Skip to content

cli/console: the deployment's SDUI component manifest reaches the metadata save door (page.requires enforcement, stage ①) #20542

Description

@objectstack-fleet

Ruled: 5902378057 · letter A + E — the channel is a kernel service under one constant key exported by @objectstack/metadata-protocol, read per publish; built together with #20312 stage ② in one domain:cli PR; this card closes not_planned, merged into #20312 stage ② (cloud#2482 follows) · 2026-09-30T01:47Z

Filed by the director seat (objectstack#12708, session_01AsCNgFBs8HCjwhyHQsFbx3) as the predecessor of #20312, per ruling 5881821895 on that card (batch #241 item 1, letter A, maintainer 「同意」): page.requires is enforced per ADR-0080 §5 in three stages, and this card is stage ①. ⛔ Not a claim.

What

No host hands the metadata save door a component manifest today, so the door cannot judge an html page's source against the deployment's components:

  • evaluateRuntimeAuthoringGate accepts an optional sduiManifest (packages/metadata-protocol/src/runtime-authoring-gate.ts:625, passed through at :697); its one call site, packages/metadata-protocol/src/protocol.ts:5148, does not pass it.
  • The CLI resolves a manifest for os validate / os build / os lint (packages/cli/src/utils/sdui-manifest.ts, resolveSduiManifest): the project's sdui.manifest.json, else @objectstack/console/dist/sdui.manifest.json. @objectstack/console's package.json exports map exposes only ./package.json, so that fallback specifier is expected to fail Node's exports check and resolve absent — NOT MEASURED; measure it first.
  • os serve does not resolve a manifest at all.

Do

  1. Measure the console fallback: does createRequire(...).resolve('@objectstack/console/dist/sdui.manifest.json') succeed under the package's exports? If not, add the subpath to @objectstack/console's exports (one line) so the CLI's existing fallback and this card's reader both work.
  2. os serve (and the standalone host path it shares) resolves the manifest through resolveSduiManifest and passes it into evaluateRuntimeAuthoringGate as sduiManifest.
  3. A host that resolves no manifest prints one boot line — 「page source and requires are not validated at save: no SDUI manifest」 — instead of degrading silently (the [finding] os validate / compile / lint validate JSX pages at parse level only when no SDUI manifest resolves, and say nothing: the author-time JSX gate silently degrades #20113 posture on the CLI side).
  4. Pins: the save door receives the manifest when the host has one; the boot line appears when it has none; the console fallback resolves.

Out of scope here, stages ② and ③ on #20312: compiling the page source at save, stamping requires, the load-time report.

Clause-②: no (nothing narrows until stage ②). Lane: domain:cli (the host and the console package); the save-door pass-through is a one-line change in metadata-protocol.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:studioChanging a running app without code — authoring, publish, docs and the portaldomain:clienhancementNew feature or requestpriority:p2Medium: important, M3

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions