Filing gate: ③ a direct task from a ruling. This is the fallback written into triage ruling objectstack-ai/objectui#11545 5967405932: "If neither holds, the claim stops and reports, and triage cards the export in objectstack." Neither held at 17.7.0. The dev's measurement is 6029776692, and the seat's release is 6029809270. Filed by the triage seat (objectstack-wide, seat post #6015, session_01AavokzJ5DndAwitDXvKy4U). ⛔ Not a claim.
Graded here: enhancement · priority:p2 (objectui#11545's priority) · domain:spec · area:access · pm:queue.
Unblocks: objectstack-ai/objectui#11545
Why
objectui's developer Public Forms page decides "published" with its own reading of the form's sharing keys. The ruling says that reading must be the server's one rule. Two routes were open, and the dev measured both on 17.7.0:
- No door answers the published set.
GET /meta/view serves stored ViewItems without it, and the forms endpoints are per-slug only.
- No package the console depends on exports the rule.
@objectstack/client, @objectstack/lint and @objectstack/spec have 0 hits. The rule ships only in @objectstack/metadata-core, which the console must not depend on (the ruling's ⛔).
The cost today, as the dev measured it (6029776692, readings A and B): on the item shape the 17.7.0 server serves, the page lists no form at all. On the legacy shape, it lists withdrawn forms as published.
The change
- Move the candidates half of
packages/metadata-core/src/anonymous-form-intake.ts into @objectstack/spec/ui, beside SharingConfigSchema, whose enabled default is the rule's crux:
publicFormSlug;
anonymousFormIntakeSlug;
anonymousFormIntakeCandidates;
anonymousFormIntakeSlugs;
- the
AnonymousFormIntakeCandidate type.
- These are pure functions with no server import, as read on
main at filing (their module imports only @objectstack/spec/security and two metadata-core helpers that this half does not call). The precedent for pure runtime helpers in spec/ui is expandViewContainer.
@objectstack/metadata-core re-exports them from spec, so one copy stays. Its posture, withdrawal-layer and object-name halves stay in metadata-core, because they read server state.
- ⛔ No change in what the rule decides. The candidate scan keeps the same three shapes, in scan order: nested
form, formViews entries, and viewKind: 'form' with config.
What it owes
- It widens a published entry, so it carries
Clause-②: yes (widening), a minor changeset and a contract review.
api-surface and export-origin baselines are regenerated by the repository's tooling.
- Pins:
- the four functions answer the same on all three shapes from
spec as they did from metadata-core;
metadata-core's existing callers and tests are unchanged;
- a parity pin shows the
metadata-core export is the spec one, not a copy.
Not this card
- What the export leaves uncovered: a withdrawal in another layer, and posture unavailability. Both stay out until a named user hits them, as the dev recommended. A server-side "published" answer would be new response surface, which defaults to no.
- The objectui side: the page change stays on objectui#11545. It restarts once objectui resolves a release that carries this export.
Filing gate: ③ a direct task from a ruling. This is the fallback written into triage ruling objectstack-ai/objectui#11545
5967405932: "If neither holds, the claim stops and reports, and triage cards the export in objectstack." Neither held at 17.7.0. The dev's measurement is6029776692, and the seat's release is6029809270. Filed by the triage seat (objectstack-wide, seat post #6015,session_01AavokzJ5DndAwitDXvKy4U). ⛔ Not a claim.Graded here:
enhancement·priority:p2(objectui#11545's priority) ·domain:spec·area:access·pm:queue.Unblocks: objectstack-ai/objectui#11545
Why
objectui's developer Public Forms page decides "published" with its own reading of the form's sharing keys. The ruling says that reading must be the server's one rule. Two routes were open, and the dev measured both on 17.7.0:
GET /meta/viewserves storedViewItems without it, and the forms endpoints are per-slug only.@objectstack/client,@objectstack/lintand@objectstack/spechave 0 hits. The rule ships only in@objectstack/metadata-core, which the console must not depend on (the ruling's ⛔).The cost today, as the dev measured it (
6029776692, readings A and B): on the item shape the 17.7.0 server serves, the page lists no form at all. On the legacy shape, it lists withdrawn forms as published.The change
packages/metadata-core/src/anonymous-form-intake.tsinto@objectstack/spec/ui, besideSharingConfigSchema, whoseenableddefault is the rule's crux:publicFormSlug;anonymousFormIntakeSlug;anonymousFormIntakeCandidates;anonymousFormIntakeSlugs;AnonymousFormIntakeCandidatetype.mainat filing (their module imports only@objectstack/spec/securityand twometadata-corehelpers that this half does not call). The precedent for pure runtime helpers inspec/uiisexpandViewContainer.@objectstack/metadata-corere-exports them fromspec, so one copy stays. Its posture, withdrawal-layer and object-name halves stay inmetadata-core, because they read server state.form,formViewsentries, andviewKind: 'form'withconfig.What it owes
Clause-②: yes (widening), aminorchangeset and a contract review.api-surfaceand export-origin baselines are regenerated by the repository's tooling.specas they did frommetadata-core;metadata-core's existing callers and tests are unchanged;metadata-coreexport is thespecone, not a copy.Not this card