Filed by the director seat, summon #32, session_016tKoy8NJa35Yih1FdzrVmn, as the second half of the maintainer's ruling E on #21079. The ruling is batch #261 item 1, maintainer 「同意E」; the record is the Ruling: comment on #21079. ⛔ Not a claim.
What was ruled
Anonymous public forms no longer take lookup, master_detail or user fields, so the anonymous record-search picker goes.
Readings that decided it (taken before the ruling, at the refs named)
- Zero producers, across all four repos.
git grep -n publicPicker origin/main, excluding packages/spec, tests and changelogs:
- objectstack
fbcc05f400: docs, the lint reader validate-preset-comparands.ts, the REST route and its ledger row only. No example declares one.
- hotcrm
fb408a7304: 0. cloud: 0.
- No first-party UI caller. objectui
main 6c3da53aee has no source that requests the picker route: git grep -n -E "lookup/|/lookup" over packages and apps (tests excluded) hits only comments and a /dev/lookup dev route. Control: the same tree hits the anonymous form's /forms/ routes (apps/console/src/components/FormPage.tsx:5).
- Pin safety. objectui at objectstack's pinned
.objectui-sha e420df310f imports neither publicPicker nor FormFieldPublicPicker*. Post-Task step 4 is satisfied: no sibling fix and no pin bump ride this removal.
Scope
Follow the spec-property-retirement skill (.claude/skills/). The ADR-0087 D2 route, immediate retirement, with no staged window.
- Spec. In
packages/spec/src/ui/view.zod.ts, FormFieldBaseSchema.publicPicker becomes a retiredKey() tombstone whose text carries the prescription below. FormFieldPublicPickerSchema and its two exported types are removed. The rest goes with them: the liveness-ledger row, the ADR-0087 registry entry, gen:schema/gen:docs/gen:api-surface, and the strictness and authorable-surface artifacts.
- REST.
- Delete the
GET /forms/:slug/lookup/:field handler in packages/rest/src/rest-server.ts, its literal guest_portal picker context, and its row in packages/rest/src/rest-route-ledger.ts.
- The public-form resolve route keeps stripping lookup /
master_detail / user fields from the anonymous rendering, now unconditionally. ⛔ No new gate (the maintainer's no-new-gates default).
LOOKUP_NOT_PUBLIC leaves packages/spec/src/api/error-code-ledger.zod.ts by that ledger's own retirement rule (ADR-0112).
- Lint and tests. Remove the
publicPicker reader in packages/lint/src/validate-preset-comparands.ts and its cases. Delete or re-pin the picker tests: packages/rest/src/public-form-lookup-*.test.ts and public-form-routes*.test.ts, the picker cases of rest-server-query-number-census.test.ts, packages/spec/src/ui/view-public-picker.test.ts, and packages/qa/dogfood/test/public-picker-queryable-key.dogfood.test.ts. Also the picker door case in packages/qa/dogfood/test/zero-set-masking.dogfood.test.ts; see Serial.
- Docs. Remove the picker section of
content/docs/ui/forms.mdx (its two tables included). The references regenerate.
- ADR-0061 (
docs/adr/0061-record-search-architecture.md:54 says anonymous search "keeps the existing publicPicker model"). Add a dated note under that entry naming the retirement and this ruling. ⛔ The original text is not rewritten. It is a separate docs-only Tier H PR for the maintainer's click, ⛔ not part of the code PR.
- Changeset. BREAKING,
Clause-②: yes (narrowing), with the ADR-0087 disposition marker. FROM → TO: delete the publicPicker block; an anonymous public form no longer offers record search. Use a select field with static options, or put the form behind sign-in.
Lane and parameters (ruled with E)
Dedupe
mcp__github__search_issues, repo-scoped, open and closed: 「retire publicPicker anonymous public form lookup picker」 → 4 hits. #21137 (open, superseded above) · #7467 (closed, the reversed ruling) · #7485 and #7486 (closed, sibling keys of the same block). None retires the key.
Dedupe words: publicPicker retirement · anonymous form lookup field · public lookup picker route · LOOKUP_NOT_PUBLIC
Generated by Claude Code
Filed by the director seat, summon #32,
session_016tKoy8NJa35Yih1FdzrVmn, as the second half of the maintainer's ruling E on #21079. The ruling is batch #261 item 1, maintainer 「同意E」; the record is theRuling:comment on #21079. ⛔ Not a claim.What was ruled
Anonymous public forms no longer take lookup,
master_detailoruserfields, so the anonymous record-search picker goes.publicPickeris enforced by the REST lookup route but declared nowhere inpackages/spec— no saved form can ever enable it #7467 ruling (option 1, "declarepublicPicker"). The maintainer reversed it in the security(plugin-security): a non-system caller who resolves no permission set is admitted to every object and read with no row scope; an empty set list grants by absence instead of answering the deny baseline #21079 decision thread.guest_portal. This card is what keeps the spec from declaring a door that no supported grant opens. So it is graded p1 alongside security(plugin-security): a non-system caller who resolves no permission set is admitted to every object and read with no row scope; an empty set list grants by absence instead of answering the deny baseline #21079, not after it.Readings that decided it (taken before the ruling, at the refs named)
git grep -n publicPicker origin/main, excludingpackages/spec, tests and changelogs:fbcc05f400: docs, the lint readervalidate-preset-comparands.ts, the REST route and its ledger row only. No example declares one.fb408a7304: 0. cloud: 0.main6c3da53aeehas no source that requests the picker route:git grep -n -E "lookup/|/lookup"overpackagesandapps(tests excluded) hits only comments and a/dev/lookupdev route. Control: the same tree hits the anonymous form's/forms/routes (apps/console/src/components/FormPage.tsx:5)..objectui-shae420df310fimports neitherpublicPickernorFormFieldPublicPicker*. Post-Task step 4 is satisfied: no sibling fix and no pin bump ride this removal.Scope
Follow the
spec-property-retirementskill (.claude/skills/). The ADR-0087 D2 route, immediate retirement, with no staged window.packages/spec/src/ui/view.zod.ts,FormFieldBaseSchema.publicPickerbecomes aretiredKey()tombstone whose text carries the prescription below.FormFieldPublicPickerSchemaand its two exported types are removed. The rest goes with them: the liveness-ledger row, the ADR-0087 registry entry,gen:schema/gen:docs/gen:api-surface, and the strictness and authorable-surface artifacts.GET /forms/:slug/lookup/:fieldhandler inpackages/rest/src/rest-server.ts, its literalguest_portalpicker context, and its row inpackages/rest/src/rest-route-ledger.ts.master_detail/userfields from the anonymous rendering, now unconditionally. ⛔ No new gate (the maintainer's no-new-gates default).LOOKUP_NOT_PUBLICleavespackages/spec/src/api/error-code-ledger.zod.tsby that ledger's own retirement rule (ADR-0112).publicPickerreader inpackages/lint/src/validate-preset-comparands.tsand its cases. Delete or re-pin the picker tests:packages/rest/src/public-form-lookup-*.test.tsandpublic-form-routes*.test.ts, the picker cases ofrest-server-query-number-census.test.ts,packages/spec/src/ui/view-public-picker.test.ts, andpackages/qa/dogfood/test/public-picker-queryable-key.dogfood.test.ts. Also the picker door case inpackages/qa/dogfood/test/zero-set-masking.dogfood.test.ts; see Serial.content/docs/ui/forms.mdx(its two tables included). The references regenerate.docs/adr/0061-record-search-architecture.md:54says anonymous search "keeps the existingpublicPickermodel"). Add a dated note under that entry naming the retirement and this ruling. ⛔ The original text is not rewritten. It is a separate docs-only Tier H PR for the maintainer's click, ⛔ not part of the code PR.Clause-②: yes (narrowing), with the ADR-0087 disposition marker. FROM → TO: delete thepublicPickerblock; an anonymous public form no longer offers record search. Use aselectfield with staticoptions, or put the form behind sign-in.Lane and parameters (ruled with E)
domain:spec, level M,mode:subagent. The contract review runs atCONTRACT_REVIEW_TIER.zero-set-masking.dogfood.test.tstoo. Whichever card claims second names the other underSerial constraints cleared. Either order is fine.pm:queue): its two defects are both on the retired key. It is closednot_plannedin the act that files this card.guestanchor; ADR-0090 D9 is declared and seeded but not enforced #21158, on hold until a first-party anonymous data door exists.Dedupe
mcp__github__search_issues, repo-scoped, open and closed: 「retire publicPicker anonymous public form lookup picker」 → 4 hits. #21137 (open, superseded above) · #7467 (closed, the reversed ruling) · #7485 and #7486 (closed, sibling keys of the same block). None retires the key.Dedupe words:
publicPicker retirement·anonymous form lookup field·public lookup picker route·LOOKUP_NOT_PUBLICGenerated by Claude Code