Skip to content

fix(detail): the approval band honors the node's lockRecord instead of assuming every approval locks (#2902) - #2906

Merged
os-zhuang merged 1 commit into
mainfrom
claude/issue-2902-review-6497df
Jul 28, 2026
Merged

fix(detail): the approval band honors the node's lockRecord instead of assuming every approval locks (#2902)#2906
os-zhuang merged 1 commit into
mainfrom
claude/issue-2902-review-6497df

Conversation

@baozhoutao

Copy link
Copy Markdown
Contributor

Closes #2902. 依赖 framework objectstack-ai/objectstack#3815(新字段 lock_record)。

定性:是 bug,且是「从来没接出来」而非回归

lockRecord 是 spec 里正式的节点配置项(ApprovalNodeConfigSchemaz.boolean().default(true)),服务端在 plugin-approvalsbeforeUpdate 钩子里严格执行。平台自己定义、自己执行的开关,UI 不读 —— 平台内部行为不一致。

git 追溯确认不是回归:objectui 的 approvalLocked#2572 引入时就是「approval_status 或有 pending request」的二值判断,#2618 只补了第二个来源,从未有过节点粒度;framework 侧的行投影也从第一版起就没带过锁信号。这个能力自诞生起就是 server-only。

影响面比 issue 描述的更大

issue 只提了 band 文案。实际上同一个信号还掐着 canEditRecordDetailView.tsx):

canEdit={... && !approvalLocked}

所以 lockRecord: false 的节点上行内编辑被整个禁掉 —— 铅笔不出现、enter() 空转。报告人是从独立「编辑」表单路由进去才存成功的,那条路没接这个门。实际业务里审批链上的单人节点(部门负责人 / 厂长)正是配 lockRecord: false,本意就是让审批人在审批时补充内容 —— 这个能力在 Console 里比 issue 写的更彻底地不存在。

改动

审批状态拆成两个信号:

  • approvalPending —— 有审批在跑。驱动 band 和撤回按钮,两者无论记录可不可改都有意义。
  • locked —— 这个审批还禁编辑。取自当前 pending 节点的 lock_record

band 两态:琥珀色锁 +「审批中已锁定」,或天蓝色时钟 +「审批中 · 可编辑」,各自独立 tooltip。撤回按钮移出 locked 分支 —— 可编辑的 pending 审批一样可以撤回,原来藏在锁分支里等于不锁的节点连撤回都没了。

InlineEditProvider 新增可选 approvalPending,缺省回落到 locked,只 thread locked 的老 host 行为完全不变。记录自身的 approval_status 仍作为无 approvals API 后端的兜底,它没有节点粒度所以只能读作锁定;老后端不返回 lock_record 时同样 fail closed —— 放出一个必然被服务端拒掉的编辑,比藏起一个本可放行的更糟。

新增 detail.approvalPendingEditable / detail.approvalPendingTooltip,十种语言全部翻译。

真机 UI 实测

showcase 后端 + objectui HMR console,推了一条真实审批走完两个节点(framework PR 里把 Manager Review 改成 lockRecord: false、Executive Review 保持 true):

  1. Data Platform 预算 600k→620k 触发 → 停在 Manager Review,API lock_record: false
  2. 详情页 band = 天蓝时钟「审批中 · 可编辑」,撤回按钮在,编辑按钮可用
  3. 双击「已花费」行内编辑,420,000 → 431,000 保存成功,落库
  4. 批准 → 进 Executive Review(lock_record: true)→ band 当场翻成琥珀色锁「审批中已锁定」
  5. 再双击同一字段 → 不进编辑,保持只读

API 同步确认两条 request:Manager Review / approved / lock_record:falseExecutive Review / pending / lock_record:true

测试

新增 12 条:band 两态 5 条(可编辑态文案 / 独立 tooltip / 锁定态仍为锁 / 只给 locked 的老 host 不变 / 无审批不渲染)、InlineEditContext 3 条(两信号独立 / 缺省回落 / 可编辑态 enter() 仍可用)、recordLockedByApproval 5 条(含 fail-closed 与「flow 推进时逐节点独立读」)。

plugin-detail + react + app-shell hooks 共 724 通过,i18n 91 通过。

合并顺序

framework PR 先合。没有它时 lock_recordundefined,本 PR 逻辑 fail closed 回落到当前行为,不会崩。

🤖 Generated with Claude Code

@vercel

vercel Bot commented Jul 28, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated (UTC)
objectui Ignored Ignored Jul 28, 2026 7:04am

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

Metric Value Budget
Main entry (gzip) 27.9 KB 350 KB
Entry file index-2g7V4-k6.js
Status PASS

📦 Bundle Size Report

Package Size Gzipped
app-shell (index.js) 8.20KB 2.97KB
app-shell (runtime-config.js) 7.42KB 2.32KB
app-shell (types.js) 0.01KB 0.04KB
app-shell (urlParams.js) 7.57KB 2.97KB
auth (AuthContext.js) 0.31KB 0.24KB
auth (AuthGuard.js) 1.17KB 0.53KB
auth (AuthProvider.js) 22.10KB 4.37KB
auth (AuthShell.js) 3.49KB 1.40KB
auth (ForgotPasswordForm.js) 12.12KB 3.41KB
auth (LoginForm.js) 17.86KB 5.29KB
auth (PreviewBanner.js) 0.90KB 0.50KB
auth (RegisterForm.js) 6.43KB 2.09KB
auth (SocialSignInButtons.js) 9.60KB 3.89KB
auth (UserMenu.js) 3.40KB 1.22KB
auth (auth-gate-events.js) 1.29KB 0.66KB
auth (authStyles.js) 5.04KB 1.72KB
auth (createAuthClient.js) 35.76KB 9.11KB
auth (createAuthenticatedFetch.js) 4.37KB 1.69KB
auth (index.js) 2.17KB 0.96KB
auth (org-roles.js) 5.50KB 2.36KB
auth (phone-identifier.js) 1.11KB 0.66KB
auth (types.js) 0.59KB 0.35KB
auth (useAuth.js) 4.91KB 0.87KB
auth (useIsWorkspaceAdmin.js) 1.61KB 0.85KB
collaboration (CommentThread.js) 18.38KB 4.49KB
collaboration (LiveCursors.js) 3.17KB 1.27KB
collaboration (PresenceAvatars.js) 3.65KB 1.42KB
collaboration (PresenceProvider.js) 2.79KB 1.13KB
collaboration (index.js) 1.25KB 0.53KB
collaboration (useCommentSearch.js) 1.98KB 0.88KB
collaboration (useConflictResolution.js) 7.75KB 1.86KB
collaboration (useMentionNotifications.js) 1.81KB 0.68KB
collaboration (usePresence.js) 6.33KB 1.84KB
collaboration (useRealtimeSubscription.js) 7.91KB 2.01KB
components (index.js) 449.62KB 97.73KB
core (index.js) 2.12KB 0.77KB
create-plugin (index.js) 9.28KB 2.98KB
data-objectstack (index.js) 127.78KB 32.15KB
fields (index.js) 218.37KB 53.54KB
i18n (LocalizationContext.js) 1.76KB 0.96KB
i18n (currency.js) 1.22KB 0.64KB
i18n (i18n.js) 4.32KB 1.77KB
i18n (index.js) 2.46KB 0.96KB
i18n (pickLocalized.js) 1.70KB 0.83KB
i18n (provider.js) 5.37KB 1.72KB
i18n (useObjectLabel.js) 25.17KB 5.80KB
i18n (useSafeTranslation.js) 3.26KB 1.44KB
layout (index.js) 38.45KB 10.67KB
mobile (MobileProvider.js) 0.92KB 0.49KB
mobile (ResponsiveContainer.js) 0.94KB 0.38KB
mobile (breakpoints.js) 1.51KB 0.70KB
mobile (createOfflineDataSource.js) 5.61KB 1.74KB
mobile (index.js) 1.50KB 0.62KB
mobile (offlineQueue.js) 3.91KB 1.35KB
mobile (pwa.js) 0.97KB 0.49KB
mobile (serviceWorker.js) 1.48KB 0.62KB
mobile (serviceWorkerSource.js) 3.41KB 1.48KB
mobile (useBreakpoint.js) 1.54KB 0.65KB
mobile (useGesture.js) 4.42KB 1.27KB
mobile (useOfflineSync.js) 1.99KB 0.72KB
mobile (usePullToRefresh.js) 2.53KB 0.85KB
mobile (useResponsive.js) 0.71KB 0.42KB
mobile (useResponsiveConfig.js) 1.36KB 0.63KB
mobile (useSpecGesture.js) 1.77KB 0.77KB
mobile (useTouchTarget.js) 1.01KB 0.54KB
permissions (MePermissionsProvider.js) 6.84KB 2.42KB
permissions (PermissionContext.js) 0.31KB 0.25KB
permissions (PermissionGuard.js) 0.89KB 0.45KB
permissions (PermissionProvider.js) 3.67KB 1.12KB
permissions (evaluator.js) 4.00KB 1.23KB
permissions (index.js) 0.91KB 0.41KB
permissions (store.js) 0.91KB 0.42KB
permissions (useFieldPermissions.js) 1.28KB 0.52KB
permissions (usePermissions.js) 1.55KB 0.71KB
plugin-ai (index.js) 15.71KB 3.79KB
plugin-calendar (index.js) 44.90KB 12.35KB
plugin-charts (index.js) 57.26KB 16.24KB
plugin-chatbot (index.js) 179.94KB 42.67KB
plugin-dashboard (index.js) 109.60KB 28.33KB
plugin-designer (index.js) 210.56KB 42.56KB
plugin-detail (index.js) 215.33KB 52.53KB
plugin-editor (index.js) 2.46KB 1.10KB
plugin-form (index.js) 103.47KB 25.10KB
plugin-gantt (index.js) 162.26KB 39.53KB
plugin-grid (index.js) 179.25KB 46.97KB
plugin-kanban (index.js) 47.82KB 13.18KB
plugin-list (index.js) 98.64KB 23.33KB
plugin-map (index.js) 16.80KB 5.24KB
plugin-markdown (index.js) 13.65KB 4.67KB
plugin-report (index.js) 37.07KB 9.81KB
plugin-timeline (index.js) 25.03KB 7.11KB
plugin-tree (index.js) 8.36KB 2.81KB
plugin-view (index.js) 85.68KB 20.85KB
providers (DataSourceProvider.js) 0.75KB 0.39KB
providers (MetadataProvider.js) 1.37KB 0.59KB
providers (ThemeProvider.js) 1.55KB 0.67KB
providers (UploadProvider.js) 11.71KB 3.53KB
providers (index.js) 0.44KB 0.22KB
providers (types.js) 0.01KB 0.04KB
react-runtime (index.js) 3.19KB 1.38KB
react (LazyPluginLoader.js) 3.77KB 1.33KB
react (SchemaRenderer.js) 18.70KB 6.09KB
react (data-invalidation.js) 5.05KB 2.08KB
react (index.js) 1.00KB 0.55KB
sdui-parser (codegen.js) 4.09KB 1.74KB
sdui-parser (index.js) 2.16KB 0.94KB
sdui-parser (parse.js) 10.04KB 2.82KB
sdui-parser (types.js) 0.29KB 0.24KB
sdui-parser (validate.js) 4.69KB 1.48KB
types (ai.js) 0.20KB 0.17KB
types (api-types.js) 0.20KB 0.18KB
types (app.js) 2.87KB 0.99KB
types (base.js) 0.20KB 0.18KB
types (blocks.js) 0.20KB 0.18KB
types (complex.js) 0.20KB 0.18KB
types (crud.js) 0.20KB 0.18KB
types (data-display.js) 0.20KB 0.18KB
types (data-protocol.js) 0.20KB 0.19KB
types (data.js) 0.20KB 0.18KB
types (designer.js) 0.77KB 0.41KB
types (disclosure.js) 0.20KB 0.18KB
types (feedback.js) 0.20KB 0.18KB
types (field-types.js) 0.20KB 0.18KB
types (form.js) 0.20KB 0.18KB
types (index.js) 1.86KB 0.91KB
types (layout.js) 0.20KB 0.18KB
types (managed-by.js) 0.19KB 0.18KB
types (mobile.js) 0.20KB 0.18KB
types (navigation.js) 0.20KB 0.18KB
types (objectql.js) 0.20KB 0.18KB
types (overlay.js) 0.20KB 0.18KB
types (permissions.js) 0.20KB 0.18KB
types (plugin-scope.js) 0.20KB 0.18KB
types (record-components.js) 0.20KB 0.19KB
types (record-semantics.js) 1.28KB 0.67KB
types (registry.js) 0.20KB 0.18KB
types (reports.js) 0.20KB 0.18KB
types (spec-report.js) 5.04KB 1.93KB
types (system-fields.js) 2.39KB 1.17KB
types (theme.js) 0.20KB 0.18KB
types (ui-action.js) 0.75KB 0.46KB
types (views.js) 0.20KB 0.18KB
types (widget.js) 0.20KB 0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

… of assuming every approval locks (#2902)

The detail page treated "a pending approval request exists" as "this record is
locked". An approval node declares `lockRecord` (default `true`), and on
`lockRecord: false` the server keeps accepting writes while that node waits —
so the console asserted a lock the backend did not enforce.

The label was the smaller half. The same conflated signal fed `canEdit`, so the
record-level inline-edit session was suppressed too: no pencils, `enter()` a
no-op. On a single-approver step — the case `lockRecord: false` exists for,
where the approver is meant to fill in the missing detail before deciding — the
capability was unreachable from the UI. And a flow chaining nodes with different
policies drew one identical band for "edit freely" and "your save dies with
RECORD_LOCKED", so the states were indistinguishable until Save failed.

Approval state is now two signals: `approvalPending` (an approval is running —
drives the band and recall, both meaningful either way) and `locked` (it also
forbids edits, from the pending node's `lock_record`). The band renders amber
lock + "Locked for approval" or sky clock + "In approval · editable", each with
its own tooltip; recall left the locked branch, since an editable pending
approval is just as recallable.

`InlineEditProvider`'s new `approvalPending` prop defaults to `locked`, so a
host threading only `locked` is unchanged. The `approval_status` fallback has no
node granularity and still reads as locked, as does a pending request from a
backend too old to report the policy — failing closed beats offering an edit the
server rejects.

Needs framework#3814 for `lock_record` on the request row.

Closes #2902

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@os-zhuang
os-zhuang merged commit 952b978 into main Jul 28, 2026
14 checks passed
@os-zhuang
os-zhuang deleted the claude/issue-2902-review-6497df branch July 28, 2026 14:38
xuyushun441-sys pushed a commit that referenced this pull request Jul 28, 2026
The approval-band half of this PR landed independently as #2906 while it
was open, so the merge is mostly a de-duplication. Resolved toward main
for everything #2906 already shipped, keeping only what is genuinely new
here.

Taken from main wholesale:
- `useRecordApprovals` — main's `lock_record` + `recordLockedByApproval`.
  This PR's field name `locks_record` was simply wrong: framework#3834
  merged as `lock_record`, which is what the server actually sends.
- `InlineEditContext` — identical `approvalPending` contract; no diff left.
- the band's markup/styling (sky "In approval · editable" variant) and the
  `approvalPendingEditable` / `approvalPendingTooltip` key names, dropping
  this PR's `inApprovalEditable*` spelling of the same two strings.

Kept from this branch:
- `disabled: approvalLocked` on the header Edit CTA. #2906 gated inline
  edit but left the full-form CTA live on a locked record, so the user
  still filled a screen before Save returned RECORD_LOCKED.
- `DetailView` no longer OR-s the `approval_status` mirror into `isLocked`
  unconditionally. A flow configuring an `approvalStatusField` mirrors
  `approval_status: 'pending'` regardless of `lockRecord`, so on a
  `lockRecord: false` node main's derivation re-locked the band while the
  host had correctly resolved "not locked" — pencils live and saves
  landing under a band reading "Locked for approval". `approvalPending &&
  !locked` is the tell that the host has an opinion (the provider defaults
  `approvalPending` to `locked`, so a pre-#2902 host can never produce it).
  Covered by a new test.
- the recall tooltip's unlocked variant, and everything in parts 2 and 3
  (batch `droppedFields` warnings, the localized by-reason toast, and
  dropping the hand-stamped `updated_at`), which main never touched.

Also drops a duplicate `Clock` import git merged in from both sides.

Green: 2849 tests across plugin-detail / data-objectstack / i18n / react /
app-shell; `pnpm type-check` clean on all 76 packages; 0 lint errors.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

DetailView「审批中已锁定」band 不读节点 lockRecord:lockRecord:false 的审批节点上照样显示锁定 + 撤回

2 participants