From 37eaf1647fb438b04dc7c7a886ac1b7bcfc75570 Mon Sep 17 00:00:00 2001 From: Jack Zhuang <50353452+hotlong@users.noreply.github.com> Date: Wed, 30 Sep 2026 10:55:01 +0800 Subject: [PATCH 1/2] docs(plugin-dev): re-anchor the dead tracker citations in packages/plugins/plugin-dev/src to the commits that decided them Six comment lines in three files cited two tracker numbers that no longer resolve. Each now cites the commit in this repository's history that decided what the line describes (ruling C+D, form C): - the security-enforcement warning asks the published `security` service, and asks it in start(): commit 7552e0337 (dev-plugin.ts x2, and three test-file comments); - plugin-hono-server's current-user endpoints key on the same published service instead of the init()-registered internals: commit c1731d023 (dev-plugin.ts x1). Comments only; every touched file keeps its line count. Claude-Session: https://claude.ai/code/session_local_1d2a197c-c20e-4e90-9be8-413d4d432289 Co-authored-by: Claude --- .../src/dev-plugin-security-enforcement-warning.test.ts | 2 +- packages/plugins/plugin-dev/src/dev-plugin.test.ts | 4 ++-- packages/plugins/plugin-dev/src/dev-plugin.ts | 6 +++--- 3 files changed, 6 insertions(+), 6 deletions(-) diff --git a/packages/plugins/plugin-dev/src/dev-plugin-security-enforcement-warning.test.ts b/packages/plugins/plugin-dev/src/dev-plugin-security-enforcement-warning.test.ts index ef4f4d170a6..5dfa39d3d05 100644 --- a/packages/plugins/plugin-dev/src/dev-plugin-security-enforcement-warning.test.ts +++ b/packages/plugins/plugin-dev/src/dev-plugin-security-enforcement-warning.test.ts @@ -50,7 +50,7 @@ import { DevPlugin } from './dev-plugin'; // the next transform that lands in this file. import '@objectstack/plugin-security'; -// [#10036] The state under test is "SecurityPlugin LOADED but its start() +// [commit 7552e0337] The state under test is "SecurityPlugin LOADED but its start() // bailed", so `@objectstack/plugin-security` is deliberately NOT mocked here — // the real plugin's real `init()`/`start()` phase split is what constructs the // state. Every OTHER optional dependency is mocked away for the same reason as diff --git a/packages/plugins/plugin-dev/src/dev-plugin.test.ts b/packages/plugins/plugin-dev/src/dev-plugin.test.ts index 8dca3903b19..ce7715ef279 100644 --- a/packages/plugins/plugin-dev/src/dev-plugin.test.ts +++ b/packages/plugins/plugin-dev/src/dev-plugin.test.ts @@ -87,7 +87,7 @@ describe('DevPlugin', () => { const plugin = new DevPlugin({ seedAdminUser: false }); await plugin.init(ctx); - // [#10036] `start()` too: the "nothing is enforcing security" warning + // [commit 7552e0337] `start()` too: the "nothing is enforcing security" warning // asserted at the bottom of this test moved to the start phase, because // `security` — the published service that means enforcement, as opposed // to the `init()`-registered internals that only mean "plugin loaded" — @@ -124,7 +124,7 @@ describe('DevPlugin', () => { ); expect(securityWarn).toBeDefined(); // …and with the plugin genuinely absent it says so, rather than reporting - // the loaded-but-failed-to-start state (#10036). + // the loaded-but-failed-to-start state (the two told apart since commit 7552e0337). expect(securityWarn![0]).toContain('SecurityPlugin is not loaded'); }); diff --git a/packages/plugins/plugin-dev/src/dev-plugin.ts b/packages/plugins/plugin-dev/src/dev-plugin.ts index 1f1ac117f46..708af69f9b2 100644 --- a/packages/plugins/plugin-dev/src/dev-plugin.ts +++ b/packages/plugins/plugin-dev/src/dev-plugin.ts @@ -1060,7 +1060,7 @@ export class DevPlugin implements Plugin { ); } // Same reasoning, same surface: "nothing is enforcing security" belongs - // next to the banner, not buried in the init log (#10036, #3900). + // next to the banner, not buried in the init log (#3900; commit 7552e0337 moved this check here from init()). this.warnIfNothingIsEnforcingSecurity(ctx); ctx.logger.info(''); ctx.logger.info(' API: /api/v1/data/:object'); @@ -1075,7 +1075,7 @@ export class DevPlugin implements Plugin { * so the slots stay empty — but silence about unenforced RBAC/RLS/masking * would be its own kind of fake). * - * ## Why this asks for `security`, and why it asks in `start()` (#10036) + * ## Why this asks for `security`, and why it asks in `start()` (commit 7552e0337) * * This used to probe `security.permissions` / `security.rls` / * `security.fieldMasker` from `init()`. Both halves of that were wrong, and @@ -1094,7 +1094,7 @@ export class DevPlugin implements Plugin { * internal handles and enforces nothing, so the warning stayed silent in * the one state where its text is literally true. (The same presence * signal misled `plugin-hono-server`'s `/auth/me/permissions`, fixed in - * #10035 by this same move — two consumers, two packages, one misread: + * commit c1731d023 by this same move — two consumers, two packages, one misread: * that is a property of the signal, not of either reader.) * * - **Wrong phase.** `security` is registered in `SecurityPlugin.start()`, From a237b10ee73b097d836b08da5af92e1bae1872f1 Mon Sep 17 00:00:00 2001 From: Jack Zhuang <50353452+hotlong@users.noreply.github.com> Date: Wed, 30 Sep 2026 10:56:21 +0800 Subject: [PATCH 2/2] chore(changeset): patch @objectstack/plugin-dev for the re-anchored provenance comments The two rewritten docblock lines reach dist (index.js, index.mjs, index.d.ts, index.d.mts), so the package ships different bytes and takes a patch changeset, in the form the earlier stages of this sweep used. Claude-Session: https://claude.ai/code/session_local_1d2a197c-c20e-4e90-9be8-413d4d432289 Co-authored-by: Claude --- .changeset/plugin-dev-provenance-anchors.md | 11 +++++++++++ 1 file changed, 11 insertions(+) create mode 100644 .changeset/plugin-dev-provenance-anchors.md diff --git a/.changeset/plugin-dev-provenance-anchors.md b/.changeset/plugin-dev-provenance-anchors.md new file mode 100644 index 00000000000..deeb47ee908 --- /dev/null +++ b/.changeset/plugin-dev-provenance-anchors.md @@ -0,0 +1,11 @@ +--- +'@objectstack/plugin-dev': patch +--- + +Provenance comments in `@objectstack/plugin-dev` were re-anchored + +Comment and docblock lines under `src/` that cited tracker numbers which no +longer resolve on GitHub now cite the commit in this repository's history that +decided the matter, and say in their own words what was decided. Comments +only: no service, boot-log line, warning text, type, export or runtime +behaviour changes.