Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 14 additions & 0 deletions .changeset/spec-remainder-provenance-anchors.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
---
'@objectstack/spec': patch
---

Provenance comments in the rest of `src/` were re-anchored

The remaining comment and docblock lines in 21 files under `src/` (among
them `api/rest-server.zod.ts`, `system/i18n-resolver.ts`,
`system/operation-message.ts`, `shared/identifiers.zod.ts`, the root
`index.ts` and `data/driver/turso.zod.ts`) cited tracker numbers that no
longer resolve on GitHub. They now cite the commit in this repository's
history that decided the matter, or the ADR amendment that records the
ruling, and say in their own words what was decided. Comments only: no type,
schema, export, message-catalog string or runtime behaviour changes.
4 changes: 2 additions & 2 deletions content/docs/references/automation/schedule-organization.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -81,8 +81,8 @@ evidence line). Before this card the two halves disagreed under `group`: the
history row was stamped from the record while the inbox and delivery rows
followed an acting context that could not exist there, so they were refused.
Filling the acting context from the record makes one run carry ONE
organization's opinion about who it belonged to — which is the defect #16659
opened on, read from the other side.
organization's opinion about who it belonged to — which is the defect commit
ecdfc9411 fixed, read from the other side.

⚠️ With ONE stated exception, so the sentence above is not read as a promise
it cannot keep. The two halves ask different questions and are answered by
Expand Down
2 changes: 1 addition & 1 deletion content/docs/references/data/driver-turso.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@ hosts dispatched `turso` for real. So a libSQL datasource could carry
then connect unauthenticated, which is precisely the failure #4410 exists to
end, surviving in the one driver #4410 could not see.

The maintainer's #6345 ruling closes it by making turso a complete builtin
The maintainer's ruling (commit e2798fab7) closes it by making turso a complete builtin
rather than a permanent exception. Optionality of the PACKAGE is orthogonal to
existence of the CONTRACT — `mongodb` and `sqlite-wasm` are optional installs
too, and both have had a contract since #4410.
Expand Down
2 changes: 1 addition & 1 deletion packages/spec/src/ai/index.ts
Original file line number Diff line number Diff line change
Expand Up @@ -41,7 +41,7 @@ export * from './build-progress.zod';
// [#12414] entry-nameability: these factories' return types expand to mention
// `/data`'s `FilterCondition` and `/automation`'s `StateNodeConfig` — both
// public on their own subpaths but not nameable from `/ai`. Same invariant
// (maintainer ruling recorded on #11350), same repair: re-export from the
// (maintainer ruling recorded in commit ece4dad31), same repair: re-export from the
// declaring module.
export type { FilterCondition } from '../data/filter.zod';
export type { StateNodeConfig } from '../automation/state-machine.zod';
24 changes: 12 additions & 12 deletions packages/spec/src/api/rest-server.zod.ts
Original file line number Diff line number Diff line change
Expand Up @@ -325,11 +325,11 @@ export const CrudOperation = z.enum([

export type CrudOperation = z.input<typeof CrudOperation>;

// `CrudEndpointPatternSchema` — REMOVED (#14691)
// `CrudEndpointPatternSchema` — REMOVED (commit b3a63d32c)
//
// The per-operation `{ method, path, summary, description }` pattern shape was
// the value type of `crud.patterns`, retired below under ADR-0049
// enforce-or-remove (the #14369 liveness census: every CRUD route is mounted
// enforce-or-remove (the liveness census commit a3d5724c8 recorded: every CRUD route is mounted
// from fixed method/path pairs in `packages/rest`'s `registerCrudEndpoints`,
// so a custom pattern was validated and never read). With its carrier key
// tombstoned the def had no consumer left, and an exported schema nothing
Expand Down Expand Up @@ -362,7 +362,7 @@ export const CrudEndpointsConfigSchema = lazySchema(() => z.object({
}).optional().describe('Enable/disable operations'),

/**
* [REMOVED in #14691] Per-operation custom URL patterns. Tombstoned rather
* [REMOVED in commit b3a63d32c] Per-operation custom URL patterns. Tombstoned rather
* than deleted: this schema is not `.strict()`, so a plain deletion would
* silently strip the key and an author would keep a config that "customizes"
* routes the server mounts from fixed pairs (ADR-0104, #3733). The mounted
Expand All @@ -386,7 +386,7 @@ export const CrudEndpointsConfigSchema = lazySchema(() => z.object({
dataPrefix: z.string().default('/data').describe('URL prefix for data endpoints'),

/**
* [REMOVED in #14691] The object-name parameter style. Every CRUD route takes
* [REMOVED in commit b3a63d32c] The object-name parameter style. Every CRUD route takes
* the object name as a PATH segment; `'query'` was validated against the enum
* and mounted exactly what `'path'` mounts. Tombstoned, not deleted — the
* schema is not `.strict()` (see `patterns` above).
Expand Down Expand Up @@ -445,7 +445,7 @@ export const MetadataEndpointsConfigSchema = lazySchema(() => z.object({
enableCache: z.boolean().default(true).describe('Enable HTTP cache headers (ETag, Last-Modified)'),

/**
* [REMOVED in #14691] The metadata cache TTL. `enableCache` selects the
* [REMOVED in commit b3a63d32c] The metadata cache TTL. `enableCache` selects the
* protocol's `getMetaItemCached` read path, which takes no TTL, and no
* `Cache-Control` / `ETag` / `Last-Modified` header was ever built from this
* value — `cacheTtl: 60` changed no header and no cache lifetime (and, having
Expand Down Expand Up @@ -541,7 +541,7 @@ export const MetadataEndpointsConfigSchema = lazySchema(() => z.object({
+ '`GET /meta/_drafts` and the `POST /meta/_migrate-stored` write door',
),
/**
* [REMOVED in #14691] Gated a route that does not exist: the REST server
* [REMOVED in commit b3a63d32c] Gated a route that does not exist: the REST server
* mounts no `GET /meta/:type/:name/schema`, so `false` removed nothing and
* `true` added nothing. Its three siblings each gate a real mount.
*/
Expand Down Expand Up @@ -604,7 +604,7 @@ export const BatchEndpointsConfigSchema = lazySchema(() => z.object({
updateMany: z.boolean().default(true).describe('Enable POST /data/:object/updateMany'),
deleteMany: z.boolean().default(true).describe('Enable POST /data/:object/deleteMany'),
/**
* [REMOVED in #14691] Gated a route that was never built: there is no
* [REMOVED in commit b3a63d32c] Gated a route that was never built: there is no
* `POST /data/:object/upsertMany` and no protocol member behind it (the
* protocol carries `createManyData` / `updateManyData` / `deleteManyData`
* and no upsert counterpart). Upsert is an operation TYPE of the generic
Expand All @@ -621,7 +621,7 @@ export const BatchEndpointsConfigSchema = lazySchema(() => z.object({
}).optional().describe('Enable/disable specific batch operations'),

/**
* [REMOVED in #14691] A server-side default for batch atomicity. No batch
* [REMOVED in commit b3a63d32c] A server-side default for batch atomicity. No batch
* handler ever consulted it: atomicity is decided per request by
* `options.atomic` in the batch body (`BatchOptionsSchema`, ADR-0119 D4 —
* opt-in, default `false`, aligned to what every caller already gets). A
Expand Down Expand Up @@ -649,8 +649,8 @@ export type BatchEndpointsConfigParsed = z.infer<typeof BatchEndpointsConfigSche
/**
* Route Generation Configuration Schema
*
* [#14691] Every key of this sub-object is a `retiredKey()` tombstone: the
* #14369 liveness census found the whole block parsed, defaulted and
* [commit b3a63d32c] Every key of this sub-object is a `retiredKey()` tombstone: the
* liveness census recorded in commit a3d5724c8 found the whole block parsed, defaulted and
* normalized into the REST server's config and never read back —
* `excludeObjects: ['sys_log']` excluded nothing, `nameTransform: 'plural'`
* mounted every route under the raw object name, and the per-object
Expand Down Expand Up @@ -753,8 +753,8 @@ export type RouteGenerationConfigParsed = z.infer<typeof RouteGenerationConfigSc
* }
*
* To keep an object off the REST data surface, declare it on the object
* (`enable.apiEnabled: false`, or an `enable.apiMethods` whitelist) — the
* `routes` sub-object's selectors were retired in #14691 because nothing read them.
* (`enable.apiEnabled: false`, or an `enable.apiMethods` whitelist) — the `routes`
* sub-object's selectors were retired by commit b3a63d32c because nothing read them.
*/
export const RestServerConfigSchema = lazySchema(() => z.object({
/**
Expand Down
2 changes: 1 addition & 1 deletion packages/spec/src/automation/control-flow.zod.ts
Original file line number Diff line number Diff line change
Expand Up @@ -348,7 +348,7 @@ export type TryCatchConfigParsed = z.infer<typeof TryCatchConfigSchema>;
* try/catch outside any loop binds neither, so their absence means "not in a
* loop", never "row unknown".
*
* `code` (#14419 / #14954) is the platform-classified error code (ADR-0112)
* `code` (commit c5a7448d5 / #14954) is the platform-classified error code (ADR-0112)
* the failing node's own result carried — `create_record`'s `DUPLICATE_RECORD`
* is the founding case — bound so a catch region can tell "the row is already
* there" from "the store is down" by branching on `$error.code` instead of
Expand Down
2 changes: 1 addition & 1 deletion packages/spec/src/automation/execution.zod.ts
Original file line number Diff line number Diff line change
Expand Up @@ -91,7 +91,7 @@ export type ExecutionStatus = z.input<typeof ExecutionStatus>;
* parent answers "what did this run cause", and until this slot existed the
* failure count did not: a parent whose child lost a row read `failed: 0`,
* which is the misreading the run-level `failed` was added to prevent
* (#13681), one level up. The slot carries a COMPLETED child's
* (commit 18d816a50), one level up. The slot carries a COMPLETED child's
* `summary.failed` and folds into the delegating node's `failures` — the same
* fold shape `acted` has, so `failed = Σ nodes[].failures` keeps holding with
* the child counted in. It is NOT the same rule as `acted` at the failed-child
Expand Down
2 changes: 1 addition & 1 deletion packages/spec/src/automation/index.ts
Original file line number Diff line number Diff line change
Expand Up @@ -43,7 +43,7 @@ export * from './time-relative-trigger.zod';
export * from './flow-trigger-kind';
// The acting-organization declaration a time-triggered flow carries, and the
// one refusal sentence the schedule trigger and the time-relative sweep both
// say it with (#16659). ⛔ `FlowSchema` does NOT emit that sentence: the key is
// say it with (commit ecdfc9411). ⛔ `FlowSchema` does NOT emit that sentence: the key is
// enforced at BIND, not at parse, because the start node's `config` is an open
// record and a parse-time requirement would make every package-shipped
// scheduled flow unparseable. Named beside `flow-trigger-kind` because the two
Expand Down
4 changes: 2 additions & 2 deletions packages/spec/src/automation/schedule-organization.zod.ts
Original file line number Diff line number Diff line change
Expand Up @@ -78,8 +78,8 @@ import { z } from 'zod';
* history row was stamped from the record while the inbox and delivery rows
* followed an acting context that could not exist there, so they were refused.
* Filling the acting context from the record makes one run carry ONE
* organization's opinion about who it belonged to — which is the defect #16659
* opened on, read from the other side.
* organization's opinion about who it belonged to — which is the defect commit
* ecdfc9411 fixed, read from the other side.
*
* ⚠️ With ONE stated exception, so the sentence above is not read as a promise
* it cannot keep. The two halves ask different questions and are answered by
Expand Down
2 changes: 1 addition & 1 deletion packages/spec/src/conversions/walk.ts
Original file line number Diff line number Diff line change
Expand Up @@ -517,7 +517,7 @@ const VIEW_CONTAINER_SLOTS = [
* is copied only when a descendant actually changed: {@link mapCollection}'s
* contract, one level further in.
*
* **Why this is centralized (#13031).** `ViewMetadataSchema` accepts three body
* **Why this is centralized (commit b799ac553).** `ViewMetadataSchema` accepts three body
* shapes and all three land in `sys_metadata` rows, but every view-family
* conversion was written against the container alone — so for a stored ViewItem
* record or a flattened overlay the whole chain was a no-op, while
Expand Down
4 changes: 2 additions & 2 deletions packages/spec/src/data/driver/turso.zod.ts
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@ import {
* then connect unauthenticated, which is precisely the failure #4410 exists to
* end, surviving in the one driver #4410 could not see.
*
* The maintainer's #6345 ruling closes it by making turso a complete builtin
* The maintainer's ruling (commit e2798fab7) closes it by making turso a complete builtin
* rather than a permanent exception. Optionality of the PACKAGE is orthogonal to
* existence of the CONTRACT — `mongodb` and `sqlite-wasm` are optional installs
* too, and both have had a contract since #4410.
Expand Down Expand Up @@ -354,7 +354,7 @@ export const TursoConfigSchema = lazySchema(() => strictObject(
* The libSQL endpoint or local file. REQUIRED — there is no default: this
* is the single fact that makes `hasLocalDefault: false` true for turso,
* and the reason both boot hosts refuse a driver selection with no URL
* rather than guessing one (#6345 fork 2).
* rather than guessing one (commit e2798fab7's fork 2).
*
* Credential-free by contract since #8082: a `user:password@` userinfo is
* refused at publish exactly like an inline `authToken` (#7990) — bind the
Expand Down
2 changes: 1 addition & 1 deletion packages/spec/src/identity/identity.zod.ts
Original file line number Diff line number Diff line change
Expand Up @@ -228,7 +228,7 @@ export type VerificationToken = z.input<typeof VerificationTokenSchema>;

/*
* `ApiKey` / `ApiKeySchema` / `ApiKeyParsed` are NOT declared here (#8715,
* maintainer-ruled DELETE 2026-08-15; ADR-0049 enforce-or-remove).
* maintainer-ruled DELETE 2026-08-15, commit 2c86fe3ea; ADR-0049 enforce-or-remove).
*
* The schema that stood here documented better-auth's `apiKey` PLUGIN shape —
* a plugin this platform does not load: `start`, `lastRefetchAt`, `enabled`
Expand Down
14 changes: 7 additions & 7 deletions packages/spec/src/index.ts
Original file line number Diff line number Diff line change
Expand Up @@ -129,8 +129,8 @@ export { defineAgent } from './ai/agent.zod';
export { defineTool } from './ai/tool.zod';
export { defineSkill } from './ai/skill.zod';

// [#11350] Root-entry nameability of the root's own inferred types. `defineStack`
// returns `ObjectStackDefinition`, which is declared `z.input<typeof
// [commit ece4dad31] Root-entry nameability of the root's own inferred types.
// `defineStack` returns `ObjectStackDefinition`, which is declared `z.input<typeof
// ObjectStackDefinitionSchema>` — a generic instantiation the declaration
// emitter does not preserve as an alias — so an un-annotated
// `export default defineStack(...)` is emitted as the STRUCTURAL expansion,
Expand All @@ -140,12 +140,12 @@ export { defineSkill } from './ai/skill.zod';
// consumer inferring through a root-entry function). All three are already
// public on their domain subpaths (`/ui`, `/automation`); this block makes the
// root entry self-consistent. Invariant (maintainer ruling 2026-08-23,
// recorded on #11350): a type that appears structurally in an entry's public
// recorded in commit ece4dad31): a type that appears structurally in an entry's public
// declarations must be nameable from that same entry.
export type { FormFieldInput } from './ui/view.zod';
export type { NavigationItemInput } from './ui/app.zod';
export type { StateNodeConfig } from './automation/state-machine.zod';
// [#11709] #11350's recorded premise delta, ruled the same way (maintainer
// [#11709] Commit ece4dad31's recorded premise delta, ruled the same way (maintainer
// decision 2026-08-25, recorded on #11709): the MINIMAL one-file consumer —
// no `/data` subpath import anywhere in its program — leaks two more
// structural mentions of `defineStack`'s return type that the three lines
Expand All @@ -155,9 +155,9 @@ export type { BaseValidationRuleShape } from './data/validation.zod';
export type { FilterCondition } from './data/filter.zod';
// [#12414] The invariant generalized to every public entry, not just the root:
// probing every `define*` factory across all 17 subpaths found the class was
// never closed by #11350/#11709 — four more entries leak a structurally-
// never closed by commit ece4dad31 or #11709 — four more entries leak a structurally-
// mentioned type through a factory return value. Same invariant (maintainer
// ruling recorded on #11350), same one-line-per-name repair: re-export from
// ruling recorded in commit ece4dad31), same one-line-per-name repair: re-export from
// the declaring module. All three are already public on their own subpaths
// (`/system`, `/ui`).
export type { Book } from './system/book.zod';
Expand Down Expand Up @@ -204,7 +204,7 @@ export type {
} from './data/authoring-key-lint';
export { defineCube } from './data/analytics.zod';
export { defineMapping } from './data/mapping.zod';
// `defineTheme` was removed at #10485 with `ui/theme.zod.ts` (ADR-0049) — see
// `defineTheme` was removed by commit 35ad101bc with `ui/theme.zod.ts` (ADR-0049) — see
// the block in `./ui/index.ts`; `app.branding` is the one colour surface.
export { defineTranslationBundle } from './system/translation.zod';
export { definePage } from './ui/page.zod';
Expand Down
4 changes: 2 additions & 2 deletions packages/spec/src/meta-spelling/metadata-url-spelling.ts
Original file line number Diff line number Diff line change
Expand Up @@ -57,7 +57,7 @@
* These are spellings that already worked at the URL boundary, including
* the camelCase ones and the five that name PLUGIN-registered kinds with no
* static registry entry at all (`webhooks`, `connectors`, … — `themes` was
* one of them until #10485 retired the carrier, and left this limb WITH
* one of them until commit 35ad101bc retired the carrier, and left this limb WITH
* the `PLURAL_TO_SINGULAR` row, which is how a retired kind exits the
* spelling contract without this module changing).
* Keeping this limb whole is what makes the derivation non-breaking: no
Expand Down Expand Up @@ -263,7 +263,7 @@ export function metaUrlSpellingRefusal(
* registry entry. A refusal quantified over the registry alone would refuse
* all five, i.e. break `PUT /meta/webhook/stripe`, which is the exact
* operation the plugin path exists to serve. (`theme` was the sixth until
* #10485 retired its carrier; dropping the `PLURAL_TO_SINGULAR` row is what
* commit 35ad101bc retired its carrier; dropping the `PLURAL_TO_SINGULAR` row is what
* moved `/meta/theme` from this set to `unrecognisedMetaTypeRefusal`'s
* verdict.)
*
Expand Down
2 changes: 1 addition & 1 deletion packages/spec/src/security/explain.zod.ts
Original file line number Diff line number Diff line change
Expand Up @@ -208,7 +208,7 @@ export const ExplainLayerSchema = lazySchema(() => z.object({
/**
* Grant-lifecycle state — ONE shared "held but not resolving, because X"
* vocabulary for every lifecycle control that can silently take a held
* grant out of resolution (#8714). Omitted/`active` = contributing
* grant out of resolution (commit 42b05af89). Omitted/`active` = contributing
* normally; the other members mean the row EXISTS but contributed
* NOTHING, and name why, so "why did access disappear" is self-answering:
*
Expand Down
2 changes: 1 addition & 1 deletion packages/spec/src/security/public-form.ts
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@
* their existing semantics: a non-system insert has its static-`readonly`
* columns stripped inside `engine.insert` (the 2026-09-03 ruling, #14147 —
* the same `isSystem`-gated strip as UPDATE), so an import seeds read-only
* columns only under a system context (`preserveAudit` is UPDATE-only, #6640);
* columns only under a system context (`preserveAudit` is UPDATE-only, commit 2ab1257c9);
* `owner_id` transfers are governed by the transfer grant.
*/
export const PUBLIC_FORM_SERVER_MANAGED_FIELDS: ReadonlySet<string> = new Set([
Expand Down
Loading
Loading