Skip to content

fix(app-shell): every envelope reader on the package surfaces renders the producer-marked userMessage - #7981

Merged
os-sam merged 1 commit into
mainfrom
claude/issue-7959-envelope-readers-user-message
Sep 6, 2026
Merged

fix(app-shell): every envelope reader on the package surfaces renders the producer-marked userMessage#7981
os-sam merged 1 commit into
mainfrom
claude/issue-7959-envelope-readers-user-message

Conversation

@os-sam

@os-sam os-sam commented Sep 6, 2026

Copy link
Copy Markdown
Collaborator

Fixes #7959

Clause-②: no — this reads a few fields that are already on the wire and renders them. No
schema's accept/reject behaviour changes, no public surface widens, no gate's scan population
moves.

What was lost

reader before after
fetchPackages (views/studio-design/packages-io.ts) throw new Error('HTTP ' + status)the body was never opened, so message, code and userMessage were discarded together opens the envelope, marked text first
apiJson (views/metadata-admin/PackagesPage.tsx) error.message ladder — no userMessage, no code shared read on top, its own legacy rungs below
duplicatePackage (same module as fetchPackages) error.message alone the same shared read

The measured cost: GET /api/v1/packages answers a 403 whose message is Reading packages requires the studio.access or setup.access capability. — a sentence that names the
capability to grant
— and fetchPackages reported it as the four characters HTTP 403.
Every caller of that read already displays words: the Studio switcher, the writability
courtesy gate and the namespace lookup all render formatMetadataError(e) (which returns
err.message) onto the shared studio-package-list sonner id (#7368's posture), and the
builder landing page puts the same string in its error banner. The plumbing was wired; there
was nothing to put in it.

The decision the card asked for: can one signature serve the call sites?

Measured first, then extracted. The three sites differ in four ways, and only one of the
four is the envelope read:

how the body is obtained failure trigger fallback text extra ladder rungs
fetchPackages Response, body unread !res.ok HTTP + STATUS none
apiJson (generic in T) already parsed (res.text() + JSON.parse) !res.ok or payload.success === false Request failed ( + STATUS + ) bare-string error, top-level message
duplicatePackage already parsed (res.json().catch(() => null)) !res.ok HTTP + STATUS none

So a helper that owns the whole failure cannot serve them — apiJson has already consumed
the body as text and its trigger is not !res.ok, and folding the fallbacks in would have
needed a fallback parameter plus a legacyRungs flag: three different things pressed into
one signature, harder to read than the copies it replaces.

A helper over the parsed body does serve all three, exactly:

export function readEnvelopeFailureText(payload: unknown): string | null

Envelope in, the person's prose out — a producer-marked error.userMessage outranking the
diagnostic error.message, with error.code appended to whichever prose won — or null when
the body carried no prose, in which case each caller states its own fallback on its own line.
apiJson's two legacy rungs stay at apiJson, deliberately: a bare-string error and a
top-level message are older runtimes' shapes and are not this envelope; folding them in
would hand every other consumer a tolerant dialect it never asked for.

New file: packages/app-shell/src/utils/apiErrorEnvelope.ts. Not exported from the package's
public entry — the surface stays where it was.

⚠️ Two things in this diff beyond the two readers the card names — declared, not slipped in

1. duplicatePackage, the fourth reader, in the same file. It read error.message alone,
dropping the mark and the code, on a route (POST /packages/:id/duplicate) served by the
dispatcher door — the twin that has emitted the marked channel since #9934. It is the same
defect class, in this card's declared file surface, and the correct shape was already pinned
by #7938 / PR #7960. Leaving a hand-rolled copy of the rule a hundred lines below the import
would have been the exact drift this extraction exists to stop. Pinned in
packages-io.envelopeUserMessage.test.ts; its existing packages-io.duplicateEnvelope.test.ts
(which is about the operation's verdict inside a 200) is untouched and still green.

2. data-testid="packages-load-error" on the PackagesPage error banner. The pins need a
stable handle: the words in that banner are the server's, so a test that located the banner
by those words could not assert what is absent from it (not.toContain(GENERIC)).

Out of scope and untouched: fetchFullPackage in StudioDesignSurface.tsx. PR #7960 is
changing that exact function and has not merged. Migrating it onto this helper is a follow-up
once #7960 lands — its landed expression and this helper already agree behaviourally, so the
migration is a deletion.

Not scoped to 5xx, deliberately

The producing door applies no status condition to this channel — "a marked text is the
producer's deliberate statement to the caller at any status" — so honouring it in one band
only would re-create, on the reading end, the divergence that door refused to create on the
writing end (ruled on #7938). The helper makes that structural rather than merely stated: the
rule takes the body and nothing else, and a pin asserts its arity, so an "only in the 5xx
band" variant cannot be written without changing a line that is pinned.

Pins — 51 new assertions across the four combinations

Three files, because "the rule is right" and "this reader actually asks it" are different
claims:

  • utils/apiErrorEnvelope.test.ts (21) — the rule where it is defined.
  • views/studio-design/packages-io.envelopeUserMessage.test.ts (17) — fetchPackages and
    duplicatePackage through real fetch mocks.
  • views/metadata-admin/PackagesPage.envelopeUserMessage.test.tsx (13) — apiJson driven
    through the rendered page, because apiJson is module-private and what the card is about is
    what the person reads.

All four combinations (message only / userMessage only / both / neither) are pinned at each
site, plus the code interactions (appended to the winning prose; bare sentence when no code;
still the bare status when a code arrives with no prose; a non-string or empty-string
userMessage is not a mark and falls through to message). fetchPackages additionally pins
that message and code now arrive at all — its loss was the whole body, not one field.

Forward control — the fix reverted, predicted before it was run

The cut reverts only the two call-site reads, keeping the helper and every pin file in
place. Deleting the helper instead would have turned every pin into MODULE_NOT_FOUND — a NOT
MEASURED reading, not a red one — and keeping it gives the run a negative control.
PackagesPage.tsx was mutated surgically (its top ladder rung only) rather than reverted
whole, because a whole-file revert would also have removed the data-testid handle and turned
every PackagesPage pin red for a reason that is not the defect.

predicted measured
apiErrorEnvelope.test.ts (negative control) 0 red / 21 green 0 red / 21 green
packages-io.envelopeUserMessage.test.ts 12 red / 5 green 12 red / 5 green
PackagesPage.envelopeUserMessage.test.tsx 8 red / 5 green 8 red / 5 green
total 20 red / 31 green Tests 20 failed / 31 passed (51)

Prediction/measurement delta: zero. The green-when-reverted guards all held: PackagesPage
§1 (message only, no code) stayed green — the pin that stops "prefer userMessage" from
being implemented as "read userMessage instead", which would blank every unmarked refusal
the platform serves today — as did §4, §6's three legacy-rung cases, and on the packages-io
side the unparseable-body and successful-read controls.

⚠️ One asymmetry, stated rather than smoothed over. fetchPackages's message-only pin
goes RED on revert, unlike #7938's. That is the defect, not a weaker pin: the pre-fix
reader opened no body, so the unmarked refusal was as lost as the marked one. The
green-when-reverted guard role is carried there by the negative controls instead, and the
apiJson twin does hold the classic form. Both files say so in their docblocks.

The control also found a defect in this PR's own tests: §7 (a 200 declaring
success: false) was sitting under a describe headed "GREEN with the fix reverted" while
being red — a claim the run does not support. It now has its own block, with a note saying
why.

Restore proved by state, not by exit code: git diff HEAD empty, git status --short
empty, and each file's worktree blob hash compared equal to its HEAD blob (an empty hash
would have been read as failure). The script carried a trap … EXIT INT TERM restore using
absolute paths, and git checkout HEAD -- PATH rather than the bare form, which would
have taken the file from the index the mutation leg wrote.

Verification — all at final commit f82ae88ad, git rev-parse --short HEAD

Run from the repository root (RUN v4.1.10 /home/user/objectui-issue-7959), exit codes
captured before any pipe.

check exit result
pnpm --filter '@object-ui/app-shell^...' build 0 dependency closure built first
pnpm exec vitest run packages/app-shell/ 0 Test Files 631 passed (631), Tests 6062 passed, 1 skipped (6063)
pnpm --filter @object-ui/app-shell run type-check 0 tsc --noEmit && tsc -p tsconfig.test.json
pnpm --filter @object-ui/app-shell run lint 0 0 errors (2894 pre-existing warnings)
node scripts/check-changeset-presence.mjs 0 ✅ 6 source file(s) of 1 released package(s) changed, and this change declares 1 changeset(s): .changeset/olive-crabs-shave.md.
node scripts/check-changeset-no-major.mjs 0 ✅ No changeset declares a major bump.
node scripts/check-control-bytes.mjs 0 6422 tracked text files scanned
node scripts/check-unreferenced-sources.mjs 0 the new util is reached (208 shipped files, 208 reached)
node scripts/check-vi-mock-specifiers.mjs 0
node scripts/check-vi-mock-inherit.mjs 0
node scripts/check-phantom-dependencies.mjs 0
node scripts/check-package-self-import.mjs 0

The type-check green is not vacuous: tsc -p tsconfig.test.json --listFiles puts all six
changed/added files in a program (the three test files appear in the test program, the three
sources in both).

The lint run is a declared narrowing, and a measured one. Scope is the @object-ui/app-shell
package rather than the repo-wide pnpm lint; --format json reports 1086 files judged, 0
errors
, all six changed files among them. Nothing untouched can have moved: eslint.config.js
configures no type-aware linting (no project / projectService), so each file's verdict
depends only on its own bytes plus the shared config, which this diff does not touch. CI runs
the full farm regardless.

Out of scope, filed rather than fixed

Neither is a duplicate: checked against all 407 open issues in this repository.

Angle-bracket placeholders are spelled as capitalised words throughout this body on purpose:
GitHub's body sanitizer eats tag-shaped fragments on save, and backticks and fenced blocks do
not protect them (AGENTS.md, "GitHub rewrites the bytes you put in an issue/PR body").

Authored by the os-dev seat, session https://claude.ai/code/session_01KbJQ1y1J12nZxYzFWhP8Q3.


🤖 Generated with Claude Code

https://claude.ai/code/session_01KbJQ1y1J12nZxYzFWhP8Q3


Generated by Claude Code

… the producer-marked userMessage

`fetchPackages` answered a refusal with `HTTP <status>` and never opened the
body, so `message`, `code` and `userMessage` were discarded together — a 403
whose envelope named the capability to grant reached the author as four
characters. `apiJson` on the package admin page read `error.message` and never
the mark, and rendered no code. `duplicatePackage`, in the same module, read
`error.message` alone.

Those were three independent implementations of "read the ADR-0112 failure
envelope" on one endpoint family, already drifted into three different answers
for the same body. They now ask one shared rule: a producer-marked
`error.userMessage` outranks the diagnostic `error.message` at any status —
presence of the field IS the producer's marking — with `error.code` appended to
whichever prose won. Each reader keeps its own fallback and, for `apiJson`, its
own legacy rungs; those are not the envelope.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KbJQ1y1J12nZxYzFWhP8Q3
@github-actions

github-actions Bot commented Sep 6, 2026

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

Metric Value Budget
Eager closure (gzip, 50 chunks) 3186.0 KB 3191.4 KB
Main entry chunk (gzip) 143.5 KB 350 KB
Entry file index-BO0uFEv5.js
Status PASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

Package Size Gzipped
app-shell (consoleActionDispatch.js) 0.20KB 0.19KB
app-shell (index.js) 15.67KB 5.75KB
app-shell (runtime-config.js) 20.68KB 7.36KB
app-shell (types.js) 0.01KB 0.04KB
app-shell (urlParams.js) 10.06KB 3.86KB
auth (ActiveOrganizationStorage.js) 25.05KB 9.16KB
auth (AuthContext.js) 0.31KB 0.24KB
auth (AuthGuard.js) 2.07KB 1.00KB
auth (AuthProvider.js) 40.18KB 10.59KB
auth (AuthShell.js) 3.49KB 1.40KB
auth (ForgotPasswordForm.js) 12.21KB 3.45KB
auth (LoginForm.js) 18.15KB 5.39KB
auth (PreviewBanner.js) 0.90KB 0.50KB
auth (RegisterForm.js) 6.65KB 2.22KB
auth (SocialSignInButtons.js) 9.61KB 3.89KB
auth (UserMenu.js) 3.41KB 1.23KB
auth (auth-gate-events.js) 1.29KB 0.66KB
auth (authStyles.js) 5.04KB 1.72KB
auth (createAuthClient.js) 40.21KB 10.80KB
auth (createAuthenticatedFetch.js) 8.46KB 3.43KB
auth (index.js) 3.19KB 1.44KB
auth (invitation-status.js) 1.22KB 0.70KB
auth (org-roles.js) 6.66KB 2.78KB
auth (phone-identifier.js) 1.11KB 0.66KB
auth (types.js) 0.59KB 0.35KB
auth (useAuth.js) 5.30KB 1.02KB
auth (useWorkspaceAdminStatus.js) 5.13KB 2.35KB
collaboration (CommentThread.js) 26.08KB 7.56KB
collaboration (LiveCursors.js) 3.17KB 1.27KB
collaboration (PresenceAvatars.js) 6.49KB 2.64KB
collaboration (PresenceProvider.js) 2.79KB 1.13KB
collaboration (index.js) 1.68KB 0.73KB
collaboration (useCollaborationTranslation.js) 6.05KB 2.52KB
collaboration (useCommentSearch.js) 1.98KB 0.88KB
collaboration (useConflictResolution.js) 7.75KB 1.86KB
collaboration (useMentionNotifications.js) 1.81KB 0.68KB
collaboration (usePresence.js) 6.33KB 1.84KB
collaboration (useRealtimeSubscription.js) 7.91KB 2.01KB
components (index.js) 497.06KB 113.79KB
core (index.js) 6.96KB 2.79KB
create-plugin (index.js) 10.08KB 3.26KB
data-objectstack (index.js) 182.08KB 50.62KB
fields (index.js) 242.44KB 61.25KB
i18n (LocalizationContext.js) 1.76KB 0.96KB
i18n (builtinAggregateLabels.js) 0.86KB 0.49KB
i18n (currency.js) 1.22KB 0.64KB
i18n (fallbackInterpolation.js) 6.25KB 2.77KB
i18n (i18n.js) 4.28KB 1.75KB
i18n (index.js) 3.65KB 1.47KB
i18n (pickLocalized.js) 7.62KB 3.26KB
i18n (provider.js) 26.89KB 9.04KB
i18n (useDisplayLocale.js) 2.85KB 1.45KB
i18n (useObjectLabel.js) 34.34KB 9.17KB
i18n (useSafeTranslation.js) 5.60KB 2.33KB
layout (index.js) 38.84KB 10.94KB
mobile (MobileProvider.js) 0.92KB 0.49KB
mobile (ResponsiveContainer.js) 0.94KB 0.38KB
mobile (breakpoints.js) 1.51KB 0.70KB
mobile (createOfflineDataSource.js) 5.61KB 1.75KB
mobile (index.js) 1.99KB 0.87KB
mobile (offlineQueue.js) 3.91KB 1.35KB
mobile (pwa.js) 0.97KB 0.49KB
mobile (serviceWorker.js) 1.48KB 0.62KB
mobile (serviceWorkerSource.js) 3.41KB 1.48KB
mobile (useBreakpoint.js) 1.54KB 0.65KB
mobile (useGesture.js) 6.96KB 1.98KB
mobile (useOfflineSync.js) 1.99KB 0.72KB
mobile (usePullToRefresh.js) 2.53KB 0.85KB
mobile (useResponsive.js) 0.72KB 0.42KB
mobile (useSpecGesture.js) 4.39KB 1.66KB
mobile (useTouchTarget.js) 1.01KB 0.54KB
permissions (MePermissionsProvider.js) 11.71KB 4.29KB
permissions (PermissionContext.js) 0.31KB 0.25KB
permissions (PermissionGuard.js) 0.89KB 0.45KB
permissions (PermissionProvider.js) 6.24KB 2.16KB
permissions (discardProofCache.js) 1.04KB 0.55KB
permissions (evaluator.js) 5.12KB 1.74KB
permissions (index.js) 0.93KB 0.41KB
permissions (store.js) 0.91KB 0.42KB
permissions (useFieldPermissions.js) 1.28KB 0.53KB
permissions (usePermissions.js) 4.83KB 2.27KB
plugin-ai (index.js) 15.16KB 3.68KB
plugin-calendar (index.js) 47.35KB 13.21KB
plugin-charts (index.js) 70.31KB 19.62KB
plugin-chatbot (index.js) 193.53KB 46.05KB
plugin-dashboard (index.js) 131.41KB 34.43KB
plugin-designer (index.js) 211.51KB 43.01KB
plugin-detail (index.js) 247.59KB 63.48KB
plugin-editor (index.js) 2.23KB 1.05KB
plugin-form (index.js) 131.01KB 32.32KB
plugin-gantt (index.js) 167.16KB 40.99KB
plugin-grid (index.js) 208.56KB 56.63KB
plugin-kanban (index.js) 52.30KB 14.49KB
plugin-list (index.js) 113.24KB 27.66KB
plugin-map (index.js) 20.35KB 6.77KB
plugin-markdown (index.js) 13.88KB 4.80KB
plugin-report (index.js) 43.42KB 11.92KB
plugin-timeline (index.js) 29.95KB 8.67KB
plugin-tree (index.js) 9.16KB 3.18KB
plugin-view (index.js) 84.33KB 20.75KB
providers (DataSourceProvider.js) 0.75KB 0.39KB
providers (MetadataProvider.js) 1.37KB 0.59KB
providers (ThemeProvider.js) 1.90KB 0.85KB
providers (UploadProvider.js) 11.66KB 3.50KB
providers (index.js) 0.45KB 0.23KB
providers (types.js) 0.01KB 0.04KB
react-runtime (index.js) 5.62KB 2.34KB
react (LazyPluginLoader.js) 4.47KB 1.63KB
react (SchemaRenderer.js) 81.07KB 26.86KB
react (data-invalidation.js) 5.05KB 2.08KB
react (index.js) 4.63KB 2.18KB
react (schema-input.js) 2.32KB 1.24KB
react (spec-input.js) 0.20KB 0.18KB
sdui-parser (codegen.js) 5.41KB 2.34KB
sdui-parser (dashboard-widget-options.js) 3.08KB 1.30KB
sdui-parser (index.js) 4.93KB 2.24KB
sdui-parser (input-type.js) 2.84KB 1.40KB
sdui-parser (parse.js) 20.57KB 5.88KB
sdui-parser (provenance.js) 3.66KB 1.82KB
sdui-parser (types.js) 0.28KB 0.23KB
sdui-parser (validate.js) 10.35KB 3.60KB
types (ai.js) 0.20KB 0.17KB
types (api-types.js) 0.20KB 0.18KB
types (app.js) 2.87KB 1.00KB
types (base.js) 0.20KB 0.18KB
types (blocks.js) 0.20KB 0.18KB
types (complex.js) 2.74KB 1.41KB
types (crud.js) 0.20KB 0.18KB
types (dashboard-filter-alias.js) 6.23KB 2.74KB
types (data-display.js) 3.75KB 1.85KB
types (data-protocol.js) 0.20KB 0.19KB
types (data.js) 0.20KB 0.18KB
types (designer.js) 1.85KB 0.85KB
types (disclosure.js) 0.20KB 0.18KB
types (error-code.js) 1.54KB 0.88KB
types (expression.js) 0.20KB 0.18KB
types (feedback.js) 0.20KB 0.18KB
types (field-types.js) 0.20KB 0.18KB
types (form.js) 0.20KB 0.18KB
types (http-inflight.js) 8.87KB 3.73KB
types (http-retry.js) 4.32KB 2.02KB
types (icon-key-migration.js) 4.26KB 1.63KB
types (index.js) 4.74KB 2.25KB
types (layout.js) 0.20KB 0.18KB
types (managed-by.js) 0.19KB 0.18KB
types (mobile.js) 4.73KB 2.28KB
types (navigation.js) 0.20KB 0.18KB
types (objectql.js) 0.20KB 0.18KB
types (overlay.js) 0.20KB 0.18KB
types (permissions.js) 0.20KB 0.18KB
types (plugin-scope.js) 0.20KB 0.18KB
types (record-components.js) 0.20KB 0.19KB
types (record-semantics.js) 1.28KB 0.67KB
types (registry.js) 0.20KB 0.18KB
types (reports.js) 0.20KB 0.18KB
types (select-option.js) 0.20KB 0.19KB
types (spec-report.js) 5.05KB 1.93KB
types (spec-ui-namespace.js) 0.20KB 0.19KB
types (system-fields.js) 3.33KB 1.54KB
types (theme.js) 6.28KB 2.87KB
types (ui-action.js) 8.11KB 3.32KB
types (views.js) 0.20KB 0.18KB
types (widget.js) 0.20KB 0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

1 participant