Skip to content

fix(console): the Public Forms page offers the anonymous URL the router serves (objectui#11769) - #11771

Merged
objectstack-fleet[bot] merged 1 commit into
mainfrom
claude/issue-11769-public-form-url-basename
Oct 7, 2026
Merged

objectstack-fleet[bot] merged 1 commit into
mainfrom
claude/issue-11769-public-form-url-basename

Conversation

@objectstack-fleet

Copy link
Copy Markdown
Contributor

Fixes #11769

Clause-②: no

What was wrong

The developer Public Forms page (apps/console/src/pages/developer/PublicFormsPage.tsx) built every anonymous form URL as ORIGIN/console/f/SLUG. That one value fed the table link, Copy URL, the iframe snippet and the React snippet, and the page also printed a literal /console/f/ beside both slug fields (the Publish dialog and the Edit dialog). No host serves the console at /console/. The framework CLI mounts it at /_console/ and injects a base href of /_console/. App.tsx turns that into the router basename (resolveBasename, BrowserRouter basename={BASENAME}), and the anonymous route is /f/:slug under that basename.

The fix

The page now asks the router where /f is served: useHref('/f'), which React Router prefixes with the basename. That one value, publicFormPath, builds the link, the copied URL, both snippets and both slug-field prefixes:

  • under a /_console mount, the page offers ORIGIN/_console/f/SLUG;
  • on a root-mounted console, it offers ORIGIN/f/SLUG.

App.tsx is unchanged and exports nothing new. The package entry gains no export, prop, type member or language-pack key. The changeset is a patch for @object-ui/console.

PM mechanism hypotheses, as measured:

  1. useHref gives the basename-prefixed path. Read in the installed react-router 7.18.2: useHref joins basename onto the resolved pathname whenever the basename is not /, and both BrowserRouter and MemoryRouter build hrefs with createPath. Confirmed by the pins below, which render under BrowserRouter.
  2. The two slug-field prefixes are the same defect. Confirmed: they now print publicFormPath, and the ablation below turns their pin red.
  3. Existing console tests mount a basename with BrowserRouter basename (authExitBasename.test.tsx, verificationCallback-10893.test.tsx) or MemoryRouter basename (FormPage.redirect.test.tsx). The new pins reuse the BrowserRouter form, which is the router App.tsx uses.

Measured before the change: the page's URL on a real mount

Framework-served console: measured. I ran @objectstack/cli 17.7.0 with its vendored @objectstack/console 17.7.0, using os serve, then os dev --fresh, on a scratch app that declares one public form with publicLink: '/forms/contact-us'.

Request Answer
GET /console/f/contact-us (what the page offered) 404 application/json, ENDPOINT_NOT_FOUND. Chromium shows the same JSON.
GET /_console/f/contact-us 200, console HTML carrying base href /_console/. In Chromium, an anonymous visitor sees the form (Name, Email, Message, Submit).
GET /f/contact-us 404 ENDPOINT_NOT_FOUND
GET / 302 to /_console/

The released bundle carries the defect. assets/PublicFormsPage-D3AT2EH9.js in @objectstack/console 17.7.0 builds the URL as ${origin}/console/f/${slug} (minified), and it also contains both /console/f/ prefixes.

Cloud-served console: NOT MEASURED. The container's egress proxy refuses cloud.objectos.ai:443 (connect_rejected, organization policy), and this session has no cloud checkout. The card's statement about cloud stays a reading, not a measurement.

In-browser check of the fixed page: NOT MEASURED. On the 17.7.0 framework runtime the Public Forms page lists no form at all (see Acceptance notes), so it shows no URL to check. The URL is pinned by the unit tests below instead.

Pins

PublicFormsPage.publicUrlBasename-11769.test.tsx renders the page inside BrowserRouter with a basename, in three mounts:

  • a /_console mount;
  • a root mount;
  • a /_console mount reached through the metadata-driven component route /apps/APP/component/developer/public-forms.

It pins, per mount:

  • the link href, its text and the copied URL are ORIGIN/_console/f/contact-us under /_console and ORIGIN/f/contact-us at root. The component route does not add its own depth to the URL.
  • the src of the iframe snippet and the src of the React snippet each hold exactly the copied URL, and each snippet holds only that one.
  • both slug-field prefixes print the same basename-prefixed route (/_console/f/ or /f/).
  • the page text contains no /console/f/.

Three existing page tests rendered the page with no router: developerMetadataEnvelope.contractEnvelope-6917, PublicFormsPage.redirect and PublicFormsPage.emptyPlaceholderAffordance-8504. useHref needs a router, which the app always provides, so these tests now render with { wrapper: MemoryRouter }. No assertion in them changed.

Ablation

This was run once and is not kept as a test. It used scripts/ablation-replace.mjs from the objectstack checkout, after the fix was committed. The mutation was proven on disk (anchor count 1 to 0, blob changed). The restore was proven by the blob matching HEAD c8a3e7d2c580 and an empty git diff HEAD.

  1. publicFormPath forced back to '/console/f', so every surface is hard-coded again: 9 of 12 failed and 3 passed. On all three mounts, the "offers" pin, the slug-field-prefix pin and the no-/console/f/ pin went red, with errors such as expected '/console/f/' to be '/_console/f/' and Unable to find an element with the text: http://localhost:3000/_console/f/contact-us. The snippet-agreement pin stayed green on all three mounts. That was expected: a consistent hard-code still agrees with itself.
  2. Only the iframe snippet pointed at ORIGIN/console/f/SLUG: 3 of 12 failed, which was the snippet-agreement pin on each mount, and 9 passed.

Verification on HEAD e90d688

Command Exit Verdict line
pnpm exec vitest run apps/console/src/pages/developer/ apps/console/src/__tests__/orphanedPageComponentRefs-10520.test.tsx 0 Test Files 11 passed (11), Tests 95 passed (95)
pnpm exec turbo run build --filter='@object-ui/console^...' --concurrency=2 (dependency closure, before type-check) 0 Tasks: 34 successful, 34 total
pnpm --filter @object-ui/console type-check (echoes type-check; --listFiles shows all 5 touched .tsx files in the program) 0 no error TS
pnpm exec eslint on the 5 touched files 0 0 errors, 12 warnings. All 12 are in PublicFormsPage.tsx and were there before: BASE 179f6fe 0e/12w, HEAD 0e/12w.
node scripts/check-changeset-presence.mjs 0 5 source file(s) of 1 released package(s) changed, and this change declares 1 changeset(s)
node scripts/check-changeset-no-major.mjs 0 No changeset declares a major bump.
pnpm check:control-bytes 0 check-control-bytes: OK
pnpm check:test-path-roots 0 check-test-path-roots: OK
pnpm check:changeset-claims 0 No pending changeset names a file this change touches.
pnpm check:pending-changeset-literals 0 No test source names a pending changeset.
pnpm check:new-line-citations 0 VERDICT new-cross-file-line-citations: 0 new citation(s)
pnpm check:vi-mock-specifiers / vi-mock-inherit / vi-mock-override-shape 0 / 0 / 0 OK each
pnpm check:phantom-deps 0 react-router-dom is already a declared dependency of @object-ui/console
pnpm check:shell-escape-residue / check:unreferenced-sources 0 / 0 OK

What the scoping covers:

  • Tests. The vitest run covers every file that imports PublicFormsPage: the 10 files under pages/developer/, plus the component-route test, which renders the registered developer:public-forms key through the route table. The rest of the console project is CI's.
  • Lint. eslint linted the 5 touched files (--format json reports 5 results). eslint.config.js turns on no type-aware linting (no projectService and no parserOptions.project), and no rule in eslint-rules/ reads other files. This diff therefore cannot change the verdict on any file it did not touch.
  • Not run locally. No locale pack changed, so the i18n gates did not apply. No package export changed, so readme-exports did not apply. check:eager-closure needs a console build and was left to CI. The import added here is react-router-dom, which App.tsx already loads eagerly, inside a page that is lazy-loaded.

Acceptance notes

  • Out of scope, reported to the seat and not filed here: on a 17.7.0 framework runtime the Public Forms page lists no public form at all. GET /api/v1/meta/view serves each view as a ViewItem with the keys name, object, viewKind, label and config. The form's sharing and sections are under config. The page reads it.spec ?? it and looks for sections and sharing on the item itself, so no item counts as a form. Measured in Chromium on that runtime: the table says "No public forms yet" for a declared public form, and "Publish form…" is disabled. The runtime refuses a view config with no viewKind with 422 and names the ViewItem shape. The page's tests use a { spec } fixture shape that this runtime does not serve. This masks the URL defect fixed here on that runtime, so the reach of this card's defect is today limited to a runtime that serves the spec shape. That is NOT MEASURED, and no such runtime was found.
  • objectui#11545 (the same page's listing rule for sharing.enabled) remains open and is not addressed here. objectstack#22079 (the server-side redirect from /forms/SLUG) is not addressed here either.
  • The files changed are the page, its three existing tests, one new test file and the changeset. All are within the claimed file surface ("the tests beside them").

Generated by Claude Code

…er serves

PublicFormsPage built every anonymous form URL as ORIGIN/console/f/SLUG and
printed /console/f/ beside both slug fields. No host mounts the console at
/console/: the framework CLI and cloud serve it at /_console/ and inject the
base href that App.tsx turns into the router basename. The anonymous route is
/f/:slug under that basename.

The page now asks the router (useHref('/f')) where the route is served. The
link, the copied URL, the iframe and React snippets and both slug-field
prefixes are built from that one value: /_console/f/SLUG under a /_console
mount, /f/SLUG on a root-mounted console.

The three existing page tests render it inside a MemoryRouter, as the app
does. New pins cover the /_console mount, the root mount and the
metadata-driven component route, and check that the snippets hold exactly the
copied URL.

Claude-Session: https://claude.ai/code/session_01CGZy1BGCjdN5cXqL9cnvB8
Co-authored-by: Claude <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

Metric Value Budget
Eager closure (gzip, 336 chunks) 3515.3 KB 3551.8 KB
Main entry chunk (gzip) 156.3 KB 350 KB
Entry file index-BGg5gkYr.js —
Status PASS —

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

Package Size Gzipped
app-shell (consoleActionDispatch.js) 0.20KB 0.19KB
app-shell (index.js) 17.82KB 6.58KB
app-shell (runtime-config.js) 22.59KB 7.89KB
app-shell (types.js) 0.01KB 0.04KB
app-shell (urlParams.js) 10.11KB 3.87KB
auth (ActiveOrganizationStorage.js) 27.95KB 10.04KB
auth (AuthContext.js) 0.31KB 0.24KB
auth (AuthGuard.js) 2.07KB 1.00KB
auth (AuthProvider.js) 40.22KB 10.61KB
auth (AuthShell.js) 3.49KB 1.40KB
auth (ForgotPasswordForm.js) 12.21KB 3.45KB
auth (LoginForm.js) 18.15KB 5.40KB
auth (PreviewBanner.js) 0.90KB 0.50KB
auth (RegisterForm.js) 6.72KB 2.24KB
auth (SocialSignInButtons.js) 9.70KB 3.93KB
auth (UserMenu.js) 3.39KB 1.21KB
auth (auth-gate-events.js) 1.29KB 0.66KB
auth (authStyles.js) 5.04KB 1.72KB
auth (createAuthClient.js) 40.70KB 10.94KB
auth (createAuthenticatedFetch.js) 8.54KB 3.46KB
auth (index.js) 3.63KB 1.64KB
auth (invitation-status.js) 1.22KB 0.70KB
auth (org-roles.js) 6.66KB 2.78KB
auth (phone-identifier.js) 1.11KB 0.66KB
auth (types.js) 0.59KB 0.35KB
auth (useAuth.js) 5.30KB 1.02KB
auth (useWorkspaceAdminStatus.js) 11.08KB 4.58KB
collaboration (CommentThread.js) 27.11KB 7.97KB
collaboration (LiveCursors.js) 3.17KB 1.27KB
collaboration (PresenceAvatars.js) 6.28KB 2.60KB
collaboration (PresenceProvider.js) 2.79KB 1.13KB
collaboration (index.js) 1.68KB 0.73KB
collaboration (useCollaborationTranslation.js) 6.50KB 2.52KB
collaboration (useCommentSearch.js) 1.98KB 0.88KB
collaboration (useConflictResolution.js) 7.75KB 1.86KB
collaboration (useMentionNotifications.js) 1.81KB 0.68KB
collaboration (usePresence.js) 6.33KB 1.84KB
collaboration (useRealtimeSubscription.js) 7.91KB 2.01KB
components (index.js) 578.94KB 139.21KB
core (index.js) 10.00KB 3.96KB
create-plugin (index.js) 27.94KB 9.51KB
data-objectstack (index.js) 235.41KB 65.46KB
fields (index.js) 266.88KB 67.46KB
i18n (LocalizationContext.js) 2.92KB 1.42KB
i18n (builtinAggregateLabels.js) 0.86KB 0.49KB
i18n (currency.js) 2.59KB 1.22KB
i18n (fallbackInterpolation.js) 6.25KB 2.77KB
i18n (i18n.js) 8.87KB 3.64KB
i18n (index.js) 5.52KB 2.39KB
i18n (pickLocalized.js) 9.86KB 3.95KB
i18n (provider.js) 39.35KB 12.88KB
i18n (translateFn.js) 0.20KB 0.18KB
i18n (useDisplayLocale.js) 3.52KB 1.76KB
i18n (useObjectLabel.js) 38.37KB 10.31KB
i18n (useSafeTranslation.js) 7.14KB 2.92KB
layout (index.js) 41.50KB 11.82KB
mobile (MobileProvider.js) 0.92KB 0.49KB
mobile (ResponsiveContainer.js) 0.94KB 0.38KB
mobile (breakpoints.js) 1.51KB 0.70KB
mobile (createOfflineDataSource.js) 5.61KB 1.75KB
mobile (index.js) 1.99KB 0.87KB
mobile (offlineQueue.js) 3.91KB 1.35KB
mobile (pwa.js) 0.97KB 0.49KB
mobile (serviceWorker.js) 1.48KB 0.62KB
mobile (serviceWorkerSource.js) 3.41KB 1.48KB
mobile (useBreakpoint.js) 1.54KB 0.65KB
mobile (useGesture.js) 6.96KB 1.98KB
mobile (useOfflineSync.js) 1.99KB 0.72KB
mobile (usePullToRefresh.js) 6.62KB 2.45KB
mobile (useResponsive.js) 0.72KB 0.42KB
mobile (useSpecGesture.js) 5.52KB 2.10KB
mobile (useTouchTarget.js) 1.01KB 0.54KB
permissions (MePermissionsProvider.js) 13.86KB 5.00KB
permissions (PermissionContext.js) 0.31KB 0.25KB
permissions (PermissionGuard.js) 0.89KB 0.45KB
permissions (PermissionProvider.js) 6.52KB 2.26KB
permissions (discardProofCache.js) 1.04KB 0.55KB
permissions (evaluator.js) 8.33KB 3.07KB
permissions (index.js) 0.93KB 0.41KB
permissions (store.js) 0.91KB 0.42KB
permissions (useFieldPermissions.js) 1.28KB 0.53KB
permissions (usePermissions.js) 4.83KB 2.27KB
plugin-ai (index.js) 16.04KB 3.92KB
plugin-calendar (index.js) 53.39KB 15.52KB
plugin-charts (index.js) 84.26KB 23.05KB
plugin-chatbot (index.js) 199.63KB 47.46KB
plugin-dashboard (index.js) 144.22KB 38.99KB
plugin-designer (index.js) 231.46KB 48.87KB
plugin-detail (index.js) 247.73KB 65.20KB
plugin-editor (index.js) 2.23KB 1.05KB
plugin-form (index.js) 176.62KB 45.75KB
plugin-gantt (index.js) 179.17KB 45.07KB
plugin-grid (index.js) 238.51KB 65.53KB
plugin-kanban (index.js) 52.17KB 16.37KB
plugin-list (index.js) 116.85KB 29.12KB
plugin-map (index.js) 25.60KB 8.62KB
plugin-markdown (index.js) 13.88KB 4.80KB
plugin-report (index.js) 44.12KB 12.29KB
plugin-timeline (index.js) 39.10KB 11.81KB
plugin-tree (index.js) 15.07KB 5.33KB
plugin-view (index.js) 90.64KB 22.85KB
providers (DataSourceProvider.js) 0.75KB 0.39KB
providers (MetadataProvider.js) 1.37KB 0.59KB
providers (ThemeProvider.js) 1.90KB 0.85KB
providers (UploadProvider.js) 11.81KB 3.58KB
providers (index.js) 0.45KB 0.23KB
providers (types.js) 0.01KB 0.04KB
react-runtime (index.js) 5.62KB 2.34KB
react (LazyPluginLoader.js) 4.47KB 1.63KB
react (SchemaRenderer.js) 120.63KB 39.56KB
react (data-invalidation.js) 5.05KB 2.08KB
react (index.js) 4.50KB 2.06KB
react (schema-input.js) 4.31KB 2.07KB
react (spec-input.js) 0.20KB 0.18KB
sdui-parser (body-dialect.js) 4.50KB 1.99KB
sdui-parser (codegen.js) 9.45KB 3.76KB
sdui-parser (dashboard-widget-options.js) 3.08KB 1.30KB
sdui-parser (index.js) 7.30KB 3.12KB
sdui-parser (input-type.js) 2.84KB 1.40KB
sdui-parser (parse.js) 25.28KB 7.80KB
sdui-parser (provenance.js) 3.84KB 1.90KB
sdui-parser (types.js) 0.28KB 0.23KB
sdui-parser (validate.js) 23.87KB 7.83KB
types (ai.js) 4.39KB 2.17KB
types (api-types.js) 0.20KB 0.18KB
types (app.js) 4.12KB 1.61KB
types (authoring-nodes.js) 0.20KB 0.19KB
types (base.js) 0.20KB 0.18KB
types (blocks.js) 0.20KB 0.18KB
types (cloud.js) 0.20KB 0.18KB
types (complex.js) 4.44KB 2.07KB
types (crud.js) 0.20KB 0.18KB
types (dashboard-filter-alias.js) 6.23KB 2.74KB
types (dashboard-widget-layout.js) 2.06KB 0.96KB
types (data-display.js) 3.75KB 1.85KB
types (data-protocol.js) 0.20KB 0.19KB
types (data.js) 0.20KB 0.18KB
types (designer.js) 1.85KB 0.85KB
types (disclosure.js) 0.20KB 0.18KB
types (error-code.js) 1.54KB 0.88KB
types (expression.js) 0.20KB 0.18KB
types (feedback.js) 0.20KB 0.18KB
types (field-types.js) 1.13KB 0.65KB
types (form.js) 0.20KB 0.18KB
types (http-inflight.js) 8.87KB 3.73KB
types (http-retry.js) 4.32KB 2.02KB
types (icon-key-migration.js) 4.26KB 1.63KB
types (index.js) 5.78KB 2.70KB
types (layout.js) 0.20KB 0.18KB
types (managed-by.js) 0.19KB 0.18KB
types (mobile.js) 5.00KB 2.39KB
types (navigation.js) 0.20KB 0.18KB
types (node-slots.js) 7.18KB 2.34KB
types (objectql.js) 0.20KB 0.18KB
types (overlay.js) 0.20KB 0.18KB
types (permissions.js) 2.52KB 1.31KB
types (plugin-scope.js) 0.20KB 0.18KB
types (record-components.js) 0.20KB 0.19KB
types (record-semantics.js) 1.28KB 0.67KB
types (registry.js) 0.20KB 0.18KB
types (reports.js) 0.20KB 0.18KB
types (select-option.js) 0.20KB 0.19KB
types (spec-report.js) 4.99KB 1.96KB
types (spec-ui-namespace.js) 0.20KB 0.19KB
types (strict-authoring-face.js) 19.93KB 7.25KB
types (system-fields.js) 3.33KB 1.54KB
types (theme.js) 6.28KB 2.87KB
types (ui-action.js) 8.11KB 3.32KB
types (views.js) 0.20KB 0.18KB
types (widget.js) 0.20KB 0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@objectstack-fleet
objectstack-fleet Bot marked this pull request as ready for review October 7, 2026 14:15
@objectstack-fleet
objectstack-fleet Bot enabled auto-merge October 7, 2026 14:15
@objectstack-fleet
objectstack-fleet Bot added this pull request to the merge queue Oct 7, 2026
Merged via the queue into main with commit 9990f9e Oct 7, 2026
45 checks passed
@objectstack-fleet
objectstack-fleet Bot deleted the claude/issue-11769-public-form-url-basename branch October 7, 2026 14:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

2 participants