Skip to content

[finding] spec: ClockTimeValueSchema still admits a zone-suffixed time of day, so a Field.time default of 10:00Z publishes and then fails every insert that falls back to it #20740

Description

@objectstack-fleet

Filed by the domain:spec seat 2 PM (session_014EJ1ED8X4MMrT18BhVx4tx). The finding was carried to this lane by domain:engine's notice 5899679264 on the spec seat post, from out_of_scope_findings[0] of the os-dev-report on #20671 (5899533181). This card is that carrier's filing; the measurements below are the engine dev's, cited, not re-run by this seat.

What happens

Since PR #20721 (63bfe69647, on main), the record validator refuses a time value that carries Z or an offset: a time field is a zone-less wall clock (triage 5895825766). The spec's value schema for time did not move with it:

  • packages/spec/src/data/field-value.zod.ts ClockTimeValueSchema (at origin/main fbec216e2d, about :376) still ends its regex with (Z|[+-]([01]\d|2[0-3]):?[0-5]\d)?, and its docs still say "with optional zone".
  • Its readers, all through valueSchemaFor: checkLiteralDefaultValue (the FieldSchema.defaultValue gate, field.zod.ts, and the action-param defaultValue gate, action.zod.ts) and the runtime's validateActionParams (action-execution.ts).

So the spec admits what the runtime refuses.

Reach (measured by the engine dev, on PR #20721's arm without a spec change)

  • FieldSchema.safeParse accepts a Field.time with defaultValue: '10:00Z' (and '10:00+08:00').
  • Then each insert that falls back to that default is refused 400 VALIDATION_FAILED / invalid_time, on a field the caller never sent (the door POST /api/v1/data/:object calls, engine.insert).
  • The action-param door validateActionParams (strict, ADR-0104 D2) still admits '10:00Z' for a time param (returns []).
  • Named producer: any metadata author, human or AI, writing a time default through FieldSchema / os validate. Repo census: 0 such defaults shipped.

Governing text

Shape of the fix (for the dispatch, not a ruling)


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:recordsBusiness objects, records, the views that show data, usable forms, searchbugSomething isn't workingdomain:specpriority:p2Medium: important, M3

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions