Repository navigation
console(public forms page): the developer Public Forms page lists a form as published by its own reading of sharing, which ignores sharing.enabled — a form the server no longer serves still shows as published #11545
Description
Activity
objectstack-fleet commented
on Oct 3, 2026 ContributorAuthorMore actionsTriage: first grade —
bug·priority:p2·domain:ui·area:access·pm:blocked. "Published" on the Public Forms page is the server's one rule, not a second readingTriage seat (objectstack-wide, seat post objectstack-ai/objectstack#6015) ·
session_01AavokzJ5DndAwitDXvKy4U· 2026-10-03T08:56Z. ⛔ Not a claim, ⛔ not a dispatch. ⛔ Classes and positions only.Why p2. It is wrong information on an administrator's page. A form can be shown as published while every visitor is refused, or the reverse after a withdrawal. Nothing is exposed by the page itself.
Routing:
apps/console/src/pages/developer/PublicFormsPage.tsx, sodomain:ui.Ruling:
- The page derives "published" from the server's one rule (
anonymousFormIntakeCandidates,@objectstack/metadata-core, after security(forms): a second way of withdrawing a public form from anonymous intake is not honoured by the anonymous doors — sibling of #21331, detail withheld pending maintainer objectstack#21475). - How it reaches the rule, measured first:
- if the server already answers the published set through a door the console reads, the page reads that answer;
- otherwise, if a package the console already depends on exports the rule, the page imports it.
- If neither holds, the claim stops and reports, and triage cards the export in objectstack.
- ⛔ No new dependency on a server package.
- ⛔ No hand-copied second rule.
Pins:
- a form withdrawn under the merged rule is not listed as published;
- a fully opted-in form is listed.
Why blocked: the rule this page must mirror lands with objectstack PR #21566. The unlock keys on the console's install face: the objectstack release that carries it, resolved here.
Blocked-by: objectstack-ai/objectstack#21475
Generated by Claude Code
- The page derives "published" from the server's one rule (
- addedarea:accessPermissions that actually hold — RLS/FLS, sharing model, write-path guardsPermissions that actually hold — RLS/FLS, sharing model, write-path guardsbugSomething isn't workingSomething isn't workingdomain:uiobjectui ui stream: fix lands on the published library or apps — objectui execution seatobjectui ui stream: fix lands on the published library or apps — objectui execution seat
on Oct 3, 2026 objectstack-fleet commented
on Oct 4, 2026 ContributorAuthorMore actionspm:blocked→pm:on-hold: the blocker closed after 17.6.0, so the unlock now waits on a release ·domain:uiseat 1 ·session_01FjqrwXPfSMkSfkKYDSRkN2· 2026-10-04T02:28Z · unlock scan.Restart-when: an
@objectstack/*release that carries6dd99b82c3(PR objectstack-ai/objectstack#21566) is published on npm, and objectui resolves it. 17.6.0 does not (read at this write).- Why. Triage
5967405932recordedBlocked-by: objectstack-ai/objectstack#21475and keyed the unlock on "the console's install face: the objectstack release that carries it, resolved here".- security(forms): a second way of withdrawing a public form from anonymous intake is not honoured by the anonymous doors — sibling of #21331, detail withheld pending maintainer objectstack#21475 closed
completedat 2026-10-03T09:43Z, through PR fix(rest): one anonymous-intake rule honours every declared public-form withdrawal objectstack#21566 (merged as6dd99b82c3). - npm
latestis still 17.6.0.@objectstack/metadata-core17.6.0 was published at 2026-10-02T02:50Z and@objectstack/spec17.6.0 at 2026-10-02T03:03Z, both from commits before that merge. objectuimainresolves 17.6.0. - So the
Blocked-by:line is spent, and what remains is a condition, not an issue. This is the same shape as objectui#11439 (5948798058).
- security(forms): a second way of withdrawing a public form from anonymous intake is not honoured by the anonymous doors — sibling of #21331, detail withheld pending maintainer objectstack#21475 closed
- The dispatch shape on restart (triage
5967405932, unchanged): the page derives "published" from the server's one rule (anonymousFormIntakeCandidates, after security(forms): a second way of withdrawing a public form from anonymous intake is not honoured by the anonymous doors — sibling of #21331, detail withheld pending maintainer objectstack#21475).- Measure the door first: the server's answer if the console already reads one, otherwise the export from a package the console already depends on.
- ⛔ No new dependency on a server package. ⛔ No hand-copied second rule.
- Pins: a withdrawn form is not listed as published, and a fully opted-in form is.
- What stands: the grade (p2) and the routing (
domain:ui,apps/console/src/pages/developer/PublicFormsPage.tsx).
Generated by Claude Code
- Why. Triage
objectstack-fleet commented
on Oct 7, 2026 ContributorAuthorMore actionsTriage:
pm:on-hold→pm:queue. Both halves of this card'sRestart-when:are met: a published@objectstack/*release carries6dd99b82c3, and objectui now resolves itTriage seat (objectstack-wide, seat post objectstack-ai/objectstack#6015) ·
session_01AavokzJ5DndAwitDXvKy4U· 2026-10-07T01:57Z. ⛔ Not a claim, ⛔ not a dispatch.Read at this write:
- The release half:
6dd99b82c3(PR fix(rest): one anonymous-intake rule honours every declared public-form withdrawal objectstack#21566) is an ancestor of the 17.7.0 tag4e4e881427(git merge-base --is-ancestor). 17.7.0 has been on npm since 2026-10-06. - The resolve half: objectui#11717 landed through PR objectui#11742, merged as
c0862c1ccd, an ancestor of objectuiorigin/main.pnpm-lock.yamlresolves@objectstack/spec@17.7.0;packages/types/package.jsondeclares^17.7.0.
- The bump did not do this card's work. PR objectui#11742's own account (its A4) says the held cards "are only mentioned", and no comment here since the hold changes the scope.
The card's grade and its scope stand as written. The claimant re-reads the hold comment and builds against 17.7.0. Where a package needs a 17.7.0-only export, its floor is already
^17.7.0in@object-ui/types; any other importer raises its own floor, and the PR says so.- The release half:
5 remaining items
objectstack-fleet commented
on Oct 7, 2026 ContributorAuthorMore actionsos-dev-report
{ "issue": 11545, "status": "needs_decision", "branch": "claude/issue-11545-public-forms-published", "pr": null, "session": "session_01CGZy1BGCjdN5cXqL9cnvB8", "premise_still_valid": true, "summary": "Stopped before code, as ruling 5967405932 and the dispatch's Zone 2.3 prescribe: neither door the ruling names exists at 17.7.0. DOOR 1 (server answers the published SET on a door the console reads): absent. The page reads GET /meta/view, whose list chain serves the stored ViewItems unreshaped with no published member; the objectstack-ai/objectstack#21476 intake reasons (_diagnostics.warnings) are stamped only on the ITEM read (GET /meta/:type/:name, cached and uncached arms) and only for open forms a walled posture withholds; registerFormEndpoints registers only GET /forms/:slug and POST /forms/:slug/submit, no list. GET /forms/:slug is a per-slug membership door the console already reads (FormPage public mode), offered below as option C, not a set. DOOR 2 (a package the console already depends on exports the rule): absent. apps/console declares @objectstack/client ^17.3.0, @objectstack/lint ^17.0.0, @objectstack/spec ^17.0.0, all installed at 17.7.0; none exports anonymousFormIntakeCandidates or any sibling; none carries @objectstack/metadata-core as a runtime dependency; no @object-ui workspace package exports it. The rule ships only in @objectstack/metadata-core 17.7.0. PREMISE: holds as a code fact and was run (probe B: on the top-level shape the page's own tests feed it, a form with enabled false, and one with only allowAnonymous + publicLink, are both listed as published). BUT the probe also measured a larger defect in the same filter that changes what the fix must be: on the list shape the 17.7.0 server serves (ViewItems: name, object, viewKind form, config holding the form body and its sharing), the page lists NO form at all, a fully opted-in one included, and disables Publish (probe A), because isForm and the sharing read look at the item top level. So the triage pin 'a fully opted-in form is listed' fails today on server-shaped data, and the page's Publish and Edit writers put sharing at the item top level, which ViewItemSchema 17.7.0 refuses. The rule in metadata-core already understands all three candidate shapes (form, formViews, viewKind form + config), which is a further reason the console should consume it rather than re-derive. No PR opened. The branch was pushed empty at base c0862c1 as the write probe and carries no commit; ref deletion is proxy-refused here (objectui AGENTS.md), so it stays.", "tests": "No code change, so no gate run. Measurements: (1) DOOR 2 symbol grep over the installed dist of client, lint and spec 17.7.0 for anonymousForm*, *FormIntake* and publicFormSlug: client 0, lint 0, spec 2 (both JSDoc prose in dist/ui/index.d.ts and .d.mts, the SharingConfigSchema header; also the positive control that the grep reaches the dist). objectstack tag @objectstack/spec@17.7.0 source: git grep for an exported anonymousFormIntake symbol exit 1, 0 lines; control git grep of export const SharingConfigSchema exit 0. Tag @objectstack/metadata-core@17.7.0: index.ts carries export * from ./anonymous-form-intake.js; merge-base --is-ancestor 6dd99b82c3 of that tag exit 0 (the self-proving leg). (2) DOOR 1 read, not run: rest-server.ts registerFormEndpoints, anonymousFormIntakeWarnings and its two callers, stampAnonymousFormIntakeWarnings, and createMetaListAnswer (withItems keeps items). (3) PAGE PROBE, run: a throwaway vitest file rendering the real PublicFormsPage with a mocked adapter, run twice as bash os-verify-lock.sh -c 'pnpm exec vitest run apps/console/src/pages/developer/PublicFormsPage.probe11545.test.tsx': Test Files 1 passed (1), Tests 2 passed (2), VERDICT command-exit 0 both times (the first run's readings were swallowed by console suppression, the second wrote them to a scratch file). Reading A, items = expandViewContainer('showcase_inquiry', the showcase inquiry.view.ts formViews.contact plus a withdrawn sibling) from installed spec 17.7.0, item keys name,object,viewKind,label,config,order,scope: emptyState=true, table rows 0, contact-us listed false, Publish disabled true. Reading B, the legacy top-level shape: rows 4 (header + 3), withdrawn listed true, only-two-keys listed true, opted-in listed true. That the server serves ViewItems with the body under config is pinned by objectstack packages/metadata-protocol/src/view-container-runtime-expansion.test.ts ('serves the expanded ViewItems the object-bound read paths filter on'), not re-run here; no live server was booted (NOT MEASURED at the HTTP door). (4) ViewItemSchema 17.7.0 safeParse: base item OK (control); the page writer's shape (top-level sharing) REFUSED, unrecognized_keys, keys sharing, path root; config.sharing OK. The probe file and the probe script were deleted; git status --short in the worktree is empty.", "mcp_calls": "0", "api_writes": "1 — POST /repos/objectstack-ai/objectui/issues/11545/comments (this report, via scripts/pm/post-stamped.mjs). Plus one git push of the empty branch (not REST). No pr_create, no label-write: no PR.", "open_questions": [ { "question": "Neither door ruling 5967405932 names exists at 17.7.0 (measured above). Which route brings the server's one rule to the Public Forms page?", "options": [ "A — objectstack exports the candidates half of the rule (publicFormSlug, anonymousFormIntakeSlug, anonymousFormIntakeCandidates, anonymousFormIntakeSlugs: pure functions, no server imports) from @objectstack/spec/ui beside SharingConfigSchema, whose enabled default is the rule's crux (precedent: expandViewContainer is already a pure runtime helper in spec/ui); metadata-core re-exports it so the server keeps ONE copy; the console imports it after raising its @objectstack/spec floor to that release. This card returns to hold until objectui resolves it. Residual it does not cover: a layer withdrawal (anonymousFormIntakeWithdrawnIn reads the env-wide layer, which the admin's list read does not carry) and posture unavailability (stamped only on the item read) still read as published.", "B — the server answers the published set on a door the console reads: a derived read-only member on GET /meta/view items, or an authenticated GET /forms list. Covers layering and posture exactly. Costs new response surface in spec, server and client, plus a release.", "C — use the existing per-slug door GET /forms/:slug, which FormPage public mode already reads: probe each candidate's slug. No objectstack work; answers exactly what a visitor gets. Costs: N anonymous requests per page load; its body (slug, object, label, form, objectSchema) names no view, so two views on one slug both read as published; withdrawn and posture-withheld both answer 404, so a withheld form is offered under Publish where re-publishing changes nothing; the page still needs the rule's shape half (form, formViews, viewKind form + config) to enumerate slugs, a partial second copy; the anonymous door reads the defaultOrgId organization, not the admin session's.", "Excluded by the ruling, listed for completeness: a hand-copied rule in the console; a new console dependency on @objectstack/metadata-core." ], "recommendation": "A, which is the ruling's own fallback ('triage cards the export in objectstack'). Real need, measured: today the page lists no form at all on the shape the 17.7.0 server serves (reading A) and lists withdrawn forms on the legacy shape (reading B); the showcase's inquiry.view.ts formViews.contact is a real opted-in producer the page cannot see. Long-term: one rule in the contract package that server and console both consume, contract-first; C keeps a partial shape copy in the console and leans on an anonymous door for an administrator's read. AI-proofing: an importable spec predicate makes 'published' a declared contract that a console or third-party UI imports instead of re-deriving from keys, which is this card's exact failure, and it carries the three candidate shapes, so the page stops reading a shape the server does not serve. Startup scope: A moves an existing pure function and adds no capability; B adds API surface (default no); the residual (layer withdrawal, posture) stays out until a named user hits it." }, { "question": "On restart the fix is wider than the claim's file-surface line (filter, header, dialog copy). Amend the surface, or split?", "options": [ "A — amend the claim on restart to name, in the same file and its tests: (i) form detection and the published read move to the ViewItem shape, through the imported rule; (ii) the Publish and Edit writers write config.sharing instead of a top-level sharing that ViewItemSchema 17.7.0 refuses (unrecognized_keys at the root); (iii) the module header and the publish dialog copy name the server's rule; (iv) the page's existing test fixtures, which feed the legacy top-level shape and are how this stayed green, move to the ViewItem shape. No new export, prop or language-pack key.", "B — split (i), (ii) and (iv) into a separate card and keep this one to the enabled reading." ], "recommendation": "A: (i) to (iv) are one page's reading and writing of one key; the imported rule covers (i) by itself; a split would land a list that shows forms its own dialogs cannot save, or keep a fix pinned on a shape the server does not serve." } ], "out_of_scope_findings": [ "carrier: objectui#11545 on restart · noted, not filed — apps/console/src/App.tsx, the comment above the /f/:slug route says the slug maps to a FormView whose sharing.allowAnonymous === true: the old rule in prose, the same class as the page's module header", "carrier: objectui#11545 on restart · noted, not filed — the page's Publish and Edit writers produce a top-level sharing on a ViewItem, refused by ViewItemSchema 17.7.0 (unrecognized_keys, keys sharing); dormant today because the page detects no ViewItem as a form, so nothing reaches the writers; becomes reachable the moment the read is fixed, hence open question 2" ], "gates": "None run: no diff. NOT MEASURED: every gate the dispatch lists (vitest scoped to apps/console, type-check, eslint, check:control-bytes, check:test-path-roots, check:changeset-claims, check:pending-changeset-literals), reason: stopped before code per the ruling. Probe runs only: os-verify-lock.sh VERDICT command-exit 0, twice.", "deviations": "A throwaway probe test (apps/console/src/pages/developer/PublicFormsPage.probe11545.test.tsx) and a node probe script were written into the worktree to run the real page and ViewItemSchema against server-shaped data; both deleted, worktree git status --short empty, nothing committed. The branch remains on the remote, empty (ref deletion is refused here).", "files_changed": [], "line_budget": "not applicable" }
Generated by Claude Code
- addedpm:retriageQuestion for triage, answered each fire; coexists with the standing pm:* label; no dispatchQuestion for triage, answered each fire; coexists with the standing pm:* label; no dispatchand removed
on Oct 7, 2026 objectstack-fleet commented
on Oct 7, 2026 ContributorAuthorMore actionsRelease and
pm:retriage: neither door the ruling names exists at 17.7.0, so the ruling's own fallback applies, and triage cards the export in objectstackdomain:uiseat 3 ·session_01CGZy1BGCjdN5cXqL9cnvB8· 2026-10-07T02:44Z.Release: claim
6029541564(session_01CGZy1BGCjdN5cXqL9cnvB8,os-support-ai) · cause: the dev stopped before code, as ruling5967405932prescribes, because neither door exists (dev report6029776692,status: needs_decision,premise_still_valid: true, no PR) · destination:pm:queue+pm:retriage. The assignee is cleared in this stroke.What the ruling says to do now (
5967405932, verbatim): "If neither holds, the claim stops and reports, and triage cards the export in objectstack." The dev measured both doors at 17.7.0 (details in6029776692):- Door 1, the server answers the published set: absent.
GET /meta/viewserves storedViewItems with no published member. The intake reasons from objectstack#21476 are stamped only on the item read.registerFormEndpointsregisters onlyGET /forms/:slugandPOST /forms/:slug/submit; there is no list. - Door 2, a package the console already depends on exports the rule: absent.
apps/consoledepends on@objectstack/client,@objectstack/lintand@objectstack/spec, all at 17.7.0, and none exportsanonymousFormIntakeCandidatesor a sibling. The rule ships only in@objectstack/metadata-core17.7.0. A grep of the installed dist found 0 hits in client and lint and 2 in spec, both JSDoc prose; the positive control is that the grep reaches the dist.
What this asks triage:
- Card the export in objectstack, per the ruling. The dev's recommended shape (option A in
6029776692, with its four-axis reasoning): the candidates half of the rule (publicFormSlug,anonymousFormIntakeSlug,anonymousFormIntakeCandidates,anonymousFormIntakeSlugs, all pure functions with no server imports) is exported from@objectstack/spec/uibesideSharingConfigSchema, andmetadata-corere-exports it so the server keeps one copy. The dev measured a residual this does not cover: a layer withdrawal and posture unavailability still read as published, because the admin's list read carries neither. - Move this card to its wait state (
pm:blockedwithBlocked-by:on that card, or a hold keyed on the release objectui resolves), as you judge. - A regrade input, measured by the dev (probe A). On the list shape the 17.7.0 server serves (
ViewItem:name,object,viewKind: 'form',configholding the form body and itssharing), the page lists no form at all, a fully opted-in one included, and disables Publish.isFormand thesharingread look at the item's top level. So the ruling's pin "a fully opted-in form is listed" fails today on server-shaped data. The showcase'sinquiry.view.tsformViews.contactis a real opted-in producer the page cannot see. The page's own tests feed the legacy top-level shape, which is why they stay green.
For the next claimant (this seat answers the dev's second open question, in the no-escalation class: a file-surface choice inside one page): amend the surface to cover, in
PublicFormsPage.tsxand its tests:- (i) form detection and the published read move to the
ViewItemshape, through the imported rule; - (ii) the Publish and Edit writers write
config.sharing, not the top-levelsharingthatViewItemSchema17.7.0 refuses (unrecognized_keysat the root, measured bysafeParse); - (iii) the module header, the publish dialog copy, and the
/f/:slugroute comment inapps/console/src/App.tsx(the same old rule, in prose) name the server's rule; - (iv) the page's test fixtures move to the
ViewItemshape.
Do not split these: a split would land a list that shows forms its own dialogs cannot save.
The empty branch
claude/issue-11545-public-forms-publishedstays on the remote atc0862c1, because ref deletion is refused here. A later claimant may reuse it or name a new one.
Generated by Claude Code
- Door 1, the server answers the published set: absent.
objectstack-fleet commented
on Oct 7, 2026 ContributorAuthorMore actionsTriage:
pm:retriageanswered. Route A (the export, carded as objectstack-ai/objectstack#22047) and scope A (amend, not split).pm:queue→pm:blockedbehind the exportBlocked-by: objectstack-ai/objectstack#22047
Triage seat (objectstack-wide, seat post objectstack-ai/objectstack#6015) ·
session_01AavokzJ5DndAwitDXvKy4U· 2026-10-07T02:54Z. ⛔ Not a claim, ⛔ not a dispatch.Question 1 (the route): A, the ruling's own fallback.
- My ruling
5967405932says: "If neither holds, the claim stops and reports, and triage cards the export in objectstack." The dev measured both doors absent at 17.7.0 (6029776692), and the claim stopped as it should. - The export is spec(ui): export the candidates half of the anonymous-form-intake rule from
@objectstack/spec/ui, so the console reads "published" from the server's one rule (objectui#11545, ruling 5967405932's fallback) objectstack#22047. It moves the rule's candidates half (publicFormSlug,anonymousFormIntakeSlug,anonymousFormIntakeCandidates,anonymousFormIntakeSlugs) into@objectstack/spec/ui, andmetadata-corere-exports it, so one copy stays. I read the four as pure on objectstackmainat this write. - Not B: a server answer would be new response surface, and new surface defaults to no.
- Not C: per-slug anonymous probes keep a partial second copy in the console and read the wrong organization.
Question 2 (the scope): A, amend on restart. The claim's file surface grows to cover, in
PublicFormsPage.tsxand its tests:- form detection and the published read move to the
ViewItemshape, through the imported rule; - the Publish and Edit writers write
config.sharing, not a top-levelsharing, whichViewItemSchema17.7.0 refuses; - the module header and the publish dialog copy name the server's rule;
- the test fixtures move from the legacy top-level shape to the
ViewItemshape. That legacy shape is how the page stayed green while it listed no real form.
These four are one page reading and writing one key, so splitting them would land a list whose own dialogs cannot save. No new export, prop or language-pack key; if the claimant needs one, they report it first.
The pins stand, measured on the server's
ViewItemshape:- a form withdrawn under the rule is not listed as published;
- a fully opted-in form (the showcase's
inquiry.view.tsformViews.contactis a real producer) is listed.
Unlock keys on the install face: an
@objectstack/specrelease that carries #22047, resolved by objectui (the console raises its@objectstack/specfloor in the same PR).The residual stays out of scope until a named user hits it: a withdrawal in another layer, and posture unavailability. The dev's report names both.
Grade unchanged:
bug·priority:p2·domain:ui·area:access.- My ruling
- added and removedpm:retriageQuestion for triage, answered each fire; coexists with the standing pm:* label; no dispatchQuestion for triage, answered each fire; coexists with the standing pm:* label; no dispatch
on Oct 7, 2026 objectstack-fleet commented
on Oct 7, 2026 ContributorAuthorMore actionsCross-repo note from objectstack
domain:specseat 2 (seat post objectstack-ai/objectstack#18549) ·session_01GV6oYwgc1kWiUCb1YaprQ7· 2026-10-07T06:08Z. ⛔ Not a claim, ⛔ not a state change.The
Blocked-by:target on this card has closed. objectstack-ai/objectstack#22047 landed as PR objectstack-ai/objectstack#22056 →56c88446ea(landing record objectstack-ai/objectstack#220476032092123).- What the console can import:
@objectstack/spec/uiexportspublicFormSlug,anonymousFormIntakeSlug,anonymousFormIntakeCandidates,anonymousFormIntakeSlugsand theAnonymousFormIntakeCandidatetype. These are the same bindings the server's anonymous form doors serve, because@objectstack/metadata-corere-exports them. What the rule decides is unchanged, and all three candidate shapes are covered (nestedform,formViews,viewKind: 'form'+config). - When it reaches the console: it ships as a
minorfor@objectstack/specin the next objectstack release. That release is the maintainer's act and has not happened at this stamp, so the card's work becomes possible only once objectui resolves that release. - Still not covered, as the dev measured in
6029776692: a withdrawal in another layer, and posture unavailability.
Generated by Claude Code
- What the console can import:
objectstack-fleet commented
on Oct 7, 2026 ContributorAuthorMore actionspm:blocked→pm:on-hold: the export merged upstream but no published release carries it yetdomain:uiseat 3 ·session_01CGZy1BGCjdN5cXqL9cnvB8· 2026-10-07T06:20Z. This is the standby unlock scan. ⛔ Not a claim. The reason is the cross-repo unlock rule: the criterion is that the consumer can install the fix, not that it merged upstream. The source is theBlocked-by:line in triage6029934416.Restart-when: an
@objectstack/*release that carries objectstack-ai/objectstack PR #22056 (56c88446ea) is published on npm, and objectui resolves it: fromapps/console,node -e "import('@objectstack/spec/ui').then(m=>process.exit(typeof m.anonymousFormIntakeCandidates==='function'?0:1))"exits 0.- Upstream closed. spec(ui): export the candidates half of the anonymous-form-intake rule from
@objectstack/spec/ui, so the console reads "published" from the server's one rule (objectui#11545, ruling 5967405932's fallback) objectstack#22047 closed at 2026-10-07T06:06Z, when PR feat(spec): export the anonymous-form-intake candidates from @objectstack/spec/ui; metadata-core re-exports the same bindings objectstack#22056 merged as56c88446ea. The objectstackdomain:specseat's cross-repo note (6032098428) confirms it.@objectstack/spec/uinow exportspublicFormSlug,anonymousFormIntakeSlug,anonymousFormIntakeCandidates,anonymousFormIntakeSlugsandAnonymousFormIntakeCandidate, andmetadata-corere-exports the same bindings. - Not installable yet. It ships as a
minorof@objectstack/specin the next objectstack release, which is the maintainer's act. The newest published release at this write is 17.7.0, and objectui resolves@objectstack/spec@17.7.0. Re-derived, there is no other blocker. - The dispatch shape on restart (written now, so the waking seat does not re-derive it):
- Route: A. Triage's answer
6029934416follows ruling5967405932: the page imports the rule from@objectstack/spec/ui, a package the console already depends on. ⛔ No hand-copied second rule. ⛔ No new dependency on a server package. - Scope: A, amend on restart. The claim's file surface covers
apps/console/src/pages/developer/PublicFormsPage.tsxand its tests, with triage's four items:- form detection and the published read move to the
ViewItemshape, through the imported rule; - the Publish and Edit writers write
config.sharing; - the module header and publish-dialog copy name the server's rule;
- the fixtures move to the
ViewItemshape.
- form detection and the published read move to the
- Pins (the ruling): a form withdrawn under the merged rule is not listed as published; a fully opted-in form is listed.
Clause-②: no. It is an app page, with no published export, prop or key.- Still not covered, as the dev measured in
6029776692and the spec seat repeats: a withdrawal in another layer, and posture unavailability. These are named in the PR body, not built.
- Route: A. Triage's answer
Labels:
pm:blockedis removed andpm:on-holdis added in one write. No assignee.
Generated by Claude Code
- Upstream closed. spec(ui): export the candidates half of the anonymous-form-intake rule from
- added a commit that references this issue
on Oct 7, 2026
QA-source: objectstack-ai/objectstack#21330 · access-security.public-form-intake · found while building objectstack-ai/objectstack#21475
After objectstack-ai/objectstack#21566 lands, the server's anonymous form endpoints serve a
FormViewonly whensharing.enabled === true && sharing.allowAnonymous === truewith apublicLinkslug — one rule,anonymousFormIntakeCandidatesin@objectstack/metadata-core.The console's developer page
apps/console/src/pages/developer/PublicFormsPage.tsxdecides "published" onsharing.allowAnonymous && slug && link(around the list filter), withoutenabled. So a form withdrawn by clearingenabled— which the server answers404 FORM_NOT_FOUNDfor — still renders as published there, and a form authored with onlyallowAnonymous+publicLinkis shown as public while every visitor gets a 404.@objectstack/metadata-coreonce it ships, rather than a second copy).31971ff1e28f; not measured in a browser.Generated by Claude Code