Skip to content

docs(auth): the org-role vocabulary is closed — correct the mirror's standing instruction (framework ADR-0108) - #2907

Merged
os-zhuang merged 1 commit into
mainfrom
claude/org-role-vocabulary-closed
Jul 28, 2026
Merged

docs(auth): the org-role vocabulary is closed — correct the mirror's standing instruction (framework ADR-0108)#2907
os-zhuang merged 1 commit into
mainfrom
claude/org-role-vocabulary-closed

Conversation

@os-zhuang

Copy link
Copy Markdown
Contributor

Follow-up to objectstack-ai/objectstack#3802 (ADR-0108), which closed the sys_member.role vocabulary server-side. Tracks the console half of objectstack-ai/objectstack#3723.

Why

packages/auth/src/org-roles.ts carried a standing instruction that is now wrong:

Until that lands, a role added server-side must be added HERE too — one place, not two.

There are no server-side additions left to chase. The framework used to register every declared position / permission name as an organization role, so this list could always fall behind the server's. That channel was retired: every value stored in sys_member.role is projected into current_user.positions, so a business role handed out that way was capability carrying none of the position system's controls — no granted_by, no validity window, no scope check.

sys_member.role is now a closed, framework-owned list of owner / admin / delegated_admin / member. An app's own business roles are positions, granted through sys_user_position or an invitation's placement (framework ADR-0105 D8).

So this mirror is complete by construction rather than by vigilance — which is the opposite of the risk the old comment was warning about.

Why this is not yet the derivation

The obvious next step is to import the names instead of restating them. It cannot be done in this PR, for a packaging reason rather than a design one:

  • the names live in @objectstack/spec as BUILTIN_MEMBERSHIP_ROLES / BUILTIN_MEMBERSHIP_ROLE_OPTIONS;
  • @object-ui/auth takes no dependency on @objectstack/spec (its deps are @object-ui/types and better-auth);
  • those constants are not in any published version — I unpacked @objectstack/spec@16.1.0 from npm and grepped its dist: zero occurrences. They ship with the first release carrying ADR-0108.

The module doc now records the exact swap for when that lands: the four export consts become a re-export and ORG_ROLES becomes [...BUILTIN_MEMBERSHIP_ROLES]. Labels and the grade ladder stay local — they are console concerns, and merging them into the name list would be the modeling error ADR-0108 D4 warns about.

What changed

  • org-roles.ts — module doc rewritten: the vocabulary is closed, the stale "add it here too" instruction removed, and the blocked derivation documented with its precise unblock condition.
  • index.ts — the one-line comment above the re-export, same correction.
  • __tests__/org-roles.test.ts — a drift guard pinning ORG_ROLES to exactly those four in display order, so divergence fails loudly instead of silently offering a value the server's enforced select would reject with a 400.

No behaviour change. The four names and their labels are what they already were; only the comments and one new assertion differ.

Test Files  12 passed (12)   Tests  91 passed (91)

type-check clean.

🤖 Generated with Claude Code

https://claude.ai/code/session_0186LhwkUBupmLJUUAMda5hU


Generated by Claude Code

…standing instruction (framework ADR-0108)

`org-roles.ts` told the next maintainer "a role added server-side must be
added HERE too". There are no server-side additions left to chase.

The framework used to register every declared `position` / `permission` name
as an organization role, so this list could always fall behind the server's.
That channel was retired (framework ADR-0108, objectstack#3723): every value
stored in `sys_member.role` is projected into `current_user.positions`, so a
business role handed out that way was capability carrying none of the position
system's controls. `sys_member.role` is now a closed, framework-owned list of
owner / admin / delegated_admin / member; an app's business roles are
positions, granted through `sys_user_position` or an invitation's placement
(framework ADR-0105 D8).

The mirror is therefore complete by construction rather than by vigilance. No
behaviour change — the four names and labels are what they already were.

Still a mirror rather than a derivation, but for a packaging reason now, not a
design one: the names live in `@objectstack/spec` as
`BUILTIN_MEMBERSHIP_ROLES`, which `@object-ui/auth` cannot import yet (this
package takes no dependency on `@objectstack/spec`, and the constants are
absent from the published 16.1.0 — they ship with the first ADR-0108 release).
The doc records the exact swap for when it can. A new test pins the list to
those four in display order so drift fails loudly instead of silently offering
a value the server's enforced select rejects.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0186LhwkUBupmLJUUAMda5hU
@vercel

vercel Bot commented Jul 28, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated (UTC)
objectui Ignored Ignored Jul 28, 2026 7:06am

Request Review

@github-actions github-actions Bot added the tests label Jul 28, 2026
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

Metric Value Budget
Main entry (gzip) 27.9 KB 350 KB
Entry file index-gVBAOvNA.js
Status PASS

📦 Bundle Size Report

Package Size Gzipped
app-shell (index.js) 8.20KB 2.97KB
app-shell (runtime-config.js) 7.42KB 2.32KB
app-shell (types.js) 0.01KB 0.04KB
app-shell (urlParams.js) 7.57KB 2.97KB
auth (AuthContext.js) 0.31KB 0.24KB
auth (AuthGuard.js) 1.17KB 0.53KB
auth (AuthProvider.js) 22.10KB 4.37KB
auth (AuthShell.js) 3.49KB 1.40KB
auth (ForgotPasswordForm.js) 12.12KB 3.41KB
auth (LoginForm.js) 17.86KB 5.29KB
auth (PreviewBanner.js) 0.90KB 0.50KB
auth (RegisterForm.js) 6.43KB 2.09KB
auth (SocialSignInButtons.js) 9.60KB 3.89KB
auth (UserMenu.js) 3.40KB 1.22KB
auth (auth-gate-events.js) 1.29KB 0.66KB
auth (authStyles.js) 5.04KB 1.72KB
auth (createAuthClient.js) 35.76KB 9.11KB
auth (createAuthenticatedFetch.js) 4.37KB 1.69KB
auth (index.js) 2.25KB 1.01KB
auth (org-roles.js) 6.72KB 2.85KB
auth (phone-identifier.js) 1.11KB 0.66KB
auth (types.js) 0.59KB 0.35KB
auth (useAuth.js) 4.91KB 0.87KB
auth (useIsWorkspaceAdmin.js) 1.61KB 0.85KB
collaboration (CommentThread.js) 18.38KB 4.49KB
collaboration (LiveCursors.js) 3.17KB 1.27KB
collaboration (PresenceAvatars.js) 3.65KB 1.42KB
collaboration (PresenceProvider.js) 2.79KB 1.13KB
collaboration (index.js) 1.25KB 0.53KB
collaboration (useCommentSearch.js) 1.98KB 0.88KB
collaboration (useConflictResolution.js) 7.75KB 1.86KB
collaboration (useMentionNotifications.js) 1.81KB 0.68KB
collaboration (usePresence.js) 6.33KB 1.84KB
collaboration (useRealtimeSubscription.js) 7.91KB 2.01KB
components (index.js) 449.62KB 97.73KB
core (index.js) 2.12KB 0.77KB
create-plugin (index.js) 9.28KB 2.98KB
data-objectstack (index.js) 127.78KB 32.15KB
fields (index.js) 218.37KB 53.54KB
i18n (LocalizationContext.js) 1.76KB 0.96KB
i18n (currency.js) 1.22KB 0.64KB
i18n (i18n.js) 4.32KB 1.77KB
i18n (index.js) 2.46KB 0.96KB
i18n (pickLocalized.js) 1.70KB 0.83KB
i18n (provider.js) 5.37KB 1.72KB
i18n (useObjectLabel.js) 25.17KB 5.80KB
i18n (useSafeTranslation.js) 3.26KB 1.44KB
layout (index.js) 38.45KB 10.67KB
mobile (MobileProvider.js) 0.92KB 0.49KB
mobile (ResponsiveContainer.js) 0.94KB 0.38KB
mobile (breakpoints.js) 1.51KB 0.70KB
mobile (createOfflineDataSource.js) 5.61KB 1.74KB
mobile (index.js) 1.50KB 0.62KB
mobile (offlineQueue.js) 3.91KB 1.35KB
mobile (pwa.js) 0.97KB 0.49KB
mobile (serviceWorker.js) 1.48KB 0.62KB
mobile (serviceWorkerSource.js) 3.41KB 1.48KB
mobile (useBreakpoint.js) 1.54KB 0.65KB
mobile (useGesture.js) 4.42KB 1.27KB
mobile (useOfflineSync.js) 1.99KB 0.72KB
mobile (usePullToRefresh.js) 2.53KB 0.85KB
mobile (useResponsive.js) 0.71KB 0.42KB
mobile (useResponsiveConfig.js) 1.36KB 0.63KB
mobile (useSpecGesture.js) 1.77KB 0.77KB
mobile (useTouchTarget.js) 1.01KB 0.54KB
permissions (MePermissionsProvider.js) 6.84KB 2.42KB
permissions (PermissionContext.js) 0.31KB 0.25KB
permissions (PermissionGuard.js) 0.89KB 0.45KB
permissions (PermissionProvider.js) 3.67KB 1.12KB
permissions (evaluator.js) 4.00KB 1.23KB
permissions (index.js) 0.91KB 0.41KB
permissions (store.js) 0.91KB 0.42KB
permissions (useFieldPermissions.js) 1.28KB 0.52KB
permissions (usePermissions.js) 1.55KB 0.71KB
plugin-ai (index.js) 15.71KB 3.79KB
plugin-calendar (index.js) 44.90KB 12.35KB
plugin-charts (index.js) 57.26KB 16.24KB
plugin-chatbot (index.js) 179.93KB 42.67KB
plugin-dashboard (index.js) 109.60KB 28.33KB
plugin-designer (index.js) 210.56KB 42.56KB
plugin-detail (index.js) 214.86KB 52.39KB
plugin-editor (index.js) 2.46KB 1.10KB
plugin-form (index.js) 103.47KB 25.10KB
plugin-gantt (index.js) 162.26KB 39.53KB
plugin-grid (index.js) 179.25KB 46.97KB
plugin-kanban (index.js) 47.82KB 13.18KB
plugin-list (index.js) 98.64KB 23.33KB
plugin-map (index.js) 16.80KB 5.24KB
plugin-markdown (index.js) 13.65KB 4.67KB
plugin-report (index.js) 37.07KB 9.81KB
plugin-timeline (index.js) 25.03KB 7.11KB
plugin-tree (index.js) 8.36KB 2.81KB
plugin-view (index.js) 85.68KB 20.85KB
providers (DataSourceProvider.js) 0.75KB 0.39KB
providers (MetadataProvider.js) 1.37KB 0.59KB
providers (ThemeProvider.js) 1.55KB 0.67KB
providers (UploadProvider.js) 11.71KB 3.53KB
providers (index.js) 0.44KB 0.22KB
providers (types.js) 0.01KB 0.04KB
react-runtime (index.js) 3.19KB 1.38KB
react (LazyPluginLoader.js) 3.77KB 1.33KB
react (SchemaRenderer.js) 18.70KB 6.09KB
react (data-invalidation.js) 5.05KB 2.08KB
react (index.js) 1.00KB 0.55KB
sdui-parser (codegen.js) 4.09KB 1.74KB
sdui-parser (index.js) 2.16KB 0.94KB
sdui-parser (parse.js) 10.04KB 2.82KB
sdui-parser (types.js) 0.29KB 0.24KB
sdui-parser (validate.js) 4.69KB 1.48KB
types (ai.js) 0.20KB 0.17KB
types (api-types.js) 0.20KB 0.18KB
types (app.js) 2.87KB 0.99KB
types (base.js) 0.20KB 0.18KB
types (blocks.js) 0.20KB 0.18KB
types (complex.js) 0.20KB 0.18KB
types (crud.js) 0.20KB 0.18KB
types (data-display.js) 0.20KB 0.18KB
types (data-protocol.js) 0.20KB 0.19KB
types (data.js) 0.20KB 0.18KB
types (designer.js) 0.77KB 0.41KB
types (disclosure.js) 0.20KB 0.18KB
types (feedback.js) 0.20KB 0.18KB
types (field-types.js) 0.20KB 0.18KB
types (form.js) 0.20KB 0.18KB
types (index.js) 1.86KB 0.91KB
types (layout.js) 0.20KB 0.18KB
types (managed-by.js) 0.19KB 0.18KB
types (mobile.js) 0.20KB 0.18KB
types (navigation.js) 0.20KB 0.18KB
types (objectql.js) 0.20KB 0.18KB
types (overlay.js) 0.20KB 0.18KB
types (permissions.js) 0.20KB 0.18KB
types (plugin-scope.js) 0.20KB 0.18KB
types (record-components.js) 0.20KB 0.19KB
types (record-semantics.js) 1.28KB 0.67KB
types (registry.js) 0.20KB 0.18KB
types (reports.js) 0.20KB 0.18KB
types (spec-report.js) 5.04KB 1.93KB
types (system-fields.js) 2.39KB 1.17KB
types (theme.js) 0.20KB 0.18KB
types (ui-action.js) 0.75KB 0.46KB
types (views.js) 0.20KB 0.18KB
types (widget.js) 0.20KB 0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-zhuang
os-zhuang marked this pull request as ready for review July 28, 2026 07:20
@os-zhuang
os-zhuang merged commit 503d3f6 into main Jul 28, 2026
14 checks passed
@os-zhuang
os-zhuang deleted the claude/org-role-vocabulary-closed branch July 28, 2026 07:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants