Filing gate: ① product defect with reach measured. Class (b), app-developer experience. reach: any app or plugin test that boots ObjectQL with AppPlugin (and often SecurityPlugin) but not plugin-auth, the reduced-kernel pattern the platform's own suites and app suites use. Measured on @objectstack/* 17.7.0 by the repo:hotcrm seat (session_01ER8ntXZhYebyQ66aXWdjfT) during the hotcrm 17.7.0 upgrade (hotcrm PR #2008), on the maintainer's word: 「10. 测试脚手架 … 以上立卡」.
Who acts on it: objectstack triage. Likely the security lane (it reads the objects), with whoever owns @objectstack/verify. ⛔ Not a claim.
Measured (hotcrm on 17.7.0)
Nine hotcrm test files boot ObjectKernel + DefaultDatasourcePlugin (memory) + MetadataPlugin + ObjectQLPlugin + AppPlugin(stack). Several also mount SecurityPlugin and SharingServicePlugin. Each then inserts a sys_user fixture. On 17.6.0 they were green. On 17.7.0:
- Every file failed at load:
Error: Object 'sys_user' not found (OBJECT_NOT_FOUND, 404). This is objectstack#21545, the engine now refusing names its registry does not hold, as the 17.7.0 notes say.
- After registering
SysUser, the five files with SecurityPlugin failed again: AuthzStoreUnavailableError: The authorization store could not be read … (failed read: sys_member) … Object 'sys_member' not found. plugin-security's own permission resolution reads an object that only plugin-auth registers.
- What it took was
test/helpers/identity-objects.ts: a stand-in plugin that registers SysUser, SysMember and SysOrganization through the manifest service under com.objectstack.plugin-auth's id, mounted in all nine harnesses (hotcrm c9678036). Imports come from @objectstack/platform-objects/identity, and the manifest header mirrors plugin-auth's.
createPlatformObjectsPlugin() does not help: it does not register the identity objects (measured: sys_user still not found with it mounted).
Why it matters
- Every app with a test suite will hit this on its 17.7.0 upgrade, and each will hand-roll the same registration, copying plugin-auth's internal manifest id and object list. That list will drift as plugin-auth's changes.
- plugin-security reading
sys_member without declaring or registering it means a security-only kernel is not bootable on its own. The authz store then reports a server outage (AuthzStoreUnavailableError) rather than a missing dependency.
A direction, for triage to rule on (⛔ not a ruling)
- Publish the preset: an
identityObjects() plugin, or the identity objects as a standalone registrable package/plugin that plugin-auth itself composes. Test kits then mount the platform's list instead of copying it. If @objectstack/verify's in-process handle is the sanctioned kit, it could include them by default. Not measured whether it does today.
- Make plugin-security's dependency explicit. Either it declares that it needs the identity objects (a clear boot error naming them), or it registers the ones its authz store reads.
Related, not duplicates
#14846 (closed): plugin-auth's own sso-register harness never registered sys_position / sys_user_position. Same family, a different harness, before #21545 made it a hard failure.
Duplicate check
Semantic issue search on objectstack, test harness register platform identity objects sys_user OBJECT_NOT_FOUND unregistered object verify kit: 2 hits, both closed.
Positive control: #14846 surfaces.
Dedupe words: identity objects test harness · sys_user not found test · AuthzStoreUnavailableError sys_member · reduced kernel plugin-auth · test kit preset
Generated by Claude Code
Filing gate: ① product defect with reach measured. Class (b), app-developer experience. reach: any app or plugin test that boots ObjectQL with
AppPlugin(and oftenSecurityPlugin) but notplugin-auth, the reduced-kernel pattern the platform's own suites and app suites use. Measured on@objectstack/*17.7.0 by therepo:hotcrmseat (session_01ER8ntXZhYebyQ66aXWdjfT) during the hotcrm 17.7.0 upgrade (hotcrm PR #2008), on the maintainer's word: 「10. 测试脚手架 … 以上立卡」.Who acts on it: objectstack triage. Likely the security lane (it reads the objects), with whoever owns
@objectstack/verify. ⛔ Not a claim.Measured (hotcrm on 17.7.0)
Nine hotcrm test files boot
ObjectKernel+DefaultDatasourcePlugin(memory) +MetadataPlugin+ObjectQLPlugin+AppPlugin(stack). Several also mountSecurityPluginandSharingServicePlugin. Each then inserts asys_userfixture. On 17.6.0 they were green. On 17.7.0:Error: Object 'sys_user' not found(OBJECT_NOT_FOUND, 404). This is objectstack#21545, the engine now refusing names its registry does not hold, as the 17.7.0 notes say.SysUser, the five files withSecurityPluginfailed again:AuthzStoreUnavailableError: The authorization store could not be read … (failed read: sys_member) … Object 'sys_member' not found. plugin-security's own permission resolution reads an object that only plugin-auth registers.test/helpers/identity-objects.ts: a stand-in plugin that registersSysUser,SysMemberandSysOrganizationthrough themanifestservice undercom.objectstack.plugin-auth's id, mounted in all nine harnesses (hotcrmc9678036). Imports come from@objectstack/platform-objects/identity, and the manifest header mirrors plugin-auth's.createPlatformObjectsPlugin()does not help: it does not register the identity objects (measured:sys_userstill not found with it mounted).Why it matters
sys_memberwithout declaring or registering it means a security-only kernel is not bootable on its own. The authz store then reports a server outage (AuthzStoreUnavailableError) rather than a missing dependency.A direction, for triage to rule on (⛔ not a ruling)
identityObjects()plugin, or the identity objects as a standalone registrable package/plugin that plugin-auth itself composes. Test kits then mount the platform's list instead of copying it. If@objectstack/verify's in-process handle is the sanctioned kit, it could include them by default. Not measured whether it does today.Related, not duplicates
#14846 (closed): plugin-auth's own sso-register harness never registered
sys_position/sys_user_position. Same family, a different harness, before #21545 made it a hard failure.Duplicate check
Semantic issue search on objectstack, test harness register platform identity objects sys_user OBJECT_NOT_FOUND unregistered object verify kit: 2 hits, both closed.
sys_account.issuer—identity-auth.json'slink_socialVERIFY is an oracle that now fails a healthy system #19217, a QA checklist field.Positive control: #14846 surfaces.
Dedupe words: identity objects test harness · sys_user not found test · AuthzStoreUnavailableError sys_member · reduced kernel plugin-auth · test kit preset
Generated by Claude Code