Skip to content

fix(list,data): bridge every spec view operator onto the filter AST (#2901) - #2974

Merged
os-zhuang merged 1 commit into
mainfrom
fix/filter-operator-ast-parity
Jul 30, 2026
Merged

fix(list,data): bridge every spec view operator onto the filter AST (#2901)#2974
os-zhuang merged 1 commit into
mainfrom
fix/filter-operator-ast-parity

Conversation

@os-zhuang

Copy link
Copy Markdown
Contributor

A stored view filter using before or after came back unfiltered. Not an error — every row, silently.

Client half of the defect; server hardening is objectstack-ai/objectstack#3948.

The defect

before/after are canonical members of the spec's VIEW_FILTER_OPERATORS (ui/view.zod.ts:90), so a stored view legitimately carries them. They are absent from VALID_AST_OPERATORS (data/filter.zod.ts:352), which gates isFilterAST().

Neither objectui translation table had an entry, so:

  1. objectFilterEntryToASTnormalizeFilterOperator ends ?? opbefore reaches the wire verbatim
  2. isFilterAST(['close_date','before','2024-01-01'])false
  3. protocol.ts:2757 assigns the array to options.where unconverted (it is a conversion gate, not a validation gate)
  4. sql-driver applyFilters walks it — the three elements are all strings, so each hits the string branch and is continued
  5. No WHERE clause. Every row returned.

Verified by executing the real spec:

["close_date","before","2024-01-01"]   isFilterAST=false   *** PASSED THROUGH UNCONVERTED ***
["status","=","active"]                isFilterAST=true    -> {"status":"active"}

The trigger is the single-condition case. toSpecFilter (view-config-utils.ts:158) returns a bare triple for one AND condition — the shape that vanishes. Two or more conditions produce a nested array, which reaches the driver's wider switch and throws instead. The failure mode flips on how many conditions the author happened to add.

Not a permission bypass, to be precise: row-scoping $and-composes as a separate arm and survives. The impact is an unfiltered result set on unscoped objects, and a confusing SQL error on scoped ones.

Also fixed

mapOperator emitted 'not in' with a space — in no spec vocabulary. Arrays never reached the wire (normalizeFilterCondition expands them into an AND of inequalities), but a non-array value escaped as an unfiltered query.

The guard found eight more on its first run

notequals, greaterthan, lessthan, greaterorequal, greaterThanOrEqual, lessorequal, lessThanOrEqual, notin.

All are spellings the spec's VIEW_FILTER_OPERATOR_ALIASES still folds — and all are live in stored metadata, because saveMeta persists the authored body verbatim (protocol.ts:4481: "The original item is kept verbatim"), so the spec's own z.preprocess(normalizeFilterOperator, …) normalizes for the validity check and then throws the result away.

The switch had been enumerating spellings by hand and had already missed eight of them, so mapOperator now matches case- and underscore-insensitively — collapsing the class rather than the instances.

Guards

Two parity tests, one per package, asserting in both directions:

  • every value in each translation table is a member of VALID_AST_OPERATORS;
  • every canonical VIEW_FILTER_OPERATORS member survives isFilterAST() in the reachable bare-triple shape;
  • every legacy alias the spec still folds also maps to a real AST operator.

So the next operator the spec adds to the view vocabulary fails a test instead of quietly returning unfiltered rows.

Needs @objectstack/spec as a devDependency in both packages — safe now that every importer resolves to a single spec version (#2950).

Verification

  • New guards: 42 pass. Full plugin-list + data-objectstack suites: 439 pass across 29 files.
  • eslint: 0 errors.
  • The guard was confirmed to fail before the fix — that is how the eight extra spellings surfaced.

🤖 Generated with Claude Code

…2901)

A stored view filter using `before` or `after` came back **unfiltered**. Not an
error — every row, silently.

`before`/`after` are canonical members of the spec's `VIEW_FILTER_OPERATORS`
(`ui/view.zod.ts`), so a view legitimately carries them. They are absent from
`VALID_AST_OPERATORS` (`data/filter.zod.ts`), which gates `isFilterAST()`.
Neither translation table had an entry, so they reached the wire verbatim, the
server's gate rejected the shape, the protocol passed the array through
unconverted, and driver-sql then skipped it entirely — no WHERE clause emitted.
See objectstack#3948 for the server-side hardening; this is the client half.

The trigger is the single-condition case: `toSpecFilter` emits a bare triple for
one AND condition, which is the shape that vanishes. Two or more conditions
produce a nested array, which reaches the driver's wider switch and throws.

Also fixes `mapOperator` emitting `'not in'` with a space — in no spec
vocabulary. Arrays never reached the wire (`normalizeFilterCondition` expands
them), but a non-array value escaped as an unfiltered query.

The new parity guard caught eight more on its first run — `notequals`,
`greaterthan`, `lessthan`, `greaterorequal`, `greaterThanOrEqual`, `lessorequal`,
`lessThanOrEqual`, `notin`. All are spellings the spec's
`VIEW_FILTER_OPERATOR_ALIASES` still folds, and all are live in stored metadata
because `saveMeta` persists the authored body verbatim, so the spec's own
`z.preprocess` normalization never reaches the row. Rather than enumerate them,
`mapOperator` now matches case- and underscore-insensitively, which collapses the
class instead of the instances.

Guards assert both tables land inside `VALID_AST_OPERATORS` and that every
canonical `VIEW_FILTER_OPERATORS` member survives `isFilterAST()` — so the next
operator the spec adds fails a test instead of returning unfiltered rows.
Requires `@objectstack/spec` as a devDependency in both packages; safe now that
all importers resolve to one spec version.

Refs #2901, objectstack#3948

Co-Authored-By: Claude <noreply@anthropic.com>
@vercel

vercel Bot commented Jul 30, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated (UTC)
objectui Ignored Ignored Jul 30, 2026 2:46am

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

Metric Value Budget
Main entry (gzip) 27.9 KB 350 KB
Entry file index-DwXpcuuB.js
Status PASS

📦 Bundle Size Report

Package Size Gzipped
app-shell (index.js) 8.20KB 2.97KB
app-shell (runtime-config.js) 7.42KB 2.32KB
app-shell (types.js) 0.01KB 0.04KB
app-shell (urlParams.js) 7.57KB 2.97KB
auth (AuthContext.js) 0.31KB 0.24KB
auth (AuthGuard.js) 1.17KB 0.53KB
auth (AuthProvider.js) 22.10KB 4.37KB
auth (AuthShell.js) 3.49KB 1.40KB
auth (ForgotPasswordForm.js) 12.12KB 3.41KB
auth (LoginForm.js) 17.86KB 5.29KB
auth (PreviewBanner.js) 0.90KB 0.50KB
auth (RegisterForm.js) 6.43KB 2.09KB
auth (SocialSignInButtons.js) 9.60KB 3.89KB
auth (UserMenu.js) 3.40KB 1.22KB
auth (auth-gate-events.js) 1.29KB 0.66KB
auth (authStyles.js) 5.04KB 1.72KB
auth (createAuthClient.js) 35.76KB 9.11KB
auth (createAuthenticatedFetch.js) 4.37KB 1.69KB
auth (index.js) 2.25KB 1.01KB
auth (org-roles.js) 6.72KB 2.85KB
auth (phone-identifier.js) 1.11KB 0.66KB
auth (types.js) 0.59KB 0.35KB
auth (useAuth.js) 4.91KB 0.87KB
auth (useIsWorkspaceAdmin.js) 1.61KB 0.85KB
collaboration (CommentThread.js) 18.38KB 4.49KB
collaboration (LiveCursors.js) 3.17KB 1.27KB
collaboration (PresenceAvatars.js) 3.65KB 1.42KB
collaboration (PresenceProvider.js) 2.79KB 1.13KB
collaboration (index.js) 1.25KB 0.53KB
collaboration (useCommentSearch.js) 1.98KB 0.88KB
collaboration (useConflictResolution.js) 7.75KB 1.86KB
collaboration (useMentionNotifications.js) 1.81KB 0.68KB
collaboration (usePresence.js) 6.33KB 1.84KB
collaboration (useRealtimeSubscription.js) 7.91KB 2.01KB
components (index.js) 450.74KB 98.10KB
core (index.js) 2.16KB 0.78KB
create-plugin (index.js) 9.28KB 2.98KB
data-objectstack (index.js) 130.52KB 32.99KB
fields (index.js) 221.10KB 54.18KB
i18n (LocalizationContext.js) 1.76KB 0.96KB
i18n (currency.js) 1.22KB 0.64KB
i18n (i18n.js) 4.32KB 1.77KB
i18n (index.js) 2.46KB 0.96KB
i18n (pickLocalized.js) 1.70KB 0.83KB
i18n (provider.js) 5.37KB 1.72KB
i18n (useObjectLabel.js) 25.17KB 5.80KB
i18n (useSafeTranslation.js) 3.26KB 1.44KB
layout (index.js) 38.45KB 10.67KB
mobile (MobileProvider.js) 0.92KB 0.49KB
mobile (ResponsiveContainer.js) 0.94KB 0.38KB
mobile (breakpoints.js) 1.51KB 0.70KB
mobile (createOfflineDataSource.js) 5.61KB 1.74KB
mobile (index.js) 1.50KB 0.62KB
mobile (offlineQueue.js) 3.91KB 1.35KB
mobile (pwa.js) 0.97KB 0.49KB
mobile (serviceWorker.js) 1.48KB 0.62KB
mobile (serviceWorkerSource.js) 3.41KB 1.48KB
mobile (useBreakpoint.js) 1.54KB 0.65KB
mobile (useGesture.js) 4.42KB 1.27KB
mobile (useOfflineSync.js) 1.99KB 0.72KB
mobile (usePullToRefresh.js) 2.53KB 0.85KB
mobile (useResponsive.js) 0.71KB 0.42KB
mobile (useResponsiveConfig.js) 1.36KB 0.63KB
mobile (useSpecGesture.js) 1.77KB 0.77KB
mobile (useTouchTarget.js) 1.01KB 0.54KB
permissions (MePermissionsProvider.js) 6.84KB 2.42KB
permissions (PermissionContext.js) 0.31KB 0.25KB
permissions (PermissionGuard.js) 0.89KB 0.45KB
permissions (PermissionProvider.js) 3.67KB 1.12KB
permissions (evaluator.js) 4.41KB 1.44KB
permissions (index.js) 0.91KB 0.41KB
permissions (store.js) 0.91KB 0.42KB
permissions (useFieldPermissions.js) 1.28KB 0.52KB
permissions (usePermissions.js) 1.55KB 0.71KB
plugin-ai (index.js) 15.71KB 3.79KB
plugin-calendar (index.js) 44.90KB 12.35KB
plugin-charts (index.js) 57.26KB 16.24KB
plugin-chatbot (index.js) 179.93KB 42.67KB
plugin-dashboard (index.js) 109.60KB 28.33KB
plugin-designer (index.js) 210.56KB 42.56KB
plugin-detail (index.js) 216.52KB 53.02KB
plugin-editor (index.js) 2.46KB 1.10KB
plugin-form (index.js) 103.32KB 25.08KB
plugin-gantt (index.js) 162.26KB 39.53KB
plugin-grid (index.js) 179.45KB 47.03KB
plugin-kanban (index.js) 47.82KB 13.18KB
plugin-list (index.js) 98.30KB 23.23KB
plugin-map (index.js) 16.80KB 5.24KB
plugin-markdown (index.js) 13.65KB 4.67KB
plugin-report (index.js) 37.77KB 10.00KB
plugin-timeline (index.js) 25.03KB 7.11KB
plugin-tree (index.js) 8.36KB 2.81KB
plugin-view (index.js) 85.47KB 20.82KB
providers (DataSourceProvider.js) 0.75KB 0.39KB
providers (MetadataProvider.js) 1.37KB 0.59KB
providers (ThemeProvider.js) 1.55KB 0.67KB
providers (UploadProvider.js) 11.71KB 3.53KB
providers (index.js) 0.44KB 0.22KB
providers (types.js) 0.01KB 0.04KB
react-runtime (index.js) 3.19KB 1.38KB
react (LazyPluginLoader.js) 3.77KB 1.33KB
react (SchemaRenderer.js) 18.70KB 6.09KB
react (data-invalidation.js) 5.05KB 2.08KB
react (index.js) 1.02KB 0.55KB
sdui-parser (codegen.js) 4.09KB 1.74KB
sdui-parser (index.js) 2.16KB 0.94KB
sdui-parser (parse.js) 10.04KB 2.82KB
sdui-parser (types.js) 0.29KB 0.24KB
sdui-parser (validate.js) 4.69KB 1.48KB
types (ai.js) 0.20KB 0.17KB
types (api-types.js) 0.20KB 0.18KB
types (app.js) 2.87KB 0.99KB
types (base.js) 0.20KB 0.18KB
types (blocks.js) 0.20KB 0.18KB
types (complex.js) 0.20KB 0.18KB
types (crud.js) 0.20KB 0.18KB
types (data-display.js) 0.20KB 0.18KB
types (data-protocol.js) 0.20KB 0.19KB
types (data.js) 0.20KB 0.18KB
types (designer.js) 0.77KB 0.41KB
types (disclosure.js) 0.20KB 0.18KB
types (feedback.js) 0.20KB 0.18KB
types (field-types.js) 0.20KB 0.18KB
types (form.js) 0.20KB 0.18KB
types (index.js) 1.86KB 0.91KB
types (layout.js) 0.20KB 0.18KB
types (managed-by.js) 0.19KB 0.18KB
types (mobile.js) 0.20KB 0.18KB
types (navigation.js) 0.20KB 0.18KB
types (objectql.js) 0.20KB 0.18KB
types (overlay.js) 0.20KB 0.18KB
types (permissions.js) 0.20KB 0.18KB
types (plugin-scope.js) 0.20KB 0.18KB
types (record-components.js) 0.20KB 0.19KB
types (record-semantics.js) 1.28KB 0.67KB
types (registry.js) 0.20KB 0.18KB
types (reports.js) 0.20KB 0.18KB
types (spec-report.js) 5.04KB 1.93KB
types (system-fields.js) 2.39KB 1.17KB
types (theme.js) 0.20KB 0.18KB
types (ui-action.js) 0.75KB 0.46KB
types (views.js) 0.20KB 0.18KB
types (widget.js) 0.20KB 0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-zhuang
os-zhuang merged commit 0ebee89 into main Jul 30, 2026
16 checks passed
@os-zhuang
os-zhuang deleted the fix/filter-operator-ast-parity branch July 30, 2026 04:46
os-zhuang added a commit that referenced this pull request Jul 30, 2026
The spec-17 addendum said "5, not 6" and then listed six package names. Six is
right: `plugin-list` and `data-objectstack` gained the devDependency in #2974,
but the body's original count of 6 came from a 13-package list that omitted
`fields`, which also lacks it. Verified against main.

The number is used to scope the parity-guard work, so a wrong one misplans it.

Refs #2901

Co-authored-by: Jack Zhuang <277994282+os-zhuang@users.noreply.github.com>
os-zhuang added a commit that referenced this pull request Jul 30, 2026
…e whole view vocabulary (#2945) (#2989)

`SPEC_TO_BUILDER_OP` resolved 10 of the spec's 19 canonical
`VIEW_FILTER_OPERATORS`. The nine it missed — not_equals, starts_with,
ends_with, greater_than, less_than, greater_than_or_equal,
less_than_or_equal, is_null, is_not_null — are all canonical members a
stored view legitimately carries, and each reached the FilterBuilder as a
raw spelling its dropdown cannot select.

Same defect and cause as #2974, one table over: spellings enumerated by
hand. Now derived from the spec's own canonical list and
VIEW_FILTER_OPERATOR_ALIASES, matched case- and separator-insensitively.

Four canonical operators have no FilterBuilder equivalent and are recorded
as asserted `null`s rather than folded onto a near-equivalent, which would
rewrite the author's operator on the next save.

Also retires BUILDER_TO_SPEC_OP + toSpecFilter — the write direction, dead
since the studio's spec-driven inspector replaced buildViewConfigSchema,
and objectui's last emitter of `'not in'`, `before` and `after` as
filter-AST operators (objectstack-ai/objectstack#3948).

@object-ui/components now exports FILTER_BUILDER_OPERATORS so tables that
map onto that vocabulary assert against it instead of restating it.

Refs #2945, #2901

Co-authored-by: Jack Zhuang <277994282+os-zhuang@users.noreply.github.com>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant