Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 11 additions & 0 deletions .changeset/20594-observability-provenance-anchors.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
---
'@objectstack/observability': patch
---

A provenance comment in `@objectstack/observability` was re-anchored

The `SEMCONV` comment beside the retired `http_request_errors_total` entry
cited a tracker number that no longer resolves on GitHub. It now cites the
commit in this repository's history that moved `http_request_duration_ms` to
the transport seam. Comment only: no metric name, label, export, type or
runtime behaviour changes.
2 changes: 1 addition & 1 deletion packages/observability/src/semconv.ts
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ export const SEMCONV = {
// status, elapsedMs}` and no throw signal at all.
// ⇒ Read the 5xx rate from `http_requests_total{status=~"5.."}` instead.
// The transport emits that family through the seam, so it covers every
// inbound surface (#9650 / #9835 / #10004) and carries the status label
// inbound surface (#9650 / #9835 / commit 1e050a5b1) and carries the status label
// this counter only stood in for. Maintainer ruling 2026-08-20.

// ── Storage — emitted by `@objectstack/service-storage` adapters ──
Expand Down
4 changes: 2 additions & 2 deletions packages/verify/src/erasure-transaction-authorization.test.ts
Original file line number Diff line number Diff line change
Expand Up @@ -160,11 +160,11 @@ describe('#10792 — the erasure route answers authorization on a pool max=1 dia
it('a signed-in plain member gets the AUTHORIZATION refusal, not 401', async () => {
const answer = await fire('POST', '/auth/admin/remove-user', { userId: targets[2] }, memberToken);
expect(answer.status, `member remove-user: ${answer.status} ${answer.body}`).toBe(403);
// #11477 (maintainer-ruled option A): the route is now shaded by an
// Commit 6dd3e6968 (maintainer-ruled option A): the route is now shaded by an
// ObjectStack raw mount whose gateAdmin runs BEFORE the break-glass guard,
// so the refusal a plain member hears is the gate's target-independent
// PERMISSION_DENIED — no longer the vendor's
// YOU_ARE_NOT_ALLOWED_TO_DELETE_USERS, which the pre-#11477 route only
// YOU_ARE_NOT_ALLOWED_TO_DELETE_USERS, which the route before that commit only
// reached after the guard had already answered. This pin's intent is
// unchanged: the member hears an AUTHORIZATION verdict, and asserting the
// code (not just the status) keeps a 403 from some unrelated layer from
Expand Down
2 changes: 1 addition & 1 deletion packages/verify/src/harness.ts
Original file line number Diff line number Diff line change
Expand Up @@ -577,7 +577,7 @@ export async function bootStack(
// booted multi-tenant off a hoisted copy — and the RLS posture a fixture
// then asserted against depended on the launcher.
//
// #10943: the undeclared FALLBACK is this package's own resolution only if
// Commit 46d34ab7c: the undeclared FALLBACK is this package's own resolution only if
// this package supplies it. A bare `import()` written inside
// `@objectstack/types` resolves against THAT package — which declares
// `@objectstack/spec` and nothing else — so the helper's documented
Expand Down
Loading