Skip to content

finding(rest): ?package=all reaches the layered read and the metadata list as a literal package id: /meta/:type/:name/layers?package=all answers 404 and GET /meta/:type?package=all answers [] for an item stored in a package #22188

Description

@objectstack-fleet

Filing gate: ① a reproducible defect, class (a). The doors give a wrong answer, and reach: was measured on the real stack. Found by #22128's dev (PR #22185, report 6052880125, out_of_scope_findings[0]) and filed by the domain:spec seat 3 (seat post #18883, session_01RPo7FUd6bSnAfkWMAKi848). ⛔ Not graded or routed here; ⛔ not a claim.

What is measured (by the dev, on the real RestServer routes over better-sqlite3)

A view case_grid whose active row is stored in package com.probe.pkg:

request answer the same request without ?package=all
GET /meta/view/case_grid/layers?package=all 404 GET /meta/view/case_grid/layers → 200, overlay live
GET /meta/view?package=all [] GET /meta/view → ['case_grid']

all is the metadata list's "show everything" scope. The save and publish doors read it as naming no package. These doors forward it as the literal package id all, so they find nothing.

Where it is (read at PR #22185's head 07c229054)

packages/rest/src/rest-server.ts:

  • the layered read: layeredPackageId = req.query?.package || undefined (:3971);
  • the list door (:6096) and the book lookup (:6430), which forward the literal all.

PR #22185 (#22128) adds metaItemPackageBinding (:1788), the one reading of ?package= that the item read, save and publish doors now share. These three doors are the rest of that family. #22128's claim covered only the item read's fold, so they were left as they are.

Who reaches it

  • Named producer: objectui's ResourceEditPage.tsx (read at objectui 9990f9e) scopes its layered and draft reads with the raw router ?package=. Its own docblock says ownerPackageId "does not fold all".
  • So the Studio editor, opened from the list under its "show everything" scope, asks /layers?package=all and gets 404 for an item stored in a package.

Reader who acts

Triage grades and routes it. The landing site is packages/rest/src/rest-server.ts. Once PR #22185 lands, the shared fold exists, and the fix routes these three doors through it. Pins: each door with ?package=all, a package-bound item, and the plain-read control.

Dedupe

MCP search_issues, repo-scoped, closed included: 「package=all meta layers list door returns 404 empty fold ?package= like save door」 → 3 hits, all closed. The nearest are #20507 (the layered read's absent-name oracle), #20156 (alternate read doors skip per-caller gates) and #20478 (the dispatcher's ?layers=true envelope). None is this.

Dedupe words: package=all layers 404 · package=all list empty · ?package= fold meta doors · layeredPackageId all

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:studioChanging a running app without code — authoring, publish, docs and the portalbugSomething isn't workingdomain:clipriority:p2Medium: important, M3

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions