Skip to content

chore(claude): allow-list the two objectui landing REST calls in settings.json (ruling #204-4 A) - #19484

Merged
hotlong merged 1 commit into
mainfrom
claude/issue-19362-objectui-landing-allow-rules
Sep 21, 2026
Merged

hotlong merged 1 commit into
mainfrom
claude/issue-19362-objectui-landing-allow-rules

Conversation

@os-project-manager

Copy link
Copy Markdown
Collaborator

Fixes #19362

Clause-②: no

Ruling and authorization, verbatim

Batch #204 item 4, letter A (maintainer 「204 同意」; record 5754492446 on #19362): the two landing endpoints are allow-listed by name for objectui, as they already are for objectstack since #19047. Written by the director seat itself under the maintainer's explicit per-PR authorization in chat (2026-09-21): 「19362 你可以直接开发,不派dev」 — the one charter exception to 「PM 永不写代码」 (a .claude/ internal-tooling PR with the authorization quoted). Per that exception the PR is ⛔ not self-reviewed and ⛔ not self-merged: the maintainer's own read and hand-merge is the review (Tier S by the register, .claude/**).

What lands

Two permissions.allow entries in .claude/settings.json, placed right after their objectstack twins:

Bash(curl -sS -X POST https://api.github.com/repos/objectstack-ai/objectui/pulls/*/ccr/ready_for_review *)
Bash(curl -sS -X PUT https://api.github.com/repos/objectstack-ai/objectui/pulls/*/ccr/auto_merge *)

deny is byte-identical; key order and formatting unchanged; the file parses (55 allow entries, 2 matching objectui/pulls/*/ccr). Nothing else changes: an APPROVED review stays forbidden for every seat account, governed surfaces stay the maintainer's, the queue still runs every gate — these two calls only take a reviewed non-governed objectui PR out of draft and hand it to the queue.

Why the seat wrote it

Two dev rounds (this card's and PR #19479's) were refused by the session permission classifier on every edit to this file ([Self-Modification], four refusals), so the dev lane is not a channel for it; the maintainer authorized the seat to write the two lines directly. Check Changeset needs skip-changeset (no package touched) — applied by the seat.

Verification

node -e 'JSON.parse(...)' exit 0 · node scripts/pm/check-settings-deny-roster.mjs exit 0 (17 content-write tools declared = enforced, unchanged) · the diff is exactly +2 lines.


Generated by Claude Code

…ings.json

The objectui spellings of the two landing-endpoint allow rules that already
exist for objectstack since #19047. Written by the director seat itself under
the maintainer's explicit per-PR authorization, verbatim: 「19362 你可以直接开发,不派dev」
— the one charter exception to 「PM 永不写代码」 (a `.claude/` internal-tooling
PR with the authorization quoted; reviewed and merged by the maintainer, never
self-merged). Every dev-seat attempt to edit this file was refused by the
session classifier (Self-Modification, 4 refusals on 2 cards); `deny` is
untouched. The card relation is declared in the PR body.

Co-Authored-By: Claude <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012GcsUbuqFGBibkEDMRC1eE
@hotlong
hotlong marked this pull request as ready for review September 21, 2026 04:05
@hotlong
hotlong added this pull request to the merge queue Sep 21, 2026
Merged via the queue into main with commit 48c39e0 Sep 21, 2026
32 checks passed
@hotlong
hotlong deleted the claude/issue-19362-objectui-landing-allow-rules branch September 21, 2026 04:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/xs skip-changeset PR has no user-facing published change; bypasses the changeset gate

Projects

None yet

2 participants