Skip to content

fix(app-shell): the marketplace load error names its real cause, and no empty state under it - #11724

Merged
objectstack-fleet[bot] merged 2 commits into
mainfrom
claude/issue-11688-marketplace-load-error-cause
Oct 6, 2026
Merged

objectstack-fleet[bot] merged 2 commits into
mainfrom
claude/issue-11688-marketplace-load-error-cause

Conversation

@objectstack-fleet

Copy link
Copy Markdown
Contributor

Fixes #11688
Clause-②: no

What was wrong (measured on main at c910630)

Browse Marketplace showed "Failed to load marketplace · Forbidden · This runtime serves the marketplace catalog itself. Check that the runtime is online.", and under it "No apps have been approved for the marketplace yet." Traced hop by hop:

  1. The runtime's marketplace proxy (MarketplaceProxyPlugin, objectstack packages/cloud-connection) forwards the upstream status, content-type and body unchanged (passthroughResponse / consumeAndMaybeCache).
  2. The upstream answer was an egress proxy's refusal. Measured from a container with the same egress posture: Node fetch of the catalog URL on cloud.objectos.ai returns 403 Forbidden, content-type: text/plain, body Host not in allowlist: cloud.objectos.ai. Add this host to your network egress settings to allow access. (the sweep's exact text).
  3. call() in marketplaceApi.ts parsed the body with res.json(), which throws on plain text, so readApiError fell back to res.statusText: "Forbidden".
  4. MarketplacePage drew one of the two "is it online" hints under every failure, and its empty-state branch keyed on the item count alone.

The dispatch's mechanism assumption 1 holds; the body is text/plain, not a JSON { error }.

What changed

  • call() (the browse requests: the catalog list and the package detail) reads the body once as text and parses JSON from it. When the response failed, the body is not JSON and content-type is text/plain, that text is the failure's message. JSON envelopes read exactly as before through readApiError; any other body that is not JSON (an HTML error page) still shows the status text. A failure a server answered still carries its status; a request no server answered rejects with what fetch threw, which has none.
  • MarketplacePage keeps the failure typed (LoadFailure: the message, and whether the online hint applies). The hint, which still names the control plane the server reported (the objectui#5504 rule, unchanged), is drawn only when no server answered (no status) or the answer was 502, 503 or 504. The server's text is a React text child, never dangerouslySetInnerHTML.
  • The empty state is not drawn while a load error is shown.
  • Partial failure: the catalog request is settled inside the batch, so its failure no longer discards the three side loads. On main, Promise.all rejected and the "Your organization" section and the installed count were never set.

No locale key was added or moved: the server's text plus the two existing hints cover every case, so Clause-②: no stands.

Where this departs from the dispatch's suggested route, and why

  • The online hint is chosen by status, not by failure kind alone. The suggested route was: answered failure, message only; network failure, hint. Measured against the runtime proxy: when the control plane really is down, the runtime answers its own 502 MARKETPLACE_PROXY_FAILED envelope (message "fetch failed"). A kind-only rule would drop the hint that names the plane in exactly the case objectui#5504 wrote it for. So 502, 503 and 504 keep the hint, and every other answered status shows the server's text alone. The card's Done-when allows "a hint chosen by status".
  • No configured-host hint under an answered refusal (mechanism assumption 2a). Both existing hints end in "check that it is online", so pairing failedHintConfigured with a 403 would draw again the wrong-cause line this card retires.
  • The failure kind is read from status, not from a new error class. The page tests mock ../marketplaceApi with factories that list specific exports. A runtime import of a class for instanceof would throw inside the catch path of every one of them. call() already stamped status on every answered failure, so the discriminant is what fetch yielded, with no message matching.
  • Partial failure fixed in place (mechanism assumption 4 asked for the check). It is the same defect class as this card (what the page draws under a load error), in a file already in the claim's surface, pinned in the same new test file, with no new gate.

Tests

All at 68c0d13, the final head, unless marked. 68c0d13 adds only the changeset to 9f2ed7f, so no TypeScript program or lint input moved between the two.

