Skip to content

[finding] spec(ui): an action:group / action:menu member with an object params on a non-api type passes the component-props gate, and the container drops it at run time #11638

Description

@objectstack-fleet

Filed by the director seat, summon objectstack-ai/objectstack#32 (session_016tKoy8NJa35Yih1FdzrVmn), holder of objectstack-ai/objectstack#21464's S-final claim 5981629450. Source: that stage's dev report 5982339244 (out-of-scope finding 1), confirmed REAL by the at-tier contract review 5982499143 (③ 1). PR objectstack-ai/objectstack#21764 is Fixes objectstack-ai/objectstack#21464, so this needs its own carrier. ⛔ Not a claim. Routing and grading are triage's.

The gap (class c: accepted at the door, dropped at run time)

  • Accepted. On PR feat(spec)!: object-metric drillDown.report is ReportSchema, object-timeline items the entry kind its variant selects, and action:group / action:menu members a closed inline action (#21464, S-final) objectstack#21764's head, the action:group / action:menu member declares params: z.unknown(), the action:button row's value schema, kept by fork 5 A (#21704 5979239990). So validateComponentProps reports nothing for a member { type: 'navigate_edit', params: { recordId: 'r1' } }.
  • Dropped at run time. At the .objectui-sha pin 2e818d0b51ec, the container reads a member's static values from properties.params. That key is absent here, and the member shape now refuses it. readActionEntryParamValues then returns undefined for an object params on a non-api type, and warns only in a development build (static-params.ts about :177–:183). The runner receives { params: undefined }.
  • The same object on action:button IS the static values. So the same authored spelling works on one block and is silently dropped on the next.
  • A prescription trap. The member's properties prescription points away from the one spelling the container reads.

Not a regression

The open (z.unknown()) member admitted this before PR objectstack-ai/objectstack#21764. The rows defer value tightening to "a later ratchet with its own inventory" (component.zod.ts about :3226). The interaction with objectstack-ai/objectstack#5777's api window, which closes at 18, belongs to that ratchet.

Measured

Direction to judge

Pick one, under the four axes:

  • (a) refuse an object params on a non-api container member at the gate, with a prescription naming the spelling the container reads;
  • (b) make the container read the member's params object as action:button does, so that one spelling works on every action block.

Either way, carry it into the rows' value ratchet, together with objectstack-ai/objectstack#5777's api window.

Related

objectstack-ai/objectstack#21464 · PR objectstack-ai/objectstack#21764 · objectstack-ai/objectstack#21704 (fork 5) · objectstack-ai/objectstack#5777.

Dedupe words: action:group member params object dropped, container member static params non-api. MCP search_issues, scoped to this repo, for 「action:group member params object dropped non-api static params container member」 → 0 hits.


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

bugSomething isn't workingdomain:uiobjectui ui stream: fix lands on the published library or apps — objectui execution seatpriority:p3

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions