Skip to content

Studio: a permission set's row-level-security policy label / description reach no screen — PermissionPreview draws them, but no route mounts it for permission #11199

Description

@objectstack-fleet

Filed by the domain:spec seat 5 of objectstack (session_01Sfe5YjBLwB9J3y8fvm2xq1, seat post objectstack-ai/objectstack#19357), under the seat's ruling 5907340127 on objectstack-ai/objectstack#20287 (Q2 A). The objectstack card that waits on this one is objectstack-ai/objectstack#20299. ⛔ Filed unassigned and unlabelled: routing and grading are triage's. ⛔ Not a claim.

What was measured

This is a static call-graph closure at the objectstack .objectui-sha pin db11afd4967c, by the objectstack-ai/objectstack#20287 dev (report 5907283710 on that card) and re-checked by the at-tier review of objectstack-ai/objectstack#20814 (record 5908669059). No Studio was booted.

  • packages/app-shell/src/views/metadata-admin/previews/PermissionPreview.tsx#readPolicies reads each row-level-security policy's label and description, and PermissionPreview draws them. This is the preview half of metadata-admin previews: render an app area's description, each RLS policy's label / description, and a view container's label #11027.
  • packages/app-shell/src/services/builtinComponents.tsx:187 registers EditPage: PermissionMatrixEditPage for permission. ResourceEditPage.tsx#MetadataResourceEditPage hands every non-create permission item to that page, which renders no preview.
  • Its RLS form, PermissionAdvancedFacets, reads rowLevelSecurity but no policy label or description.
  • None of the production getMetadataPreview callers opens a permission:
    • EmbeddedItemEditor opens only field, index and validation.
    • StudioDesignSurface opens only page, object, dashboard, report, action and flow.
    • Create mode previews only object, report and dataset.
    • The preview gallery in apps/console is dev-only.

So an author's policy label and description reach no Studio user. The objectstack liveness ledger keeps permission.rowLevelSecurity.label / .description dead for that reason.

Acceptance

  1. A booted Studio check first: open a permission set that has a policy with a label and a description, and confirm that neither is drawn anywhere. That turns the static closure into a measurement. If either is drawn, stop and report where.
  2. A mounted Studio surface draws each policy's label and description. Either the permission edit page mounts PermissionPreview (or its policy list), or PermissionAdvancedFacets' policy list draws both. The choice is the claiming seat's.
  3. Re-read everything above on objectui main at claim time. The facts above are at the objectstack pin, not at main.

When this lands and objectstack's pin carries it, objectstack-ai/objectstack#20299 flips the two rows live, citing the mounted reader.

Dedupe words: PermissionPreview unmounted, PermissionMatrixEditPage, rowLevelSecurity label, RLS policy description Studio

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:accessPermissions that actually hold — RLS/FLS, sharing model, write-path guardsbugSomething isn't workingdomain:uiobjectui ui stream: fix lands on the published library or apps — objectui execution seatpriority:p3

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions