Skip to content

refactor(app-shell): a permission set's advanced facets pick with the shared Select (objectui#11865) - #12017

Merged
objectstack-fleet[bot] merged 1 commit into
mainfrom
claude/issue-11865-access-facets-select
Oct 9, 2026
Merged

objectstack-fleet[bot] merged 1 commit into
mainfrom
claude/issue-11865-access-facets-select

Conversation

@objectstack-fleet

Copy link
Copy Markdown
Contributor

Part of #11865
Clause-②: no

Slice k of the card's claim (comment 6071773793): the permission set's advanced facets. An RLS policy's operation and a tab's visibility, the two native select elements in PermissionAdvancedFacets, now pick with the shared Select through one module-private FacetPicker. That is the pattern the card's landed slices use (objectui#11976 through objectui#12013).

What changes

  • FacetPicker is module-private, not exported. Its items carry index tokens, so a stored value that no option carries gets an item of its own, labelled with the value. That holds even for '', which SelectItem refuses. Picking that item writes nothing.
  • Each pick hands the option's own value to the same setPolicies / setTabs update the native onChange made.
  • Read-only follows the primitive (objectui#11781). With writable false, each trigger is disabled and wears SelectTrigger's own disabled look. The native selects were disabled the same way.
  • The native selects had no label, and the triggers have none either.
  • The triggers gain data-testid values: rls-operation- plus the policy index, and tab-visibility- plus the tab key. These are DOM attributes only.

Prior work. This conversion first rode PR objectui#12000's branch (commit 703fb048c). Commit 93fdcf2 put it back for first-load bytes only, under the seat's ruling 6067513366. Today's main carries the same base blobs for both edited files (1a922755 and 38dd28a1), so the conversion is restored from that history byte for byte. Everything below is re-measured on main 5d77c099b from scratch. The pin gains three things: the fourth picker's four rows, a stored empty operation, and the empty-key row the Add tab button creates.

H1 to H4, measured

  • H1, value parity: held. A scratch probe ran on main's blob. It fired a change event on every option of all four native selects as mounted (two policies, two tabs) and recorded, as JSON text, the draft each setDraft updater produced. The pin's WRITES table checks every option of every picker against those literals, 18 rows in all.
    • 14 rows write the identical draft.
    • The 4 re-pick rows write nothing on head. On base, jsdom's change event fired for the already-selected option; a browser does not fire it there.
    • Neither picker has an empty or "none" option. '' arises only as a stored value, pinned under H3.
  • H2, labels, keyboard and read-only: held.
    • No accessible name before or after. On base the probe found 4 unnamed comboboxes, all of them the native selects; the pin requires exactly the 4 triggers to be the unnamed comboboxes.
    • Enter opens a picker, and Enter on an option selects it. Pinned, with the write.
    • Read-only: each trigger is disabled, carries the primitive's disabled: classes, and does not open. CONTROL: when writable, the same triggers are enabled.
  • H3, a stored value outside the options: held.
    • An operation read and a visibility default show as themselves. The native selects showed "all" and "Visible" there. The outside item is listed first, and re-picking it writes nothing.
    • A stored operation of '' gets its own item; the native select showed "all". Picking "insert" writes the literal the native control wrote.
  • H4, first-load bytes: +190 B gzip. See below.

First-load bytes

Measured with apps/console CI=true pnpm exec vite build, under the verify lock, with both legs in this worktree at 5c72930b4. The head leg builds the tree as committed. The base leg builds it with the panel at main's blob; the landing and the restore were proved by hash, and git diff HEAD read 0 bytes afterwards. The other three files of this diff are tests and a changeset, which the console bundle does not carry, so the base leg is main's bundle.

Leg eagerGzipBytes eagerRawBytes Budget script
main 5d77c099b (panel at its blob) 3,235,851 10,889,025 3160.0 KB of 3204.6 KB, headroom 44.5 KB
head 5c72930b4 3,236,041 10,889,366 3160.2 KB of 3204.6 KB, headroom 44.4 KB
  • The delta is +190 B gzip and +341 B raw, under the dispatch's +1,024 B stop line. 289 of 2474 chunks are eager on both legs.
  • Per chunk, the eager src chunk grows by 341 B raw and 191 B gzip. PermissionAdvancedFacets ships there: the base leg's src chunk holds its perm.rls.checkPlaceholder key, and src is the head leg's only grown chunk.
  • The entry chunk has 0 B raw and 1 B less gzip. Only the src chunk's hashed name inside it changed.

Tests

  • New pin PermissionAdvancedFacets.sharedSelect-11865.test.tsx, 28 tests.
  • PermissionMatrixEditor.packageDoorFacets.test.tsx authored a tab visibility with a change event on the native select. It now opens the trigger and picks Hidden, as a user does.
  • Reverse leg. The implementation was committed at 5c72930b4. The panel was then written back to main's blob 1a922755, proved by hash (2 native selects, 0 FacetPicker).
    • The pin plus packageDoorFacets read 30 failed | 1 passed (31), VITEST-EXIT 1. The predicted direction was red.
    • Red: all 28 pins, and the 2 packageDoorFacets cases that author a tab visibility. Green: its third case, which authors none.
    • The restore used git checkout HEAD -- on the absolute path. Proof: hash 4244a1c8 equals the HEAD blob, git diff HEAD 0 bytes, 0 status entries.
    • The panel is imported by relative path, so no dist is involved.

Gates on HEAD 5c72930b4

  • Vitest, repo-root pnpm exec vitest run --maxWorkers=2, lock VERDICT command-exit 0: Test Files 43 passed (43), Tests 389 passed (389). The run covers 41 suites plus the two repo-wide pins, column-identity.ratchet and one-authority-per-exported-name-6273. The 41 are the suites a git grep names for the facets, the permission matrix, RLS, tab visibility or the Access pillar. They include the facets' own suites and the pin, the 17 PermissionMatrixEditor.* suites, the CEL field and test-run suites, and the four StudioDesignSurface access suites.
  • Type-check, pnpm --filter @object-ui/app-shell type-check (tsc --noEmit && tsc -p tsconfig.test.json): exit 0. It ran after pnpm --workspace-concurrency=2 --filter '@object-ui/app-shell^...' run build (Scope: 29 of 47, exit 0). By --listFilesOnly, the panel is in both programs and both test files are in the test program.
  • ESLint, pnpm exec eslint on the 3 touched .tsx files: exit 0, 0 errors, 8 warnings. All 8 are on main: each modified file's per-rule multiset equals its main blob's, via --stdin. The new pin has none.
  • Light gates, all exit 0:
    • check-changeset-presence: "3 source file(s) of 1 released package(s) changed, and this change declares 1 changeset(s)";
    • check-changeset-no-major, check-changeset-fixed, check-changeset-overwrite, check:changeset-claims and check:pending-changeset-literals;
    • check:new-line-citations: "0 new citation(s)";
    • check:control-bytes, check:test-path-roots, and the three check:vi-mock-* gates;
    • check:unreferenced-sources, check:i18n-keys, check:metadata-write-doors, check:handler-key-reads and check:self-import.
  • Declared to CI: the full pnpm test farm and repo-wide pnpm lint.

Files

  • packages/app-shell/src/views/metadata-admin/PermissionAdvancedFacets.tsx
  • packages/app-shell/src/views/metadata-admin/PermissionAdvancedFacets.sharedSelect-11865.test.tsx (new)
  • packages/app-shell/src/views/metadata-admin/PermissionMatrixEditor.packageDoorFacets.test.tsx
  • .changeset/11865-k-permission-facets-shared-select.md, a patch for @object-ui/app-shell

No docs edit. packages/app-shell/README.md names the facets without naming a control kind, and content/docs describes neither picker.

Acceptance notes

  • Neither picker has an accessible name, on main as now; the dispatch asks each control to keep the name it has today. Naming them would need new i18n keys, which this slice may not add. Not filed: it is a11y polish, and no public door was measured.

Implemented by an os-dev subagent of the domain:ui seat 2, session https://claude.ai/code/session_01MgfduSkFrfM3eorB3UGfAU.


Generated by Claude Code

… shared Select (objectui#11865)

An RLS policy's operation and a tab's visibility were browser-native
selects. They now use the shared Radix Select through one module-private
FacetPicker, the pattern the card's earlier slices landed: items carry
index tokens, a stored value outside the options shows as its own item,
and read-only disables the trigger through the primitive. Each pick hands
the option's own value to the same draft update as before.

The conversion is restored from PR objectui#12000's history (commit
703fb04), where it was put back for first-load bytes only, and
re-verified against today's main. The pin gains the fourth picker's rows,
a stored empty operation, and the empty-key row the Add tab button
creates, each against literals read from the native control on main.

Claude-Session: https://claude.ai/code/session_01MgfduSkFrfM3eorB3UGfAU
Co-authored-by: Claude <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

Metric Value Budget
Eager closure (gzip, 289 chunks) 3160.3 KB 3204.6 KB
Main entry chunk (gzip) 71.6 KB 350 KB
Entry file index-CO9CSjDB.js —
Status PASS —

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

Package Size Gzipped
app-shell (consoleActionDispatch.js) 0.20KB 0.19KB
app-shell (index.js) 19.52KB 7.19KB
app-shell (runtime-config.js) 22.59KB 7.89KB
app-shell (types.js) 0.01KB 0.04KB
app-shell (urlParams.js) 10.11KB 3.87KB
auth (ActiveOrganizationStorage.js) 27.95KB 10.04KB
auth (AuthContext.js) 0.31KB 0.24KB
auth (AuthGuard.js) 2.07KB 1.00KB
auth (AuthProvider.js) 40.22KB 10.61KB
auth (AuthShell.js) 3.49KB 1.40KB
auth (ForgotPasswordForm.js) 12.21KB 3.45KB
auth (LoginForm.js) 18.15KB 5.40KB
auth (PreviewBanner.js) 0.90KB 0.50KB
auth (RegisterForm.js) 6.72KB 2.24KB
auth (SocialSignInButtons.js) 9.70KB 3.93KB
auth (UserMenu.js) 3.39KB 1.21KB
auth (auth-gate-events.js) 1.29KB 0.66KB
auth (authStyles.js) 5.04KB 1.72KB
auth (createAuthClient.js) 41.19KB 11.12KB
auth (createAuthenticatedFetch.js) 8.54KB 3.46KB
auth (index.js) 3.63KB 1.64KB
auth (invitation-status.js) 1.22KB 0.70KB
auth (org-roles.js) 6.66KB 2.78KB
auth (phone-identifier.js) 1.11KB 0.66KB
auth (types.js) 0.59KB 0.35KB
auth (useAuth.js) 5.30KB 1.02KB
auth (useWorkspaceAdminStatus.js) 11.08KB 4.58KB
collaboration (CommentThread.js) 27.11KB 7.97KB
collaboration (LiveCursors.js) 3.17KB 1.27KB
collaboration (PresenceAvatars.js) 6.28KB 2.60KB
collaboration (PresenceProvider.js) 2.79KB 1.13KB
collaboration (index.js) 1.68KB 0.73KB
collaboration (useCollaborationTranslation.js) 6.50KB 2.52KB
collaboration (useCommentSearch.js) 1.98KB 0.88KB
collaboration (useConflictResolution.js) 7.75KB 1.86KB
collaboration (useMentionNotifications.js) 1.81KB 0.68KB
collaboration (usePresence.js) 6.33KB 1.84KB
collaboration (useRealtimeSubscription.js) 7.91KB 2.01KB
components (index.js) 587.83KB 141.44KB
core (index.js) 10.00KB 3.96KB
create-plugin (index.js) 27.94KB 9.51KB
data-objectstack (index.js) 240.39KB 67.09KB
fields (index.js) 268.74KB 68.04KB
i18n (LocalizationContext.js) 2.92KB 1.42KB
i18n (builtinAggregateLabels.js) 0.86KB 0.49KB
i18n (currency.js) 2.59KB 1.22KB
i18n (fallbackInterpolation.js) 6.25KB 2.77KB
i18n (i18n.js) 8.87KB 3.64KB
i18n (index.js) 5.52KB 2.39KB
i18n (pickLocalized.js) 9.86KB 3.95KB
i18n (provider.js) 39.35KB 12.88KB
i18n (translateFn.js) 0.20KB 0.18KB
i18n (useDisplayLocale.js) 3.52KB 1.76KB
i18n (useObjectLabel.js) 36.87KB 9.88KB
i18n (useSafeTranslation.js) 7.14KB 2.92KB
layout (index.js) 41.50KB 11.82KB
mobile (MobileProvider.js) 0.92KB 0.49KB
mobile (ResponsiveContainer.js) 0.94KB 0.38KB
mobile (breakpoints.js) 1.51KB 0.70KB
mobile (createOfflineDataSource.js) 5.61KB 1.75KB
mobile (index.js) 1.99KB 0.87KB
mobile (offlineQueue.js) 3.91KB 1.35KB
mobile (pwa.js) 0.97KB 0.49KB
mobile (serviceWorker.js) 1.48KB 0.62KB
mobile (serviceWorkerSource.js) 3.41KB 1.48KB
mobile (useBreakpoint.js) 1.54KB 0.65KB
mobile (useGesture.js) 6.96KB 1.98KB
mobile (useOfflineSync.js) 1.99KB 0.72KB
mobile (usePullToRefresh.js) 6.62KB 2.45KB
mobile (useResponsive.js) 0.72KB 0.42KB
mobile (useSpecGesture.js) 5.52KB 2.10KB
mobile (useTouchTarget.js) 1.01KB 0.54KB
permissions (MePermissionsProvider.js) 13.86KB 5.00KB
permissions (PermissionContext.js) 0.31KB 0.25KB
permissions (PermissionGuard.js) 0.89KB 0.45KB
permissions (PermissionProvider.js) 6.52KB 2.26KB
permissions (discardProofCache.js) 1.04KB 0.55KB
permissions (evaluator.js) 8.33KB 3.07KB
permissions (index.js) 0.93KB 0.41KB
permissions (store.js) 0.91KB 0.42KB
permissions (useFieldPermissions.js) 1.28KB 0.53KB
permissions (usePermissions.js) 4.83KB 2.27KB
plugin-ai (index.js) 16.04KB 3.92KB
plugin-calendar (index.js) 53.43KB 15.54KB
plugin-charts (index.js) 84.71KB 23.25KB
plugin-chatbot (index.js) 199.63KB 47.46KB
plugin-dashboard (index.js) 144.20KB 38.95KB
plugin-designer (index.js) 233.53KB 49.80KB
plugin-detail (index.js) 248.57KB 65.47KB
plugin-editor (index.js) 2.23KB 1.05KB
plugin-form (index.js) 177.11KB 45.88KB
plugin-gantt (index.js) 179.17KB 45.07KB
plugin-grid (index.js) 249.56KB 69.16KB
plugin-kanban (index.js) 52.22KB 16.38KB
plugin-list (index.js) 117.83KB 29.43KB
plugin-map (index.js) 27.24KB 9.03KB
plugin-markdown (index.js) 13.88KB 4.80KB
plugin-report (index.js) 44.12KB 12.29KB
plugin-timeline (index.js) 39.10KB 11.81KB
plugin-tree (index.js) 15.07KB 5.33KB
plugin-view (index.js) 91.16KB 22.97KB
providers (DataSourceProvider.js) 0.75KB 0.39KB
providers (MetadataProvider.js) 1.37KB 0.59KB
providers (ThemeProvider.js) 1.90KB 0.85KB
providers (UploadProvider.js) 11.81KB 3.58KB
providers (index.js) 0.45KB 0.23KB
providers (types.js) 0.01KB 0.04KB
react-runtime (index.js) 5.62KB 2.34KB
react (LazyPluginLoader.js) 4.47KB 1.63KB
react (SchemaRenderer.js) 120.63KB 39.56KB
react (data-invalidation.js) 5.05KB 2.08KB
react (index.js) 4.50KB 2.06KB
react (schema-input.js) 4.31KB 2.07KB
react (spec-input.js) 0.20KB 0.18KB
sdui-parser (body-dialect.js) 4.50KB 1.99KB
sdui-parser (codegen.js) 9.45KB 3.76KB
sdui-parser (dashboard-widget-options.js) 3.07KB 1.30KB
sdui-parser (index.js) 7.30KB 3.12KB
sdui-parser (input-type.js) 2.84KB 1.40KB
sdui-parser (parse.js) 25.28KB 7.80KB
sdui-parser (provenance.js) 3.84KB 1.90KB
sdui-parser (types.js) 0.28KB 0.23KB
sdui-parser (validate.js) 23.87KB 7.83KB
types (ai.js) 4.39KB 2.17KB
types (api-types.js) 0.20KB 0.18KB
types (app.js) 4.12KB 1.61KB
types (authoring-nodes.js) 0.20KB 0.19KB
types (base.js) 0.20KB 0.18KB
types (blocks.js) 0.20KB 0.18KB
types (cloud.js) 0.20KB 0.18KB
types (complex.js) 4.44KB 2.07KB
types (crud.js) 0.20KB 0.18KB
types (dashboard-filter-alias.js) 6.23KB 2.74KB
types (dashboard-widget-layout.js) 2.06KB 0.96KB
types (data-display.js) 3.75KB 1.85KB
types (data-protocol.js) 0.20KB 0.19KB
types (data.js) 0.20KB 0.18KB
types (designer.js) 1.85KB 0.85KB
types (disclosure.js) 0.20KB 0.18KB
types (error-code.js) 1.54KB 0.88KB
types (expression.js) 0.20KB 0.18KB
types (feedback.js) 0.20KB 0.18KB
types (field-types.js) 1.13KB 0.65KB
types (form.js) 0.20KB 0.18KB
types (http-inflight.js) 8.87KB 3.73KB
types (http-retry.js) 4.32KB 2.02KB
types (icon-key-migration.js) 4.26KB 1.63KB
types (index.js) 5.78KB 2.70KB
types (layout.js) 0.20KB 0.18KB
types (managed-by.js) 0.19KB 0.18KB
types (mobile.js) 5.00KB 2.39KB
types (navigation.js) 0.20KB 0.18KB
types (node-slots.js) 7.18KB 2.34KB
types (objectql.js) 0.20KB 0.18KB
types (overlay.js) 0.20KB 0.18KB
types (permissions.js) 2.52KB 1.31KB
types (plugin-scope.js) 0.20KB 0.18KB
types (record-components.js) 0.20KB 0.19KB
types (record-semantics.js) 1.28KB 0.67KB
types (registry.js) 0.20KB 0.18KB
types (reports.js) 0.20KB 0.18KB
types (select-option.js) 0.20KB 0.19KB
types (spec-report.js) 4.99KB 1.96KB
types (spec-ui-namespace.js) 0.20KB 0.19KB
types (strict-authoring-face.js) 19.93KB 7.25KB
types (system-fields.js) 3.33KB 1.54KB
types (theme.js) 6.28KB 2.87KB
types (ui-action.js) 8.11KB 3.32KB
types (views.js) 0.20KB 0.18KB
types (widget.js) 0.20KB 0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@objectstack-fleet
objectstack-fleet Bot marked this pull request as ready for review October 9, 2026 01:25
@objectstack-fleet
objectstack-fleet Bot enabled auto-merge October 9, 2026 01:25
@objectstack-fleet
objectstack-fleet Bot added this pull request to the merge queue Oct 9, 2026
Merged via the queue into main with commit 1ad0c08 Oct 9, 2026
45 checks passed
@objectstack-fleet
objectstack-fleet Bot deleted the claude/issue-11865-access-facets-select branch October 9, 2026 01:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants