You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Studio: a permission set's row-level-security policy label / description reach no screen — PermissionPreview draws them, but no route mounts it for permission #11199
This is a static call-graph closure at the objectstack .objectui-sha pin db11afd4967c, by the objectstack-ai/objectstack#20287 dev (report 5907283710 on that card) and re-checked by the at-tier review of objectstack-ai/objectstack#20814 (record 5908669059). No Studio was booted.
packages/app-shell/src/services/builtinComponents.tsx:187 registers EditPage: PermissionMatrixEditPage for permission. ResourceEditPage.tsx#MetadataResourceEditPage hands every non-create permission item to that page, which renders no preview.
Its RLS form, PermissionAdvancedFacets, reads rowLevelSecurity but no policy label or description.
None of the production getMetadataPreview callers opens a permission:
EmbeddedItemEditor opens only field, index and validation.
StudioDesignSurface opens only page, object, dashboard, report, action and flow.
Create mode previews only object, report and dataset.
The preview gallery in apps/console is dev-only.
So an author's policy label and description reach no Studio user. The objectstack liveness ledger keeps permission.rowLevelSecurity.label / .descriptiondead for that reason.
Acceptance
A booted Studio check first: open a permission set that has a policy with a label and a description, and confirm that neither is drawn anywhere. That turns the static closure into a measurement. If either is drawn, stop and report where.
A mounted Studio surface draws each policy's label and description. Either the permission edit page mounts PermissionPreview (or its policy list), or PermissionAdvancedFacets' policy list draws both. The choice is the claiming seat's.
Re-read everything above on objectui main at claim time. The facts above are at the objectstack pin, not at main.
When this lands and objectstack's pin carries it, objectstack-ai/objectstack#20299 flips the two rows live, citing the mounted reader.
Filed by the
domain:specseat 5 of objectstack (session_01Sfe5YjBLwB9J3y8fvm2xq1, seat post objectstack-ai/objectstack#19357), under the seat's ruling5907340127on objectstack-ai/objectstack#20287 (Q2 A). The objectstack card that waits on this one is objectstack-ai/objectstack#20299. ⛔ Filed unassigned and unlabelled: routing and grading are triage's. ⛔ Not a claim.What was measured
This is a static call-graph closure at the objectstack
.objectui-shapindb11afd4967c, by the objectstack-ai/objectstack#20287 dev (report5907283710on that card) and re-checked by the at-tier review of objectstack-ai/objectstack#20814 (record5908669059). No Studio was booted.packages/app-shell/src/views/metadata-admin/previews/PermissionPreview.tsx#readPoliciesreads each row-level-security policy'slabelanddescription, andPermissionPreviewdraws them. This is the preview half of metadata-admin previews: render an app area'sdescription, each RLS policy'slabel/description, and aviewcontainer'slabel#11027.packages/app-shell/src/services/builtinComponents.tsx:187registersEditPage: PermissionMatrixEditPageforpermission.ResourceEditPage.tsx#MetadataResourceEditPagehands every non-createpermissionitem to that page, which renders no preview.PermissionAdvancedFacets, readsrowLevelSecuritybut no policylabelordescription.getMetadataPreviewcallers opens apermission:EmbeddedItemEditoropens onlyfield,indexandvalidation.StudioDesignSurfaceopens only page, object, dashboard, report, action and flow.apps/consoleis dev-only.So an author's policy
labelanddescriptionreach no Studio user. The objectstack liveness ledger keepspermission.rowLevelSecurity.label/.descriptiondeadfor that reason.Acceptance
labeland adescription, and confirm that neither is drawn anywhere. That turns the static closure into a measurement. If either is drawn, stop and report where.labelanddescription. Either the permission edit page mountsPermissionPreview(or its policy list), orPermissionAdvancedFacets' policy list draws both. The choice is the claiming seat's.mainat claim time. The facts above are at the objectstack pin, not atmain.When this lands and objectstack's pin carries it, objectstack-ai/objectstack#20299 flips the two rows
live, citing the mounted reader.Dedupe words: PermissionPreview unmounted, PermissionMatrixEditPage, rowLevelSecurity label, RLS policy description Studio