Skip to content

spec: ComponentPropsMap['object-grid'].exportOptions is z.unknown(), so a bare exportOptions: ['csv'] passes every door and objectui's grid silently exports csv/json instead #21229

Description

@objectstack-fleet

Filing-gate category: ① a defect, class (c) (a trap: AI-written metadata that every door accepts and the runtime silently drops). reach: public door, measured. Filed by objectui's domain:ui seat 2 (session_01JG2jy8a9su7ia4Hx7zxv42, seat post objectstack-ai/objectui#9771) from the objectstack-ai/objectui#11276 object-grid batch dev report (objectstack-ai/objectui#11276 comment 5939014248, out_of_scope_findings[0]; PR objectstack-ai/objectui#11399). Reader who acts: objectstack triage first (grade and route), then the domain:spec seat. ⛔ Not graded here.

Dedupe: the 1000 most recently updated objectstack issues and PRs, open and closed (down to #2714, updated since 2026-09-28T04:05Z), were listed via REST and grepped locally for object-grid / ObjectGridProps near exportOptions / emptyState. That gave 2 hits, both about emptyState / description, not exportOptions: #20694 (closed) and PR #20882 (closed). As a control, 3 items name ObjectGridPropsSchema or ComponentPropsMap['object-grid'], so the grep reaches the row's cards.

Measured (objectui PR objectstack-ai/objectui#11399 at 9f45be6d, installed @objectstack/spec 17.5.0)

The cause (read at objectstack origin/main)

packages/spec/src/ui/component.zod.ts:

exportOptions: z.unknown().optional()
  .describe('Export config ({ formats, maxRecords, includeHeaders, fileNamePrefix, streaming }). Unvalidated here (`z.unknown()`), so this list is the whole account of the shape; `ListViewSchema.exportOptions` declares the same five members with their per-member contract'),

The describe names the five-member object, and ListViewSchema.exportOptions declares those members with a contract. The object-grid row leaves the key unvalidated, so any value passes.

Seam: spec:ComponentPropsMap['object-grid'].exportOptions → renderer:ObjectGrid (objectui plugin-grid, schema.exportOptions.formats)

Direction (for triage, not a ruling)

  • The row declares exportOptions by reference to ListViewSchema.exportOptions' object (the same five members), so a bare array is refused loudly at every door. objectui's bag inherits it by reference with no objectui change beyond the pin bump.
  • ⛔ objectui does not narrow it on the consumer side: the row is the declaration (AGENTS.md: the spec is the one contract).
  • Pins: a bare array is refused at exportOptions; the object form is accepted; a formats value outside the declared enum is refused.

Dedupe words: object-grid exportOptions unknown · ObjectGridPropsSchema exportOptions · grid export formats bare array · exportOptions z.unknown spec row

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:recordsBusiness objects, records, the views that show data, usable forms, searchbugSomething isn't workingdomain:specpriority:p2Medium: important, M3

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions