Repository navigation
fix(console): the Public Forms page offers the anonymous URL the router serves (objectui#11769) - #11771
Merged
objectstack-fleet[bot] merged 1 commit intoOct 7, 2026
Conversation
…er serves
PublicFormsPage built every anonymous form URL as ORIGIN/console/f/SLUG and
printed /console/f/ beside both slug fields. No host mounts the console at
/console/: the framework CLI and cloud serve it at /_console/ and inject the
base href that App.tsx turns into the router basename. The anonymous route is
/f/:slug under that basename.
The page now asks the router (useHref('/f')) where the route is served. The
link, the copied URL, the iframe and React snippets and both slug-field
prefixes are built from that one value: /_console/f/SLUG under a /_console
mount, /f/SLUG on a root-mounted console.
The three existing page tests render it inside a MemoryRouter, as the app
does. New pins cover the /_console mount, the root mount and the
metadata-driven component route, and check that the snippets hold exactly the
copied URL.
Claude-Session: https://claude.ai/code/session_01CGZy1BGCjdN5cXqL9cnvB8
Co-authored-by: Claude <noreply@anthropic.com>
Contributor
✅ Console Performance Budget
The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it. 📦 Bundle Size Report
Size Limits
|
objectstack-fleet
Bot
deleted the
claude/issue-11769-public-form-url-basename
branch
October 7, 2026 14:33
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #11769
Clause-②: no
What was wrong
The developer Public Forms page (
apps/console/src/pages/developer/PublicFormsPage.tsx) built every anonymous form URL asORIGIN/console/f/SLUG. That one value fed the table link, Copy URL, the iframe snippet and the React snippet, and the page also printed a literal/console/f/beside both slug fields (the Publish dialog and the Edit dialog). No host serves the console at/console/. The framework CLI mounts it at/_console/and injects a base href of/_console/.App.tsxturns that into the router basename (resolveBasename,BrowserRouter basename={BASENAME}), and the anonymous route is/f/:slugunder that basename.The fix
The page now asks the router where
/fis served:useHref('/f'), which React Router prefixes with the basename. That one value,publicFormPath, builds the link, the copied URL, both snippets and both slug-field prefixes:/_consolemount, the page offersORIGIN/_console/f/SLUG;ORIGIN/f/SLUG.App.tsxis unchanged and exports nothing new. The package entry gains no export, prop, type member or language-pack key. The changeset is apatchfor@object-ui/console.PM mechanism hypotheses, as measured:
useHrefgives the basename-prefixed path. Read in the installed react-router 7.18.2:useHrefjoinsbasenameonto the resolved pathname whenever the basename is not/, and bothBrowserRouterandMemoryRouterbuild hrefs withcreatePath. Confirmed by the pins below, which render underBrowserRouter.publicFormPath, and the ablation below turns their pin red.BrowserRouter basename(authExitBasename.test.tsx,verificationCallback-10893.test.tsx) orMemoryRouter basename(FormPage.redirect.test.tsx). The new pins reuse theBrowserRouterform, which is the routerApp.tsxuses.Measured before the change: the page's URL on a real mount
Framework-served console: measured. I ran
@objectstack/cli17.7.0 with its vendored@objectstack/console17.7.0, usingos serve, thenos dev --fresh, on a scratch app that declares one public form withpublicLink: '/forms/contact-us'.GET /console/f/contact-us(what the page offered)application/json,ENDPOINT_NOT_FOUND. Chromium shows the same JSON.GET /_console/f/contact-us/_console/. In Chromium, an anonymous visitor sees the form (Name, Email, Message, Submit).GET /f/contact-usENDPOINT_NOT_FOUNDGET //_console/The released bundle carries the defect.
assets/PublicFormsPage-D3AT2EH9.jsin@objectstack/console17.7.0 builds the URL as${origin}/console/f/${slug}(minified), and it also contains both/console/f/prefixes.Cloud-served console: NOT MEASURED. The container's egress proxy refuses
cloud.objectos.ai:443(connect_rejected, organization policy), and this session has no cloud checkout. The card's statement about cloud stays a reading, not a measurement.In-browser check of the fixed page: NOT MEASURED. On the 17.7.0 framework runtime the Public Forms page lists no form at all (see Acceptance notes), so it shows no URL to check. The URL is pinned by the unit tests below instead.
Pins
PublicFormsPage.publicUrlBasename-11769.test.tsxrenders the page insideBrowserRouterwith a basename, in three mounts:/_consolemount;/_consolemount reached through the metadata-driven component route/apps/APP/component/developer/public-forms.It pins, per mount:
href, its text and the copied URL areORIGIN/_console/f/contact-usunder/_consoleandORIGIN/f/contact-usat root. The component route does not add its own depth to the URL.srcof the iframe snippet and thesrcof the React snippet each hold exactly the copied URL, and each snippet holds only that one./_console/f/or/f/)./console/f/.Three existing page tests rendered the page with no router:
developerMetadataEnvelope.contractEnvelope-6917,PublicFormsPage.redirectandPublicFormsPage.emptyPlaceholderAffordance-8504.useHrefneeds a router, which the app always provides, so these tests now render with{ wrapper: MemoryRouter }. No assertion in them changed.Ablation
This was run once and is not kept as a test. It used
scripts/ablation-replace.mjsfrom the objectstack checkout, after the fix was committed. The mutation was proven on disk (anchor count 1 to 0, blob changed). The restore was proven by the blob matching HEADc8a3e7d2c580and an emptygit diff HEAD.publicFormPathforced back to'/console/f', so every surface is hard-coded again: 9 of 12 failed and 3 passed. On all three mounts, the "offers" pin, the slug-field-prefix pin and the no-/console/f/pin went red, with errors such asexpected '/console/f/' to be '/_console/f/'andUnable to find an element with the text: http://localhost:3000/_console/f/contact-us. The snippet-agreement pin stayed green on all three mounts. That was expected: a consistent hard-code still agrees with itself.ORIGIN/console/f/SLUG: 3 of 12 failed, which was the snippet-agreement pin on each mount, and 9 passed.Verification on HEAD
e90d688pnpm exec vitest run apps/console/src/pages/developer/ apps/console/src/__tests__/orphanedPageComponentRefs-10520.test.tsxTest Files 11 passed (11),Tests 95 passed (95)pnpm exec turbo run build --filter='@object-ui/console^...' --concurrency=2(dependency closure, before type-check)Tasks: 34 successful, 34 totalpnpm --filter @object-ui/console type-check(echoestype-check;--listFilesshows all 5 touched.tsxfiles in the program)error TSpnpm exec eslinton the 5 touched files0 errors, 12 warnings. All 12 are inPublicFormsPage.tsxand were there before: BASE179f6fe0e/12w, HEAD 0e/12w.node scripts/check-changeset-presence.mjs5 source file(s) of 1 released package(s) changed, and this change declares 1 changeset(s)node scripts/check-changeset-no-major.mjsNo changeset declares a major bump.pnpm check:control-bytescheck-control-bytes: OKpnpm check:test-path-rootscheck-test-path-roots: OKpnpm check:changeset-claimsNo pending changeset names a file this change touches.pnpm check:pending-changeset-literalsNo test source names a pending changeset.pnpm check:new-line-citationsVERDICT new-cross-file-line-citations: 0 new citation(s)pnpm check:vi-mock-specifiers/vi-mock-inherit/vi-mock-override-shapeOKeachpnpm check:phantom-depsreact-router-domis already a declared dependency of@object-ui/consolepnpm check:shell-escape-residue/check:unreferenced-sourcesOKWhat the scoping covers:
PublicFormsPage: the 10 files underpages/developer/, plus the component-route test, which renders the registereddeveloper:public-formskey through the route table. The rest of the console project is CI's.--format jsonreports 5 results).eslint.config.jsturns on no type-aware linting (noprojectServiceand noparserOptions.project), and no rule ineslint-rules/reads other files. This diff therefore cannot change the verdict on any file it did not touch.i18ngates did not apply. No package export changed, soreadme-exportsdid not apply.check:eager-closureneeds a console build and was left to CI. The import added here isreact-router-dom, whichApp.tsxalready loads eagerly, inside a page that is lazy-loaded.Acceptance notes
GET /api/v1/meta/viewserves each view as a ViewItem with the keysname,object,viewKind,labelandconfig. The form'ssharingandsectionsare underconfig. The page readsit.spec ?? itand looks forsectionsandsharingon the item itself, so no item counts as a form. Measured in Chromium on that runtime: the table says "No public forms yet" for a declared public form, and "Publish form…" is disabled. The runtime refuses a view config with noviewKindwith 422 and names the ViewItem shape. The page's tests use a{ spec }fixture shape that this runtime does not serve. This masks the URL defect fixed here on that runtime, so the reach of this card's defect is today limited to a runtime that serves thespecshape. That is NOT MEASURED, and no such runtime was found.sharing.enabled) remains open and is not addressed here. objectstack#22079 (the server-side redirect from/forms/SLUG) is not addressed here either.Generated by Claude Code