Skip to content

chore(deps): upgrade @objectstack/* 17.0.0-rc.5 → 17.0.0-rc.6 (maintainer order), and re-measure tracked upstream-mirror behavior #1059

Description

@huangyiirene

Mandate

Maintainer order (huangyi, 2026-08-11, PM chat session session_01NM6o28jmBgsyTRQHutn7LC), verbatim:

objectstack 应该升级到最新的 17.0.0-rc.6 立一单立刻处理。

Current state (measured at filing)

  • package.json pins all @objectstack/* packages at 17.0.0-rc.5 (13 entries: account, cli, driver-memory, driver-sql, driver-sqlite-wasm, metadata, objectql, runtime, service-analytics, service-automation, spec, formula, + create tooling where applicable).
  • Upstream tag create-objectstack@17.0.0-rc.6 exists on objectstack-ai/objectstack; the dev must verify the full @objectstack/* family is published at rc.6 on npm before bumping (re-check: pnpm view @objectstack/spec versions --json | tail).

Scope (precedent: #901, the rc.2 → rc.3 upgrade card)

  1. Bump every @objectstack/* dependency in package.json to 17.0.0-rc.6; regenerate pnpm-lock.yaml.
  2. Keep objectstack.config.ts engines.protocol and objectstack.manifest.json consistent with the new pin ([17.0-rc2验收] objectstack.config.ts 的 engines.protocol 仍是 ^17.0.0-rc.1,与 objectstack.manifest.json(rc.2)及 build 产物不一致 #728 precedent: config/manifest/build must not diverge).
  3. Full verification: pnpm build, pnpm validate, pnpm lint, full test suite, and a dev-server boot smoke check.
  4. Re-measure tracked upstream-mirror cards where a cheap repro exists and report which changed on rc.6 (do not deep-dive; one probe each): [17.0-rc][疑似平台] member_default* 通配授权(C/R/E)并集合并进每个成员 —— 应用的 explicit-allow 对象门在建/读/改三轴上被整体架空,任何 profile 都能在任何对象上建记录 #703 [17.0-rc][疑似平台] 写扩权全部失灵:modifyAllRecords 对行级写门无效,edit 级 sys_record_share 实际只给读 —— sales_manager 改不了任何非本人创建的记录 #705 回归:#547 实测通过的 marketing_campaign_updates RLS 写扩权在 rc.2 上失效(403);同 PR 的 campaign_member 扩权仍工作 #706 [17.0-rc][疑似平台] 自动化引擎 create_record(系统扫)插入的行 owner_id/organization_id/created_by 全 NULL —— 出生即连 admin 都无法改删;demo_bootstrap 十分钟内会"自愈" owner_id,真实安装没有这根拐杖 #700 [17.0-rc][疑似平台] crm_case 自动编号计数器落后于既有 case_number:REST 建单连续 409,每次失败还烧掉一个号(实测重试 25 次才成功) #698 (permissions/RLS/counter), Address fields render as raw JSON on the record detail page #664 (address JSON), FlowVariableSchema has no defaultValue, so a flow variable cannot be declared bound — the obvious remedy for an unbound-variable condition does not exist #651 (FlowVariableSchema.defaultValue), 批量写(multi: true)路径上 ctx.previous 恒为空 —— 15 个读 previous 的 hook 在该路径全部空转,知识文章可被批量写成「已发布但从未复核」 #779 (ctx.previous on multi), 页面组件文案没有翻译位:12 处用户可见字符串(首页占 10)在 zh/ja/es 下只能是英文,而 dashboards.widgets 有同形的翻译面 #1004 (page component i18n), [17.0-rc][疑似平台] datetime 字段的时间窗过滤返回空集(客服仪表盘全空) #520 [17.0-rc][疑似平台] script action 的 body 写库被 FORBIDDEN(admin 用户) #521 [17.0-rc][疑似平台] 全局(无 objectName)action 无法派发,且 UI 把失败当成功静默吞掉 #522 [17.0-rc][疑似平台] flow 型 action 菜单项无响应;screen flow 服务端失败无任何 UI 回显 #524 [17.0-rc][疑似平台] 多 tab 新建表单校验失败后丢失已填值且布局错乱 #525 (p0/p1 platform suspects). A one-line verdict per card in the PR body is enough; behavior changes get a comment on the respective card.
  5. Changeset required by CI.

Known adjacencies

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

configurationBuild and app configuration filespm:dispatchedDispatched to a dev agent by /pm-dispatchprio:p1Next in line once P0s clear

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions