Skip to content

chore(deps): upgrade @objectstack/* to 17.6.0 - #1982

Merged
hotlong merged 1 commit into
mainfrom
upgrade/objectstack-17.6.0
Oct 2, 2026
Merged

hotlong merged 1 commit into
mainfrom
upgrade/objectstack-17.6.0

Conversation

@hotlong

@hotlong hotlong commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Description

Upgrade HotCRM from @objectstack/* 17.5.0 to 17.6.0, done the way an end user would do it. The upgrade was exercised in place on a database created by HotCRM on 17.5.0, then walked in a browser. This PR is one of the verification lanes for the 17.6.0 release. The tables below record what was run against each line of the 17.6.0 Upgrade checklist (content/docs/releases/v17/17-6.mdx in objectstack) and what was observed.

Method.

  1. On main (17.5.0), I built HotCRM and booted it on a fresh SQLite file, which ran the seed load. I then signed up the first admin and wrote probe records through REST: an account, which started a pending approval; a contact; an opportunity; a case; an event with datetime values; a campaign with date values; and an anonymous Web-to-Lead submission. I also saved one list view through PUT /api/v1/meta/view, with an 「is empty」 filter on a text field. A copy of that DB was kept as the 17.5.0 baseline.
  2. On this branch I moved the pins and regenerated the lockfile. I ran every os command on the checklist, booted 17.6.0 on a copy of the 17.5.0 DB, and walked the console with Playwright (Chromium). For each difference I found, I booted 17.5.0 on the same DB to tell regressions from older behaviour.

Type of Change

  • Breaking change (platform upgrade, dependency pins)
  • Documentation update

Related Issues

Related to hotcrm#1970 (the 17.5.0 upgrade). This PR closes its "Known issue": grouped lists with object columns load rows again on the 17.6.0 console.

Changes Made

  • package.json: all 21 @objectstack/* pins move 17.5.0 → 17.6.0, exact. pnpm-lock.yaml was regenerated by pnpm install: 725 → 727 packages: entries, 54 @objectstack/* keys moved 1:1, and hono@4.13.3 left the tree.
  • objectstack.manifest.json / objectstack.config.ts: specVersion and engines.protocol move to ^17.6.0. That is still protocol major 17, so it meets the checklist's "leave on 17" line and follows the repo's own convention (docs/MAINTENANCE.md §3).
  • Six page:header blocks drop breadcrumb. The key was retired in 17.6.0 (page-header-breadcrumb-removed). The six pages are App Launcher, Sales Home, Account Detail, Lead Detail, Opportunity Detail and Case Detail. No visible change: the app shell still draws its breadcrumb trail.
  • Audit-log docs (FAQ + Security & Compliance, en / zh-Hans / zh-Hant): Setup → Audit Logs no longer shows delete rows, logout rows or login rows whose session has ended to any non-system reader, admins included. I verified this in the browser: I deleted a record, and its delete row is stored but appears in neither audit-log screen.
  • Re-scoped pin claims: the What's new platform line (three locales), docs/STATUS.md, and three comments that called 17.5.0 the current pin. Claims that say "not re-run on 17.5.0" are dated truth and are unchanged. The sweep was a grep for 17.5. A stale claim written without a version number would not show up in it.
  • .changeset/objectstack-17-6-0.md.

Upgrade checklist → 17.6.0, line by line

"Applies?" means whether HotCRM has anything the line describes.

Before you upgrade

Line Applies? What I ran Observed
Find app-declared anonymous endpoints (authRequired: false) No grep authRequired over src/ and the config. Anonymous submit of both public forms, over REST and in the browser at /_console/f/contact-us, on 17.5.0 and 17.6.0 HotCRM declares no authRequired: false endpoint. Its two public forms (web_to_lead → /forms/contact-us, web_to_case → /forms/support, sharing.allowAnonymous) still create their records on 17.6.0: 201, and the browser shows "Thank you!". GET /api/v1/forms/:slug serves the form. The case form has no lookup field, so the publicPicker retirement does not reach it.
Grant a permission set where fallbackPermissionSet: null No grep fallbackPermissionSet HotCRM does not embed the runtime. The six hits are test harnesses that pass the app's default set, and all six tests pass.
Grant manage_platform_settings for datasource / external_catalog reads on /meta No grep for datasource metadata and for authoring capabilities in permission sets HotCRM ships no datasource or external_catalog metadata, and no permission set holds only manage_metadata / studio.access / setup.access.
List stored flows that share a packaged flow's name No Startup log on the 17.5.0 DB. GET /api/v1/automation/_status No shadow warnings. The 17.5.0 DB stores no flow rows (sys_metadata has one row, a view). _status lists 31 flows. Every flow that is not bound says why: scheduled work is off by deployment policy, the same as on 17.5.0. No subflow refusals.
Find stored datetime values before year 1000 Yes (data) — none found $lt '1000-01-01T00:00:00.000Z' over REST on five fields, and SQL over all 18 datetime columns of the 17.5.0 DB 0 rows.
Fix Turso datasource configs (mode: 'local' + syncUrl) No — HotCRM declares no datasource.

Getting onto the release

Line Applies? What I ran Observed
Move all @objectstack/* pins as one set; regenerate the lockfile; pnpm update hono if flagged Yes Edited package.json, then pnpm install 21 pins moved. Lockfile 725 → 727 entries. The older hono under the MCP SDK left the tree, so pnpm update hono is not needed. One peer warning (better-auth wants better-sqlite3@^12, @objectstack/cli has 13.0.3) is unchanged from 17.5.0: same versions in both locks.
Leave protocol declarations on 17 Yes — ^17.6.0 in both places. Still major 17, and the runtime loads it.
os migrate meta --from 17, then os migrate meta --stored --apply Yes os migrate meta --from 17. os migrate meta --stored (preview), then --stored --apply --yes, both on the 17.5.0 DB --from 17: 19 mechanical edits. 6 page-header-breadcrumb-removed, applied in source by this PR. 13 flow-decision-mode-inclusive-explicit, the same 13 that 17.5.0 offered; deliberately not written, since every one partitions its out-edges (see hotcrm#1970). 263 generic "manual change" notices, none naming HotCRM metadata. --stored: "Examined 1 stored metadata row … already on protocol 17.0.0 — nothing to rewrite"; --apply rewrote 0. ⚠️ See platform issue A: the preview wrote to app tables.
os migrate audit-metadata-bodies, then --apply Yes Dry run, --apply --yes, then --apply again for idempotence, on the 17.5.0 DB sys_audit_log: 2 scanned, 0 to rewrite. sys_activity: 2 scanned, 0. "Nothing to rewrite". The second --apply gives the same result. ⚠️ The dry run also wrote to app tables (platform issue A).

Metadata and build

Line Applies? What I ran Observed
Rewrite cube sql / dataset field that is not a column; delete refreshKey No os validate. grep refreshKey Validate passes, so every dataset member names a column. No refreshKey.
Delete connector triggers / syncConfig / fieldMappings No grep No connectors.
Rewrite page/view shapes (div→box, requires, endpoint→target, subform columns, grouping, publicPicker, breadcrumb) Yes — breadcrumb only os migrate meta --from 17. grep 6 breadcrumb deleted. No html pages, endpoint, subforms, line-item or master-detail blocks, or publicPicker. The 4 grouping values already have the { fields: [{ field }] } shape.
Fix new author-time refusals (picklist refs, api flow secret, action translation keys, JSON/multi-value dimensions, dimensionless multi-value pie/…) No os validate, os build Both exit 0. None of these fire.
Write time defaults/values as a bare wall clock Yes (one action param) Browser: Schedule a Meeting on an account, Start Time 14:30 POST /api/v1/actions/crm_account/schedule_meeting 200. The event was stored with start_datetime: 2026-11-05T14:30:00.000Z. No time field or time default anywhere.
(os validate --strict) — os validate --strict on 17.5.0 and 17.6.0 Red on both. Not a HotCRM gate (pnpm verify does not run it). 17.5.0 fails on 23 warnings. 17.6.0 fails on the same 23 plus 88 from the newly firing rules: 84 unconsumed-widget-option (dashboard options.icon / format / columns / striped / density / pivot keys that no renderer reads) and 4 liveness-dead-property (rowLevelSecurity[].label / description on two permission sets). These are dead keys. Removing them changes nothing at runtime. Not done here, to keep the upgrade PR minimal; proposed as a follow-up.

Data and database

Line Applies? What I ran Observed
Review sharing rules / views using 「is empty」 on text or multi-value fields Yes (stored data only) grep over source. A stored list view from 17.5.0 with is_empty on crm_case.resolution. SQL The source uses none. The stored view still loads (31 rows) and re-saves (rename → PUT 200). The 17.5.0 data holds no '' text value (resolution: 31 NULL, 0 empty string), so the wider meaning changes no result here.
Review saved filters, list views, dashboard widgets, reports for refused filter / aggregate shapes Yes Browser walk of 20 list views, 5 dashboards and 7 record pages, recording every non-GET API call and every 4xx/5xx No refused query anywhere. The 5 dashboards draw the same number of chart elements on 17.5.0 and 17.6.0 (13 / 21 / 12 / 14 / 17), and no /analytics/dataset/query failed.
Send import files with ISO 8601 dates Yes POST /api/v1/data/crm_campaign/import and the console Import wizard (CSV) As documented. 2026-07-15 and 2026-07-16 00:00:00 import. 07/15/2026, 46218 (Excel serial) and 2026-02-30 fail their row with invalid_date, and the rest of the batch imports. The wizard reports "2 created, 1 skipped — Row 2: Start Date: "07/15/2026" is not a valid date".
Remote Turso _objectstack_sequences without key_hash No — SQLite only.

Deployment and configuration

Line Applies? What I ran Observed
Grant auditors what they need to read Yes (docs) Deleted a campaign as the platform admin, then read sys_audit_log over REST and in both Setup audit-log screens The create and delete rows are stored (SQL), but the admin is served neither. Both Setup screens omit them. HotCRM's FAQ and Security page claimed otherwise; fixed in this PR.
--visibility private on first os plugin publish No grep HotCRM publishes with scripts/publish-marketplace.mjs, not os plugin publish.
Know the console issues at this pin Yes (Studio) Browser. Created a writable package and object in Studio, then a dataset in Setup › Metadata › Dataset and a datasource in Setup › Datasources All three known issues are confirmed where reachable. Dataset: a new count measure from the designer gets 422 measures.0.field [invalid_format]. Datasource: External with no external block gets 400 … schemaMode='external' requires 'external' settings. Html page: HotCRM has no html page and Studio offered no html-page authoring in the walk, so this one was not exercised. HotCRM's own metadata is read-only in Studio (a code package), so none of the three reaches HotCRM's datasets or pages.
Override of validation.field.invalid_date / invalid_datetime No grep No such override.

Application code, hooks and flows

Line Applies? What I ran Observed
Customer flows: status: 'obsolete', not the toggle; enable subflows first; no _ names No grep. _status No customer-authored flows, no flow name starts with _, no toggle calls.
Every http node's signingSecret renders to a value Yes (2 nodes) Read src/sales/flows/_billing-endpoint.ts The two billing hand-off nodes take signingSecret from HOTCRM_BILLING_SIGNING_SECRET. When the variable is unset the constant is undefined, so the key is absent and the node sends unsigned (allowed). When it is set the value is a non-empty literal. Neither case hits "renders to nothing".
Stop sending formula with strictReadonlyWrites; read ctx.submitted No grep No strictReadonlyWrites, and no hook reads a formula from ctx.input.data.
Migration-chain imports / --clone-from / os dev --no-watch / nextUtcCalendarDay No grep None used. tsc --noEmit is clean.
Custom hosts and drivers (AnalyticsService wiring, findOne stand-ins, ISecurityService) Tests only pnpm test Nine tests build AnalyticsService by hand. All 3725 tests pass on 17.6.0 unchanged.
Publish data.record.*, not bare record.* No grep No plugin publishes events.

Commands

Command 17.6.0 result
os validate ✅ exit 0, 111 warnings (17.5.0 CLI on the 17.5.0 source: 23)
os validate --strict ❌ exit 1, red on 17.5.0 too (see above). Not a repo gate
os build ✅ exit 0
os lint ✅ exit 0, 104 warnings / 16 suggestions (17.5.0: 16 / 16). The +88 are the two newly firing rules
pnpm verify (validate, typecheck, lint, i18n gate, hygiene, token ratchet, build, test) ✅ green. 173 files, 3725 passed, 1 skipped. No test changed
pnpm test:e2e (against the upgraded 17.5.0 DB) ✅ 16 / 16
Boot 17.6.0 on the 17.5.0-created DB ✅ clean. Seed replay inserted 0, updated 196, skipped 158, errored 0, and all probe records are intact

Browser walk (Playwright, Chromium, 17.6.0 on the 17.5.0-created DB)

Area Result
Sign-in, app home ✅
List views: Accounts, Contacts (grouped by account, collapsed), Leads, Opportunities, Quotes, Contracts, Products (grouped), Cases, Knowledge Articles (grouped), Events, Forecasts (grouped), Campaigns, Campaign Members, My Tasks / Deals / Leads / Cases / Events, Account Workbench ✅ Every one rendered rows, with no API error. The grouped grids now load rows. On 17.5.0, Products still shows Unknown field '[object Object]' (re-checked side by side), so hotcrm#1970's known issue is closed.
Record pages: account, lead, opportunity, case, contact, quote, contract ✅ No API errors. The shell breadcrumb still draws.
Dashboards: Executive, Sales Performance, Sales Activity, Service Overview, CRM Overview ✅ 13 / 21 / 12 / 14 / 17 chart elements, identical to 17.5.0. No failed dataset query.
Approvals ✅ A request started on 17.5.0 was approved on 17.6.0 through POST /api/v1/approvals/requests/:id/approve, with the admin staffed into sales_manager. The account's approval_status became approved. ⚠️ My Pending in the Approvals Inbox does not list position-routed requests (platform issue B). That is unchanged from 17.5.0. Submitted by me and All list them.
Flows ✅ The Close Case screen flow ran: confirm, then the screen, then the knowledge-article picker (4 options), then submit. The case closed with resolved_by_article set. Schedule a Meeting (date and time params) ran too.
Import, including date cells ✅ Matches the documented 17.6.0 rule (see the Data table).
zh-CN locale, full document load per page ✅ Navigation, list views, a dashboard, four record pages and the Approvals Inbox all render in zh-CN, with no API errors. Every page was a full goto, not a client-side route change.
Studio saves Object ✅: new package (the "New Package" dialog works again at this pin), then a new object as a draft, then publish (publish-drafts 200). App / nav ✅ as a draft. ⚠️ "Add nav item" autosaves the empty item at once, and the console shows 422 navigation.1.objectName until an object is picked. View ✅: renamed a stored 17.5.0 view, PUT /meta/view 200. Dataset ❌ known issue, count measure refused. Datasource ❌ known issue, External refused. Page — not exercised (HotCRM has no html page).
Public form, anonymous ✅ /_console/f/contact-us rendered, submitted, and showed "Thank you!" (201).

Other things seen, all unchanged from 17.5.0 (so not regressions):

  • Every console page calls GET /api/v1/usage/storage and gets 404.
  • lead_assignment fails its notify_std node on an ownerless Web-to-Lead ("every recipient template resolved to nothing: {record.owner_id}").
  • A boot's seed replay claims ownerless non-seed leads for the first admin.

Platform issues

⚠️ Not filed yet. This session could not attach objectstack-ai/objectstack, because the request was denied by the session's permission policy, so I could not search for duplicates or open issues there. The drafts below go to the maintainer to file. Neither is an authorization defect.

  • A — os migrate meta --stored (preview) and os migrate audit-metadata-bodies (dry run) write to application tables (17.6.0 regression for --stored).
    • Steps: make a SQLite DB with HotCRM on 17.5.0 (boot, seed, sign up). Copy it. On 17.6.0, run os migrate meta --stored --database-url file:<copy>, with no --apply.
    • Expected: a read-only preview; the file is unchanged.
    • Actual: the command boots the app's seed loader. On crm_contact, crm_lead, crm_opportunity and five more tables it bumps updated_at, stamps organization_id on seeded rows that had none, and rewrites relative-date seed values. It also logs ERROR [SeedLoader] Failed to write sys_activity …: cannot modify sys_activity because it is a view, because sys_activity is a rotation view on that DB.
    • Comparison: the 17.5.0 CLI on the same file changes nothing (row hashes identical) and logs no SeedLoader error. audit-metadata-bodies without --apply (new in 17.6.0) does the same writes.
  • B — Approvals Inbox "My Pending" never lists position-routed requests.
    • Steps: HotCRM's approval flows route to positions. sys_approval_request.pending_approvers holds position:sales_manager. Staff a user into sales_manager (a sys_user_position row). Open Approvals Inbox → My Pending as that user.
    • Expected: the request is listed.
    • Actual: "No requests". The console asks GET /api/v1/approvals/requests?status=pending&approverId=<id>,<email>,role:platform_admin,role:org_owner,role:sales_manager,…, which spells positions as role:, so nothing matches.
    • Comparison: the same happens on 17.5.0, so this is not a 17.6.0 regression. It does hide every HotCRM approval from its approvers.
  • Release-notes note: 748b240 (#21270, ScheduledWorkPolicy.hostDisabledReason) is in the 17.6.0 code (@objectstack/service-automation dist), but no CHANGELOG.md in the installed 17.6.0 packages mentions #21270 or hostDisabledReason. HotCRM does not use it.

Testing

  • pnpm verify green (unit tests, lint, build, validate, typecheck, i18n gate, hygiene)
  • pnpm test:e2e 16 / 16 against the upgraded DB
  • Manual browser testing (above)
  • New tests added (none needed; no test changed)

🤖 Generated with Claude Code

https://claude.ai/code/session_01WXp8E7s1gzSBje9ZwwqVux


Generated by Claude Code

Move all 21 @objectstack/* dependencies 17.5.0 -> 17.6.0 together, with
specVersion and engines.protocol at ^17.6.0 (still protocol 17), and
regenerate pnpm-lock.yaml from the public registry.

Adopt what 17.6.0 changes for this app:

- pages: delete `breadcrumb` from the six `page:header` blocks that set
  it. 17.6.0 retires the key (page-header-breadcrumb-removed); no
  renderer ever drew it, and the app shell's own trail is unchanged.
- docs: the audit log no longer shows delete rows, logout rows or
  ended-session login rows to any non-system reader, administrators
  included. Correct the FAQ answer that sent admins to Setup > Audit
  Logs for deletions, and add a note to Security & Compliance, in all
  three locales.
- docs: the What's new platform line and docs/STATUS.md name 17.6.0;
  three comments that called 17.5.0 the current pin now date
  themselves.

Exercised in place on a database created by HotCRM on 17.5.0:
`os migrate meta --stored [--apply]` and `os migrate
audit-metadata-bodies [--apply]` had nothing to rewrite, and 17.6.0
booted on it cleanly. The 17.5.0 known issue (grouped lists showing
INVALID_FIELD) is fixed by the 17.6.0 console.

Co-Authored-By: Claude <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WXp8E7s1gzSBje9ZwwqVux
@vercel

vercel Bot commented Oct 2, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
hotcrm Ignored Ignored Oct 2, 2026 5:11am UTC

Request Review

hotlong commented Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

The two platform issues drafted under "Platform issues" are now filed in objectstack. I searched for duplicates first and found none.


Generated by Claude Code

@hotlong
hotlong marked this pull request as ready for review October 2, 2026 07:32
@hotlong
hotlong added this pull request to the merge queue Oct 2, 2026
Merged via the queue into main with commit 68f3701 Oct 2, 2026
11 checks passed
akarma-synetal pushed a commit to akarma-synetal/framework that referenced this pull request Oct 7, 2026
…ai#21362)

## What this is

The release-time half of the 17.6.0 release notes, following objectstack-ai#20623 for
17.5.0.

The page `content/docs/releases/v17/17-6.mdx` landed before publish
(objectstack-ai#21290) with a RELEASE-TIME TODO. 17.6.0 was published to `latest` on
2026-10-02 from the version commit `617f25f8` (objectstack-ai#20639):
`@objectstack/cli` at 02:53Z, `@objectstack/spec` at 03:03Z. This PR
makes the TODO's edits, deletes both TODO comments, and updates
`content/docs/releases/v17/index.mdx`.

Docs-only, two files under the release-owned `content/docs/releases/`.
Nothing is published, hence `skip-changeset`.

Clause-②: no

## What changed

**`17-6.mdx`**

- **Publish date.** 2026-10-02, 3 days after 17.5.0.
- **Count.** The version commit consumed **337** changesets (the
`.changeset/*.md` files it deletes, README excluded). The draft read
338.
- The 69 `CHANGELOG.md` files that carry a 17.6.0 section at `617f25f8`
list 496 per-package entries (198 minor, 298 patch) in 48 of those
files.
  - Those entries de-duplicate to the same 337.
- Every consumed changeset was already in the draft, so nothing new
needed folding in.
  - New in 17.6.0: 337 − 16 shipped in 17.5.0 = **321**.
- **New section "Also shipped in 17.6.0 — not in its CHANGELOG".**
- `748b240` (objectstack-ai#21270, `hostDisabledReason`) is an ancestor of the version
commit, but the version commit did not consume its changeset.
- The npm packages therefore carry it, and no 17.6.0 CHANGELOG names it.
HotCRM's upgrade observed the same (objectstack-ai/hotcrm#1982).
- This is the same window that produced 17.5.0's seven stragglers. I
filed it as objectstack-ai#21361.
- **Console.**
  - The pin stayed `31971ff1e28f`.
- The known-issues list gains the zh-CN defect: console strings render
in English (objectui#11326, fixed upstream in `d0fba91aa`). objectstack-ai#21330
confirmed it on 17.6.0.
- The release verification reproduced the dataset and datasource saves
on 17.6.0.
- **New section "Known issues found after publish".** It draws on the
three 17.6.0 verification lanes:
  - the HotCRM upgrade, objectstack-ai/hotcrm#1982;
  - the North Star path on the published packages, objectstack-ai#21318;
  - the P0 + 17.6-risk checklist run, objectstack-ai#21330.

  The issues it lists:
- objectstack-ai#21349: the `--stored` and `audit-metadata-bodies` previews write to
the database;
- objectstack-ai#21321 / objectstack-ai#21322: local package install loses script action bodies, and
a hot install leaves flows unbound;
- objectstack-ai#21323 / objectstack-ai#21324: `verify` passes a refused stack, and its `--json`
output is not clean;
- objectstack-ai#21350: "My Pending" misses position-routed approvals (pre-existing);
  - objectstack-ai#21332: a cloned flow reaches no Studio surface;
  - objectstack-ai#21158: anonymous endpoints;
  - the console pin issues.

The authorization-class finding in objectstack-ai#21330 (R2) is deliberately not
described here.
- **Upgrade checklist.** 19 of 30 lines are now marked *Exercised on
HotCRM (a 17.5.0 app with a 17.5.0-created SQLite DB), 2026-10-02*, each
with what was observed, taken from hotcrm#1982's per-line table.
  - Lines that do not apply to HotCRM stay *Not exercised*.
- Two lines gain a ⚠️ for objectstack-ai#21349, telling operators to run the previews
on a copy.
- One line is new: `os validate --strict` now fails on dead keys. HotCRM
got +88 warnings.
- **Unchanged.** objectstack-ai#21158 is still open, so its "no supported channel"
lines stay.

**`v17/index.mdx`** (following objectstack-ai#20623)

- The frontmatter description runs through 17.6.0.
- The status blockquote says 17.6.0 is released and current, published
2026-10-02, taking over from 17.5.0. A plain install resolves 17.6.0,
and the minors warning names 17.6.0.
- A new "17.6.0 stays in that register" paragraph links the breaking
changes, the known issues and the checklist.
- The per-release list marks 17.6.0 as current. The checklist callout
records that 17.5.0 → 17.6.0 was exercised in part (19 lines, on
HotCRM), and the checklist links lead with 17.6.0.
- The top-level `content/docs/releases/index.mdx` already reads "current
series: 17.6.0", stamped at version time.

## Verification

Run locally on the head commit. All of these pass:

- `check-issue-citations --base origin/main`
- `check-doc-anchors` (406 links)
- `check-role-word`
- `check-release-page-status`
- `check-release-section-coverage`, plain and `--strict`
- `check:release-index-currency-sync`
- `check-docs-single-h1`
- `check-release-notes`
- `check-doc-frontmatter`

Both pages compile as MDX with `@mdx-js/mdx` 3 + `remark-gfm`.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_014VGCS11YUtYAiinRcdqQwL

---
_Generated by [Claude
Code](https://claude.ai/code/session_014VGCS11YUtYAiinRcdqQwL)_

Co-authored-by: Claude <noreply@anthropic.com>
akarma-synetal pushed a commit to akarma-synetal/framework that referenced this pull request Oct 7, 2026
…ui 0858267e, 8001068b, 3ae91930 and d0fba91aa) (objectstack-ai#21380)

Clause-②: no

Moves the bundled Console's objectui pin from `31971ff1e28f` (the pin
17.6.0 shipped) to current objectui `main`,
`89cad75d55702cc4f267bead5bf267de575d5842`, so the Console carries the
four fixes 17.6.0's release verification found missing (objectstack-ai#21330,
objectstack-ai/hotcrm#1982, and the "Known console issues" list in
`content/docs/releases/v17/17-6.mdx`).

## Range

`31971ff1e28f..89cad75d5570`: 64 non-merge commits, 74 releasing
changesets (16 declared breaking), 14 release-nothing, 6 commits without
a changeset. `git merge-base --is-ancestor <c> origin/main` exits 0 in
an objectui clone for the old pin and for each fix commit below;
`89cad75d5570` is `origin/main`.

Breaking entries: `990a2d616` (objectui retires its bare `tree` / `view`
node-type keys and the bare field-widget fallbacks), `063832222`
(`@object-ui/plugin-designer` TypeScript face), `f9c8c4e45` (two
`@object-ui/core` exports), `063119f2b` (an unevaluable gate is a
fault), `138ad4554` / `6aa029b63` (authored `flex` / `object-grid` take
the `properties` bag), `a1a44d621` (`page` refuses `maxWidth` /
`padding`), `e100589f3` (app `mobileNavMode` refused), `1a88ce22f`
(dashboard widget `chartConfig.*` structure keys).

## The four fixes this bump carries

| defect at `31971ff1e28f` | objectui fix |
|---|---|
| Studio's dataset designer saves a count measure with `field: ''`,
refused `422 measures.0.field` | `0858267e` (objectui#11402) |
| The datasource editor saves an External / Validate-only datasource
without the `external` block, refused `400` since objectstack-ai#21133 | `8001068b`
(objectui#11368) |
| Both page editors send the served `requires` back, so republishing an
html page that gained a plugin component is refused `422
page-requires-disagrees-with-source` | `3ae91930` (objectui#11357) |
| zh-CN reverts to English on a full page load (objectui#11326; objectstack-ai#21330
R4) | `d0fba91aa` |

## What changed here, and why

- `.objectui-sha` and `.changeset/console-89cad75d5570.md`, written by
`scripts/bump-objectui.sh --no-commit` (auto level `minor`). The
script's `adr-0087: TODO` placeholder is answered `not-required
(no-migration-prescription)`, in the wording the previous two bumps
used, naming all 16 upstream breaking entries: each is objectui's own
surface, or (`chartConfig.*`) mirrors keys `ui/dashboard.zod.ts` already
retired and tombstoned.
- `packages/sdui-parser/objectui-lockstep.json`, re-recorded with `pnpm
gen:sdui-lockstep`: 214 grammar lines, 25 codes, containment predicate
`76c18fb95d1f`, all unchanged; no port owed.
- `sdui.manifest.json` + `scripts/sdui-manifest.record.json`, from `node
scripts/gen-sdui-manifest-node.mjs` over the tree `pnpm objectui:build`
built at the pin: 107 components, none added or removed;
`object-kanban`, `object-calendar`, `object-gantt`, `object-timeline`,
`object-map` and `object-tree` changed their published inputs
(objectui#11168 slices 3–5, objectui#11293).
- The 49 asserting pin citations in `packages/spec/src`
(`check:objectui-pin-citations` turns red on any pin move), re-measured
at the new pin: anchors mapped through each cited file's diff and
re-read, block hashes and corpus counts re-taken with a method that
first reproduced every `31971ff1e` number. This regenerates
`packages/spec/src/migrations/registry.ts` and
`content/docs/references/ui/view.mdx`, and adds
`.changeset/objectui-pin-citations-89cad75d5570.md` (`@objectstack/spec`
patch, since the `FormField.span` describe and six migration
descriptions name the pin). Records whose claims moved, not only their
numbers: `object-map`'s declared-block `style` precedence (`mapStyle`
now first, objectui#11168 slice 3; the `getMapConfig` return quote is
rewritten); `object-tree`'s `navigation` read and `ObjectTreeSchema`
mirror now carry the row's keys uncast, and objectui's record-source
table drops the retired bare `tree` / `view:tree` keys (objectui#10859
batch 8); two `object-timeline` anchors that were already one line off
at `31971ff1e` are corrected. No key, default, enum member or export
moves.
- No example, test or gate needed adapting for the breaking entries: the
showcase's html pages compile flat JSX attributes, which the renderer
still hoists, and its `type: 'tree'` view and field are spec-level
types, not the retired bare node keys. The browser run below covers
both.

## Browser verification (`examples/app-showcase`, this branch)

`pnpm dev -- --fresh --ui --no-watch -p 41733` (own ephemeral DB, seeded
admin), `check:console-sha` = `objectui@89cad75d5570`, driven in
headless Chromium (`/opt/pw-browsers`) with every request captured. A
writable package `com.acme.pinprobe` with one object `pinprobe_item` was
created through `POST /api/v1/packages` and the metadata API for the
authoring checks.

| defect | drive | result at `89cad75d5570` |
|---|---|---|
| dataset `field: ''` | metadata editor on dataset `pin_ds` → Add
measure → name `row_count`, Aggregate `count`, Field left blank → ⌘S |
`PUT /meta/dataset/pin_ds?mode=draft` carries
`{"name":"row_count","aggregate":"count"}` (no `field` key) → **200**;
publish → **200**; the served measure has no `field` |
| datasource `external` block | Setup → Datasources → New datasource,
SQLite `:memory:`, Schema mode External, then Validate only, no
credential | `POST /api/v1/datasources` carries `"external":{}` →
**201** for both `external` and `validate-only` |
| page `requires` echo | html page published with `<box>` only (served
`requires: ["ui"]`); metadata editor Source → add `<object-kanban
objectName="pinprobe_item" groupBy="status" />` → ⌘S → publish | save
body carries no `requires` → **200**; publish → **200**; the server
stamps `requires: ["ui","plugin-kanban"]` |
| zh-CN on full load |
`/_console/apps/com.objectstack.account/component/approvals/inbox`,
`localStorage['objectui-locale']='zh-CN'`, full reload | h1 **审批中心**,
tabs **待我审批 / 我发起的 / 全部**, `<html lang="zh-CN">`, `i18n-locale-zh-*.js`
fetched (before the switch: "Approvals Inbox") |

Smoke: sign-in lands on the `/_console/home` launcher; the showcase JSX
home page (Capability Map, `<flex>` / `<box>`) renders; the
`showcase_task` list grid; a task record page; the
`showcase_ops_dashboard` dashboard with KPIs and charts; the Studio
landing and the writable package's object surface. 0 page errors.
Non-2xx responses were only `401 /auth/get-session` before sign-in, `404
/usage/storage`, `501 /ai/usage` (no AI provider) and `404 ?state=draft`
no-draft probes. Only the PIDs this run started were stopped.

## Gates and tests run locally

`check-adr-0087-registration --base origin/main`, `check:console-sha`,
`check:console-injection`, `check:sdui-lockstep`, `check-sdui-manifest`,
`check:objectui-pin-citations` (49 matching; `--verify-anchors`: 7
anchor content assertions verified at `89cad75d5`),
`check:migration-registry`, `check:objectui-bump`, `@objectstack/spec
check:generated` (after `gen:docs`) — all exit 0. `pnpm build` exit 0.
The console build passed its single-zod canary and spec-injection check.
`pnpm --filter @objectstack/spec test`: 598 files, 17512 passed, 1 todo.
`pnpm --filter @objectstack/sdui-parser test`: 218 passed. `pnpm
--filter @objectstack/spec typecheck`: exit 0.

Environment, not a product change: objectui's `jsdom` needs Node `>=
22.22.2`; the container has 22.22.0, so a Node 22.23.3 was prepended to
`PATH` for the console build and the dev boot.

---
_Generated by [Claude
Code](https://claude.ai/code/session_01CuUktjSyZWTP2mU4ywPGA6)_

---------

Co-authored-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backend Server-side behaviour — hooks, flows, actions configuration Build and app configuration files dependencies Dependency bumps and lockfile changes documentation Improvements or additions to documentation metadata Declarative metadata — schema, security posture, UI surfaces

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants