Skip to content

docs(design): §03 records that objectstack#16215 landed, leaving #16137 as the sole gate - #31

Merged
os-sam merged 1 commit into
mainfrom
claude/design-03-16215-landed
Sep 7, 2026
Merged

docs(design): §03 records that objectstack#16215 landed, leaving #16137 as the sole gate#31
os-sam merged 1 commit into
mainfrom
claude/design-03-16215-landed

Conversation

@os-sam

@os-sam os-sam commented Sep 7, 2026

Copy link
Copy Markdown
Collaborator

What

DESIGN.md §03 recorded the employer self-onboarding expiry condition as "#16215 + #16137". Half of it has now landed, so §03 says which half and what is left.

objectstack#16215 merged 2026-09-07T06:15Z: @objectstack/organizations is now an Apache-2.0 package and the org-scoping registrar is in the open core. That retires the reason §03 gave — that the multi-organization runtime was closed-source.

What did not change

The operative conclusion. Employers still cannot self-register. What changed is the reason:

  • #16215 merged — the multi-org runtime is open.
  • #16137 has not landed — still open, still pm:blocked, no PR, no assignee.

This distinction is load-bearing and easy to get wrong, so it is worth being exact: #16215's own PR body explicitly declines to claim the acceptance that matters to this app.

This PR does not claim the acceptance criterion. An open-only install with OS_TENANCY_POSTURE=isolated and OS_ALLOW_DEGRADED_TENANCY unset, booting with the wall ACTIVE and enforcing the matrix, is not measured here and is not claimed. objectstack serve still resolves the runtime from the served app's own declaration and is not wired to mount this package off the posture.

So the package being open does not by itself make multiOrgPostureEffective() true on an open deployment, and the beforeCreateOrganization FORBIDDEN branch still fires. Reading "the multi-org package is open-sourced" as "employers can self-register now" would have been exactly the wrong inference — which is why this is written down rather than left to be re-derived.

A future re-check now only has to look at #16137.

Two lines changed, both in §03

  • The forward-compatibility bullet — #16215 开源多组织包 now reads 已于 2026-09-07 合并;仍待 #16137 接通 serve 挂载.
  • The 到期条件 paragraph becomes 到期条件(两项,已满足一项) with the two conditions itemised, ✅ / ⬜, each with its evidence.

Nothing else in §03 moves. The tenancy wall split contract, the accessible_org_ids defect note (#18 / objectstack#16518, still open and unassigned upstream), and the seeker-side membershipPolicy: 'invite-only' rule are untouched.

Gates

Not run, and the change cannot affect them. This is a single markdown file; validate, lint and typecheck all read src/ and objectstack.config.ts, neither of which is in the diff. Recording that honestly rather than installing the dependency tree in a fresh worktree to produce a green that would prove nothing about this change.

Process

No card — this is a PM record correction prompted by watching the upstream blocker, so there is no issue to claim or close. File-disjoint from both dispatches in flight (#27+#25 on src/data/ + package.json + README.md, #3 on src/views/ + seeker.nav.ts).


🤖 Generated with Claude Code

https://claude.ai/code/session_01PbJ5Cy9KDAzeQHo8bsMadG


Generated by Claude Code

…37 as the sole gate

DESIGN.md §03 stated the employer self-onboarding expiry condition as
"#16215 + #16137". objectstack#16215 merged on 2026-09-07:
@objectstack/organizations is now an Apache-2.0 package and the
org-scoping registrar is in the open core.

That satisfies one of the two conditions, so record which one and what
is left. #16137 is still open, pm:blocked and has no PR, and #16215's
own PR body explicitly declines to claim the bootable-open-wall
acceptance: objectstack serve still resolves the runtime from the
served app's own declaration and is not wired to mount the package off
the posture.

The operative conclusion is unchanged -- employers still cannot
self-register -- but the reason is now narrower, and a future re-check
only has to look at #16137 rather than re-derive the whole question.

Documentation only; no metadata changed, so validate/lint/typecheck
cannot be affected and were not run.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PbJ5Cy9KDAzeQHo8bsMadG
@os-sam
os-sam marked this pull request as ready for review September 7, 2026 10:16
@os-sam
os-sam merged commit 36987fc into main Sep 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant