Skip to content

fix(app-shell): an inherited member is not a URL filter operator suffix - #9845

Merged
os-sales merged 2 commits into
mainfrom
claude/issue-9507-url-filter-op-prototype-chain
Sep 18, 2026
Merged

os-sales merged 2 commits into
mainfrom
claude/issue-9507-url-filter-op-prototype-chain

Conversation

@os-sales

Copy link
Copy Markdown
Collaborator

Fixes #9507

Clause-②: no

parseUrlFilterTriples decided "is this suffix an operator" by indexing URL_FILTER_OPS — a plain object literal — with a suffix that comes from the address bar, and testing the result for truthiness. Object.prototype answered that question too, so filter[amount][constructor]=1 emitted a filter condition whose operator was a JavaScript function. The function's own docblock says an unknown operator suffix is ignored, never silently downgraded to equality; for these suffixes it was neither.

The repair: remove the construction, not the spellings

URL_FILTER_OPS is built with no prototype (Object.assign(Object.create(null), {…})), so an own entry is the only thing a lookup in it can find.

A denylist of constructor / toString / hasOwnProperty was considered and refused: it is a spelling-level patch that the next member of a prototype this module does not own walks straight past. The red run below shows why that is not hypothetical — the sweep that enumerates Object.prototype failed naming twelve leaking members on this tree, not the three the card had measured, and __proto__ among them is a different shape of the same defect (its inherited accessor yielded Object.prototype itself, so that suffix produced an operator that was an object, not a function). A three-name denylist would have closed a quarter of the population and read as a fix.

Nothing on the exported face moves (this is what Clause-②: no rests on): same exported name, same Record of string to string type, same four entries gte lte gt lt, same behaviour under spread, Object.keys and Object.entries — which is how ObjectDataPage inverts the map to bridge a triple's operator to the spec's alias spelling, and what drillEmptyBucketNavHost-9085.test.ts already pins. No exported symbol is added or removed.

⭐ What the consumers actually did — the half the card and triage both flagged as NOT measured

Driven on the pre-change parser through each consumer's own real code (not a mock), then re-driven after the repair. None of the three was a crash, and neither "会崩" nor "无害" was the answer:

consumer before the repair after
filter-chip row (groupFilterChips) did not throw. The function operator matched neither range arm, so it fell to the equality default (= VALUE) and drew a confident amount = 1 chip — the "silently downgraded to equality" outcome the contract rules out, rendered as if the user had asked for it no chip
"Save as view" fold (buildSaveAsViewSpec) did not throw and did not persist. A function is not a string, so it survives normalizeFilterOperator unchanged and ViewFilterRuleSchema refuses it; the rule was dropped with one console.warn and the saved ViewItem carried no filter key at all, passing the record gate same output, and now with no warn, because nothing reaches the fold
list query (not named on the card — schema.filter → toFilterNode) the triples passed through by reference, untouched (no rule objects to lower), and JSON.stringify turned the function into null on the wire: $filter: [["amount",null,"1"]] — a condition with no operator in it toFilterNode folds the empty list to undefined, so the $filter slot is skipped entirely

⚠️ The card's worst case did not materialise, and that is a measurement, not an assumption: a function-valued operator could not be written into stored view metadata. The spec's rule gate is the thing that stopped it. What the user did get was worse than a render glitch in a quieter way — the chip row asserted amount = 1 while the saved view silently contained no such condition and the list query went out malformed. Three surfaces, three different wrong answers, no error anywhere.

The consumer measurement is reported rather than pinned: after this repair that state is unreachable from a URL, so a permanent test at a consumer would assert about an input the parser can no longer produce. The pin belongs where the defect is.

Tests

packages/app-shell/src/views/drillUrlFilters.test.ts — the module's own suite, where its siblings already live.

  • the card's three suffixes, kept literal as executable evidence of the repro;
  • a sweep that enumerates Object.getOwnPropertyNames(Object.prototype) at run time rather than listing today's members, so a member added to the language is covered without anyone remembering to (AGENTS.md 完善设计器的每一个细节 #9 — the population is re-derived, never written down). Its failure message names every leaking suffix;
  • paired with an assertion that all four declared operators still resolve, read out of the exported map — without it, a parser that stopped emitting anything at all would pass the sweep vacuously;
  • the exported four-entry shape, so the repair cannot move a published face;
  • the card's positive control filter[amount][nope]=1 → nothing, which was correct before and after and proves the suite would notice a regression in the opposite direction.

Direction, decided before running: RED before, GREEN after.

before  (4d963a26 + tests only)   Tests  4 failed | 29 passed (33)
        ×  emits nothing for `filter[amount][constructor]=1`
        ×  emits nothing for `filter[amount][toString]=1`
        ×  emits nothing for `filter[amount][hasOwnProperty]=1`
        ×  emits nothing for ANY member of Object.prototype, enumerated not listed
           AssertionError: expected [ 'constructor', …(11) ] to deeply equal []
after                             Tests  33 passed (33)

Gates

All at 21ef238f (post-merge of origin/main), each exit code captured before any pipe.

command exit
pnpm exec vitest run packages/app-shell/ (whole affected package) 0 — 717 files, 7058 passed, 1 skipped
pnpm exec tsc --noEmit && pnpm exec tsc -p tsconfig.test.json (in packages/app-shell) 0 — the second tsc is why the test file is typechecked too
pnpm --workspace-concurrency=2 --filter '@object-ui/app-shell^...' build 0 — dependency closure, required before typecheck resolved @object-ui/*
pnpm exec eslint . (in packages/app-shell) 0 — 0 errors; the 3037 warnings are the package's pre-existing population, 0 of them on either changed file
node scripts/check-changeset-presence.mjs 0
pnpm check:control-bytes 0
pnpm check:new-line-citations 0 — 0 new citations
pnpm check:changeset-claims 0
pnpm check:pending-changeset-literals 0
pnpm check:test-path-roots 0

The lint reading is a declared narrowing, with its three pieces of evidence: the universe is eslint's own resolution of the package directory (eslint ., not a file list of mine); the file count is read from --format json; and the invariance holds because this config enables no type-aware linting (its languageOptions declares no parserOptions.project / projectService) and no rule under eslint-rules/ reads another file — so this diff cannot move the verdict on a file it does not contain. Repo-wide pnpm lint over the other packages is CI's run.

Acceptance notes

Out-of-scope observations, recorded here rather than filed or fixed:

  • The inverse WRITE-side map does not carry this shape. The docblock names RANGE_OP_PARAM as the inverse of URL_FILTER_OPS, so it was checked: it is only ever read through Object.entries() — an own-enumerable iteration — and never indexed by an externally chosen key. collectFilterParams does index a caller-supplied object (ops[NULL_FILTER.key], ops[op]), but only with the fixed keys $null / $gte / $lte / $gt / $lt, none of which is an Object.prototype member. No repair is owed and none was made. Whether it belonged in this PR was a scope call; it turned out not to be a defect.
  • @objectstack/spec's normalizeFilterOperator indexes its own alias table the same bare way (VIEW_FILTER_OPERATOR_ALIASES[op]), so a string operator naming an inherited member returns a function. Not filed: it is a different repository, it is unreachable from this path (this parser's operators come from URL_FILTER_OPS' values), and the outcome does not diverge — both the inherited member and the verbatim string land outside VIEW_FILTER_OPERATORS and are refused by the enum. Named here because it is the same construction and a future reader deserves to know it was looked at rather than missed. Carrier if anyone picks it up: whoever next touches that alias table.

Deviations

  • The dispatch brief's file surface says this module's tests live under packages/app-shell/src/views/__tests__/. On this tree they do not — drillUrlFilters.test.ts and every sibling that exercises this module sit directly in packages/app-shell/src/views/. The existing suite was extended in place rather than a new file opened in a directory this module has never used. The substantive fence (one source file, its tests, one changeset) is unbreached; the directory clause was falsified against the tree.

🤖 Generated with Claude Code

https://claude.ai/code/session_01Xm4WFhEe5mwcgyqHjxR2hn


Generated by Claude Code

`parseUrlFilterTriples` resolved a `filter[<field>][<op>]` suffix by indexing
`URL_FILTER_OPS` — a plain object literal — and testing the result for
truthiness. The suffix comes from the address bar, so `Object.prototype`
answered that question too: `[constructor]`, `[toString]`, `[hasOwnProperty]`
each emitted a triple whose OPERATOR WAS A FUNCTION, and `[__proto__]` one whose
operator was `Object.prototype` itself. The function's own contract says an
unknown suffix is ignored, never silently downgraded to equality; for these it
was neither.

The map now has no prototype, so an own entry is the only thing a lookup can
find. No denylist: that is a spelling-level patch the next member of a prototype
this module does not own walks straight past. The exported face is unchanged —
same name, same `Record<string, string>`, same four entries, same behaviour
under spread and `Object.entries`.

The accompanying sweep enumerates `Object.prototype` at run time rather than
listing today's members, and is paired with an assertion that the four declared
operators still resolve so it cannot pass vacuously.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Xm4WFhEe5mwcgyqHjxR2hn
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

Metric Value Budget
Eager closure (gzip, 329 chunks) 3049.8 KB 3104.5 KB
Main entry chunk (gzip) 145.7 KB 350 KB
Entry file index-CPjwiXCD.js —
Status PASS —

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

Package Size Gzipped
app-shell (consoleActionDispatch.js) 0.20KB 0.19KB
app-shell (index.js) 16.69KB 6.21KB
app-shell (runtime-config.js) 20.68KB 7.36KB
app-shell (types.js) 0.01KB 0.04KB
app-shell (urlParams.js) 10.06KB 3.86KB
auth (ActiveOrganizationStorage.js) 25.05KB 9.16KB
auth (AuthContext.js) 0.31KB 0.24KB
auth (AuthGuard.js) 2.07KB 1.00KB
auth (AuthProvider.js) 40.18KB 10.59KB
auth (AuthShell.js) 3.49KB 1.40KB
auth (ForgotPasswordForm.js) 12.21KB 3.45KB
auth (LoginForm.js) 18.15KB 5.39KB
auth (PreviewBanner.js) 0.90KB 0.50KB
auth (RegisterForm.js) 6.65KB 2.22KB
auth (SocialSignInButtons.js) 9.61KB 3.89KB
auth (UserMenu.js) 3.41KB 1.23KB
auth (auth-gate-events.js) 1.29KB 0.66KB
auth (authStyles.js) 5.04KB 1.72KB
auth (createAuthClient.js) 40.21KB 10.80KB
auth (createAuthenticatedFetch.js) 8.46KB 3.43KB
auth (index.js) 3.19KB 1.44KB
auth (invitation-status.js) 1.22KB 0.70KB
auth (org-roles.js) 6.66KB 2.78KB
auth (phone-identifier.js) 1.11KB 0.66KB
auth (types.js) 0.59KB 0.35KB
auth (useAuth.js) 5.30KB 1.02KB
auth (useWorkspaceAdminStatus.js) 11.08KB 4.58KB
collaboration (CommentThread.js) 26.08KB 7.56KB
collaboration (LiveCursors.js) 3.17KB 1.27KB
collaboration (PresenceAvatars.js) 6.49KB 2.64KB
collaboration (PresenceProvider.js) 2.79KB 1.13KB
collaboration (index.js) 1.68KB 0.73KB
collaboration (useCollaborationTranslation.js) 6.05KB 2.52KB
collaboration (useCommentSearch.js) 1.98KB 0.88KB
collaboration (useConflictResolution.js) 7.75KB 1.86KB
collaboration (useMentionNotifications.js) 1.81KB 0.68KB
collaboration (usePresence.js) 6.33KB 1.84KB
collaboration (useRealtimeSubscription.js) 7.91KB 2.01KB
components (index.js) 545.74KB 130.75KB
core (index.js) 8.94KB 3.59KB
create-plugin (index.js) 27.94KB 9.51KB
data-objectstack (index.js) 215.98KB 59.97KB
fields (index.js) 249.23KB 62.88KB
i18n (LocalizationContext.js) 1.76KB 0.96KB
i18n (builtinAggregateLabels.js) 0.86KB 0.49KB
i18n (currency.js) 1.22KB 0.64KB
i18n (fallbackInterpolation.js) 6.25KB 2.77KB
i18n (i18n.js) 8.87KB 3.64KB
i18n (index.js) 5.22KB 2.26KB
i18n (pickLocalized.js) 9.86KB 3.95KB
i18n (provider.js) 32.15KB 10.49KB
i18n (useDisplayLocale.js) 2.85KB 1.45KB
i18n (useObjectLabel.js) 34.34KB 9.17KB
i18n (useSafeTranslation.js) 5.60KB 2.33KB
layout (index.js) 38.83KB 10.95KB
mobile (MobileProvider.js) 0.92KB 0.49KB
mobile (ResponsiveContainer.js) 0.94KB 0.38KB
mobile (breakpoints.js) 1.51KB 0.70KB
mobile (createOfflineDataSource.js) 5.61KB 1.75KB
mobile (index.js) 1.99KB 0.87KB
mobile (offlineQueue.js) 3.91KB 1.35KB
mobile (pwa.js) 0.97KB 0.49KB
mobile (serviceWorker.js) 1.48KB 0.62KB
mobile (serviceWorkerSource.js) 3.41KB 1.48KB
mobile (useBreakpoint.js) 1.54KB 0.65KB
mobile (useGesture.js) 6.96KB 1.98KB
mobile (useOfflineSync.js) 1.99KB 0.72KB
mobile (usePullToRefresh.js) 2.53KB 0.85KB
mobile (useResponsive.js) 0.72KB 0.42KB
mobile (useSpecGesture.js) 5.52KB 2.10KB
mobile (useTouchTarget.js) 1.01KB 0.54KB
permissions (MePermissionsProvider.js) 13.52KB 4.88KB
permissions (PermissionContext.js) 0.31KB 0.25KB
permissions (PermissionGuard.js) 0.89KB 0.45KB
permissions (PermissionProvider.js) 6.24KB 2.16KB
permissions (discardProofCache.js) 1.04KB 0.55KB
permissions (evaluator.js) 8.39KB 3.10KB
permissions (index.js) 0.93KB 0.41KB
permissions (store.js) 0.91KB 0.42KB
permissions (useFieldPermissions.js) 1.28KB 0.53KB
permissions (usePermissions.js) 4.83KB 2.27KB
plugin-ai (index.js) 14.81KB 3.63KB
plugin-calendar (index.js) 49.92KB 14.22KB
plugin-charts (index.js) 71.61KB 20.05KB
plugin-chatbot (index.js) 195.34KB 46.51KB
plugin-dashboard (index.js) 131.44KB 34.65KB
plugin-designer (index.js) 215.94KB 44.33KB
plugin-detail (index.js) 253.37KB 65.90KB
plugin-editor (index.js) 2.23KB 1.05KB
plugin-form (index.js) 136.74KB 34.16KB
plugin-gantt (index.js) 167.62KB 41.26KB
plugin-grid (index.js) 212.61KB 57.90KB
plugin-kanban (index.js) 48.10KB 14.94KB
plugin-list (index.js) 112.74KB 27.70KB
plugin-map (index.js) 21.48KB 6.99KB
plugin-markdown (index.js) 13.88KB 4.80KB
plugin-report (index.js) 43.41KB 11.93KB
plugin-timeline (index.js) 30.07KB 8.74KB
plugin-tree (index.js) 10.58KB 3.72KB
plugin-view (index.js) 85.05KB 21.01KB
providers (DataSourceProvider.js) 0.75KB 0.39KB
providers (MetadataProvider.js) 1.37KB 0.59KB
providers (ThemeProvider.js) 1.90KB 0.85KB
providers (UploadProvider.js) 11.66KB 3.50KB
providers (index.js) 0.45KB 0.23KB
providers (types.js) 0.01KB 0.04KB
react-runtime (index.js) 5.62KB 2.34KB
react (LazyPluginLoader.js) 4.47KB 1.63KB
react (SchemaRenderer.js) 104.82KB 34.67KB
react (data-invalidation.js) 5.05KB 2.08KB
react (index.js) 4.63KB 2.18KB
react (schema-input.js) 4.25KB 2.04KB
react (spec-input.js) 0.20KB 0.18KB
sdui-parser (codegen.js) 6.58KB 2.74KB
sdui-parser (dashboard-widget-options.js) 3.08KB 1.30KB
sdui-parser (index.js) 5.66KB 2.50KB
sdui-parser (input-type.js) 2.84KB 1.40KB
sdui-parser (kanban-quick-add.js) 3.89KB 1.87KB
sdui-parser (parse.js) 25.28KB 7.80KB
sdui-parser (provenance.js) 3.66KB 1.82KB
sdui-parser (types.js) 0.28KB 0.23KB
sdui-parser (validate.js) 14.82KB 4.99KB
types (ai.js) 4.11KB 2.06KB
types (api-types.js) 0.20KB 0.18KB
types (app.js) 2.87KB 1.00KB
types (base.js) 0.20KB 0.18KB
types (blocks.js) 0.20KB 0.18KB
types (complex.js) 2.93KB 1.49KB
types (crud.js) 0.20KB 0.18KB
types (dashboard-filter-alias.js) 6.23KB 2.74KB
types (data-display.js) 3.75KB 1.85KB
types (data-protocol.js) 0.20KB 0.19KB
types (data.js) 0.20KB 0.18KB
types (designer.js) 1.85KB 0.85KB
types (disclosure.js) 0.20KB 0.18KB
types (error-code.js) 1.54KB 0.88KB
types (expression.js) 0.20KB 0.18KB
types (feedback.js) 0.20KB 0.18KB
types (field-types.js) 0.20KB 0.18KB
types (form.js) 0.20KB 0.18KB
types (http-inflight.js) 8.87KB 3.73KB
types (http-retry.js) 4.32KB 2.02KB
types (icon-key-migration.js) 4.26KB 1.63KB
types (index.js) 4.74KB 2.25KB
types (layout.js) 0.20KB 0.18KB
types (managed-by.js) 0.19KB 0.18KB
types (mobile.js) 4.73KB 2.28KB
types (navigation.js) 0.20KB 0.18KB
types (objectql.js) 0.20KB 0.18KB
types (overlay.js) 0.20KB 0.18KB
types (permissions.js) 0.20KB 0.18KB
types (plugin-scope.js) 0.20KB 0.18KB
types (record-components.js) 0.20KB 0.19KB
types (record-semantics.js) 1.28KB 0.67KB
types (registry.js) 0.20KB 0.18KB
types (reports.js) 0.20KB 0.18KB
types (select-option.js) 0.20KB 0.19KB
types (spec-report.js) 5.05KB 1.93KB
types (spec-ui-namespace.js) 0.20KB 0.19KB
types (strict-authoring-face.js) 14.04KB 5.36KB
types (system-fields.js) 3.33KB 1.54KB
types (theme.js) 6.28KB 2.87KB
types (ui-action.js) 8.11KB 3.32KB
types (views.js) 0.20KB 0.18KB
types (widget.js) 0.20KB 0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-sales
os-sales marked this pull request as ready for review September 18, 2026 09:48

Copy link
Copy Markdown
Collaborator Author

Reviewed, green and ready at 2026-09-18T09:49Z — ACCEPT recorded on objectui#9507, comment 5728114372, stamped 2026-09-18T09:33Z. CI on head 21ef238f: 33 success · 3 skipped · 0 pending · 0 non-success; the three skips are Test (coverage), dependabot and Test (coverage shard ${{ matrix.shard }}/4), all expected. Path surface carries no governed file.

⛔ This seat cannot put it in the merge queue — same refusal, same cause, already recorded in full on PR objectui#9804: PUT .../ccr/auto_merge is refused by this session's auto-mode classifier as [Self-Approval]. ⚠️ That refusal's explanation has since been corrected on objectui#9804: it is not the shared identity — os-sales queues os-sales-authored PRs routinely on this board — it is this session's configuration.

⇒ A pointer, not a fourth report: the blocker, what this seat will not do about it, and the two ways to unblock it all live on objectui#9804. ⛔ No auto-merge attempt was made here; the refusal is predictable and retrying a denied action class unchanged is repetition, not a reading.

Divergence, measured with GET /compare rather than mergeable_state (which flaps between behind, clean and unstable within minutes): this PR is diverged, behind_by 1, no conflict. Its three siblings are behind by 19 / 17 / 16 and also conflict-free. ⛔ No update-branch run on any of them: a merge queue builds its own merge commit against current main, and the harness signals a real un-mergeable transition — so the numbers are recorded rather than pre-emptively acted on.

Nothing else is outstanding on this PR. It stays watched until merged or closed.

Posted by the domain:ui seat 3 (session_01Xm4WFhEe5mwcgyqHjxR2hn).


Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

finding(app-shell): parseUrlFilterTriples accepts an Object.prototype member as a URL filter operator, emitting a triple whose operator is a function

2 participants