02:48
… data }` envelope its routes answer (objectui#11628)

The `/datasources/:name/external/*` client returned the whole body and read
`tables` / `draft` / `catalog` / `{ ok, results }` off its top level, where
the server never puts them: every route there answers through the shared
`sendOk`. The panel listed no remote tables, showed no catalog timestamp,
crashed Validation on `results.length`, and left the import dialog
unreachable. `readExternalData` now unwraps `data` once for the four routes
and refuses a 2xx body that is not the envelope instead of reading it as
empty.

The same reader's failure arm ran `String(body.error)` over the ADR-0112
nested envelope, so every refusal read `[object Object]` and the 503
`SERVICE_UNAVAILABLE` hint never fired. Refusals now go through app-shell's
`readEnvelopeFailureText`. The `/meta` save door the import uses keeps its
own reader: it answers a nested capability refusal and a flat validation
refusal, and both now reach the user.

`api.test.ts` moves to the measured wire shapes, so it fails on the old
client.

Claude-Session: https://claude.ai/code/session_015W8GBu6sBiqus2L2xjMsAL
Co-authored-by: Claude <noreply@anthropic.com>
…e read (objectui#11628)

Claude-Session: https://claude.ai/code/session_015W8GBu6sBiqus2L2xjMsAL
Co-authored-by: Claude <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

Metric Value Budget
Eager closure (gzip, 331 chunks) 3316.5 KB 3330.4 KB
Main entry chunk (gzip) 151.6 KB 350 KB
Entry file index-CSlVPSkq.js —
Status PASS —

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

Package Size Gzipped
app-shell (consoleActionDispatch.js) 0.20KB 0.19KB
app-shell (index.js) 17.22KB 6.37KB
app-shell (runtime-config.js) 22.52KB 7.86KB
app-shell (types.js) 0.01KB 0.04KB
app-shell (urlParams.js) 10.11KB 3.87KB
auth (ActiveOrganizationStorage.js) 27.95KB 10.04KB
auth (AuthContext.js) 0.31KB 0.24KB
auth (AuthGuard.js) 2.07KB 1.00KB
auth (AuthProvider.js) 40.22KB 10.61KB
auth (AuthShell.js) 3.49KB 1.40KB
auth (ForgotPasswordForm.js) 12.21KB 3.45KB
auth (LoginForm.js) 18.17KB 5.40KB
auth (PreviewBanner.js) 0.90KB 0.50KB
auth (RegisterForm.js) 6.72KB 2.24KB
auth (SocialSignInButtons.js) 9.70KB 3.93KB
auth (UserMenu.js) 3.39KB 1.21KB
auth (auth-gate-events.js) 1.29KB 0.66KB
auth (authStyles.js) 5.04KB 1.72KB
auth (createAuthClient.js) 40.70KB 10.94KB
auth (createAuthenticatedFetch.js) 8.54KB 3.46KB
auth (index.js) 3.63KB 1.64KB
auth (invitation-status.js) 1.22KB 0.70KB
auth (org-roles.js) 6.66KB 2.78KB
auth (phone-identifier.js) 1.11KB 0.66KB
auth (types.js) 0.59KB 0.35KB
auth (useAuth.js) 5.30KB 1.02KB
auth (useWorkspaceAdminStatus.js) 11.08KB 4.58KB
collaboration (CommentThread.js) 27.11KB 7.97KB
collaboration (LiveCursors.js) 3.17KB 1.27KB
collaboration (PresenceAvatars.js) 6.28KB 2.60KB
collaboration (PresenceProvider.js) 2.79KB 1.13KB
collaboration (index.js) 1.68KB 0.73KB
collaboration (useCollaborationTranslation.js) 6.50KB 2.52KB
collaboration (useCommentSearch.js) 1.98KB 0.88KB
collaboration (useConflictResolution.js) 7.75KB 1.86KB
collaboration (useMentionNotifications.js) 1.81KB 0.68KB
collaboration (usePresence.js) 6.33KB 1.84KB
collaboration (useRealtimeSubscription.js) 7.91KB 2.01KB
components (index.js) 573.76KB 137.62KB
core (index.js) 10.00KB 3.96KB
create-plugin (index.js) 27.94KB 9.51KB
data-objectstack (index.js) 232.57KB 64.51KB
fields (index.js) 262.75KB 66.62KB
i18n (LocalizationContext.js) 1.76KB 0.96KB
i18n (builtinAggregateLabels.js) 0.86KB 0.49KB
i18n (currency.js) 2.59KB 1.22KB
i18n (fallbackInterpolation.js) 6.25KB 2.77KB
i18n (i18n.js) 8.87KB 3.64KB
i18n (index.js) 5.24KB 2.27KB
i18n (pickLocalized.js) 9.86KB 3.95KB
i18n (provider.js) 39.35KB 12.88KB
i18n (translateFn.js) 0.20KB 0.18KB
i18n (useDisplayLocale.js) 3.52KB 1.76KB
i18n (useObjectLabel.js) 35.66KB 9.49KB
i18n (useSafeTranslation.js) 7.14KB 2.92KB
layout (index.js) 39.47KB 11.25KB
mobile (MobileProvider.js) 0.92KB 0.49KB
mobile (ResponsiveContainer.js) 0.94KB 0.38KB
mobile (breakpoints.js) 1.51KB 0.70KB
mobile (createOfflineDataSource.js) 5.61KB 1.75KB
mobile (index.js) 1.99KB 0.87KB
mobile (offlineQueue.js) 3.91KB 1.35KB
mobile (pwa.js) 0.97KB 0.49KB
mobile (serviceWorker.js) 1.48KB 0.62KB
mobile (serviceWorkerSource.js) 3.41KB 1.48KB
mobile (useBreakpoint.js) 1.54KB 0.65KB
mobile (useGesture.js) 6.96KB 1.98KB
mobile (useOfflineSync.js) 1.99KB 0.72KB
mobile (usePullToRefresh.js) 6.62KB 2.45KB
mobile (useResponsive.js) 0.72KB 0.42KB
mobile (useSpecGesture.js) 5.52KB 2.10KB
mobile (useTouchTarget.js) 1.01KB 0.54KB
permissions (MePermissionsProvider.js) 13.86KB 5.00KB
permissions (PermissionContext.js) 0.31KB 0.25KB
permissions (PermissionGuard.js) 0.89KB 0.45KB
permissions (PermissionProvider.js) 6.52KB 2.26KB
permissions (discardProofCache.js) 1.04KB 0.55KB
permissions (evaluator.js) 8.33KB 3.07KB
permissions (index.js) 0.93KB 0.41KB
permissions (store.js) 0.91KB 0.42KB
permissions (useFieldPermissions.js) 1.28KB 0.53KB
permissions (usePermissions.js) 4.83KB 2.27KB
plugin-ai (index.js) 16.04KB 3.92KB
plugin-calendar (index.js) 53.17KB 15.46KB
plugin-charts (index.js) 84.26KB 23.05KB
plugin-chatbot (index.js) 198.22KB 46.97KB
plugin-dashboard (index.js) 143.54KB 38.79KB
plugin-designer (index.js) 231.41KB 48.84KB
plugin-detail (index.js) 245.97KB 64.67KB
plugin-editor (index.js) 2.23KB 1.05KB
plugin-form (index.js) 177.09KB 45.89KB
plugin-gantt (index.js) 179.16KB 45.06KB
plugin-grid (index.js) 235.92KB 64.87KB
plugin-kanban (index.js) 50.06KB 15.74KB
plugin-list (index.js) 116.72KB 29.10KB
plugin-map (index.js) 25.60KB 8.62KB
plugin-markdown (index.js) 13.88KB 4.80KB
plugin-report (index.js) 44.12KB 12.29KB
plugin-timeline (index.js) 38.80KB 11.71KB
plugin-tree (index.js) 14.51KB 5.15KB
plugin-view (index.js) 90.23KB 22.73KB
providers (DataSourceProvider.js) 0.75KB 0.39KB
providers (MetadataProvider.js) 1.37KB 0.59KB
providers (ThemeProvider.js) 1.90KB 0.85KB
providers (UploadProvider.js) 11.81KB 3.58KB
providers (index.js) 0.45KB 0.23KB
providers (types.js) 0.01KB 0.04KB
react-runtime (index.js) 5.62KB 2.34KB
react (LazyPluginLoader.js) 4.47KB 1.63KB
react (SchemaRenderer.js) 120.63KB 39.56KB
react (data-invalidation.js) 5.05KB 2.08KB
react (index.js) 4.50KB 2.06KB
react (schema-input.js) 4.31KB 2.07KB
react (spec-input.js) 0.20KB 0.18KB
sdui-parser (body-dialect.js) 4.50KB 1.99KB
sdui-parser (codegen.js) 9.45KB 3.76KB
sdui-parser (dashboard-widget-options.js) 3.08KB 1.30KB
sdui-parser (index.js) 7.30KB 3.12KB
sdui-parser (input-type.js) 2.84KB 1.40KB
sdui-parser (parse.js) 25.28KB 7.80KB
sdui-parser (provenance.js) 3.84KB 1.90KB
sdui-parser (types.js) 0.28KB 0.23KB
sdui-parser (validate.js) 23.87KB 7.83KB
types (ai.js) 4.39KB 2.17KB
types (api-types.js) 0.20KB 0.18KB
types (app.js) 4.12KB 1.61KB
types (authoring-nodes.js) 0.20KB 0.19KB
types (base.js) 0.20KB 0.18KB
types (blocks.js) 0.20KB 0.18KB
types (cloud.js) 0.20KB 0.18KB
types (complex.js) 4.44KB 2.07KB
types (crud.js) 0.20KB 0.18KB
types (dashboard-filter-alias.js) 6.23KB 2.74KB
types (dashboard-widget-layout.js) 2.06KB 0.96KB
types (data-display.js) 3.75KB 1.85KB
types (data-protocol.js) 0.20KB 0.19KB
types (data.js) 0.20KB 0.18KB
types (designer.js) 1.85KB 0.85KB
types (disclosure.js) 0.20KB 0.18KB
types (error-code.js) 1.54KB 0.88KB
types (expression.js) 0.20KB 0.18KB
types (feedback.js) 0.20KB 0.18KB
types (field-types.js) 1.13KB 0.65KB
types (form.js) 0.20KB 0.18KB
types (http-inflight.js) 8.87KB 3.73KB
types (http-retry.js) 4.32KB 2.02KB
types (icon-key-migration.js) 4.26KB 1.63KB
types (index.js) 5.78KB 2.70KB
types (layout.js) 0.20KB 0.18KB
types (managed-by.js) 0.19KB 0.18KB
types (mobile.js) 5.00KB 2.39KB
types (navigation.js) 0.20KB 0.18KB
types (node-slots.js) 7.18KB 2.34KB
types (objectql.js) 0.20KB 0.18KB
types (overlay.js) 0.20KB 0.18KB
types (permissions.js) 2.52KB 1.31KB
types (plugin-scope.js) 0.20KB 0.18KB
types (record-components.js) 0.20KB 0.19KB
types (record-semantics.js) 1.28KB 0.67KB
types (registry.js) 0.20KB 0.18KB
types (reports.js) 0.20KB 0.18KB
types (select-option.js) 0.20KB 0.19KB
types (spec-report.js) 4.99KB 1.96KB
types (spec-ui-namespace.js) 0.20KB 0.19KB
types (strict-authoring-face.js) 19.93KB 7.25KB
types (system-fields.js) 3.33KB 1.54KB
types (theme.js) 6.28KB 2.87KB
types (ui-action.js) 8.11KB 3.32KB
types (views.js) 0.20KB 0.18KB
types (widget.js) 0.20KB 0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@objectstack-fleet
objectstack-fleet Bot marked this pull request as ready for review October 5, 2026 04:02
@objectstack-fleet
objectstack-fleet Bot enabled auto-merge October 5, 2026 04:02
@objectstack-fleet
objectstack-fleet Bot added this pull request to the merge queue Oct 5, 2026
Merged via the queue into main with commit 0abd4f9 Oct 5, 2026
45 checks passed
@objectstack-fleet
objectstack-fleet Bot deleted the claude/issue-11628-external-envelope branch October 5, 2026 04:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

2 participants