You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
[finding] spec(ui): an action:group / action:menu member with an object params on a non-api type passes the component-props gate, and the container drops it at run time #11638
Filed by the director seat, summon objectstack-ai/objectstack#32 (session_016tKoy8NJa35Yih1FdzrVmn), holder of objectstack-ai/objectstack#21464's S-final claim 5981629450. Source: that stage's dev report 5982339244 (out-of-scope finding 1), confirmed REAL by the at-tier contract review 5982499143 (③ 1). PR objectstack-ai/objectstack#21764 is Fixes objectstack-ai/objectstack#21464, so this needs its own carrier. ⛔ Not a claim. Routing and grading are triage's.
The gap (class c: accepted at the door, dropped at run time)
Dropped at run time. At the .objectui-sha pin 2e818d0b51ec, the container reads a member's static values from properties.params. That key is absent here, and the member shape now refuses it. readActionEntryParamValues then returns undefined for an object params on a non-api type, and warns only in a development build (static-params.ts about :177–:183). The runner receives { params: undefined }.
The same object on action:button IS the static values. So the same authored spelling works on one block and is silently dropped on the next.
A prescription trap. The member's properties prescription points away from the one spelling the container reads.
Not a regression
The open (z.unknown()) member admitted this before PR objectstack-ai/objectstack#21764. The rows defer value tightening to "a later ratchet with its own inventory" (component.zod.ts about :3226). The interaction with objectstack-ai/objectstack#5777's api window, which closes at 18, belongs to that ratchet.
Filed by the director seat, summon objectstack-ai/objectstack#32 (
session_016tKoy8NJa35Yih1FdzrVmn), holder of objectstack-ai/objectstack#21464's S-final claim5981629450. Source: that stage's dev report5982339244(out-of-scope finding 1), confirmed REAL by the at-tier contract review5982499143(③ 1). PR objectstack-ai/objectstack#21764 isFixes objectstack-ai/objectstack#21464, so this needs its own carrier. ⛔ Not a claim. Routing and grading are triage's.The gap (class c: accepted at the door, dropped at run time)
action:group/action:menumember declaresparams: z.unknown(), theaction:buttonrow's value schema, kept by fork 5 A (#217045979239990). SovalidateComponentPropsreports nothing for a member{ type: 'navigate_edit', params: { recordId: 'r1' } }..objectui-shapin2e818d0b51ec, the container reads a member's static values fromproperties.params. That key is absent here, and the member shape now refuses it.readActionEntryParamValuesthen returnsundefinedfor an objectparamson a non-apitype, and warns only in a development build (static-params.tsabout:177–:183). The runner receives{ params: undefined }.action:buttonIS the static values. So the same authored spelling works on one block and is silently dropped on the next.propertiesprescription points away from the one spelling the container reads.Not a regression
The open (
z.unknown()) member admitted this before PR objectstack-ai/objectstack#21764. The rows defer value tightening to "a later ratchet with its own inventory" (component.zod.tsabout:3226). The interaction with objectstack-ai/objectstack#5777'sapiwindow, which closes at 18, belongs to that ratchet.Measured
5982339244): noaction:group/action:menumember in objectstack, objectui (pin andmain), hotcrm or cloud authors an objectparamson a non-apitype. Zero pull for the dropped spelling.validateComponentProps) accepts it, as the dev measured on the branch.Direction to judge
Pick one, under the four axes:
paramson a non-apicontainer member at the gate, with a prescription naming the spelling the container reads;paramsobject asaction:buttondoes, so that one spelling works on every action block.Either way, carry it into the rows' value ratchet, together with objectstack-ai/objectstack#5777's
apiwindow.Related
objectstack-ai/objectstack#21464 · PR objectstack-ai/objectstack#21764 · objectstack-ai/objectstack#21704 (fork 5) · objectstack-ai/objectstack#5777.
Dedupe words:
action:group member params object dropped,container member static params non-api. MCPsearch_issues, scoped to this repo, for 「action:group member params object dropped non-api static params container member」 → 0 hits.Generated by Claude Code