Skip to content

spec(forms): retire publicPicker — anonymous public forms stop taking lookup / master_detail / user fields, and the anonymous picker route goes (ruling E on #21079) #21180

Description

@objectstack-fleet

Filed by the director seat, summon #32, session_016tKoy8NJa35Yih1FdzrVmn, as the second half of the maintainer's ruling E on #21079. The ruling is batch #261 item 1, maintainer 「同意E」; the record is the Ruling: comment on #21079. ⛔ Not a claim.

What was ruled

Anonymous public forms no longer take lookup, master_detail or user fields, so the anonymous record-search picker goes.

Readings that decided it (taken before the ruling, at the refs named)

  • Zero producers, across all four repos. git grep -n publicPicker origin/main, excluding packages/spec, tests and changelogs:
    • objectstack fbcc05f400: docs, the lint reader validate-preset-comparands.ts, the REST route and its ledger row only. No example declares one.
    • hotcrm fb408a7304: 0. cloud: 0.
  • No first-party UI caller. objectui main 6c3da53aee has no source that requests the picker route: git grep -n -E "lookup/|/lookup" over packages and apps (tests excluded) hits only comments and a /dev/lookup dev route. Control: the same tree hits the anonymous form's /forms/ routes (apps/console/src/components/FormPage.tsx:5).
  • Pin safety. objectui at objectstack's pinned .objectui-sha e420df310f imports neither publicPicker nor FormFieldPublicPicker*. Post-Task step 4 is satisfied: no sibling fix and no pin bump ride this removal.

Scope

Follow the spec-property-retirement skill (.claude/skills/). The ADR-0087 D2 route, immediate retirement, with no staged window.

  1. Spec. In packages/spec/src/ui/view.zod.ts, FormFieldBaseSchema.publicPicker becomes a retiredKey() tombstone whose text carries the prescription below. FormFieldPublicPickerSchema and its two exported types are removed. The rest goes with them: the liveness-ledger row, the ADR-0087 registry entry, gen:schema/gen:docs/gen:api-surface, and the strictness and authorable-surface artifacts.
  2. REST.
    • Delete the GET /forms/:slug/lookup/:field handler in packages/rest/src/rest-server.ts, its literal guest_portal picker context, and its row in packages/rest/src/rest-route-ledger.ts.
    • The public-form resolve route keeps stripping lookup / master_detail / user fields from the anonymous rendering, now unconditionally. ⛔ No new gate (the maintainer's no-new-gates default).
    • LOOKUP_NOT_PUBLIC leaves packages/spec/src/api/error-code-ledger.zod.ts by that ledger's own retirement rule (ADR-0112).
  3. Lint and tests. Remove the publicPicker reader in packages/lint/src/validate-preset-comparands.ts and its cases. Delete or re-pin the picker tests: packages/rest/src/public-form-lookup-*.test.ts and public-form-routes*.test.ts, the picker cases of rest-server-query-number-census.test.ts, packages/spec/src/ui/view-public-picker.test.ts, and packages/qa/dogfood/test/public-picker-queryable-key.dogfood.test.ts. Also the picker door case in packages/qa/dogfood/test/zero-set-masking.dogfood.test.ts; see Serial.
  4. Docs. Remove the picker section of content/docs/ui/forms.mdx (its two tables included). The references regenerate.
  5. ADR-0061 (docs/adr/0061-record-search-architecture.md:54 says anonymous search "keeps the existing publicPicker model"). Add a dated note under that entry naming the retirement and this ruling. ⛔ The original text is not rewritten. It is a separate docs-only Tier H PR for the maintainer's click, ⛔ not part of the code PR.
  6. Changeset. BREAKING, Clause-②: yes (narrowing), with the ADR-0087 disposition marker. FROM → TO: delete the publicPicker block; an anonymous public form no longer offers record search. Use a select field with static options, or put the form behind sign-in.

Lane and parameters (ruled with E)

Dedupe

mcp__github__search_issues, repo-scoped, open and closed: 「retire publicPicker anonymous public form lookup picker」 → 4 hits. #21137 (open, superseded above) · #7467 (closed, the reversed ruling) · #7485 and #7486 (closed, sibling keys of the same block). None retires the key.

Dedupe words: publicPicker retirement · anonymous form lookup field · public lookup picker route · LOOKUP_NOT_PUBLIC


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:accessPermissions that actually hold — RLS/FLS, sharing model, write-path guardsdomain:specpriority:p1High: required for production / M2security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions