Skip to content

test(plugins): serve batch 2's four network-escape probes from doubles - #8013

Merged
baozhoutao merged 2 commits into
mainfrom
claude/issue-7307-network-escapes-batch2
Sep 6, 2026
Merged

test(plugins): serve batch 2's four network-escape probes from doubles#8013
baozhoutao merged 2 commits into
mainfrom
claude/issue-7307-network-escapes-batch2

Conversation

@baozhoutao

Copy link
Copy Markdown
Contributor

Part of #7307 — batch 2 of the network-escape burn-down (batch 1 was #7999).

The four /api/v1/security/explain rows left in the ledger for plugin-kanban and
plugin-gantt now serve that probe from the recording double batch 1 landed, and
their lines leave KNOWN_ESCAPES and PINNED_LEDGER in the same commit.

Per file

file endpoint hook it escaped through double
packages/plugin-kanban/src/ObjectKanban.navWidthDefault.test.tsx POST /api/v1/security/explain useRecordEditable.ts:76 (apiFetch ?? fetch) per-test installExplainDouble() in beforeEach
packages/plugin-kanban/src/ObjectKanban.overlayTitleI18n.test.tsx POST /api/v1/security/explain useRecordEditable.ts:76 per-test installExplainDouble() in beforeEach
packages/plugin-kanban/src/ObjectKanban.overlayTitleNoProviderFallback.test.tsx POST /api/v1/security/explain useRecordEditable.ts:76 per-test installExplainDouble() in beforeEach
packages/plugin-gantt/src/ObjectGantt.navWidthDefault.test.tsx POST /api/v1/security/explain useRecordEditable.ts:76 per-test installExplainDouble() in beforeEach

Mechanism, measured rather than assumed. A trap-guarded stack probe on the
guard's own attribution point says all four take ONE route, not the two batch 1
found: RecordDetailDrawer renders DetailView, which calls useRecordEditable
twice per open (DetailView.tsx:290 for edit, :296 for delete). At
useRecordEditable.ts:76 the hook degrades from the host's authenticated
apiFetch to the global fetch — by design, so a standalone embed keeps
rendering — and under happy-dom that global is a real HTTP client whose document
URL is http://localhost:3000, so the relative path resolved to a live socket.
The read is best-effort (catch leaves the record editable), which is why every
one of these files stayed green while its request always failed. The probe was
reverted by git checkout HEAD -- and the guard is byte-identical to HEAD
afterwards.

The double is batch 1's shape verbatim: vi.stubGlobal('fetch', router) in
beforeEach, cleanup() before vi.unstubAllGlobals() in afterEach (#7439
ordering). It is a router, not a sink — it records every URL it is handed and
afterEach fails on any URL that is not the explain route, so an escape
elsewhere reds here instead of vanishing into the hook's catch. It answers the
permissive verdict, which is the same downstream state the failing request
produced (useRecordEditable initialises allowed to true and its failure
path leaves it there), so no existing assertion changes meaning. Only the
single-recordId response shape is reached from these four files; the batched
branch is kept so the router stays byte-identical to its siblings rather than
forking per file. Nothing is skipped, quarantined or silenced.

Ledger arithmetic

16 to 12, in both lists. The four names are deleted from KNOWN_ESCAPES in
vitest.setup.network-escape-guard.ts and from PINNED_LEDGER in
scripts/__tests__/network-escape-ledger.test.ts in this one commit. Checked in
lockstep by diffing the quoted paths of the two literals against each other on
the branch: empty diff, both at 12. Remaining 12: app-shell 8, plugin-detail 4.

Evidence

Per file, before then after (attribution lines / ECONNREFUSED lines, then the
post-fix run):

file before after
ObjectKanban.navWidthDefault 6 / 30 0 / 0, Tests 3 passed
ObjectKanban.overlayTitleI18n 12 / 60 0 / 0, Tests 7 passed
ObjectKanban.overlayTitleNoProviderFallback 4 / 20 0 / 0, Tests 2 passed
ObjectGantt.navWidthDefault 4 / 20 0 / 0, Tests 2 passed

pnpm exec vitest run packages/plugin-kanban/ packages/plugin-gantt/ scripts/__tests__/network-escape-ledger.test.ts
on this head: exit 0, Test Files 87 passed (87), Tests 619 passed (619), and
zero lines matching network-escape or ECONNREFUSED in the whole run.

Ablation (on the committed tree, one script with trap ... EXIT INT TERM and
absolute paths). One converted file's double reverted to its pre-batch-2 blob
while its line stayed deleted from BOTH ledgers. Mutation proven on disk:
ObjectGantt.navWidthDefault.test.tsx blob e9ba5b8e to 28f37a60 (equal to
the e1545cf base blob), anchors installExplainDouble 2 to 0 and
vi.stubGlobal 1 to 0, that path present 0 times in each ledger during the run.
Predicted direction red; OBSERVED red — exit 1, Tests 2 failed (2),
Network escape: this test reached a REAL socket at http://localhost:3000/api/v1/security/explain
naming file: packages/plugin-gantt/src/ObjectGantt.navWidthDefault.test.tsx.
Restore proven: git checkout HEAD -- path, blob back to e9ba5b8e,
git diff HEAD on that path empty, git status --porcelain empty.

Gates, exit codes captured by redirect-then-capture, never through a pipe:

  • node scripts/check-changeset-presence.mjs exit 0 — "4 source file(s) of 2
    released package(s) changed, and this change declares 1 changeset(s)"; the
    changeset has an EMPTY frontmatter, the explicit exemption for a test-only
    change under a released package.
  • pnpm check:control-bytes exit 0 (6443 tracked text files), plus a
    grep -naP self-scan of the control range over all 7 changed paths, no hits.
  • node scripts/check-governed-queue-guard.mjs --test over all 7 changed paths:
    exit 0, "NOT GOVERNED — 7 path(s) checked against 5 governed surface(s)".
  • pnpm type-check:scripts exit 0 · pnpm check:vi-mock-inherit exit 0 ·
    pnpm check:vi-mock-specifiers exit 0.
  • Per-package type-check and lint for plugin-kanban and plugin-gantt:
    exit 0, 0 errors, proven non-vacuous rather than assumed —
    tsc -p tsconfig.test.json --listFiles names each edited test file exactly
    once, and eslint --format json lists each edited file among the linted set
    (37 and 91 files). Warning counts unchanged: every no-explicit-any warning in
    the touched files sits on a pre-existing line above this diff's hunks. The
    type-check task dependsOn ^build, so turbo built the dependency closure.

Concurrency note (A3)

Yes — a #5174 batch-18 PR on one of these packages exists: #8009,
docs(plugin-gantt): compile the gantt README's 18 blocks and drop its ledger entry
, opened after this branch was cut. Its file list read over git is
packages/plugin-gantt/README.md and scripts/check-doc-snippet-types.mjs
zero overlap with the 7 files here. main moved by two commits while this batch
was in flight (#8003, #8002) and has been merged into this branch; the suites,
the ablation and every gate above were re-run on the merged head after that.

Live E2E (informational) is red on every branch today for an upstream reason
(#7990 / objectstack#16186), not for anything in this diff.

🤖 Generated with Claude Code

https://claude.ai/code/session_01MM7kaS4dPpYHV5BsMyu4tQ


Generated by Claude Code

The three plugin-kanban files and the one plugin-gantt file left in the
network-escape ledger for `/api/v1/security/explain` now answer that probe
from a recording double instead of a real socket, and their lines leave
`KNOWN_ESCAPES` and `PINNED_LEDGER` together — 16 rows to 12 in both.

Mechanism, traced with a stack probe on the guard's attribution point rather
than assumed: all four go through ONE hook. RecordDetailDrawer renders
DetailView, which calls `useRecordEditable` twice per open (edit, then
delete); at `useRecordEditable.ts:76` the hook degrades from the host's
authenticated `apiFetch` to the global `fetch`, and under happy-dom that
global is a real HTTP client whose document URL is `http://localhost:3000`.
The read is best-effort, which is why every one of these files stayed green
while its request always failed.

The double is the shape #5225 settled on and batch 1 landed in
`ObjectCalendar.navWidthDefault.test.tsx`: a router, not a sink. It records
every URL it is handed and `afterEach` fails on any URL that is not the
explain route, so an escape elsewhere reds here instead of vanishing into the
hook's `catch`; `cleanup()` runs before `vi.unstubAllGlobals()` so no verdict
effect can settle with the real fetch back in place (#7439). It answers the
permissive verdict, which is the same downstream state the failing request
produced — `useRecordEditable` initialises `allowed` to true and its failure
path leaves it there — so no existing assertion changes meaning. Nothing is
skipped, quarantined or silenced.

Part of #7307

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MM7kaS4dPpYHV5BsMyu4tQ
@github-actions

github-actions Bot commented Sep 6, 2026

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

Metric Value Budget
Eager closure (gzip, 50 chunks) 3186.0 KB 3191.4 KB
Main entry chunk (gzip) 143.5 KB 350 KB
Entry file index-BO0uFEv5.js
Status PASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

Package Size Gzipped
app-shell (consoleActionDispatch.js) 0.20KB 0.19KB
app-shell (index.js) 15.67KB 5.75KB
app-shell (runtime-config.js) 20.68KB 7.36KB
app-shell (types.js) 0.01KB 0.04KB
app-shell (urlParams.js) 10.06KB 3.86KB
auth (ActiveOrganizationStorage.js) 25.05KB 9.16KB
auth (AuthContext.js) 0.31KB 0.24KB
auth (AuthGuard.js) 2.07KB 1.00KB
auth (AuthProvider.js) 40.18KB 10.59KB
auth (AuthShell.js) 3.49KB 1.40KB
auth (ForgotPasswordForm.js) 12.21KB 3.45KB
auth (LoginForm.js) 18.15KB 5.39KB
auth (PreviewBanner.js) 0.90KB 0.50KB
auth (RegisterForm.js) 6.65KB 2.22KB
auth (SocialSignInButtons.js) 9.61KB 3.89KB
auth (UserMenu.js) 3.41KB 1.23KB
auth (auth-gate-events.js) 1.29KB 0.66KB
auth (authStyles.js) 5.04KB 1.72KB
auth (createAuthClient.js) 40.21KB 10.80KB
auth (createAuthenticatedFetch.js) 8.46KB 3.43KB
auth (index.js) 3.19KB 1.44KB
auth (invitation-status.js) 1.22KB 0.70KB
auth (org-roles.js) 6.66KB 2.78KB
auth (phone-identifier.js) 1.11KB 0.66KB
auth (types.js) 0.59KB 0.35KB
auth (useAuth.js) 5.30KB 1.02KB
auth (useWorkspaceAdminStatus.js) 5.13KB 2.35KB
collaboration (CommentThread.js) 26.08KB 7.56KB
collaboration (LiveCursors.js) 3.17KB 1.27KB
collaboration (PresenceAvatars.js) 6.49KB 2.64KB
collaboration (PresenceProvider.js) 2.79KB 1.13KB
collaboration (index.js) 1.68KB 0.73KB
collaboration (useCollaborationTranslation.js) 6.05KB 2.52KB
collaboration (useCommentSearch.js) 1.98KB 0.88KB
collaboration (useConflictResolution.js) 7.75KB 1.86KB
collaboration (useMentionNotifications.js) 1.81KB 0.68KB
collaboration (usePresence.js) 6.33KB 1.84KB
collaboration (useRealtimeSubscription.js) 7.91KB 2.01KB
components (index.js) 497.06KB 113.79KB
core (index.js) 6.96KB 2.79KB
create-plugin (index.js) 10.08KB 3.26KB
data-objectstack (index.js) 182.08KB 50.62KB
fields (index.js) 242.44KB 61.25KB
i18n (LocalizationContext.js) 1.76KB 0.96KB
i18n (builtinAggregateLabels.js) 0.86KB 0.49KB
i18n (currency.js) 1.22KB 0.64KB
i18n (fallbackInterpolation.js) 6.25KB 2.77KB
i18n (i18n.js) 4.28KB 1.75KB
i18n (index.js) 3.65KB 1.47KB
i18n (pickLocalized.js) 7.62KB 3.26KB
i18n (provider.js) 26.89KB 9.04KB
i18n (useDisplayLocale.js) 2.85KB 1.45KB
i18n (useObjectLabel.js) 34.34KB 9.17KB
i18n (useSafeTranslation.js) 5.60KB 2.33KB
layout (index.js) 38.84KB 10.94KB
mobile (MobileProvider.js) 0.92KB 0.49KB
mobile (ResponsiveContainer.js) 0.94KB 0.38KB
mobile (breakpoints.js) 1.51KB 0.70KB
mobile (createOfflineDataSource.js) 5.61KB 1.75KB
mobile (index.js) 1.99KB 0.87KB
mobile (offlineQueue.js) 3.91KB 1.35KB
mobile (pwa.js) 0.97KB 0.49KB
mobile (serviceWorker.js) 1.48KB 0.62KB
mobile (serviceWorkerSource.js) 3.41KB 1.48KB
mobile (useBreakpoint.js) 1.54KB 0.65KB
mobile (useGesture.js) 6.96KB 1.98KB
mobile (useOfflineSync.js) 1.99KB 0.72KB
mobile (usePullToRefresh.js) 2.53KB 0.85KB
mobile (useResponsive.js) 0.72KB 0.42KB
mobile (useSpecGesture.js) 4.39KB 1.66KB
mobile (useTouchTarget.js) 1.01KB 0.54KB
permissions (MePermissionsProvider.js) 11.71KB 4.29KB
permissions (PermissionContext.js) 0.31KB 0.25KB
permissions (PermissionGuard.js) 0.89KB 0.45KB
permissions (PermissionProvider.js) 6.24KB 2.16KB
permissions (discardProofCache.js) 1.04KB 0.55KB
permissions (evaluator.js) 5.12KB 1.74KB
permissions (index.js) 0.93KB 0.41KB
permissions (store.js) 0.91KB 0.42KB
permissions (useFieldPermissions.js) 1.28KB 0.53KB
permissions (usePermissions.js) 4.83KB 2.27KB
plugin-ai (index.js) 15.16KB 3.68KB
plugin-calendar (index.js) 47.35KB 13.21KB
plugin-charts (index.js) 70.31KB 19.62KB
plugin-chatbot (index.js) 193.53KB 46.05KB
plugin-dashboard (index.js) 131.41KB 34.43KB
plugin-designer (index.js) 211.51KB 43.01KB
plugin-detail (index.js) 247.59KB 63.48KB
plugin-editor (index.js) 2.23KB 1.05KB
plugin-form (index.js) 131.01KB 32.32KB
plugin-gantt (index.js) 167.16KB 40.99KB
plugin-grid (index.js) 208.56KB 56.63KB
plugin-kanban (index.js) 52.30KB 14.49KB
plugin-list (index.js) 113.24KB 27.66KB
plugin-map (index.js) 20.35KB 6.77KB
plugin-markdown (index.js) 13.88KB 4.80KB
plugin-report (index.js) 43.42KB 11.92KB
plugin-timeline (index.js) 29.95KB 8.67KB
plugin-tree (index.js) 9.16KB 3.18KB
plugin-view (index.js) 84.33KB 20.75KB
providers (DataSourceProvider.js) 0.75KB 0.39KB
providers (MetadataProvider.js) 1.37KB 0.59KB
providers (ThemeProvider.js) 1.90KB 0.85KB
providers (UploadProvider.js) 11.66KB 3.50KB
providers (index.js) 0.45KB 0.23KB
providers (types.js) 0.01KB 0.04KB
react-runtime (index.js) 5.62KB 2.34KB
react (LazyPluginLoader.js) 4.47KB 1.63KB
react (SchemaRenderer.js) 81.07KB 26.86KB
react (data-invalidation.js) 5.05KB 2.08KB
react (index.js) 4.63KB 2.18KB
react (schema-input.js) 2.32KB 1.24KB
react (spec-input.js) 0.20KB 0.18KB
sdui-parser (codegen.js) 5.41KB 2.34KB
sdui-parser (dashboard-widget-options.js) 3.08KB 1.30KB
sdui-parser (index.js) 4.93KB 2.24KB
sdui-parser (input-type.js) 2.84KB 1.40KB
sdui-parser (parse.js) 20.57KB 5.88KB
sdui-parser (provenance.js) 3.66KB 1.82KB
sdui-parser (types.js) 0.28KB 0.23KB
sdui-parser (validate.js) 10.35KB 3.60KB
types (ai.js) 0.20KB 0.17KB
types (api-types.js) 0.20KB 0.18KB
types (app.js) 2.87KB 1.00KB
types (base.js) 0.20KB 0.18KB
types (blocks.js) 0.20KB 0.18KB
types (complex.js) 2.74KB 1.41KB
types (crud.js) 0.20KB 0.18KB
types (dashboard-filter-alias.js) 6.23KB 2.74KB
types (data-display.js) 3.75KB 1.85KB
types (data-protocol.js) 0.20KB 0.19KB
types (data.js) 0.20KB 0.18KB
types (designer.js) 1.85KB 0.85KB
types (disclosure.js) 0.20KB 0.18KB
types (error-code.js) 1.54KB 0.88KB
types (expression.js) 0.20KB 0.18KB
types (feedback.js) 0.20KB 0.18KB
types (field-types.js) 0.20KB 0.18KB
types (form.js) 0.20KB 0.18KB
types (http-inflight.js) 8.87KB 3.73KB
types (http-retry.js) 4.32KB 2.02KB
types (icon-key-migration.js) 4.26KB 1.63KB
types (index.js) 4.74KB 2.25KB
types (layout.js) 0.20KB 0.18KB
types (managed-by.js) 0.19KB 0.18KB
types (mobile.js) 4.73KB 2.28KB
types (navigation.js) 0.20KB 0.18KB
types (objectql.js) 0.20KB 0.18KB
types (overlay.js) 0.20KB 0.18KB
types (permissions.js) 0.20KB 0.18KB
types (plugin-scope.js) 0.20KB 0.18KB
types (record-components.js) 0.20KB 0.19KB
types (record-semantics.js) 1.28KB 0.67KB
types (registry.js) 0.20KB 0.18KB
types (reports.js) 0.20KB 0.18KB
types (select-option.js) 0.20KB 0.19KB
types (spec-report.js) 5.05KB 1.93KB
types (spec-ui-namespace.js) 0.20KB 0.19KB
types (system-fields.js) 3.33KB 1.54KB
types (theme.js) 6.28KB 2.87KB
types (ui-action.js) 8.11KB 3.32KB
types (views.js) 0.20KB 0.18KB
types (widget.js) 0.20KB 0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

Copy link
Copy Markdown
Contributor Author

Standing-down note — Live E2E (informational) is red on this head (59ccee7) as it is on main and on every branch today: the upstream base-red anchored on #7990 (objectstack#16186). It is continue-on-error by design, never blocks the queue, and touches nothing this diff changes (four test files, the two ledger literals, one empty changeset). Not this PR's to fix; no re-run requested. Every other non-skipped check is green at 09:20Z. Flipping ready and arming.


Generated by Claude Code

@baozhoutao
baozhoutao marked this pull request as ready for review September 6, 2026 09:20
@baozhoutao
baozhoutao added this pull request to the merge queue Sep 6, 2026
Merged via the queue into main with commit eeda78a Sep 6, 2026
33 of 34 checks passed
@baozhoutao
baozhoutao deleted the claude/issue-7307-network-escapes-batch2 branch September 6, 2026 09:37
baozhoutao pushed a commit that referenced this pull request Sep 6, 2026
Batch 18 (PR #8009) and objectui#7307 batch 2 (PR #8013) landed while this batch
was measuring. Both gate-file changes are removals inside UNGATED_DOCS on
different lines, for different documents.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FhBNJcLRZLe8M87VcUgpKr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants