Skip to content

docs(skills): name the complete public-form opt-in the anonymous form endpoints read - #21650

Merged
os-zhuang merged 1 commit into
mainfrom
claude/issue-21567-api-skill-public-form-optin
Oct 4, 2026
Merged

os-zhuang merged 1 commit into
mainfrom
claude/issue-21567-api-skill-public-form-optin

Conversation

@objectstack-fleet

Copy link
Copy Markdown
Contributor

Fixes #21567
Clause-②: no

What

The published objectstack-api skill's public-form section named two of the three sharing keys the anonymous form endpoints read, and the objectstack-ui skill's UI-assembly row repeated the omission. An AI following either authors a form that both GET /api/v1/forms/:slug and POST /api/v1/forms/:slug/submit answer 404 FORM_NOT_FOUND. Both now state the complete opt-in as the merged rule reads it, plus the walled-posture condition and its remedy.

Skill text only (skills/**, Tier H). Nothing under packages/** is touched; the shipped migration prose in packages/spec/src/migrations/** stays as written (triage ruling 5967394091, "Not here").

The rule the text now describes (read on origin/main 15fe567)

  • packages/spec/src/ui/sharing.zod.ts:95 — enabled: z.boolean().default(false).describe('Enable public sharing'); :102 — allowAnonymous: z.boolean().optional().default(false).
  • packages/metadata-core/src/anonymous-form-intake.ts:66-68 — the three checks (s.enabled !== true, s.allowAnonymous !== true, publicLink a non-empty string); :57-59 — publicFormSlug folds /forms/x, forms/x and x into one slug.
  • packages/rest/src/rest-server.ts:10807 and :10977 — both doors answer 404 FORM_NOT_FOUND whenever resolveFormBySlug returns null, which it also does for a form the posture withholds (:10781-10789).
  • packages/metadata-core/src/anonymous-form-intake.ts:212 — a wall is in force only on a posture postureEnforcesWall admits (group / isolated); :223-225 — the remedy text: declare tenancy: { enabled: false } on an object whose rows belong to no organization.
  • packages/metadata-protocol/src/runtime-authoring-gate.ts:404 — PUBLIC_FORM_INTAKE_UNAVAILABLE = 'public-form-intake-unavailable', a warning the authoring gate raises for a view write (save and publish).

Every skills/** site that describes the opt-in

Sweep at 15fe567: git grep -n -i over skills/ for allowAnonymous, publicLink, anonymous form, public form, forms/:slug, Web-to-Lead, web-to-case, guest_portal, walled.

Site (line numbers at 15fe567) Verdict
skills/objectstack-api/SKILL.md:77-78 — "Any FormView declared with sharing.allowAnonymous: true and a publicLink slug is auto-mounted at:" changed — names all three keys, the enabled default, and the 404 FORM_NOT_FOUND answer when one is missing
skills/objectstack-api/SKILL.md:94 — "with allowAnonymous / publicLink" changed — now enabled / allowAnonymous / publicLink
skills/objectstack-api/SKILL.md:85-94 — the paragraph after the route block changed — one sentence names the walled-posture condition, the public-form-intake-unavailable warning on save and publish, and the tenancy: { enabled: false } remedy
skills/objectstack-ui/SKILL.md:208 — the UI-assembly table's public-form row changed — the row now shows sharing: { enabled: true, allowAnonymous: true, publicLink: 'slug' }
skills/objectstack-data/SKILL.md:188 — "public forms" in the list of surfaces a field's conditional rule applies to already correct — names the surface, not the opt-in
skills/objectstack-data/references/_index.md:57, skills/objectstack-ui/references/_index.md:48 already correct — file pointers to sharing.zod.ts, no opt-in prose

No other hit; guest_portal and Web-to-Lead occur only inside the edited section.

