Skip to content

fix(console): the audit log names the actor and filters by a user lookup (objectui#11701) - #11739

Merged
objectstack-fleet[bot] merged 3 commits into
mainfrom
claude/issue-11701-audit-actor-name
Oct 6, 2026
Merged

objectstack-fleet[bot] merged 3 commits into
mainfrom
claude/issue-11701-audit-actor-name

Conversation

@objectstack-fleet

Copy link
Copy Markdown
Contributor

Fixes #11701
Clause-②: no

The console's Audit Log page (/system/audit-log, component ref audit:log) printed sys_audit_log.user_id as a truncated raw id, and its actor filter was a free-text box that took an id. This PR makes the page name the actor and turns the filter into a user lookup. The whole change is in apps/console/src/pages/system/AuditLogPage.tsx. The producer side needed no change.

What changed

  • The fetch. The page's one /api/v1/data/sys_audit_log read now sends $expand=user_id. No request is added.
  • The actor column. It shows the user's name, with the user id as its title (shown on hover). For a user the server could not resolve, the column shows the id (truncated, with the full id on hover). A row with an empty user_id reads "System", and the recorded actor principal (such as svc:NAME) shows on hover.
  • The drawer. The Actor row shows the name with the full id below it. A row with no user shows "System" and the principal.
  • The filter. The free-text input is now LookupField from @object-ui/fields, with reference: 'sys_user'. It writes the chosen user's id to filter.user_id. Removing the chip writes null, which removes the filter. "Clear filters" still resets it.

Which path, and why (the order's Zone 2 assumptions, measured)

  1. Page shape. It matches the order. The page used a raw fetch with $filter / $orderby / $top / $skip, rendered truncate(r.user_id, 18) in monospace, and had a free-text Input that wrote filter.user_id. Confirmed on main at 22b503c.

  2. Name source: the expansion, not a batched read. I read objectstack at 1fb274e61c, fetched into a named ref:

    • sys_audit_log.user_id is Field.lookup('sys_user', ...) in packages/plugins/plugin-audit/src/objects/sys-audit-log.object.ts.
    • The protocol's list normalizer folds $expand onto expand. assertExpandTargetsExist accepts a reference-typed field that names a target.
    • expandRelatedRecords in packages/objectql/src/engine.ts loads the referenced ids in one id $in read through the engine's own find, so sys_user's full read gate applies. It puts each record in place of its id. When the user is missing or the read is refused, it keeps the bare id.
    • sys_user declares nameField: 'name'.
    • The audit plugin's read-visibility and field-redaction hooks do not touch user_id or the expansion.

    So the expansion takes one request, keeps the id visible for deleted users, and applies the permissions of the referenced object. A separate batched sys_user read would add a request to do what the engine already does.

  3. The filter widget: LookupField, not UserField. @object-ui/fields already exports both, so nothing new is exported. UserField serves user-type fields, and it always adds a banned not-equal-true candidate filter (withBannedFilter). With it, nobody could pick a deactivated user, and that is the user an audit search most often needs. sys_audit_log.user_id is declared as a lookup to sys_user, and LookupField with reference: 'sys_user' is the widget for that declaration. The page gets the adapter from useAdapter() (@object-ui/app-shell), as the other system pages do. Inline create stays off, which is already the default for sys_ references.

  4. Copy. The page's labels stay English literals: "Actor", "Any user", "System". No i18n key is added. The lookup uses its existing keys (common.select, table.search, lookup.*).

Tests (at 8e17dbf)

The new suite is apps/console/src/pages/system/AuditLogPage.actorName-11701.test.tsx, with 7 tests. It stubs both data seams the page reads. fetch answers /data/sys_audit_log the way the engine answers $expand=user_id, and it applies a $filter on user_id. useAdapter serves sys_user to the lookup. The tests pin these behaviours:

  • every list request sends $expand=user_id;
  • a change by the seeded admin shows "Admin User", with the id on hover;
  • an unresolved user shows the id, with the id on hover;
  • a change with no user reads "System", with the principal on hover;
  • the drawer shows the name and the full id;
  • choosing the admin in the lookup sends a $filter of the admin's user_id, and only the admin's row is listed;
  • removing the chosen user drops the $filter, and every row is listed again.

Every run below went through os-verify-lock.sh with slot issue-11701:

Command Result
pnpm exec vitest run on the new suite and consoleFaces.displayLocale-9909.test.tsx (the other suite that renders this page) 2 files, 19 passed
pnpm exec vitest run apps/console/ (the whole console package, run from the repo root) 155 files, 1806 passed
pnpm --workspace-concurrency=2 --filter '@object-ui/console^...' run build exit 0 (35 packages)
pnpm --filter @object-ui/console run type-check exit 0. tsc --listFilesOnly lists both changed files.
pnpm --filter @object-ui/console run lint exit 0, 0 errors. The two warnings in this file, err: any in the catch and the useEffect that calls load, are on code that was already there.

Ablation: one leg, predicted before the run to turn two pins red. HEAD carried the fix. ablation-replace.mjs changed the face.name return in ActorCell so the same span renders truncate(face.id, 18). That puts the raw id back where the name was. The anchor count went from 1 to 0, and the blob went from 970a60a9c060 to f13067506aca. The suite read 2 failed, 5 passed. The two failures were "shows the seeded admin's name ..." and "choosing the admin ... lists the admin's row", and both read Expected ... Admin User, Received: usr_admin_0001. After the restore, the blob was 970a60a9c060, equal to HEAD, git diff HEAD was empty, and git status was clean. The suite imports the page by relative path, so the ablation hits src directly and needs no dist step.

Gates (at 8e17dbf, each exit 0)

check-changeset-presence, check-changeset-no-major, check-changeset-fixed, check:new-line-citations (0 new), check:control-bytes, check:changeset-claims (its corpus is this change's one changeset), check:pending-changeset-literals, check-governed-queue-guard --test over the three paths (NOT GOVERNED), check:vi-mock-specifiers, check:vi-mock-inherit, check:vi-mock-override-shape, check:test-path-roots, check:i18n-keys, check:phantom-deps, check:unused-deps, check:element-data-source-declaration, check:handler-key-reads, check:metadata-write-doors, check:unreferenced-sources.

check:vi-mock-inherit rejected the suite's first vi.mock('@object-ui/app-shell') factory, which listed useAdapter by hand. The factory now spreads the real module (commit 8e17dbf).

NOT MEASURED:

  • check:eager-closure: exit 2 because a prerequisite is missing. It needs apps/console/dist/eager-closure.json, which comes from a console vite build that was not run here. Both places that mount this page load it through React lazy with a dynamic import (AppContent.tsx, registerSystemComponents.tsx), so the new imports land in the page's lazy chunk. CI measures this gate.
  • A live backend and browser run. The objectstack checkout in this container is not installed or built. The $expand path was therefore checked by reading the source at 1fb274e61c, and the page by the stubbed suite above.
  • Repo-wide lint and the full pnpm test belong to CI.

Changeset

.changeset/11701-audit-actor-name.md declares '@object-ui/console': patch. The page is part of an app, and no package entry changes. That matches the console-only precedents 11633-verify-email-get.md and 11677-approvals-summary-faces.md. The changeset body says Clause-②: no.

Acceptance notes

  • objectui#11697 keeps the composite and record-map half. This PR does not touch it.
  • Observation, not filed: when the lookup's dropdown lists sys_user rows, LookupField previews the email column through EmailCellRenderer, and that renderer's copy control is a button inside the option button. React logs "button cannot contain a nested button". It showed up in this suite's stderr on a failing run. It does not fail a test, and it comes from @object-ui/fields, not from this page. It was not measured at a public entry point, so it is noted here and not filed.
  • Observation, not filed: the page still reads through a raw fetch with credentials: 'include', not the console adapter. AGENTS.md §7 asks for @objectstack/client. That predates this change, which kept the one fetch and added $expand to it.

Generated by Claude Code

claude added 3 commits October 6, 2026 17:06
…kup (objectui#11701)

The list fetch asks for `$expand=user_id`, so the engine puts each actor's
`sys_user` record in place of its id. The actor column shows the user's name
with the id on hover, a user the engine could not resolve shows the id, and a
change no user made reads "System" with the recorded principal on hover. The
drawer shows the name and the full id.

The free-text actor box is replaced by the `sys_user` lookup from
`@object-ui/fields`. It commits the chosen user's id to `filter.user_id`, and
removing the chip clears it.

Claude-Session: https://claude.ai/code/session_01FngvPpdrnhHMdHHq6vwwju
Co-authored-by: Claude <noreply@anthropic.com>
…surface (objectui#11701)

`check-vi-mock-inherit` refuses a hand-listed factory for a judged workspace
package. The mock now spreads the real module and overrides `useAdapter` only.

Claude-Session: https://claude.ai/code/session_01FngvPpdrnhHMdHHq6vwwju
Co-authored-by: Claude <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

Metric Value Budget
Eager closure (gzip, 331 chunks) 3325.9 KB 3330.4 KB
Main entry chunk (gzip) 154.3 KB 350 KB
Entry file index-CDdeNNoX.js —
Status PASS —

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

Package Size Gzipped
app-shell (consoleActionDispatch.js) 0.20KB 0.19KB
app-shell (index.js) 17.82KB 6.58KB
app-shell (runtime-config.js) 22.52KB 7.86KB
app-shell (types.js) 0.01KB 0.04KB
app-shell (urlParams.js) 10.11KB 3.87KB
auth (ActiveOrganizationStorage.js) 27.95KB 10.04KB
auth (AuthContext.js) 0.31KB 0.24KB
auth (AuthGuard.js) 2.07KB 1.00KB
auth (AuthProvider.js) 40.22KB 10.61KB
auth (AuthShell.js) 3.49KB 1.40KB
auth (ForgotPasswordForm.js) 12.21KB 3.45KB
auth (LoginForm.js) 18.15KB 5.40KB
auth (PreviewBanner.js) 0.90KB 0.50KB
auth (RegisterForm.js) 6.72KB 2.24KB
auth (SocialSignInButtons.js) 9.70KB 3.93KB
auth (UserMenu.js) 3.39KB 1.21KB
auth (auth-gate-events.js) 1.29KB 0.66KB
auth (authStyles.js) 5.04KB 1.72KB
auth (createAuthClient.js) 40.70KB 10.94KB
auth (createAuthenticatedFetch.js) 8.54KB 3.46KB
auth (index.js) 3.63KB 1.64KB
auth (invitation-status.js) 1.22KB 0.70KB
auth (org-roles.js) 6.66KB 2.78KB
auth (phone-identifier.js) 1.11KB 0.66KB
auth (types.js) 0.59KB 0.35KB
auth (useAuth.js) 5.30KB 1.02KB
auth (useWorkspaceAdminStatus.js) 11.08KB 4.58KB
collaboration (CommentThread.js) 27.11KB 7.97KB
collaboration (LiveCursors.js) 3.17KB 1.27KB
collaboration (PresenceAvatars.js) 6.28KB 2.60KB
collaboration (PresenceProvider.js) 2.79KB 1.13KB
collaboration (index.js) 1.68KB 0.73KB
collaboration (useCollaborationTranslation.js) 6.50KB 2.52KB
collaboration (useCommentSearch.js) 1.98KB 0.88KB
collaboration (useConflictResolution.js) 7.75KB 1.86KB
collaboration (useMentionNotifications.js) 1.81KB 0.68KB
collaboration (usePresence.js) 6.33KB 1.84KB
collaboration (useRealtimeSubscription.js) 7.91KB 2.01KB
components (index.js) 578.98KB 139.21KB
core (index.js) 10.00KB 3.96KB
create-plugin (index.js) 27.94KB 9.51KB
data-objectstack (index.js) 233.72KB 64.83KB
fields (index.js) 263.36KB 66.69KB
i18n (LocalizationContext.js) 1.76KB 0.96KB
i18n (builtinAggregateLabels.js) 0.86KB 0.49KB
i18n (currency.js) 2.59KB 1.22KB
i18n (fallbackInterpolation.js) 6.25KB 2.77KB
i18n (i18n.js) 8.87KB 3.64KB
i18n (index.js) 5.52KB 2.39KB
i18n (pickLocalized.js) 9.86KB 3.95KB
i18n (provider.js) 39.35KB 12.88KB
i18n (translateFn.js) 0.20KB 0.18KB
i18n (useDisplayLocale.js) 3.52KB 1.76KB
i18n (useObjectLabel.js) 37.51KB 10.04KB
i18n (useSafeTranslation.js) 7.14KB 2.92KB
layout (index.js) 41.18KB 11.71KB
mobile (MobileProvider.js) 0.92KB 0.49KB
mobile (ResponsiveContainer.js) 0.94KB 0.38KB
mobile (breakpoints.js) 1.51KB 0.70KB
mobile (createOfflineDataSource.js) 5.61KB 1.75KB
mobile (index.js) 1.99KB 0.87KB
mobile (offlineQueue.js) 3.91KB 1.35KB
mobile (pwa.js) 0.97KB 0.49KB
mobile (serviceWorker.js) 1.48KB 0.62KB
mobile (serviceWorkerSource.js) 3.41KB 1.48KB
mobile (useBreakpoint.js) 1.54KB 0.65KB
mobile (useGesture.js) 6.96KB 1.98KB
mobile (useOfflineSync.js) 1.99KB 0.72KB
mobile (usePullToRefresh.js) 6.62KB 2.45KB
mobile (useResponsive.js) 0.72KB 0.42KB
mobile (useSpecGesture.js) 5.52KB 2.10KB
mobile (useTouchTarget.js) 1.01KB 0.54KB
permissions (MePermissionsProvider.js) 13.86KB 5.00KB
permissions (PermissionContext.js) 0.31KB 0.25KB
permissions (PermissionGuard.js) 0.89KB 0.45KB
permissions (PermissionProvider.js) 6.52KB 2.26KB
permissions (discardProofCache.js) 1.04KB 0.55KB
permissions (evaluator.js) 8.33KB 3.07KB
permissions (index.js) 0.93KB 0.41KB
permissions (store.js) 0.91KB 0.42KB
permissions (useFieldPermissions.js) 1.28KB 0.53KB
permissions (usePermissions.js) 4.83KB 2.27KB
plugin-ai (index.js) 16.04KB 3.92KB
plugin-calendar (index.js) 53.39KB 15.52KB
plugin-charts (index.js) 84.26KB 23.05KB
plugin-chatbot (index.js) 198.81KB 47.14KB
plugin-dashboard (index.js) 144.26KB 38.97KB
plugin-designer (index.js) 231.46KB 48.87KB
plugin-detail (index.js) 247.28KB 65.06KB
plugin-editor (index.js) 2.23KB 1.05KB
plugin-form (index.js) 177.09KB 45.89KB
plugin-gantt (index.js) 179.16KB 45.06KB
plugin-grid (index.js) 238.51KB 65.53KB
plugin-kanban (index.js) 52.17KB 16.37KB
plugin-list (index.js) 116.85KB 29.12KB
plugin-map (index.js) 25.60KB 8.62KB
plugin-markdown (index.js) 13.88KB 4.80KB
plugin-report (index.js) 44.12KB 12.29KB
plugin-timeline (index.js) 38.90KB 11.74KB
plugin-tree (index.js) 15.07KB 5.33KB
plugin-view (index.js) 90.23KB 22.73KB
providers (DataSourceProvider.js) 0.75KB 0.39KB
providers (MetadataProvider.js) 1.37KB 0.59KB
providers (ThemeProvider.js) 1.90KB 0.85KB
providers (UploadProvider.js) 11.81KB 3.58KB
providers (index.js) 0.45KB 0.23KB
providers (types.js) 0.01KB 0.04KB
react-runtime (index.js) 5.62KB 2.34KB
react (LazyPluginLoader.js) 4.47KB 1.63KB
react (SchemaRenderer.js) 120.63KB 39.56KB
react (data-invalidation.js) 5.05KB 2.08KB
react (index.js) 4.50KB 2.06KB
react (schema-input.js) 4.31KB 2.07KB
react (spec-input.js) 0.20KB 0.18KB
sdui-parser (body-dialect.js) 4.50KB 1.99KB
sdui-parser (codegen.js) 9.45KB 3.76KB
sdui-parser (dashboard-widget-options.js) 3.08KB 1.30KB
sdui-parser (index.js) 7.30KB 3.12KB
sdui-parser (input-type.js) 2.84KB 1.40KB
sdui-parser (parse.js) 25.28KB 7.80KB
sdui-parser (provenance.js) 3.84KB 1.90KB
sdui-parser (types.js) 0.28KB 0.23KB
sdui-parser (validate.js) 23.87KB 7.83KB
types (ai.js) 4.39KB 2.17KB
types (api-types.js) 0.20KB 0.18KB
types (app.js) 4.12KB 1.61KB
types (authoring-nodes.js) 0.20KB 0.19KB
types (base.js) 0.20KB 0.18KB
types (blocks.js) 0.20KB 0.18KB
types (cloud.js) 0.20KB 0.18KB
types (complex.js) 4.44KB 2.07KB
types (crud.js) 0.20KB 0.18KB
types (dashboard-filter-alias.js) 6.23KB 2.74KB
types (dashboard-widget-layout.js) 2.06KB 0.96KB
types (data-display.js) 3.75KB 1.85KB
types (data-protocol.js) 0.20KB 0.19KB
types (data.js) 0.20KB 0.18KB
types (designer.js) 1.85KB 0.85KB
types (disclosure.js) 0.20KB 0.18KB
types (error-code.js) 1.54KB 0.88KB
types (expression.js) 0.20KB 0.18KB
types (feedback.js) 0.20KB 0.18KB
types (field-types.js) 1.13KB 0.65KB
types (form.js) 0.20KB 0.18KB
types (http-inflight.js) 8.87KB 3.73KB
types (http-retry.js) 4.32KB 2.02KB
types (icon-key-migration.js) 4.26KB 1.63KB
types (index.js) 5.78KB 2.70KB
types (layout.js) 0.20KB 0.18KB
types (managed-by.js) 0.19KB 0.18KB
types (mobile.js) 5.00KB 2.39KB
types (navigation.js) 0.20KB 0.18KB
types (node-slots.js) 7.18KB 2.34KB
types (objectql.js) 0.20KB 0.18KB
types (overlay.js) 0.20KB 0.18KB
types (permissions.js) 2.52KB 1.31KB
types (plugin-scope.js) 0.20KB 0.18KB
types (record-components.js) 0.20KB 0.19KB
types (record-semantics.js) 1.28KB 0.67KB
types (registry.js) 0.20KB 0.18KB
types (reports.js) 0.20KB 0.18KB
types (select-option.js) 0.20KB 0.19KB
types (spec-report.js) 4.99KB 1.96KB
types (spec-ui-namespace.js) 0.20KB 0.19KB
types (strict-authoring-face.js) 19.93KB 7.25KB
types (system-fields.js) 3.33KB 1.54KB
types (theme.js) 6.28KB 2.87KB
types (ui-action.js) 8.11KB 3.32KB
types (views.js) 0.20KB 0.18KB
types (widget.js) 0.20KB 0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

audit log: the actor column shows a truncated raw user id and the actor filter is free text, not a user lookup (split from objectui#11697)

2 participants