  • Dependency closure: pnpm --workspace-concurrency=2 --filter '@object-ui/app-shell^...' build: exit 0, 29 projects.
  • app-shell's own suite, run from the repo root: pnpm exec vitest run --maxWorkers=2 packages/app-shell/: Test Files 1032 passed | 1 skipped (1033), Tests 10173 passed | 9 skipped (10182), lock VERDICT command-exit 0.
  • New pin, verbose (MarketplacePage.loadFailureCause-11688.test.tsx, at 9f2ed7f): 8/8 passed. The cases: the plain-text 403 allowlist refusal under both config shapes, a JSON envelope refusal, an HTML error page, a network failure, the runtime proxy's 502, the empty-catalog control, and the partial failure.
  • pnpm --filter @object-ui/app-shell type-check (at 9f2ed7f): exit 0. The new test is in tsconfig.test.json's program (--listFiles: 1 hit).
  • pnpm --filter @object-ui/app-shell lint (at 9f2ed7f): exit 0, 0 errors. Warnings per touched file, BASE then HEAD: MarketplacePage.tsx 3 then 2 (one any removed), marketplaceApi.ts 36 then 36, the new test 0.
  • Gates, each exit 0 with its own green verdict line: check:new-line-citations (0 new citations), check:control-bytes, check:changeset-claims, check:pending-changeset-literals, changeset:check (fixed group, no major), scripts/check-changeset-presence.mjs, check:i18n-keys, check:vi-mock-specifiers, check:vi-mock-inherit, check:vi-mock-override-shape, check:test-path-roots, and scripts/check-governed-queue-guard.mjs --test over the four paths (NOT GOVERNED).

Ablation (one leg: the failure-kind split reverted)

Run at 9f2ed7f, with the fix committed, through objectstack's scripts/ablation-replace.mjs in wrap mode (its own restore trap), plus a shell trap that restores from HEAD:

  • Mutation: showOnlineHint: status === undefined || UNREACHABLE_STATUSES.has(status), became showOnlineHint: true,, which draws the hint under every failure, as on main. On disk: anchor 1 to 0, replacement 0 to 1, blob 9a231e78 to df420a1c.
  • Predicted: both 403 rows and the JSON-envelope refusal go red on the hint assertion, and the other five stay green. Observed: Tests 3 failed | 5 passed (8); all three fail at expect(screen.queryByTestId('marketplace-load-hint')).toBeNull().
  • Restore: the blob after restore equals the blob at HEAD (9a231e78), and git diff HEAD is empty (0 bytes).

Acceptance notes (observed, not changed here)

  • The same-origin hint can be false on a CLI-served runtime. failedHintSameOrigin says "This runtime serves the marketplace catalog itself", keyed on runtime-config cloudUrl being empty. objectstack's own isControlPlaneDeclined header says the CLI passes controlPlaneUrl: '' on both the cloud-connected and the air-gapped arm, while resolveCloudUrl points the marketplace proxy at https://cloud.objectos.ai by default. The sweep's runtime was exactly that shape. This PR stops drawing the hint under a 403; it still appears there for a network failure or a 502/503/504. Reported to the seat as a finding, with no edit here.
  • Same class, untouched: installLocal, installPackage, uninstallLocal, the local sample-data actions and reseedSampleData / purgeSampleData in marketplaceApi.ts still parse JSON only, so a text/plain refusal there still shows the status text. Carrier: none.
  • The runtime proxy forwards a foreign hop's text/plain refusal as its own answer, not in the { success: false, error: { code, message } } envelope its own failures use. Carrier: none.
  • The objectui#5504 pins in MarketplacePage.disabledState.test.tsx model "control plane merely down" as a rejection with no status (CATALOG_404). Under this PR that is the no-response leg, so they stay green unchanged; the real 502 shape is pinned in the new file. They are not renamed here.

Changeset

.changeset/11688-marketplace-load-error-cause.md: @object-ui/app-shell patch (a rendered-behaviour fix in a published package; no key, no export).


Generated by Claude Code

claude added 2 commits October 6, 2026 14:13
…no empty state under it

A 403 the server answered in text/plain ("Host not in allowlist: ...") was
shown as the bare status text "Forbidden", followed by the fixed "check that
the runtime is online" hint and then "No apps have been approved for the
marketplace yet."

- call() reads the body once as text and, when it is not JSON and is
  text/plain, uses that text as the failure's message.
- MarketplacePage keeps the failure typed: the online hint is drawn only
  when no server answered, or the answer was 502/503/504.
- The empty state is not drawn while a load error is shown, and a catalog
  failure no longer discards the side loads (org packages, installed count).

Claude-Session: https://claude.ai/code/session_01FngvPpdrnhHMdHHq6vwwju
Co-authored-by: Claude <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

Metric Value Budget
Eager closure (gzip, 331 chunks) 3324.0 KB 3330.4 KB
Main entry chunk (gzip) 153.6 KB 350 KB
Entry file index-BqQTC2gA.js —
Status PASS —

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

Package Size Gzipped
app-shell (consoleActionDispatch.js) 0.20KB 0.19KB
app-shell (index.js) 17.82KB 6.58KB
app-shell (runtime-config.js) 22.52KB 7.86KB
app-shell (types.js) 0.01KB 0.04KB
app-shell (urlParams.js) 10.11KB 3.87KB
auth (ActiveOrganizationStorage.js) 27.95KB 10.04KB
auth (AuthContext.js) 0.31KB 0.24KB
auth (AuthGuard.js) 2.07KB 1.00KB
auth (AuthProvider.js) 40.22KB 10.61KB
auth (AuthShell.js) 3.49KB 1.40KB
auth (ForgotPasswordForm.js) 12.21KB 3.45KB
auth (LoginForm.js) 18.15KB 5.40KB
auth (PreviewBanner.js) 0.90KB 0.50KB
auth (RegisterForm.js) 6.72KB 2.24KB
auth (SocialSignInButtons.js) 9.70KB 3.93KB
auth (UserMenu.js) 3.39KB 1.21KB
auth (auth-gate-events.js) 1.29KB 0.66KB
auth (authStyles.js) 5.04KB 1.72KB
auth (createAuthClient.js) 40.70KB 10.94KB
auth (createAuthenticatedFetch.js) 8.54KB 3.46KB
auth (index.js) 3.63KB 1.64KB
auth (invitation-status.js) 1.22KB 0.70KB
auth (org-roles.js) 6.66KB 2.78KB
auth (phone-identifier.js) 1.11KB 0.66KB
auth (types.js) 0.59KB 0.35KB
auth (useAuth.js) 5.30KB 1.02KB
auth (useWorkspaceAdminStatus.js) 11.08KB 4.58KB
collaboration (CommentThread.js) 27.11KB 7.97KB
collaboration (LiveCursors.js) 3.17KB 1.27KB
collaboration (PresenceAvatars.js) 6.28KB 2.60KB
collaboration (PresenceProvider.js) 2.79KB 1.13KB
collaboration (index.js) 1.68KB 0.73KB
collaboration (useCollaborationTranslation.js) 6.50KB 2.52KB
collaboration (useCommentSearch.js) 1.98KB 0.88KB
collaboration (useConflictResolution.js) 7.75KB 1.86KB
collaboration (useMentionNotifications.js) 1.81KB 0.68KB
collaboration (usePresence.js) 6.33KB 1.84KB
collaboration (useRealtimeSubscription.js) 7.91KB 2.01KB
components (index.js) 574.74KB 137.95KB
core (index.js) 10.00KB 3.96KB
create-plugin (index.js) 27.94KB 9.51KB
data-objectstack (index.js) 233.72KB 64.83KB
fields (index.js) 262.75KB 66.62KB
i18n (LocalizationContext.js) 1.76KB 0.96KB
i18n (builtinAggregateLabels.js) 0.86KB 0.49KB
i18n (currency.js) 2.59KB 1.22KB
i18n (fallbackInterpolation.js) 6.25KB 2.77KB
i18n (i18n.js) 8.87KB 3.64KB
i18n (index.js) 5.52KB 2.39KB
i18n (pickLocalized.js) 9.86KB 3.95KB
i18n (provider.js) 39.35KB 12.88KB
i18n (translateFn.js) 0.20KB 0.18KB
i18n (useDisplayLocale.js) 3.52KB 1.76KB
i18n (useObjectLabel.js) 35.66KB 9.49KB
i18n (useSafeTranslation.js) 7.14KB 2.92KB
layout (index.js) 41.18KB 11.71KB
mobile (MobileProvider.js) 0.92KB 0.49KB
mobile (ResponsiveContainer.js) 0.94KB 0.38KB
mobile (breakpoints.js) 1.51KB 0.70KB
mobile (createOfflineDataSource.js) 5.61KB 1.75KB
mobile (index.js) 1.99KB 0.87KB
mobile (offlineQueue.js) 3.91KB 1.35KB
mobile (pwa.js) 0.97KB 0.49KB
mobile (serviceWorker.js) 1.48KB 0.62KB
mobile (serviceWorkerSource.js) 3.41KB 1.48KB
mobile (useBreakpoint.js) 1.54KB 0.65KB
mobile (useGesture.js) 6.96KB 1.98KB
mobile (useOfflineSync.js) 1.99KB 0.72KB
mobile (usePullToRefresh.js) 6.62KB 2.45KB
mobile (useResponsive.js) 0.72KB 0.42KB
mobile (useSpecGesture.js) 5.52KB 2.10KB
mobile (useTouchTarget.js) 1.01KB 0.54KB
permissions (MePermissionsProvider.js) 13.86KB 5.00KB
permissions (PermissionContext.js) 0.31KB 0.25KB
permissions (PermissionGuard.js) 0.89KB 0.45KB
permissions (PermissionProvider.js) 6.52KB 2.26KB
permissions (discardProofCache.js) 1.04KB 0.55KB
permissions (evaluator.js) 8.33KB 3.07KB
permissions (index.js) 0.93KB 0.41KB
permissions (store.js) 0.91KB 0.42KB
permissions (useFieldPermissions.js) 1.28KB 0.53KB
permissions (usePermissions.js) 4.83KB 2.27KB
plugin-ai (index.js) 16.04KB 3.92KB
plugin-calendar (index.js) 53.39KB 15.52KB
plugin-charts (index.js) 84.26KB 23.05KB
plugin-chatbot (index.js) 198.81KB 47.14KB
plugin-dashboard (index.js) 143.75KB 38.87KB
plugin-designer (index.js) 231.46KB 48.87KB
plugin-detail (index.js) 247.25KB 65.05KB
plugin-editor (index.js) 2.23KB 1.05KB
plugin-form (index.js) 177.09KB 45.89KB
plugin-gantt (index.js) 179.16KB 45.06KB
plugin-grid (index.js) 238.48KB 65.51KB
plugin-kanban (index.js) 52.17KB 16.37KB
plugin-list (index.js) 116.72KB 29.10KB
plugin-map (index.js) 25.60KB 8.62KB
plugin-markdown (index.js) 13.88KB 4.80KB
plugin-report (index.js) 44.12KB 12.29KB
plugin-timeline (index.js) 38.90KB 11.74KB
plugin-tree (index.js) 14.51KB 5.15KB
plugin-view (index.js) 90.23KB 22.73KB
providers (DataSourceProvider.js) 0.75KB 0.39KB
providers (MetadataProvider.js) 1.37KB 0.59KB
providers (ThemeProvider.js) 1.90KB 0.85KB
providers (UploadProvider.js) 11.81KB 3.58KB
providers (index.js) 0.45KB 0.23KB
providers (types.js) 0.01KB 0.04KB
react-runtime (index.js) 5.62KB 2.34KB
react (LazyPluginLoader.js) 4.47KB 1.63KB
react (SchemaRenderer.js) 120.63KB 39.56KB
react (data-invalidation.js) 5.05KB 2.08KB
react (index.js) 4.50KB 2.06KB
react (schema-input.js) 4.31KB 2.07KB
react (spec-input.js) 0.20KB 0.18KB
sdui-parser (body-dialect.js) 4.50KB 1.99KB
sdui-parser (codegen.js) 9.45KB 3.76KB
sdui-parser (dashboard-widget-options.js) 3.08KB 1.30KB
sdui-parser (index.js) 7.30KB 3.12KB
sdui-parser (input-type.js) 2.84KB 1.40KB
sdui-parser (parse.js) 25.28KB 7.80KB
sdui-parser (provenance.js) 3.84KB 1.90KB
sdui-parser (types.js) 0.28KB 0.23KB
sdui-parser (validate.js) 23.87KB 7.83KB
types (ai.js) 4.39KB 2.17KB
types (api-types.js) 0.20KB 0.18KB
types (app.js) 4.12KB 1.61KB
types (authoring-nodes.js) 0.20KB 0.19KB
types (base.js) 0.20KB 0.18KB
types (blocks.js) 0.20KB 0.18KB
types (cloud.js) 0.20KB 0.18KB
types (complex.js) 4.44KB 2.07KB
types (crud.js) 0.20KB 0.18KB
types (dashboard-filter-alias.js) 6.23KB 2.74KB
types (dashboard-widget-layout.js) 2.06KB 0.96KB
types (data-display.js) 3.75KB 1.85KB
types (data-protocol.js) 0.20KB 0.19KB
types (data.js) 0.20KB 0.18KB
types (designer.js) 1.85KB 0.85KB
types (disclosure.js) 0.20KB 0.18KB
types (error-code.js) 1.54KB 0.88KB
types (expression.js) 0.20KB 0.18KB
types (feedback.js) 0.20KB 0.18KB
types (field-types.js) 1.13KB 0.65KB
types (form.js) 0.20KB 0.18KB
types (http-inflight.js) 8.87KB 3.73KB
types (http-retry.js) 4.32KB 2.02KB
types (icon-key-migration.js) 4.26KB 1.63KB
types (index.js) 5.78KB 2.70KB
types (layout.js) 0.20KB 0.18KB
types (managed-by.js) 0.19KB 0.18KB
types (mobile.js) 5.00KB 2.39KB
types (navigation.js) 0.20KB 0.18KB
types (node-slots.js) 7.18KB 2.34KB
types (objectql.js) 0.20KB 0.18KB
types (overlay.js) 0.20KB 0.18KB
types (permissions.js) 2.52KB 1.31KB
types (plugin-scope.js) 0.20KB 0.18KB
types (record-components.js) 0.20KB 0.19KB
types (record-semantics.js) 1.28KB 0.67KB
types (registry.js) 0.20KB 0.18KB
types (reports.js) 0.20KB 0.18KB
types (select-option.js) 0.20KB 0.19KB
types (spec-report.js) 4.99KB 1.96KB
types (spec-ui-namespace.js) 0.20KB 0.19KB
types (strict-authoring-face.js) 19.93KB 7.25KB
types (system-fields.js) 3.33KB 1.54KB
types (theme.js) 6.28KB 2.87KB
types (ui-action.js) 8.11KB 3.32KB
types (views.js) 0.20KB 0.18KB
types (widget.js) 0.20KB 0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@objectstack-fleet
objectstack-fleet Bot marked this pull request as ready for review October 6, 2026 15:38
@objectstack-fleet
objectstack-fleet Bot enabled auto-merge October 6, 2026 15:38
@objectstack-fleet
objectstack-fleet Bot added this pull request to the merge queue Oct 6, 2026
Merged via the queue into main with commit 9cf08d9 Oct 6, 2026
45 checks passed
@objectstack-fleet
objectstack-fleet Bot deleted the claude/issue-11688-marketplace-load-error-cause branch October 6, 2026 15:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

2 participants