You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
#20802 analytics half (domain:services): the cube read and the analytics read scope answer { relation: { field: value } } as the engine seam now serves it — as the caller, capped, one answer on every face #20887
Filing gate: ④ a coordination node, the per-layer child of #20802. It carries the half of ruling 5907789183 (maintainer 「20802 同意」) that lives in packages/services/service-analytics. Reader: the domain:services seat, which claims it once it is queued.
Filed by the domain:engine execution seat 1 (session_01DEvba2nBuD4tWzfq8r8NFY, os-support-ai), which landed the engine half. ⛔ Filed bare: routing and grading belong to triage. ⛔ Not a claim.
What the ruling asks of this half (verbatim, 5907789183)
"The same answer on every face: CRUD (engine.find, POST /api/v1/data/:object/query) and the analytics cube read the same form the same way once the seam serves it; the analytics read-scope refusal of the nested form aligns with the seam's permission rule."
What exists today (re-check at origin/main)
The cube read flattens the form into a dotted member (profile.verified), resolved through the cube's declared join. git grep -n "Nested relation (e.g." origin/main -- packages/services/service-analytics/src/strategies/filter-normalizer.ts → 1
Whether that answers the engine's rows, runs as the caller with the related object's row scope and field permissions, and is bounded, is this card's to measure.
The read scope refuses the form. git grep -n 'non-$ key means a nested relation' origin/main -- packages/services/service-analytics/src/read-scope-sql.ts → 1
Scope for whoever takes it (⛔ not a ruling)
For one dataset, the cube read answers the form with the same rows the engine answers:
single-valued and multi-valued relations;
a related field the caller cannot read is refused loudly, never emptied;
past the cap, refused, never truncated.
Measure the NativeSQL and ObjectQL strategies both.
The read scope's refusal is either lifted to serve the form under the same permission rule, or kept with words that name the served route. The seat that claims this card says which, and why.
⛔ No driver change (D4 (b)). ⛔ No second copy of the permission rule.
Dedupe
mcp__github__search_issues, repo-scoped, open and closed, in the act that filed this card:
Filing gate: ④ a coordination node, the per-layer child of #20802. It carries the half of ruling 5907789183 (maintainer 「20802 同意」) that lives in
packages/services/service-analytics. Reader: thedomain:servicesseat, which claims it once it is queued.Filed by the
domain:engineexecution seat 1 (session_01DEvba2nBuD4tWzfq8r8NFY,os-support-ai), which landed the engine half. ⛔ Filed bare: routing and grading belong to triage. ⛔ Not a claim.Why now
main. PR feat(objectql): serve the nested-relation filter in where — lowered at the engine seam, the related object read as the caller, a loud cap, drivers untouched (#20802) #20872 was merged asca5408c62(landing record on [Decision] v18:查询能否直接按关联记录的字段筛选(例:「客户行业 = 科技」的商机) #20802).{ relation: { field: value } }is served inwhereat the [finding] 仓内存在 5 个独立的过滤器→谓词编译器,每次语义裁决成本 ×5 —— 值得立「谓词编译收敛」调查程序(#5298 成本清单副产品) #5930 seam:fields: ['id'],limitcap+1);$in, or an$orof$containsper id for a multi-valued relation;RELATION_FILTER_ID_CAP(1000, exported by@objectstack/objectql), refused loudly past it;403 PERMISSION_DENIED.main. [finding] 仓内存在 5 个独立的过滤器→谓词编译器,每次语义裁决成本 ×5 —— 值得立「谓词编译收敛」调查程序(#5298 成本清单副产品) #5930 step 3 (#5930 step 3: the shared filter lowering at the analytics seams (the analyticswhere/ preview door, the read scope) and the memory cube face's door, with the F5 / F11 output vocabulary #20810, PR feat(service-analytics,driver-memory): the shared filter lowering at the analytics seams and the cube face's new door (#5930 step 3) #20857,793fb839) runs the shared lowering at the analyticswheredoor, the preview, the read scope and the memory cube face.What the ruling asks of this half (verbatim, 5907789183)
"The same answer on every face: CRUD (
engine.find,POST /api/v1/data/:object/query) and the analytics cube read the same form the same way once the seam serves it; the analytics read-scope refusal of the nested form aligns with the seam's permission rule."What exists today (re-check at
origin/main)profile.verified), resolved through the cube's declared join.git grep -n "Nested relation (e.g." origin/main -- packages/services/service-analytics/src/strategies/filter-normalizer.ts→ 1Whether that answers the engine's rows, runs as the caller with the related object's row scope and field permissions, and is bounded, is this card's to measure.
git grep -n 'non-$ key means a nested relation' origin/main -- packages/services/service-analytics/src/read-scope-sql.ts→ 1Scope for whoever takes it (⛔ not a ruling)
Measure the NativeSQL and ObjectQL strategies both.
Dedupe
mcp__github__search_issues, repo-scoped, open and closed, in the act that filed this card:jsonfield, compiled by NativeSQLStrategy, answers one group per serialized document on SQLite and 500 on PostgreSQL; the engine door #20783 closes does not see it #20807 (open) is ajsondimension. #5930 step 3: the shared filter lowering at the analytics seams (the analyticswhere/ preview door, the read scope) and the memory cube face's door, with the F5 / F11 output vocabulary #20810, [finding] a no-operator object under a lookup, master_detail or json field answers per driver: the declared nested-relation filter returns no rows on memory and a 400 on SQL, and a json object comparand deep-equals on memory and is refused on SQL #20745, [finding]skills/objectstack-queryteaches the nested relation filter{ relation: { field: value } }as a working form; no data-path driver serves it, and PR #20781 makes the engine refuse it #20782, [finding] service-analytics read scope: compileScopedFilterToSql applies no whole-day upper bound and binds a temporal comparand as written, so an RLS $lte on a bare day drops the rest of that day in NativeSQL analytics #20733, security: the analytics ObjectQL execute face answers a row-level read scope it cannot run withINVALID_FILTER/ 400 whose message echoes the policy's field name and comparands — the disclosure #5367 closed for the native / echo faces #19995, A list inside a nested-relation condition in a dataset or measure filter ({ account: { region: ['a'] } }) passes the save-time schema door and is refused only when the chart runs #20080 / A list inside a nested-relation condition in a dataset or measure filter ({ account: { region: ['a'] } }) passes the save-time schema door and is refused only when the chart runs #20081 and service-analytics: the NativeSQL read-scope compiler and the/analytics/sqlecho compile two scope shapes the shared comparand faces refuse (plain-object comparand under$eq, null member in$in): one scope, two answers across faces #20018 are closed neighbours. None carries this half.Dedupe words:
20802 analytics half·cube read nested relation filter as the caller·read scope nested relation refusal servedGenerated by Claude Code