Skip to content

feat(grid): gate list row Edit/Delete and bulk delete on the effective operation set (objectstack#3720) - #2889

Merged
os-zhuang merged 1 commit into
mainfrom
claude/list-row-edit-delete-batch-9nd6hi
Jul 28, 2026
Merged

feat(grid): gate list row Edit/Delete and bulk delete on the effective operation set (objectstack#3720)#2889
os-zhuang merged 1 commit into
mainfrom
claude/list-row-edit-delete-batch-9nd6hi

Conversation

@os-zhuang

Copy link
Copy Markdown
Contributor

Closes objectstack-ai/objectstack#3720 — the fourth surface objectstack#3391 left open.

The gap

The three earlier rounds all route through resolveCrudAffordances:

face PR
toolbar (ObjectView Import, ListView/ObjectGrid Export) #2823
detail / form (header Edit/Delete, inline-edit, form field lock) #2832 + #2876
related lists (RelatedRecordActionsBridge) #2832

The main list's row CRUD does not — it has its own resolver
(plugin-grid/src/rowCrudAffordances.ts), so none of those rounds ever reached it.
Its gate was:

operations ?? { update: !!onEdit, delete: !!onDelete }   ← default all-open
  ∧ userActions.{edit,delete} explicit-false opt-out

ObjectView wires onEdit/onDelete unconditionally and view JSON rarely declares
operations, so the gate was effectively always-on. ObjectGrid's effectiveApiOps was
computed but fed only to Export. Net effect: a caller whose effective set carried neither
update nor delete still got the row kebab's Edit/Delete and the bulk delete — the
most destructive affordance on the list.

Changes

plugin-grid · resolveRowCrudAffordances — takes managedBy and
effectiveApiOperations, and resolves the object verdict through the shared
resolveCrudAffordances policy, so the row gate is now the same decision the toolbar,
record header, form and related lists make. Also returns objectCanDelete: bulk delete
rides onBulkDelete, a different callback from the row onDelete, so it must not be
judged by whether the row handler happens to be wired.

plugin-grid · ObjectGrid — threads the existing effectiveApiOps into the row
gate, and applies the delete verdict to bulk delete across all three entry points: the
implicit ['delete'], an author-declared bulkActions: ['delete'], and any
bulkActionDefs entry with operation: 'delete'. A declared bulk action is a wiring
declaration, not a permission grant. Custom action ids and non-delete operations pass
through untouched — they route through the action runner with their own gates.

plugin-list · ListView — its own bulk bar (the non-grid views: kanban / calendar /
gallery; the grid path delegates to ObjectGrid) drops its built-in delete under the
same verdict.

Checklist item 4 — the ADR-0103 bucket lock

Confirmed genuinely missing, and fixed here. rowCrudAffordances documented it as
"applied upstream via the view's operations.*", but the all-open default meant it never
was, and the server's apiOperations doesn't carry it either — annotateEffectiveApiOperations
derives from apiMethods + the export axis, not from managedBy. So an engine-owned
system / append-only / better-auth object leaked a generic row Edit/Delete that the
engine rejects (assertEngineOwnedWriteAllowed). Running the shared policy applies it;
a userActions opt-in still re-opens it (e.g. sys_user's edit).

⚠️ This is the one behavior change beyond the permission gate: engine-owned-bucket
objects lose their generic row Edit/Delete kebab entries in the main list. That aligns them
with the toolbar, detail header, form and related lists, which already hide those.

Checklist item 3 — other rowActions consumers

  • ListView — forwards to ObjectGrid for the grid path (inherits the gate); its own
    bulk bar is gated above. Note it is currently inert in the console: no first-party
    consumer passes onBulkAction, so it is covered by the shared-policy unit tests rather
    than a DOM probe.
  • Mobile card view — no separate face. ObjectGrid's stacked-card branch filters the
    _actions column out entirely, so it never surfaced row CRUD.
  • plugin-view/ObjectView — passes onEdit/onDelete/onBulkDelete into ObjectGrid
    and inherits the gate.
  • components/data-table — the generic, object-less table; no effective set exists for it.

Tests

14 component-level probes against the real ObjectGrid with usePermissions mocked,
asserting the user-visible outcome (menu items / selection checkboxes / bulk button) —
the issue's matrix, with its control group kept:

case effective set row Edit/Delete + selection
A baseline ['get','list','create','update','delete'] shown ✅
B this issue ['get','list'] hidden
C control full, but userActions:{edit:false,delete:false} hidden ✅

plus independent update/delete gating, the undefined fallback, both
intersection-never-union invariants, the bucket matrix, and the declared
bulkActions / bulkActionDefs filters.

28 unit cases on the resolver (the 10 pre-existing ones kept).

Probes verified to actually observe the bug: reverting the wiring turns 6 red without
the effective-set argument and 2 red without managedBy.

Suites run green: plugin-grid 279, plugin-list 163, app-shell 60, plugin-view 91.
Lint 0 errors; the 4 TS declaration errors plugin-grid emits are pre-existing on main
(ObjectGrid.tsx:677-678 i18n defaults, importParsers.ts:352).

Not done

No end-to-end browser check — this environment has no backend/preview stack. The evidence
is component-level plus the server-side code walk in the issue.


Generated by Claude Code

…e operation set (#3720)

The fourth surface #3391 left open. The toolbar (objectui#2823), detail/form
(#3546) and related lists (#3546) all route through `resolveCrudAffordances`;
the main list's row CRUD has its own resolver and none of those rounds reached
it. Its gate was `operations ?? { update: !!onEdit, delete: !!onDelete }`, and
ObjectView wires onEdit/onDelete unconditionally while view JSON rarely declares
`operations` — so it was effectively always-on. A caller whose effective set
carried neither `update` nor `delete` still got the row kebab's Edit/Delete and
the bulk delete.

- plugin-grid `resolveRowCrudAffordances` takes `managedBy` +
  `effectiveApiOperations` and resolves the object verdict through the shared
  `resolveCrudAffordances` policy, so the row gate is the same decision every
  other face makes. It also returns `objectCanDelete` — bulk delete rides
  `onBulkDelete`, a different callback from the row `onDelete`, so it must not
  be judged by whether the row handler happens to be wired.
- plugin-grid `ObjectGrid` threads its existing `effectiveApiOps` (until now fed
  only to Export) into the row gate, and applies the delete verdict to bulk
  delete: the implicit `['delete']`, a declared `bulkActions: ['delete']`, and
  any `bulkActionDefs` entry with `operation: 'delete'`. A declared bulk action
  is a wiring declaration, not a permission grant. Custom ids and non-delete
  operations pass through untouched.
- plugin-list `ListView`'s own bulk bar (the non-grid views; the grid path
  delegates to ObjectGrid) drops its built-in `delete` under the same verdict.

Also closes the ADR-0103 gap on this chain: `rowCrudAffordances` documented the
bucket lock as "applied upstream via the view's `operations.*`", but the
all-open default meant it never was — an engine-owned system / append-only /
better-auth object leaked a generic row Edit/Delete the engine rejects. The
shared policy applies it; a `userActions` opt-in still re-opens it (sys_user).

Semantics match the earlier rounds: intersection, never union. A missing
effective set (unrestricted object / older backend / no PermissionProvider)
preserves current behavior.

Tests: 14 component-level ObjectGrid probes over the issue's matrix (A full set,
B read-only, C the userActions opt-out control group) covering the row kebab,
multi-select, declared bulkActions and bulkActionDefs, plus the bucket cases;
28 unit cases on the resolver. Verified the probes fail without the wiring —
6 fail without the effective-set arg, 2 without `managedBy`.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UQQ42DcujEPonLQ3hort4t
@vercel

vercel Bot commented Jul 28, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated (UTC)
objectui Ignored Ignored Jul 28, 2026 2:34am

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

Metric Value Budget
Main entry (gzip) 27.9 KB 350 KB
Entry file index-DdndxXX3.js
Status PASS

📦 Bundle Size Report

Package Size Gzipped
app-shell (index.js) 8.20KB 2.97KB
app-shell (runtime-config.js) 7.42KB 2.32KB
app-shell (types.js) 0.01KB 0.04KB
app-shell (urlParams.js) 7.57KB 2.97KB
auth (AuthContext.js) 0.31KB 0.24KB
auth (AuthGuard.js) 1.17KB 0.53KB
auth (AuthProvider.js) 22.10KB 4.37KB
auth (AuthShell.js) 3.49KB 1.40KB
auth (ForgotPasswordForm.js) 12.12KB 3.41KB
auth (LoginForm.js) 17.86KB 5.29KB
auth (PreviewBanner.js) 0.90KB 0.50KB
auth (RegisterForm.js) 6.43KB 2.09KB
auth (SocialSignInButtons.js) 9.60KB 3.89KB
auth (UserMenu.js) 3.40KB 1.22KB
auth (auth-gate-events.js) 1.29KB 0.66KB
auth (authStyles.js) 5.04KB 1.72KB
auth (createAuthClient.js) 35.76KB 9.11KB
auth (createAuthenticatedFetch.js) 4.37KB 1.69KB
auth (index.js) 1.83KB 0.79KB
auth (phone-identifier.js) 1.11KB 0.66KB
auth (types.js) 0.59KB 0.35KB
auth (useAuth.js) 4.91KB 0.87KB
auth (useIsWorkspaceAdmin.js) 1.61KB 0.85KB
collaboration (CommentThread.js) 18.38KB 4.49KB
collaboration (LiveCursors.js) 3.17KB 1.27KB
collaboration (PresenceAvatars.js) 3.65KB 1.42KB
collaboration (PresenceProvider.js) 2.79KB 1.13KB
collaboration (index.js) 1.25KB 0.53KB
collaboration (useCommentSearch.js) 1.98KB 0.88KB
collaboration (useConflictResolution.js) 7.75KB 1.86KB
collaboration (useMentionNotifications.js) 1.81KB 0.68KB
collaboration (usePresence.js) 6.33KB 1.84KB
collaboration (useRealtimeSubscription.js) 7.91KB 2.01KB
components (index.js) 449.81KB 97.81KB
core (index.js) 2.12KB 0.77KB
create-plugin (index.js) 9.28KB 2.98KB
data-objectstack (index.js) 127.78KB 32.15KB
fields (index.js) 218.37KB 53.54KB
i18n (LocalizationContext.js) 1.76KB 0.96KB
i18n (currency.js) 1.22KB 0.64KB
i18n (i18n.js) 4.32KB 1.77KB
i18n (index.js) 2.46KB 0.96KB
i18n (pickLocalized.js) 1.70KB 0.83KB
i18n (provider.js) 5.37KB 1.72KB
i18n (useObjectLabel.js) 25.17KB 5.80KB
i18n (useSafeTranslation.js) 3.26KB 1.44KB
layout (index.js) 38.45KB 10.67KB
mobile (MobileProvider.js) 0.92KB 0.49KB
mobile (ResponsiveContainer.js) 0.94KB 0.38KB
mobile (breakpoints.js) 1.51KB 0.70KB
mobile (createOfflineDataSource.js) 5.61KB 1.74KB
mobile (index.js) 1.50KB 0.62KB
mobile (offlineQueue.js) 3.91KB 1.35KB
mobile (pwa.js) 0.97KB 0.49KB
mobile (serviceWorker.js) 1.48KB 0.62KB
mobile (serviceWorkerSource.js) 3.41KB 1.48KB
mobile (useBreakpoint.js) 1.54KB 0.65KB
mobile (useGesture.js) 4.42KB 1.27KB
mobile (useOfflineSync.js) 1.99KB 0.72KB
mobile (usePullToRefresh.js) 2.53KB 0.85KB
mobile (useResponsive.js) 0.71KB 0.42KB
mobile (useResponsiveConfig.js) 1.36KB 0.63KB
mobile (useSpecGesture.js) 1.77KB 0.77KB
mobile (useTouchTarget.js) 1.01KB 0.54KB
permissions (MePermissionsProvider.js) 6.84KB 2.42KB
permissions (PermissionContext.js) 0.31KB 0.25KB
permissions (PermissionGuard.js) 0.89KB 0.45KB
permissions (PermissionProvider.js) 3.67KB 1.12KB
permissions (evaluator.js) 4.00KB 1.23KB
permissions (index.js) 0.91KB 0.41KB
permissions (store.js) 0.91KB 0.42KB
permissions (useFieldPermissions.js) 1.28KB 0.52KB
permissions (usePermissions.js) 1.55KB 0.71KB
plugin-ai (index.js) 15.71KB 3.79KB
plugin-calendar (index.js) 44.90KB 12.35KB
plugin-charts (index.js) 55.86KB 15.77KB
plugin-chatbot (index.js) 179.53KB 42.79KB
plugin-dashboard (index.js) 109.60KB 28.33KB
plugin-designer (index.js) 210.56KB 42.56KB
plugin-detail (index.js) 214.86KB 52.39KB
plugin-editor (index.js) 2.46KB 1.10KB
plugin-form (index.js) 103.47KB 25.10KB
plugin-gantt (index.js) 162.26KB 39.53KB
plugin-grid (index.js) 178.13KB 46.73KB
plugin-kanban (index.js) 47.82KB 13.18KB
plugin-list (index.js) 98.67KB 23.30KB
plugin-map (index.js) 16.80KB 5.24KB
plugin-markdown (index.js) 13.65KB 4.67KB
plugin-report (index.js) 37.07KB 9.81KB
plugin-timeline (index.js) 25.03KB 7.11KB
plugin-tree (index.js) 8.36KB 2.81KB
plugin-view (index.js) 85.67KB 20.85KB
providers (DataSourceProvider.js) 0.75KB 0.39KB
providers (MetadataProvider.js) 1.37KB 0.59KB
providers (ThemeProvider.js) 1.55KB 0.67KB
providers (UploadProvider.js) 11.71KB 3.53KB
providers (index.js) 0.44KB 0.22KB
providers (types.js) 0.01KB 0.04KB
react-runtime (index.js) 3.19KB 1.38KB
react (LazyPluginLoader.js) 3.77KB 1.33KB
react (SchemaRenderer.js) 18.70KB 6.09KB
react (data-invalidation.js) 5.05KB 2.08KB
react (index.js) 1.00KB 0.55KB
sdui-parser (codegen.js) 4.09KB 1.74KB
sdui-parser (index.js) 2.16KB 0.94KB
sdui-parser (parse.js) 10.04KB 2.82KB
sdui-parser (types.js) 0.29KB 0.24KB
sdui-parser (validate.js) 4.69KB 1.48KB
types (ai.js) 0.20KB 0.17KB
types (api-types.js) 0.20KB 0.18KB
types (app.js) 2.87KB 0.99KB
types (base.js) 0.20KB 0.18KB
types (blocks.js) 0.20KB 0.18KB
types (complex.js) 0.20KB 0.18KB
types (crud.js) 0.20KB 0.18KB
types (data-display.js) 0.20KB 0.18KB
types (data-protocol.js) 0.20KB 0.19KB
types (data.js) 0.20KB 0.18KB
types (designer.js) 0.77KB 0.41KB
types (disclosure.js) 0.20KB 0.18KB
types (feedback.js) 0.20KB 0.18KB
types (field-types.js) 0.20KB 0.18KB
types (form.js) 0.20KB 0.18KB
types (index.js) 1.86KB 0.91KB
types (layout.js) 0.20KB 0.18KB
types (managed-by.js) 0.19KB 0.18KB
types (mobile.js) 0.20KB 0.18KB
types (navigation.js) 0.20KB 0.18KB
types (objectql.js) 0.20KB 0.18KB
types (overlay.js) 0.20KB 0.18KB
types (permissions.js) 0.20KB 0.18KB
types (plugin-scope.js) 0.20KB 0.18KB
types (record-components.js) 0.20KB 0.19KB
types (record-semantics.js) 1.28KB 0.67KB
types (registry.js) 0.20KB 0.18KB
types (reports.js) 0.20KB 0.18KB
types (spec-report.js) 5.04KB 1.93KB
types (system-fields.js) 2.39KB 1.17KB
types (theme.js) 0.20KB 0.18KB
types (ui-action.js) 0.75KB 0.46KB
types (views.js) 0.20KB 0.18KB
types (widget.js) 0.20KB 0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-zhuang
os-zhuang marked this pull request as ready for review July 28, 2026 02:46
@os-zhuang
os-zhuang merged commit ba45145 into main Jul 28, 2026
14 checks passed
@os-zhuang
os-zhuang deleted the claude/list-row-edit-delete-batch-9nd6hi branch July 28, 2026 02:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

列表行级 edit/delete 与批量删除未接入服务端 effective 操作集(#3391 遗漏的第四个面)

2 participants