diff --git a/docs/adr/0061-record-search-architecture.md b/docs/adr/0061-record-search-architecture.md index 4030cf5f955..dd5d4275d6d 100644 --- a/docs/adr/0061-record-search-architecture.md +++ b/docs/adr/0061-record-search-architecture.md @@ -53,6 +53,8 @@ The default contract is `$search: string` (plus existing `$filter`/scope). **Fie ### D5 — Security: search is a thin layer over the gated `find()` Search runs through the **same query pipeline as `find()`** — RLS, field-level security, and row filters apply automatically; **no separate unguarded search path**. Results respect the **ADR-0045 materialization/visibility gate** (draft vs published). The `$searchFields` override is subset-validated (D1). **Secret / encrypted / PII fields are never searchable** (excluded from default, rejected from override). Public/anonymous search keeps the existing `publicPicker` model (projection + `maxResults` ≤ 50, no enumeration). LIKE wildcards are escaped (driver-sql already does). +> **Note (2026-10-01) — anonymous search retired.** The `publicPicker` model the sentence above keeps is retired by the maintainer's ruling E on [#21079](https://github.com/objectstack-ai/objectstack/issues/21079) ([comment 5933054144](https://github.com/objectstack-ai/objectstack/issues/21079#issuecomment-5933054144), 2026-10-01), which reverses the [#7467](https://github.com/objectstack-ai/objectstack/issues/7467) model (declare `publicPicker`). Anonymous public forms no longer take lookup, `master_detail` or `user` fields: the public-form resolve route leaves them off the anonymous rendering unconditionally, the anonymous record-search route `GET /forms/:slug/lookup/:field` is deleted, and `publicPicker` is a `retiredKey()` tombstone under ADR-0087 D2 (immediate retirement). So there is no public/anonymous record search; the rest of D5 stands. The retirement is [#21180](https://github.com/objectstack-ai/objectstack/issues/21180). + ### D6 — Global search: fan-out now, unified `searchAll` is Tier 2 Global search this phase = **client fan-out over the per-object Tier-1 resolver** (CommandPalette already fans out; it only needs per-object search to actually filter) — zero new server surface. The unified server `searchAll` with cross-object relevance is **Tier 2** (it needs a unified index to rank well). **Knowledge/vector stays a separate subsystem**; "blended" record+knowledge search is future and out of scope, but API-compatible.