Repository navigation
fix(plugin-list): re-land the toolbar field-list read, rolled back for first-load bytes only (objectui#11984) - #12016
Merged
Conversation
… for first-load bytes only (objectui#11984) fix(plugin-list): the hide-fields, Group and Row color lists and the user-filter chips ask the field read (objectui#11984) (#11999) Fixes #11984 Clause-②: no The list toolbar's hide-fields popover, Group editor and Row color select no longer offer a field the caller may not read, and neither do its user-filter chips. Each now asks `canReadField`, the predicate objectui#11962 gave the Filter panel and the Sort picker, behind the same `isLoaded` gate. This is the family's third card, after objectui#11925 (filter) and objectui#11943 (sort), and it carries the enumeration pin triage asked for (`6063905126`). ## What changes All in `packages/plugin-list/src/ListView.tsx`: - **`allFields` asks the read.** It is the one list the hide-fields popover, the Group editor and the Row color select offer, and the compact toolbar's View settings popover hands it to the same three sections. A column the caller may not read is offered by none of them. Before the permission answer loads, nothing is withheld, as the column gate defers. - **The user-filter chips ask it too** (`filterElements`, now a memo declared below `perms`). A dropdown or toggle chip on an unreadable field is dropped, whether the author named the field or `resolvedUserFilters` derived it from the definition: a value chosen on it is a filter the server refuses, and the list blanks. One exception, shaped like the Sort picker's: a chip whose field a held selection names (the applied user filter, or a host-restored `userFilterSelections`) stays, so that filter can be cleared. Preset tabs pass through. - **Stored configuration on an unreadable field is kept as stored:** - a grouping level stays visible and removable. `GroupingEditor` already mounts a value its options lack as its own entry, labelled with the field name, so the level reads `secret_note` (the raw name), its remove button works, and no other level and no "Add group field" offers it. Nothing fires `onGroupingChange` until the user edits. - a hidden-field entry is withheld from both hide-fields lists: not listed, not counted in the badge, not cleared by "Show all", and every write puts it back. Without this, "Show all" would rewrite the view for its other viewers through an entry this caller was never shown. - a row-color rule is withheld from both Row color selects: they show None with no Clear, and the trigger is not marked. The rule stays in `rowColorConfig`; `ListView` has no row-color callback, so nothing writes it back to a host. It colors nothing for this caller anyway: the server masks the field out of their rows. - **Comments.** The `canReadField` docblock and the `effectiveFields` comment now name every list that asks the read, and point at the enumeration pin for which lists exist instead of asserting a list. **Named in-place fix: the user-filter chips.** The card names three lists; the chips are a fourth. Triage's ruling asks every field list `ListView` and its toolbar offer to pass the predicate, the probe found the derived chips offering an unreadable select field (below), and the change is the same defect class, the same predicate, in the file this claim holds, under the same gates. The seat may want to add the `resolvedUserFilters` / `filterElements` region to the claim's file surface. ## The dispatch's hypotheses - **H0, read first (objectstack `51290bca`, read only): the server refuses a grouping on an unreadable field; it does not reveal it.** The grid's header query rides `POST /data/:object/query`, and `findData` routes a body carrying `groupBy` to `engine.aggregate`. plugin-security refuses it twice over: step 2.9's `assertReadableQueryFields` walks `groupBy` (with `where`, `orderBy`, `having` and `aggregations`) and throws `PermissionDeniedError` (`code` `PERMISSION_DENIED`, `status` 403, reason `field_predicate_denied`); step 2.5b refuses any `groupBy` or aggregation field the query-guard map marks unreadable on an `aggregate`. The same step-2.9 guard answers a user-filter `where` on such a field with 403. Read from source; not measured against a running server. - **H1 holds.** Measured first on `main` through the real `ListView` with a probe (deleted, never committed): with a `/me/permissions` answer marking two fields unreadable, the Sort picker withheld them, so the answer was loaded and denying, while the hide-fields popover, the Group editor, the Row color select, all three View settings sections and the derived user-filter chips offered them. Now each omits them, behind `isLoaded`, with a readable control in each. - **H2 holds**: the enumeration pin below, with two scratch ablations that add an unfiltered list. - **H3**: as described above, and pinned. - **H4**: the budget bot's reading comes after CI. Local estimate only: the minified `ListView` module grows by 628 B, 214 B gzipped on its own (esbuild, gzip -9, `b13ea3c67` against `d9a6f718b`); the latest PR readings were 3311.2 KB against the 3312.0 KB ceiling. ## Pins `packages/plugin-list/src/__tests__/ListView.fieldListRead-11984.test.tsx`, 20 tests: 1. **The enumeration pin**, per toolbar layout (wide and compact). A sweep opens every popover the toolbar renders (anything carrying `aria-haspopup`), opens every combobox inside it, and reads every option and checkbox. The popovers that offer a field of the view must equal `FIELD_LIST_TRIGGERS` (wide: Color, Filter, Group, Hide fields, Sort; compact: Filter, Sort, View settings), so a new field list fails until it is listed. For a restricted caller nothing it reads, nor the toolbar's own text (the chips), may name an unreadable field. Control: with full read every enumerated list offers it. Its bound is written in the file: a list behind a further click, such as a collapsed section, needs a row in `POSITIONS`. 2. **One pin per position** (`POSITIONS`, 10 rows: the Filter panel, the Sort picker, the hide-fields popover, the Group editor, the Row color select, the user-filter chips derived and authored, and the three View settings sections). With no permission answer and with full read the list is identical and includes the unreadable fields; restricted, it is that list minus them. Plus **before `isLoaded`**: a provider refetching with the restricted answer still held offers every field in the hide-fields list, the chips and the Group editor. 3. **Stored configuration**: the grouping level, the hidden-field entry (with a full-read control), the row-color rule (with a full-read control), and a chip kept by a restored selection that leaves once the selection is cleared. ## Reverse check On the committed tree `d9a6f718b`, each mutation landed and was restored through objectstack's `scripts/ablation-replace.mjs` (anchor 1 to 0, blob changed; restore blob equal to `HEAD`, `git diff HEAD` empty), running the new file plus the three family files (`ListView.filterFieldRead-11925`, `ListView.sortFieldRead-11943`, `ListView.sortRemovableOnly-11943`), 37 tests. Every observation matched its prediction: | Mutation | Observed | |---|---| | M1: `allFields` drops the read | 11 failed / 26 passed: both restricted sweeps, the six `allFields` positions, before-isLoaded, the stored grouping and hidden-field cases | | M2: the chips drop the read | 6 / 31: both restricted sweeps, both chip positions, before-isLoaded, the restored-selection chip | | M3: the chips drop the in-use exception | 1 / 36: the restored-selection chip | | M4: nothing is withheld from `hiddenFields` | 1 / 36: the stored hidden-field case | | M5: the row-color rule is not withheld | 1 / 36: the stored row-color case | | M6, scratch: an unfiltered native select added inside the Group popover | 1 / 36: the wide restricted sweep; the Group editor's own pin stays green | | M7, scratch: a new toolbar popover listing every column | 4 / 33: all four sweeps (an unlisted field list; restricted, also an unreadable field) | | M8: the Filter panel drops the read | 8 / 29: both restricted sweeps, the Filter position, five objectui#11925 pins | | M9: the Sort picker drops the read | 10 / 27: both restricted sweeps, the Sort position, three objectui#11943 read pins, four removable-only pins | M3, M5 and M6 were first sent with a replacement that contained its own anchor. `ablation-replace` refused each before any test ran, with the restore proven, so those first attempts measured nothing; they were re-anchored and re-run, and the rows above are the re-runs. ## Gates On `HEAD` `d9a6f718b`, heavy runs through the container's verify lock: - `pnpm --workspace-concurrency=2 --filter '@object-ui/plugin-list^...' build`: `VERDICT command-exit 0`, scope 13 of 47 workspace projects. - `pnpm --filter @object-ui/plugin-list type-check` (`tsc --noEmit && tsc -p tsconfig.test.json`): `VERDICT command-exit 0`; `--listFilesOnly` lists the new test file. - `pnpm exec vitest run --maxWorkers=2` over every `plugin-list` test file naming `ListView`, `canReadField`, `hiddenFields`, `rowColor` or `GroupingEditor` (101 files by `git grep -l`, the new one included), plus `packages/core/src/utils/__tests__/column-identity.ratchet.test.ts` and `scripts/__tests__/one-authority-per-exported-name-6273.test.ts`: `Test Files 103 passed (103)`, `Tests 1137 passed (1137)`, `VERDICT command-exit 0`. - `node scripts/check-changeset-presence.mjs` exit 0 ("2 source file(s) of 1 released package(s) changed, and this change declares 1 changeset(s)"); `node scripts/check-changeset-no-major.mjs` exit 0. - `pnpm check:new-line-citations` exit 0, `VERDICT new-cross-file-line-citations: 0 new citation(s)`; `pnpm check:control-bytes` exit 0. - Also exit 0: `check:changeset-claims`, `check:pending-changeset-literals`, `check:test-path-roots`, `check:vi-mock-specifiers`, `check:vi-mock-inherit`, `check:vi-mock-override-shape`, `check:i18n-keys`, `check:shell-escape-residue`, `check:unreferenced-sources`, `check:phantom-deps`. - **Lint, narrowed and measured.** `pnpm exec eslint --format json` over the two touched TS files (the config's `**/*.{ts,tsx}` population): 2 files, 0 errors. `ListView.tsx` carries 187 warnings, equal to its base blob linted over stdin; the new test carries 0. `eslint.config.js` enables no type-aware linting, so the diff cannot move an untouched file's verdict. Repo-wide lint is CI's. ## Acceptance notes - **Docs.** The package README and `content/docs` say nothing about which toolbar lists ask the field read, so nothing there became false. They are outside the claim's file surface and are not edited. - **Out of scope, measured, reported for the seat, not fixed here:** a host-restored user-filter selection (`userFilterSelections`) on a chip derived from the definition (`userFilters` with `element: 'dropdown'` and no `fields`) is dropped when the definition loads after mount. With full read and no permission provider, the chip showed no selection and the fetch carried no `$filter`; with the same field named by the author, the fetch carried `["status","=","open"]`. The chip state is initialised once, from the fields present at mount, and a derived list has none until the definition loads. Producers: app-shell's `ObjectView`, `ObjectDataPage` and `InterfaceListPage` pass URL-restored `userFilterSelections`. - Observation, not filed: the `allFields` lists label a column by its declared `label` or the i18n resolver, falling back to the raw name, so with unlabelled columns they read `title` where the Sort picker reads `Title`. Unchanged here. - Changeset: `.changeset/11984-toolbar-field-lists-read.md`, a patch for `@object-ui/plugin-list`. Session: `https://claude.ai/code/session_01MgfduSkFrfM3eorB3UGfAU` --- _Generated by [Claude Code](https://claude.ai/code/session_01MgfduSkFrfM3eorB3UGfAU)_ --------- Claude-Session: https://claude.ai/code/session_01MgfduSkFrfM3eorB3UGfAU Co-authored-by: Claude <noreply@anthropic.com>
Contributor
✅ Console Performance Budget
The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it. 📦 Bundle Size Report
Size Limits
|
This was referenced Oct 9, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #11984
Clause-②: no
This re-lands the reviewed toolbar field-list read change, unchanged. It first landed as
aa67386a5(PR objectui#11999; review6067089341, addendum6068120860).902fbe190(PR objectui#12009, anchor objectui#12007) rolled it back for first-load bytes only. objectui#11939's reclaim (PR objectui#11982,4babf40) re-pinned the eager-closure ceiling with room for it, so the card's hold6069699361is met. Claim:6071749217.What this PR is
git cherry-pick aa67386a5ontomain5d77c099b. It applied with no conflict.aa67386a5:packages/plugin-list/src/ListView.tsx;packages/plugin-list/src/__tests__/ListView.fieldListRead-11984.test.tsx;.changeset/11984-toolbar-field-lists-read.md.allFieldsaskscanReadFieldbehindisLoaded. It is the list the hide-fields popover, the Group editor, the Row color select and the compact View settings popover's same three sections offer.Same change, measured (H1)
git diff aa67386a5^ aa67386a5andgit diff 5d77c099b HEADgive the samegit patch-id --stable(e4d60e6d8e55), and their added and removed lines are identical.aa67386a5.Gates, on HEAD
602e4b9cdpnpm --workspace-concurrency=2 --filter '@object-ui/plugin-list^...' build, under the verify lock:Scope: 13 of 47 workspace projects,VERDICT command-exit 0.pnpm --filter @object-ui/plugin-list type-check, which echoestsc --noEmit && tsc -p tsconfig.test.json:VERDICT command-exit 0.tsc -p tsconfig.test.json --listFilesOnlylists the new pin.pnpm exec vitest run --maxWorkers=2 packages/plugin-list/ packages/core/src/utils/__tests__/column-identity.ratchet.test.ts scripts/__tests__/one-authority-per-exported-name-6273.test.ts, from the repo root under the lock:Test Files 122 passed (122),Tests 1297 passed (1297),VERDICT command-exit 0.plugin-listdirectory. It is a superset of the 102 files that nameListView,canReadField,hiddenFields,rowColororGroupingEditor.node scripts/check-changeset-presence.mjs:2 source file(s) of 1 released package(s) changed, and this change declares 1 changeset(s).node scripts/check-changeset-no-major.mjs.node scripts/check-changeset-overwrite.mjs:1 changeset(s) added, 0 modified, 0 deleted.pnpm check:new-line-citations:VERDICT new-cross-file-line-citations: 0 new citation(s).pnpm check:control-bytes.check:changeset-claims,pending-changeset-literals,test-path-roots,vi-mock-specifiers,vi-mock-inherit,vi-mock-override-shape,i18n-keys,shell-escape-residue,unreferenced-sources,phantom-deps,handler-key-readsandmetadata-write-doors.pnpm exec eslint --format jsonover the two touched TS files. The population is the config's**/*.{ts,tsx}.ListView.tsxhas 187 warnings, equal tomain's blob linted over stdin. The new pin has 0.eslint.config.jssets noparserOptions.projectorprojectService, so the diff cannot move an untouched file's verdict. Repo-wide lint is CI's.Reverse check (H2), on committed
602e4b9cdListView.tsxwas put back onmain's blob (95728f40b987) bygit checkout 5d77c099b, under a trap restore. On disk,canReadFieldwent from 13 to 6.Tests 15 failed | 5 passed (20). The failures were both enumeration sweeps, every per-position pin, the before-isLoadedpin and the four stored-configuration pins.git checkout HEAD: the on-disk blob equals HEAD's (565dae2c04a8), andgit diff HEADis empty.Tests 20 passed (20).First-load bytes (H3)
Bundle Analysisbudget bot reads the eager closure.main's, go in the dev report on the card after CI. ⛔scripts/check-eager-closure-budget.mjsis not touched.Acceptance notes
content/docssay nothing about which toolbar lists ask the field read, so nothing there became false. They are outside the claim's file surface..changeset/12007-revert-toolbar-field-list-read.mdstays as it is, per the claim. No release has run since the first landing:packages/plugin-list/CHANGELOG.mdnames neither this card nor objectui#11925, which landed earlier. So the next release notes carry both the rollback entry and this card's entry. Whether to drop the rollback entry before that release is the seat's call; this PR does not touch it.Session:
https://claude.ai/code/session_01MgfduSkFrfM3eorB3UGfAUGenerated by Claude Code