Readings

File Lines before → after Tokens before → after (ceiling)
skills/objectstack-api/SKILL.md 428 → 434 (+6, the +6 net-line budget) 4634 → 4758 (6319; headroom 1561)
skills/objectstack-ui/SKILL.md 310 → 310 3854 → 3854 (3856; headroom 2) — bytes 15415 → 15415; the edited row is 179 bytes before and after
Bundle: sum of every skills/*/SKILL.md 4397 → 4403 —

Tokens are the ratchet's own convention, ceil(bytes / 4); the gate's lines at 4adec02: "skills/objectstack-api/SKILL.md is 4758 tokens (ceiling 6319; headroom 1561)" and "skills/objectstack-ui/SKILL.md is 3854 tokens (ceiling 3856; headroom 2)". The objectstack-ui row paid for its three keys inside the same line: the label "Public / anonymous form" is now "Public form" (the cell still carries allowAnonymous), and "/ Web-to-Case" and "Auto-exposed" are dropped (the API skill's section keeps "Web-to-Lead / Web-to-Case"). No other line of that file moved; the sibling card #21537 holds the subforms example at :72-85. origin/main was still 15fe567 when this PR was opened, so no merge was owed.

Tests

All 24 gate families that node scripts/pm/dispatch-gates.mjs --commands derives for this diff were run locally at 4adec025, each exit captured before any pipe. --ran reconciliation: "24 derived famil(ies) accounted for — 24 run, 0 NOT-MEASURED (a DERIVED zero — all 24 recorded an exit code and none of them is 3)". Verdict lines:

  • node scripts/check-skills-token-ratchet.mjs exit 0 — "✓ check-skills-token-ratchet: 54 authored bundle file(s) within their ceilings; 10 generator-owned file(s) measured, not ratcheted."; --self-test exit 0 — "65 cases pass".
  • node scripts/check-doc-route-spelling.mjs --advisory exit 0 — "✓ route-spelling guard (advisory): population clean — every shape-matched literal spells its ledger row."; --self-test exit 0.
  • pnpm check:skill-identifier-liveness exit 0 — "Leg 1: 457 citation(s) over 53 published file(s) checked against 118365 implementation word tokens (0 ledgered exemption(s)); Leg 2: 8 registered exhaustive section(s), 0 ledgered gap(s)."
  • pnpm --filter @objectstack/spec run check:skill-docs exit 0 — "✅ Skill docs in sync" (after pnpm --filter @objectstack/spec build under the verify lock, VERDICT command-exit 0).
  • pnpm --filter @objectstack/lint run check:doc-formula-expressions — first run exit 3, PREREQUISITE NOT MET (@objectstack/formula and @objectstack/lint not built; "Nothing was measured"); after turbo run build --filter=@objectstack/formula --filter=@objectstack/lint under the lock, exit 0.
  • pnpm check:corpus-claim-drift, check:doc-authoring, check:role-word, check:skill-compatibility, check:skill-frame-sync, check:nul-bytes, check:agent-test-spelling, check:cross-package-test-inputs, check:driver-memory-census, check:gitlink-declared, check:pm-governed-merges, check:refd-timer-probe, check:watch-hint-literal, node scripts/check-ci-filter-parity.mjs, node scripts/check-closing-keyword-parity.mjs (and --self-test), node scripts/check-comment-mask-corpus.mjs — all exit 0.
  • Control-character self-scan over both files (the grep -naP spelling from the agent rules): clean.

Not run locally, CI owns them: the repo-wide pnpm lint, the type-check lanes and the package test suites — no package source changed.

维护者速读(草稿)

改了什么: 两份对外发布的技能页(objectstack-api、objectstack-ui)里描述「匿名公开表单」开关的句子,原来只写了 allowAnonymous: true 和 publicLink 两个键。现在补齐第三个键 enabled: true(schema 默认是 false),写明三者缺一则两个匿名端点都答 404 FORM_NOT_FOUND,并加一句:在 group / isolated 这类带租户墙的部署姿态下,目标对象若按组织列隔离,表单同样不对外提供,保存与发布时会收到 public-form-intake-unavailable 警告,补救是对不归属任何组织的对象声明 tenancy: { enabled: false }。

为什么改: 运行时规则已在 PR #21566 落地到 main:三个键齐全才服务。技能文本是 AI 写元数据的直接依据,按旧文本写出来的表单会被两个端点同时拒绝,而作者不知道为什么。本 PR 让文本与已合并的规则、与 SharingConfigSchema 的默认值完全一致。

风险与代价(含回滚): 纯文本改动,不碰 packages/**,无 changeset(skip-changeset)。objectstack-ui/SKILL.md 的 token 棘轮只剩 2 的余量,所以那一行用同一行内的删字付账(行标签「Public / anonymous form」改为「Public form」,去掉「/ Web-to-Case」与「Auto-exposed」);objectstack-api/SKILL.md 净增 6 行,在 PM 给的 +6 预算内。回滚:revert 本 PR 即可,没有派生产物。

席位意见:

你要做的: 这是 Tier H 受管面(skills/**),需要你的 APPROVED review;批准后由席位落地。请顺带看一眼 objectstack-ui 那一行的措辞取舍是否接受(标签缩短、去掉 Web-to-Case)。

Acceptance notes

  • Noted, not filed (code comments, not authoring guidance; carrier: none): examples/app-showcase/src/ui/views/inquiry.view.ts:10 and examples/app-showcase/src/data/objects/inquiry.object.ts:10, and the header comments of packages/qa/dogfood/test/showcase-public-form.dogfood.test.ts:5 and showcase-public-form-withdrawal.dogfood.test.ts:7, narrate the opt-in with the two-key wording; the example view itself declares all three keys (inquiry.view.ts:70-73), as does examples/app-crm/src/views/lead.view.ts:124-126.
  • CHANGELOG.md:607 carries the pre-rule wording — release-owned history, never edited in a code PR.
  • content/docs/ui/forms.mdx:23 and :234 already name sharing.enabled: true + sharing.allowAnonymous: true + publicLink; nothing owed there.
  • The slug-normalisation fact (/forms/x, forms/x and x are one slug) is not in the skill text — it did not fit the +6 line budget; both example apps spell publicLink: '/forms/contact-us', which the UI row's publicLink: 'slug' placeholder admits.
  • The commit's author/committer name is objectstack-fleet[bot] (set with -c user.name on this one commit; the container default is Claude); the trailer pair is the model-free form the pre-push hook accepted.

Generated by Claude Code

… endpoints read

The objectstack-api public-form section and the objectstack-ui assembly row named
two of the three `sharing` keys the anonymous form endpoints require. Both now
name `enabled: true` (schema default `false`), `allowAnonymous: true` and a
`publicLink` slug, the `404 FORM_NOT_FOUND` answer when any one is missing, and
the walled-posture condition with its `tenancy: { enabled: false }` remedy.

Co-authored-by: Claude <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CB6W87z22K2yjUCDyVrJRk
@github-actions github-actions Bot added size/s documentation Improvements or additions to documentation labels Oct 4, 2026
@objectstack-fleet objectstack-fleet Bot added the skip-changeset PR has no user-facing published change; bypasses the changeset gate label Oct 4, 2026
@objectstack-fleet

Copy link
Copy Markdown
Contributor Author

Contract review

Served-tier: CONTRACT_REVIEW_TIER
Head-sha: 4adec0257ce8917a63f03615b73a46be59329676
Local-runs: none

Read-only shape: the diff against the merge base 15fe567, card #21567 with every comment, and this head's check-runs; nothing built or run locally. Reviewed by the dispatch seat in seat (served tier equals the constant's value, read from get_session). Review face: skills/**, governed rule text (Tier H). Readings taken at 2026-10-04T00:14Z.

① Derived judgments

  • Accept set: unchanged. The diff is prose in two published skill files (skills/objectstack-api/SKILL.md +10/−4, skills/objectstack-ui/SKILL.md +1/−1); no schema, export, error code, route or runtime behaviour moves. Clause-②: no holds, and the direction of the text change is a narrowing of what an author is told works (two keys → three keys plus a posture condition), never a widening.
  • Statements the diff adds, each checked against origin/main 15fe567: sharing.enabled defaults to false (packages/spec/src/ui/sharing.zod.ts:95); the doors serve a form only when enabled, allowAnonymous and a non-empty publicLink all hold (packages/metadata-core/src/anonymous-form-intake.ts:66-68); both doors answer 404 FORM_NOT_FOUND (packages/rest/src/rest-server.ts:10807, :10977), and a form withheld on a walled posture is resolved to null before them (:10778-10789); the walled condition and its remedy sentence (anonymous-form-intake.ts:212, :223-225); the warning name raised for view writes (packages/metadata-protocol/src/runtime-authoring-gate.ts:404, :449, :1168). Correct, every one.
  • Scope: the claim's two files only; nothing under packages/**; the shipped migration prose stays as triage ruled.

② Semver level

  • No released package publishes from this diff (skills/** ships by npx skills add, outside every package files[]). No changeset owed; skip-changeset is the correct declaration. No ADR-0087 disposition applies.

③ Boundary flags

Implemented-by: claude/issue-21567-api-skill-public-form-optin
Reviewed-by: session_01CB6W87z22K2yjUCDyVrJRk

VERDICT: PASS

@objectstack-fleet

Copy link
Copy Markdown
Contributor Author

维护者速读(终稿)— PR #21650(#21567)· skills seat 1 · 2026-10-04T00:27Z

改了什么: 两份对外发布的技能页里描述「匿名公开表单」开关的句子。objectstack-api 的公开表单一节现在写全三个键:enabled: true(schema 默认 false)、allowAnonymous: true、publicLink slug,缺一则两个匿名端点都答 404 FORM_NOT_FOUND;另加一句:带租户墙的部署姿态(group / isolated)下,按组织列隔离的对象上的表单同样不对外提供,保存与发布会收到 public-form-intake-unavailable 警告,补救是对不归属任何组织的对象声明 tenancy: { enabled: false }。objectstack-ui 的 UI 装配表那一行同步写全三个键,并在同一行内删字付账(该文件 token 棘轮余量只有 2)。

为什么改: 运行时规则已在 PR #21566 落到 main(三个键齐全才服务);技能是 AI 写元数据的直接依据,按旧文本写出的表单会被两个端点同时拒绝而作者不知道为什么。本 PR 让文本与已合并的规则、与 SharingConfigSchema 的默认值一致,并同步 #21476 落地的 walled 条件。

风险与代价(含回滚): 纯技能文本,不碰 packages/**,无 changeset(skip-changeset);objectstack-api/SKILL.md +6 行(派发预算内),objectstack-ui/SKILL.md 行数与 token 均不变。席内契约复核 PASS(5974907048),必查门禁 Lint & Repo Gates 与 TypeScript Type Check 已绿。回滚 = revert 本 PR 的单个 commit。

席位意见: 建议批准。每一句都对照 sharing.zod.ts:95、anonymous-form-intake.ts:66-68 / :212 / :223-225、rest-server.ts:10778-10789 / :10807 / :10977、runtime-authoring-gate.ts:404 核过。UI 行把标签「Public / anonymous form」缩为「Public form」、去掉「/ Web-to-Case」与「Auto-exposed」,是为了在 2 个 token 的余量里付账;语义不丢(单元格仍写 allowAnonymous,API 页保留 Web-to-Lead / Web-to-Case)。与 PR #21651(#21537)共用 skills/objectstack-ui/SKILL.md 但区域不相交,先批哪个都可以,席位串行落地。

你要做的(一个动作): 在 PR #21650 上给一次 APPROVED review;批准后由席位清标、ready、挂 auto-merge 入队。

@os-zhuang
os-zhuang marked this pull request as ready for review October 4, 2026 01:08
@os-zhuang
os-zhuang added this pull request to the merge queue Oct 4, 2026
Merged via the queue into main with commit 1a23054 Oct 4, 2026
44 checks passed
@os-zhuang
os-zhuang deleted the claude/issue-21567-api-skill-public-form-optin branch October 4, 2026 01:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation size/s skip-changeset PR has no user-facing published change; bypasses the changeset gate

Projects

None yet

3 participants