Skip to content

metadata-protocol: on a host-config kernel the object save door runs the authoring gate before the package door, so a packaged object's publish save can answer 422 INVALID_METADATA where an environment kernel answers 403 NOT_OVERRIDABLE (#8184's sibling) #22220

Description

@objectstack-fleet

Filing gate: ① a product defect, a misleading refusal.

What the source says (packages/metadata-protocol/src/protocol.ts, read at origin/main 7d7943dd0d)

saveMetaItem checks in this order:

  • :20222–:20231: refusePackagedBaseOverride (403 NOT_OVERRIDABLE), only inside if (this.environmentId !== undefined).
  • :20709: the runtime authoring gate (assertRuntimeAuthoringRules, 422 INVALID_METADATA).
  • :21020: repo.put, whose first act is SysMetadataRepository.assertAllowed (sys-metadata-repository.ts:615). This is where a host-config kernel, whose environmentId is undefined, meets the package door.

So on a host-config kernel, which is the CLI's assembler and the showcase's boot shape (:17834–:17836), the authoring gate answers before the package door. On an environment kernel the package door answers first. The comment at :20242–:20248 holds "one request, one refusal code, on both kernels" for the lock gate. #8184 (closed, 003feae65) settled the same property for the package door itself. The authoring gate has no such ordering.

What was measured (showcase, pnpm dev -- --fresh, default composition, OS_METADATA_WRITABLE unset, the seeded admin)

The request is a publish PUT /api/v1/meta/object/sys_approval_request carrying the served body. The object is packaged under com.objectstack.service.approvals, and object is allowOrgOverride: false.

without the lift (5d1d1aca6d) with the pass-4 lift (7d7943dd0d + probe)
publish 403 NOT_OVERRIDABLE 422 INVALID_METADATA, 8 issues on the actions' visible
draft 403 NOT_OVERRIDABLE 403 NOT_OVERRIDABLE (drafts are not gated)

What the author is told: a 422 names 8 predicates. The author cannot repair them through this door, and after editing them gets the 403, which is the basic verdict. An environment kernel answers 403 before the gate (source reading; not booted).

Reach today: not measured

Passes 1–3 and the formula pass already run the authoring gate on an object write. So a publish save of any packaged object whose body the gate refuses may answer 422 before 403 on host-config today. The shipped corpus carries no such body, so this needs an author-edited one.

Reader

Triage grades and routes this; the fix lands in packages/metadata-protocol's save door. #8184's shape is the precedent: the condition answers one way on every kernel, and the package door asks a topology-independent predicate before the gate. This card does not settle whether the gate should come after the package door on both kernels.

Dedupe

MCP search_issues, repo-scoped, closed included:

Dedupe words: authoring gate before package door host-config · packaged object save refusal code differs by kernel topology · saveMetaItem refusePackagedBaseOverride environmentId order gate

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:apiThe API a customer can call, and integrations — REST, connectors, webhooks, jobsbugSomething isn't workingdomain:enginepm:dispatchedpriority:p3

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions