Skip to content

fix(console): the sign-in page renders from the built-in packs, and the application's translations load after sign-in (objectui#12034) - #12042

Merged
objectstack-fleet[bot] merged 4 commits into
mainfrom
claude/issue-12034-console-i18n-after-signin
Oct 9, 2026
Merged

objectstack-fleet[bot] merged 4 commits into
mainfrom
claude/issue-12034-console-i18n-after-signin

Conversation

@objectstack-fleet

Copy link
Copy Markdown
Contributor

Fixes #12034
Clause-②: no

The console's sign-in page now renders from the built-in language packs and makes no /api/v1/i18n request. Once the page load is signed in, the application's translations and locale list are read with the session's credentials, through the data adapter's own request path. This is the objectui half of the ruling on objectstack-ai/objectstack#22146 (6074960686, batch 300, item 1, letter A).

Order. This card lands first. objectstack-ai/objectstack#22432 (the framework's anonymous refusal on /i18n) is Blocked-by: objectui#12034 and moves the framework's .objectui-sha pin past this merge in its own PR. Nothing here touches the framework or its pin.

What changed

  • apps/console/src/i18nSession.ts (new): the session answer the two loaders wait for. It is fed by the console AuthProvider's existing onAuthStateChange prop, so the session authority is the provider itself. Nothing reads the session a second time, and nothing lifts a token out of storage. It also exports i18nFetch = withSettleSignal(createAuthenticatedFetch()), the same request path AdapterProvider builds for the data adapter.
  • apps/console/src/loadLanguage.ts, apps/console/src/loadLocales.ts: each loader first awaits the session answer. Signed out, it sends no request and answers {} or []. Signed in, it reads through i18nFetch (bearer, X-Tenant-ID, Accept-Language, session-rotation adoption, settle-signal count). Not yet answered (isLoading), it waits, and the wait ends when the session read ends. It never rejects.
  • apps/console/src/App.tsx: onAuthStateChange={publishAuthState} on the console's AuthProvider. This is the session state the post-sign-in load hangs on, named here as the claim asks.
  • apps/console/src/main.tsx: a comment only. The I18nProvider mount and its two props are unchanged.
  • Tests: the two loader suites, and one pin file for the card's three pins: apps/console/src/__tests__/i18nAfterSignIn-12034.test.tsx.
  • .changeset/12034-console-i18n-after-signin.md: a patch for @object-ui/console.

No new prop, export or key on I18nProvider or packages/i18n. The provider is used through its existing loadLanguage and loadLocales props. Docs: no page in content/docs describes the console's translation loading. git grep for the loaders and the /i18n routes finds none, and the only mention is the sentence in guide/console.md and guide/deployment.md that the i18n endpoints hang off VITE_SERVER_URL, which is still true. So no docs page is edited.

The hypotheses, measured

The readings below come from a fake framework whose /i18n answers 401 UNAUTHENTICATED to any caller without the session's bearer (the head of objectstack-ai/objectstack#22432). It knows the bearer only. That models a deployment where no session cookie rides along, such as a console built with an absolute VITE_SERVER_URL. The probe ran the real App and the real LoginPage on main's blobs of the loaders, App.tsx and main.tsx.

  • H1, partly falsified. On main, the sign-in page's page load made 2 reads (translations/zh and locales). Neither carried Authorization, and both got 401. The "never re-fetches after sign-in" half does not hold. Every console sign-in exits through a full-page navigation (window.location.assign in LoginPage, RegisterPage and SetupPage; authExitBasename.test.tsx pins it). So the loaders run again on the page load after sign-in: 2 more reads, still with no Authorization, both 401. The fetches use the default credentials: 'same-origin', so on a same-origin cookie deployment the session cookie does ride along, and that post-sign-in read would have been served. The bearer was never sent.
  • H2, partly falsified. On head, a signed-in page load's reads wait for the provider's first answer. That is one get-session round trip, the same answer AuthGuard waits for before it renders anything signed in. The reads then carry Bearer and get 200. "The first render already has the application's labels" holds on neither main nor head: I18nProvider never holds the first render for its loader. Pin 2 shows the actual sequence on one mounted heading: the authored literal Lead first, then 线索 once the held response is released.
  • H3, holds with no re-run. Because sign-in ends in a page load, the post-sign-in load is that page load's own loader call. The loader's Promise settles when the session is answered, and the provider's existing store write (addResourceBundle with bindI18nStore: 'added') re-renders every reader. No key remount (AGENTS.md commandment 8 refuses one), and no changeLanguage to the same language: that call runs through the provider's languageChanged choke point and would persist the language as an explicit user choice. A session that begins in place, with no page load, is not re-run (see Acceptance notes). The provider has no re-run hook for that: loadedAppLangs and askedForLocales guard it.
  • H4, holds by falling back, not by waiting. The sign-in page renders from the built-in pack, in Chinese in the pin. The first render after sign-in shows built-in strings plus the authored literal for the application label. A MutationObserver recorder over every frame of the sign-in to app path records zero raw keys, and a control proves the recorder catches a key drawn raw. The card's raw-key premise did not reproduce on main either: against the head of runtime: the /i18n dispatcher domain answers an anonymous caller — handleI18nRequest makes no shouldDenyAnonymous call, unlike every other dispatcher domain (ADR-0056 D2); with an objectui companion for the Console sign-in page objectstack#22432, main showed the signed-in user Lead (the untranslated authored literal) and zero raw keys. The application-bundle readers (useObjectLabel, useSettingsLabel) fall back to the authored literal. The spec's I18nLabel refuses a keyed { key, defaultValue } form (key?: never), so a spec-legal label has no form that could render as its key. Key coverage of built-in t() call sites is check:i18n-keys's job, and it is green.
  • H5, neutral. Eager closure eagerGzipBytes: base 049012bf0 3,238,404 B, head 27caa7d0b 3,238,537 B, a difference of +133 B gzip. The ceiling is 3,281,467 B. pnpm check:eager-closure prints: Console eager closure is 3162.6 KB gzipped across 289 of 2474 chunks (budget: 3204.6 KB, headroom: 41.9 KB). Both builds used CI=true pnpm exec vite build in apps/console, under the verify lock.

Pins and the reverse leg

The pin file renders the REAL App. That means the real AuthProvider props (so the real onAuthStateChange wire), the real route table, the real LoginPage and the real ProtectedRoute. Only the auth network client is the test's. The I18nProvider mount is main.tsx's, transcribed: that module boots the page when it is imported.

  1. Signed out on /login: the sign-in itself goes through the real form, and no /i18n request is made across that whole page load. The labels are the built-in zh pack's.
  2. Signed in: the reads carry Bearer and get 200. The mounted heading re-renders from Lead to 线索 (objectui#10382: the assertion is on rendered text, not on a request count).
  3. The whole sign-in to app path against the 401 framework draws no raw key on any frame, and no /i18n read gets a status other than 200.
  4. Control: the recorder catches console.noSuchKey12034 drawn raw.

Reverse leg at 27caa7d0b. All four of loadLanguage.ts, loadLocales.ts, App.tsx and main.tsx were swapped for main's blobs, with the hash of each checked equal to 049012bf0's. Result: 7 red (pins 1, 2, 3 and the four new loader session-rule tests), 13 green (the control and the pre-existing loader tests). Restored with git checkout HEAD: each blob hash matched HEAD's and git diff HEAD was empty. A second ablation removed only the onAuthStateChange={publishAuthState} wire from App.tsx: pins 2 and 3 went red, and pin 1 and the control stayed green, as expected, because without the wire the loaders never ask at all. Restore proven the same way.

Gates (head 27caa7d0b)

  • pnpm exec vitest run over 40 files: the three touched or new test files; every apps/console suite that mounts I18nProvider, LoginPage or App (31 files); the suites that read main.tsx or App.tsx source (bootSplash, insecure-origin-crypto.placement, faviconAfterNavigation, tabTitleAfterNavigation, consoleToasterAnchor.ratchet-7482, auth-namespace-3546, runtimeConfigBootDedup); column-identity.ratchet and one-authority-per-exported-name-6273. Result: Test Files 40 passed (40), Tests 290 passed (290).
  • pnpm --filter @object-ui/console type-check (the dependency closure built first with turbo): exit 0. Its program includes the three test files, counted with --listFiles.
  • pnpm exec eslint on the 8 touched source and test files: 0 errors, 0 warnings.
  • node scripts/check-changeset-presence.mjs: ✅ 8 source file(s) of 1 released package(s) changed, and this change declares 1 changeset(s). node scripts/check-changeset-no-major.mjs: ✅.
  • pnpm check:new-line-citations: 0 new citation(s). check:control-bytes, check:i18n-keys, check:vi-mock-specifiers, check:vi-mock-inherit, check:vi-mock-override-shape, check:test-path-roots, check:changeset-claims, check:pending-changeset-literals, check:unreferenced-sources, check:phantom-deps, check:eager-closure: all exit 0.
  • Not run locally, declared to CI: the repo-wide pnpm lint and the full pnpm test. docs:check-links and check:spec-symbols do not apply, because content/docs is not touched.

Changeset rule: AGENTS.md §9 Housekeeping. apps/console is in the fixed release group, and src/ changed, so it takes a changeset: a patch. The claim's Clause-②: no still stands, because no export, prop or contract changes. But @object-ui/console is a published package (publishConfig.access: public, ships dist), not only an application.

examples/console-starter, measured and not edited

The starter hands I18nProvider only loadLanguage, which is a bare fetch, and it signs in IN PLACE (DefaultLoginPage calls navigate('/'), with no page load). A probe with the starter's real loader and the 401 framework read like this. Before sign-in: 1 read with no Authorization, 401. After an in-place sign-in: 0 reads. The heading stayed Lead for the session. So once objectstack-ai/objectstack#22432 lands, a starter user who signs in sees untranslated application labels until they reload. That is true on every deployment, cookie or not, because the read before sign-in is anonymous everywhere and the provider never asks again. After a reload, a same-origin cookie deployment is served and a bearer-only one gets 401 again. The console's gate is not a drop-in fix there: with an in-place sign-in, the page-load call would have to wait for a sign-in, not for the first answer. The starter has no loadLocales.

Acceptance notes

  • A session that begins in place keeps the built-in packs until the next page load. No console path does that today: every exit is a page load, and the pin above holds it. If one is ever added, its application labels stay untranslated, with no error. Pins 2 and 3 cover the wire, not that path.
  • Latency. The signed-in read now starts at the session answer, not at mount, so it runs one get-session round trip later than before. It still runs in parallel with the adapter connect and the metadata reads, which start at that same answer.
  • Impersonation and owner change. The application bundle read at sign-in is not re-read when the session owner changes in place (impersonation, objectui#4467). That is unchanged from main, and the bundle is per deployment, not per user.
  • The i18n reads now count in window.__objectui.pendingRequests, as the data adapter's reads do. An automated driver's idle predicate waits for the translations.

Generated by Claude Code

claude added 4 commits October 9, 2026 07:50
…s credentials (objectui#12034)

The two loaders main.tsx hands to I18nProvider ran on the provider's first
commit, before AuthProvider had answered, with a bare fetch: the sign-in page
read /api/v1/i18n anonymously, and a signed-in boot carried the session only
when a same-origin cookie rode along.

They now wait for this page load's session answer (fed by AuthProvider's
onAuthStateChange in App.tsx). Signed out, they request nothing and the
sign-in page renders from the built-in packs. Signed in, they read through
createAuthenticatedFetch(), the data adapter's own request path.

Claude-Session: https://claude.ai/code/session_01MgfduSkFrfM3eorB3UGfAU
Co-authored-by: Claude <noreply@anthropic.com>
…cated /i18n load after sign-in (objectui#12034)

Three pins through the real App against a framework that refuses an anonymous
/i18n read: no /i18n request on the sign-in page (through the sign-in itself),
the application label re-rendered from the authenticated read on the mounted
heading, and no raw key on any frame of the sign-in to app path, with a
control showing the recorder catches a raw key.

Claude-Session: https://claude.ai/code/session_01MgfduSkFrfM3eorB3UGfAU
Co-authored-by: Claude <noreply@anthropic.com>
… adapter's own fetch does (objectui#12034)

The adapter's request path is withSettleSignal(createAuthenticatedFetch()); the
two /i18n reads now take the whole of it, so an automated driver's idle
predicate waits for the application's translations too.

Claude-Session: https://claude.ai/code/session_01MgfduSkFrfM3eorB3UGfAU
Co-authored-by: Claude <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

Metric Value Budget
Eager closure (gzip, 289 chunks) 3162.6 KB 3204.6 KB
Main entry chunk (gzip) 71.7 KB 350 KB
Entry file index-DDl94v8_.js —
Status PASS —

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

Package Size Gzipped
app-shell (consoleActionDispatch.js) 0.20KB 0.19KB
app-shell (index.js) 19.52KB 7.19KB
app-shell (runtime-config.js) 22.59KB 7.89KB
app-shell (types.js) 0.01KB 0.04KB
app-shell (urlParams.js) 10.11KB 3.87KB
auth (ActiveOrganizationStorage.js) 27.95KB 10.04KB
auth (AuthContext.js) 0.31KB 0.24KB
auth (AuthGuard.js) 2.07KB 1.00KB
auth (AuthProvider.js) 40.22KB 10.61KB
auth (AuthShell.js) 3.49KB 1.40KB
auth (ForgotPasswordForm.js) 12.21KB 3.45KB
auth (LoginForm.js) 18.15KB 5.40KB
auth (PreviewBanner.js) 0.90KB 0.50KB
auth (RegisterForm.js) 6.72KB 2.24KB
auth (SocialSignInButtons.js) 9.70KB 3.93KB
auth (UserMenu.js) 3.39KB 1.21KB
auth (auth-gate-events.js) 1.29KB 0.66KB
auth (authStyles.js) 5.04KB 1.72KB
auth (createAuthClient.js) 41.19KB 11.12KB
auth (createAuthenticatedFetch.js) 8.54KB 3.46KB
auth (index.js) 3.63KB 1.64KB
auth (invitation-status.js) 1.22KB 0.70KB
auth (org-roles.js) 6.66KB 2.78KB
auth (phone-identifier.js) 1.11KB 0.66KB
auth (types.js) 0.59KB 0.35KB
auth (useAuth.js) 5.30KB 1.02KB
auth (useWorkspaceAdminStatus.js) 11.08KB 4.58KB
collaboration (CommentThread.js) 27.11KB 7.97KB
collaboration (LiveCursors.js) 3.17KB 1.27KB
collaboration (PresenceAvatars.js) 6.28KB 2.60KB
collaboration (PresenceProvider.js) 2.79KB 1.13KB
collaboration (index.js) 1.68KB 0.73KB
collaboration (useCollaborationTranslation.js) 6.50KB 2.52KB
collaboration (useCommentSearch.js) 1.98KB 0.88KB
collaboration (useConflictResolution.js) 7.75KB 1.86KB
collaboration (useMentionNotifications.js) 1.81KB 0.68KB
collaboration (usePresence.js) 6.33KB 1.84KB
collaboration (useRealtimeSubscription.js) 7.91KB 2.01KB
components (index.js) 587.83KB 141.44KB
core (index.js) 10.00KB 3.96KB
create-plugin (index.js) 27.94KB 9.51KB
data-objectstack (index.js) 240.39KB 67.09KB
fields (index.js) 268.74KB 68.04KB
i18n (LocalizationContext.js) 2.92KB 1.42KB
i18n (builtinAggregateLabels.js) 0.86KB 0.49KB
i18n (currency.js) 2.59KB 1.22KB
i18n (fallbackInterpolation.js) 6.25KB 2.77KB
i18n (i18n.js) 8.87KB 3.64KB
i18n (index.js) 5.52KB 2.39KB
i18n (pickLocalized.js) 9.86KB 3.95KB
i18n (provider.js) 39.35KB 12.88KB
i18n (translateFn.js) 0.20KB 0.18KB
i18n (useDisplayLocale.js) 3.52KB 1.76KB
i18n (useObjectLabel.js) 36.87KB 9.88KB
i18n (useSafeTranslation.js) 7.14KB 2.92KB
layout (index.js) 41.50KB 11.82KB
mobile (MobileProvider.js) 0.92KB 0.49KB
mobile (ResponsiveContainer.js) 0.94KB 0.38KB
mobile (breakpoints.js) 1.51KB 0.70KB
mobile (createOfflineDataSource.js) 5.61KB 1.75KB
mobile (index.js) 1.99KB 0.87KB
mobile (offlineQueue.js) 3.91KB 1.35KB
mobile (pwa.js) 0.97KB 0.49KB
mobile (serviceWorker.js) 1.48KB 0.62KB
mobile (serviceWorkerSource.js) 3.41KB 1.48KB
mobile (useBreakpoint.js) 1.54KB 0.65KB
mobile (useGesture.js) 6.96KB 1.98KB
mobile (useOfflineSync.js) 1.99KB 0.72KB
mobile (usePullToRefresh.js) 6.62KB 2.45KB
mobile (useResponsive.js) 0.72KB 0.42KB
mobile (useSpecGesture.js) 5.52KB 2.10KB
mobile (useTouchTarget.js) 1.01KB 0.54KB
permissions (MePermissionsProvider.js) 13.86KB 5.00KB
permissions (PermissionContext.js) 0.31KB 0.25KB
permissions (PermissionGuard.js) 0.89KB 0.45KB
permissions (PermissionProvider.js) 6.52KB 2.26KB
permissions (discardProofCache.js) 1.04KB 0.55KB
permissions (evaluator.js) 8.33KB 3.07KB
permissions (index.js) 0.93KB 0.41KB
permissions (store.js) 0.91KB 0.42KB
permissions (useFieldPermissions.js) 1.28KB 0.53KB
permissions (usePermissions.js) 4.83KB 2.27KB
plugin-ai (index.js) 16.04KB 3.92KB
plugin-calendar (index.js) 53.43KB 15.54KB
plugin-charts (index.js) 84.71KB 23.25KB
plugin-chatbot (index.js) 201.52KB 47.99KB
plugin-dashboard (index.js) 144.20KB 38.95KB
plugin-designer (index.js) 233.53KB 49.80KB
plugin-detail (index.js) 248.57KB 65.47KB
plugin-editor (index.js) 2.23KB 1.05KB
plugin-form (index.js) 177.11KB 45.88KB
plugin-gantt (index.js) 179.17KB 45.07KB
plugin-grid (index.js) 249.62KB 69.16KB
plugin-kanban (index.js) 52.77KB 16.56KB
plugin-list (index.js) 120.25KB 30.26KB
plugin-map (index.js) 27.24KB 9.03KB
plugin-markdown (index.js) 13.88KB 4.80KB
plugin-report (index.js) 44.12KB 12.29KB
plugin-timeline (index.js) 39.10KB 11.81KB
plugin-tree (index.js) 15.07KB 5.33KB
plugin-view (index.js) 91.20KB 23.04KB
providers (DataSourceProvider.js) 0.75KB 0.39KB
providers (MetadataProvider.js) 1.37KB 0.59KB
providers (ThemeProvider.js) 1.90KB 0.85KB
providers (UploadProvider.js) 11.81KB 3.58KB
providers (index.js) 0.45KB 0.23KB
providers (types.js) 0.01KB 0.04KB
react-runtime (index.js) 5.62KB 2.34KB
react (LazyPluginLoader.js) 4.47KB 1.63KB
react (SchemaRenderer.js) 120.63KB 39.56KB
react (data-invalidation.js) 5.05KB 2.08KB
react (index.js) 4.50KB 2.06KB
react (schema-input.js) 4.31KB 2.07KB
react (spec-input.js) 0.20KB 0.18KB
sdui-parser (body-dialect.js) 4.50KB 1.99KB
sdui-parser (codegen.js) 9.45KB 3.76KB
sdui-parser (dashboard-widget-options.js) 3.07KB 1.30KB
sdui-parser (index.js) 7.30KB 3.12KB
sdui-parser (input-type.js) 2.84KB 1.40KB
sdui-parser (parse.js) 25.28KB 7.80KB
sdui-parser (provenance.js) 3.84KB 1.90KB
sdui-parser (types.js) 0.28KB 0.23KB
sdui-parser (validate.js) 23.87KB 7.83KB
types (ai.js) 4.39KB 2.17KB
types (api-types.js) 0.20KB 0.18KB
types (app.js) 4.12KB 1.61KB
types (authoring-nodes.js) 0.20KB 0.19KB
types (base.js) 0.20KB 0.18KB
types (blocks.js) 0.20KB 0.18KB
types (cloud.js) 0.20KB 0.18KB
types (complex.js) 4.44KB 2.07KB
types (crud.js) 0.20KB 0.18KB
types (dashboard-filter-alias.js) 6.23KB 2.74KB
types (dashboard-widget-layout.js) 2.06KB 0.96KB
types (data-display.js) 3.75KB 1.85KB
types (data-protocol.js) 0.20KB 0.19KB
types (data.js) 0.20KB 0.18KB
types (designer.js) 1.85KB 0.85KB
types (disclosure.js) 0.20KB 0.18KB
types (error-code.js) 1.54KB 0.88KB
types (expression.js) 0.20KB 0.18KB
types (feedback.js) 0.20KB 0.18KB
types (field-types.js) 1.13KB 0.65KB
types (form.js) 0.20KB 0.18KB
types (http-inflight.js) 8.87KB 3.73KB
types (http-retry.js) 4.32KB 2.02KB
types (icon-key-migration.js) 4.26KB 1.63KB
types (index.js) 5.78KB 2.70KB
types (layout.js) 0.20KB 0.18KB
types (managed-by.js) 0.19KB 0.18KB
types (mobile.js) 5.00KB 2.39KB
types (navigation.js) 0.20KB 0.18KB
types (node-slots.js) 7.18KB 2.34KB
types (objectql.js) 0.20KB 0.18KB
types (overlay.js) 0.20KB 0.18KB
types (permissions.js) 2.52KB 1.31KB
types (plugin-scope.js) 0.20KB 0.18KB
types (record-components.js) 0.20KB 0.19KB
types (record-semantics.js) 1.28KB 0.67KB
types (registry.js) 0.20KB 0.18KB
types (reports.js) 0.20KB 0.18KB
types (select-option.js) 0.20KB 0.19KB
types (spec-report.js) 4.99KB 1.96KB
types (spec-ui-namespace.js) 0.20KB 0.19KB
types (strict-authoring-face.js) 19.93KB 7.25KB
types (system-fields.js) 3.33KB 1.54KB
types (theme.js) 6.28KB 2.87KB
types (ui-action.js) 8.11KB 3.32KB
types (views.js) 0.20KB 0.18KB
types (widget.js) 0.20KB 0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@objectstack-fleet
objectstack-fleet Bot marked this pull request as ready for review October 9, 2026 08:32
@objectstack-fleet
objectstack-fleet Bot enabled auto-merge October 9, 2026 08:32
@objectstack-fleet
objectstack-fleet Bot added this pull request to the merge queue Oct 9, 2026
Merged via the queue into main with commit 47b1f0b Oct 9, 2026
45 checks passed
@objectstack-fleet
objectstack-fleet Bot deleted the claude/issue-12034-console-i18n-after-signin branch October 9, 2026 08:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

2 participants