chore: version packages - #5
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and publish to npm yourself or setup this action to publish automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.
Releases
@haverstack/[email protected]
Minor Changes
#4
6fb20b3Thanks @cuibonobo! - Adopt core 0.37: record permissions are associations, and six operations no longer bump a versionPermission[]is gone. A record's ACL is two association kinds over the same table —{ kind: 'permission', label: 'read' | 'write', grantee }and{ kind: 'anyone', label: 'read' }— withgrantAccess()/revokeAccess()adding and withdrawing exactly oneelement.
hstack permfollows: it no longer reads the whole list, edits an entry andwrites the array back, a read-modify-write that silently discarded whatever a second
admin granted in between.
The flags move with the model.
--publicbecomes--anyone, which carriesreadalone(
--writebeside it is refused rather than written and bounced).--groupnow requires--role memberor--role admin, because member and admin are two different elements andneither is a safe guess.
perm rmnaming neither--readnor--writewithdraws thetarget's access entirely; naming one withdraws just that one.
perm add --read --writegrants read first and
perm rmwithdraws write first, which is the one ordering thatsatisfies core's rule that no write lands in a set whose grantee cannot read it. New:
hstack perm ls <id>prints the whole ACL.hstack grant's target is core's requiredGrantGranteeunion:--defaultbecomes--authenticated(any entity holding a DID — a tier below--anyone, which also reachesanonymous requesters), and
--grouptakes--role.grant lsaccepts the same flags asa query, widened by the listing-only
--role any, andgrant rmreports how many grantsit withdrew now that
revoke()returns them.associate,dissociate,permissions,reparent,unlistandlistare no-bump:they leave
versionandupdatedAtexactly where they stand.tag,link,permandattachtherefore stop printing a version that did not move, and compare the recordbefore and after instead — a repeat now says
already taggedrather than claiming a writethat did not happen.
hstack commitreports the version its ownmutate()produced,since the tag and attachment reconcile that follow cannot move it.
Also:
hstack rm --hardreports the files the purged record referenced (core'sdelete()returns them, because destroying the record destroys the only rows namingthem), and
hstack attach addrecords anattachmentRecordIdso a filename resolves tothe upload that reference came from.
Not backwards compatible. The SQLite schema is create-if-missing with no migrations,
so a database written before core 0.37 keeps its old tables and fails on the first
permission write. Existing stacks must be recreated.
#4
b5e514eThanks @cuibonobo! - Name every association target the same way: one--to, parsed once, narrowed per commandlink,permandgranteach had their own way of spelling the other end — ten flagsbetween them (
--to-record,--stack-url,--to-entity,--to-external,--external-id,--anyone,--entity,--group,--role,--authenticated), threesets of "exactly one of" rules, and three shapes for what is, to the person typing, one
idea. They now share
--to <target>:The vocabulary is the CLI's own and deliberately wider than any single core union. Core
keeps three apart on purpose — a
RelationshipTargetnames no role, aPermissionGranteehas no record scope, andanyoneis a kind rather than a grantee —and that split is right for the data model and wrong for a person, who is naming Alice
either way. So one grammar parses, and each command narrows to the arms it accepts,
refusing the rest by name. The narrowing is where core's distinctions are enforced.
Exactly one shape is inferred: a leading
did:is an entity, because a DID is the oneidentifier every command takes and
entity:did:key:…reads badly on the most frequentcall. Everything else names its scheme, and an unknown one is an error rather than a
fallback.
external:nests its namespace rather than sharing the top-level scheme slot,since
nsis open and user-chosen — letting it compete withgroup:/record:wouldreserve words out of a namespace the CLI does not own.
formatTarget()isparseTarget()'s inverse, soperm lsandgrant lsnow printtargets unelided in the grammar their own commands accept: a listing row is a command
argument.
grant ls --role anybecomes--to group:<id>/any, which also puts thelisting widening and the world-read tier in structurally different slots instead of one
letter apart.
The single seam is the point. The deferred
--pickselector resolves a filter to an idand substitutes it into the invoking command; against three flag shapes that would have
been three substitution paths.
Every entry point hands back one command's own narrow type —
parsePermissionTarget(),parseGrantTarget(),parseGrantQuery()andparseLinkTarget(), returning core'sPermissionGrantee,GrantGrantee,GrantQueryand
RelationshipTarget. The wide union is module-private and never escapes, so theper-command table is enforced by the type system rather than by remembering to call a
narrowing step. One shared parser still backs all four: one grammar to keep correct
rather than four that can drift.
A target from the wrong tier is refused and told what to say instead, never converted.
grant --to anyoneis pointed atauthenticated;link --to group:X/memberatrecord:X;perm/grant --to record:Xatgroup:X/<role>. The one asymmetry isdeliberate:
perm --to authenticatedis not offeredanyoneas a synonym, becauseanyoneis the wider tier — it names it and says so, leaving the widening a choice.buildRelationshipTargetand thePermTargetOptions/GrantTargetOptions/LinkTargetOptionstypes are gone — the target is a string now.