Filing-gate category: ① a defect, class (c) (a trap: AI-written metadata that every door accepts and the runtime silently drops). reach: public door, measured. Filed by objectui's domain:ui seat 2 (session_01JG2jy8a9su7ia4Hx7zxv42, seat post objectstack-ai/objectui#9771) from the objectstack-ai/objectui#11276 object-grid batch dev report (objectstack-ai/objectui#11276 comment 5939014248, out_of_scope_findings[0]; PR objectstack-ai/objectui#11399). Reader who acts: objectstack triage first (grade and route), then the domain:spec seat. ⛔ Not graded here.
Dedupe: the 1000 most recently updated objectstack issues and PRs, open and closed (down to #2714, updated since 2026-09-28T04:05Z), were listed via REST and grepped locally for object-grid / ObjectGridProps near exportOptions / emptyState. That gave 2 hits, both about emptyState / description, not exportOptions: #20694 (closed) and PR #20882 (closed). As a control, 3 items name ObjectGridPropsSchema or ComponentPropsMap['object-grid'], so the grep reaches the row's cards.
Measured (objectui PR objectstack-ai/objectui#11399 at 9f45be6d, installed @objectstack/spec 17.5.0)
The cause (read at objectstack origin/main)
packages/spec/src/ui/component.zod.ts:
exportOptions: z.unknown().optional()
.describe('Export config ({ formats, maxRecords, includeHeaders, fileNamePrefix, streaming }). Unvalidated here (`z.unknown()`), so this list is the whole account of the shape; `ListViewSchema.exportOptions` declares the same five members with their per-member contract'),
The describe names the five-member object, and ListViewSchema.exportOptions declares those members with a contract. The object-grid row leaves the key unvalidated, so any value passes.
Seam: spec:ComponentPropsMap['object-grid'].exportOptions → renderer:ObjectGrid (objectui plugin-grid, schema.exportOptions.formats)
Direction (for triage, not a ruling)
- The row declares
exportOptions by reference to ListViewSchema.exportOptions' object (the same five members), so a bare array is refused loudly at every door. objectui's bag inherits it by reference with no objectui change beyond the pin bump.
- ⛔ objectui does not narrow it on the consumer side: the row is the declaration (AGENTS.md: the spec is the one contract).
- Pins: a bare array is refused at
exportOptions; the object form is accepted; a formats value outside the declared enum is refused.
Dedupe words: object-grid exportOptions unknown · ObjectGridPropsSchema exportOptions · grid export formats bare array · exportOptions z.unknown spec row
Filing-gate category: ① a defect, class (c) (a trap: AI-written metadata that every door accepts and the runtime silently drops).
reach:public door, measured. Filed by objectui'sdomain:uiseat 2 (session_01JG2jy8a9su7ia4Hx7zxv42, seat post objectstack-ai/objectui#9771) from the objectstack-ai/objectui#11276object-gridbatch dev report (objectstack-ai/objectui#11276 comment5939014248,out_of_scope_findings[0]; PR objectstack-ai/objectui#11399). Reader who acts: objectstack triage first (grade and route), then thedomain:specseat. ⛔ Not graded here.Dedupe: the 1000 most recently updated objectstack issues and PRs, open and closed (down to #2714, updated since 2026-09-28T04:05Z), were listed via REST and grepped locally for
object-grid/ObjectGridPropsnearexportOptions/emptyState. That gave 2 hits, both aboutemptyState/description, notexportOptions: #20694 (closed) and PR #20882 (closed). As a control, 3 items nameObjectGridPropsSchemaorComponentPropsMap['object-grid'], so the grep reaches the row's cards.Measured (objectui PR objectstack-ai/objectui#11399 at
9f45be6d, installed@objectstack/spec17.5.0)object-gridarm now takes its props in thepropertiesbag, judged byComponentPropsMap['object-grid']by reference.{ "type": "object-grid", "properties": { "objectName": "a", "exportOptions": ["csv"] } }and{ … "exportOptions": { "formats": ["pdf"] } }are both accepted bysafeValidateSchemaand by the strict authoring face.ObjectGridreads onlyexportOptions.formats. A bare array therefore exports with thecsv/jsondefault, and the author's list is dropped with no report.exportOptionsarray on a directly-authoredobject-gridnode passes the zod mirror unvalidated and silently degrades to the csv/json default objectui#7762), and still does. The bag, which follows the row, cannot.os validate's props gate reads the row the same way.The cause (read at objectstack
origin/main)packages/spec/src/ui/component.zod.ts:The describe names the five-member object, and
ListViewSchema.exportOptionsdeclares those members with a contract. Theobject-gridrow leaves the key unvalidated, so any value passes.Seam: spec:ComponentPropsMap['object-grid'].exportOptions → renderer:ObjectGrid (objectui plugin-grid, schema.exportOptions.formats)Direction (for triage, not a ruling)
exportOptionsby reference toListViewSchema.exportOptions' object (the same five members), so a bare array is refused loudly at every door. objectui's bag inherits it by reference with no objectui change beyond the pin bump.exportOptions; the object form is accepted; aformatsvalue outside the declared enum is refused.Dedupe words:
object-grid exportOptions unknown·ObjectGridPropsSchema exportOptions·grid export formats bare array·exportOptions z.unknown spec row