Skip to content

fix(dashboard,charts): resolve {current_user_id} in widget filters (framework #3574) - #2857

Merged
os-zhuang merged 1 commit into
mainfrom
fix/dashboard-widget-current-user
Jul 27, 2026
Merged

fix(dashboard,charts): resolve {current_user_id} in widget filters (framework #3574)#2857
os-zhuang merged 1 commit into
mainfrom
fix/dashboard-widget-current-user

Conversation

@os-zhuang

Copy link
Copy Markdown
Contributor

Runtime half of objectstack-ai/objectstack#3574. Authoring-time gate + spec vocabulary: objectstack-ai/objectstack#3594.

Why widgets never resolved the token

A dashboard widget filtered on {current_user_id} rendered 0 — the token reached SQL as a literal, matched no row, and nothing was logged anywhere. The same token in a list-view filter resolved fine, so a user-scoped list and a user-scoped widget over the same data disagreed.

There was no shared resolver. Three ad-hoc implementations had grown up independently, each understanding only the filter shape its own surface used:

implementation handles
ObjectView.substituteFilterTokens arrays onlyif (!Array.isArray(filter)) return filter
ObjectDataPage inline ternary URL [field, op, value] triples
NavigationRenderer.applyNavTemplate hrefs, never filters

That first one is the crux: widget filters are MongoDB-style objects, so ObjectView's helper would have been a silent no-op even if someone had thought to call it. Widgets therefore got nothing — DatasetWidget called resolveDateMacros alone, which is precisely why {today} worked in a widget and {current_user_id} silently did not.

Six widgets were affected, not one: DatasetWidget, ObjectMetricWidget, ObjectDataTable, ObjectPivotTable, ObjectChart (dataset-bound and inline paths).

What changed

  • @object-ui/coreutils/filter-tokens.ts: resolveContextTokens plus resolveFilterPlaceholders, which expands every placeholder vocabulary in one call. That combined entry point is the actual fix for the class of bug: resolving only some vocabularies is what happened here. The walk handles arrays and plain objects uniformly, so one resolver covers both platform filter shapes.
  • @object-ui/reactFilterScopeProvider / useFilterScope. The renderer packages deliberately don't depend on @object-ui/auth, so the shell supplies the session values. Kept separate from PredicateScopeContext, which is the expression evaluation scope and carries no organization — widening it for filter resolution would couple two unrelated contracts.
  • plugin-dashboard / plugin-charts — all six widgets now resolve both vocabularies. The chart's compareTo comparison filter gets the session pass too; otherwise the overlay series silently ignored the owner clause the primary series honoured.
  • app-shellObjectView and ObjectDataPage now delegate to the shared resolver, gaining {current_org_id} and date macros. Two of the three ad-hoc implementations are deleted rather than joined by a fourth.

Behaviour on an unresolvable token

Left intact, not dropped. Leaving it yields an empty result; dropping the clause would widen the result set and show a signed-out viewer everyone's data. It is no longer silent — the resolver warns naming the token, and suggests the intended spelling for known near-misses ({current_user}, {user_id}, {organization_id}), each of which is a correct spelling somewhere else in the platform.

Verification

Live browser, real stack (app-todo on a fresh wasm-SQLite DB, console dev server on workspace packages): a metric widget filtered on { owner: '{current_user_id}' } reads 3 against Total Tasks 8, matching exactly the three records assigned to the signed-in user. Console clean, no errors.

Regression test proven red. DatasetWidget.filterTokens.test.tsx asserts on the runtimeFilter actually handed to queryDataset — the seam the bug lived at. Reverting DatasetWidget to resolveDateMacros turns 4 of its 5 cases red.

No regressions. core + react + plugin-dashboard + plugin-charts: 1581 passing. app-shell: 1848 passing. tsc --noEmit clean on all five changed packages.

🤖 Generated with Claude Code

…ramework #3574)

A dashboard widget filtered on `{current_user_id}` rendered `0`. The token
reached SQL as a literal, matched no row, and nothing was logged on the client
or the server — a silent zero that reads as "you have no work" rather than
"this filter did not resolve". The same token in a list-view filter resolved
correctly, so a user-scoped list and a user-scoped widget over the same data
disagreed.

There was no shared resolver. Three ad-hoc implementations had grown up
independently — ObjectView for list views, ObjectDataPage for URL filter
triples, NavigationRenderer for hrefs — each understanding only the filter shape
its own surface used. ObjectView's opened with
`if (!Array.isArray(filter)) return filter`, so it could not have been reused by
dashboard widgets even in principle: widget filters are MongoDB-style objects.
Widgets therefore got no resolution at all — DatasetWidget called
resolveDateMacros and nothing else, which is why `{today}` worked in a widget
and `{current_user_id}` silently did not.

- core: new utils/filter-tokens.ts with resolveContextTokens and
  resolveFilterPlaceholders. The latter expands EVERY placeholder vocabulary in
  one call and is what surfaces should use; resolving only some of them is the
  whole defect. The walk handles arrays and plain objects uniformly, so one
  resolver covers both platform filter shapes.
- react: new FilterScopeProvider / useFilterScope. The renderer packages
  deliberately do not depend on @object-ui/auth, so the shell supplies the
  session values. Separate from PredicateScopeContext, which is the expression
  evaluation scope and carries no organization.
- plugin-dashboard / plugin-charts: all six widgets that previously resolved
  date macros only now resolve both vocabularies — DatasetWidget,
  ObjectMetricWidget, ObjectDataTable, ObjectPivotTable, and ObjectChart
  (dataset-bound and inline paths). The chart's compareTo comparison filter gets
  the session pass too, or the overlay series silently ignores the owner clause
  the primary series honours.
- app-shell: ObjectView's local substituteFilterTokens and ObjectDataPage's
  inline `=== '{current_user_id}'` ternary now delegate to the shared resolver,
  so both also gain {current_org_id} and date macros. Two of the three ad-hoc
  implementations are gone rather than joined by a fourth.

An unresolvable token is left intact rather than dropped: leaving it yields an
empty result, whereas dropping the clause would WIDEN the result set and show a
signed-out viewer everyone's data. It is no longer silent — the resolver warns,
naming the token, and suggests the intended spelling for known near-misses.

Verified end-to-end against a live app-todo stack: a metric widget filtered on
`{ owner: '{current_user_id}' }` read 3 against Total Tasks 8, matching the
three records assigned to the signed-in user.

Co-Authored-By: Claude <noreply@anthropic.com>
@vercel

vercel Bot commented Jul 27, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated (UTC)
objectui Ignored Ignored Jul 27, 2026 8:44am

Request Review

@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

Metric Value Budget
Main entry (gzip) 28.0 KB 350 KB
Entry file index-BgGHC2_e.js
Status PASS

📦 Bundle Size Report

Package Size Gzipped
app-shell (index.js) 8.20KB 2.97KB
app-shell (runtime-config.js) 7.42KB 2.32KB
app-shell (types.js) 0.01KB 0.04KB
app-shell (urlParams.js) 7.57KB 2.97KB
auth (AuthContext.js) 0.31KB 0.24KB
auth (AuthGuard.js) 1.17KB 0.53KB
auth (AuthProvider.js) 21.70KB 4.21KB
auth (AuthShell.js) 3.49KB 1.40KB
auth (ForgotPasswordForm.js) 12.12KB 3.41KB
auth (LoginForm.js) 17.86KB 5.29KB
auth (PreviewBanner.js) 0.90KB 0.50KB
auth (RegisterForm.js) 6.43KB 2.09KB
auth (SocialSignInButtons.js) 9.60KB 3.89KB
auth (UserMenu.js) 3.40KB 1.22KB
auth (auth-gate-events.js) 1.29KB 0.66KB
auth (authStyles.js) 5.04KB 1.72KB
auth (createAuthClient.js) 33.74KB 8.53KB
auth (createAuthenticatedFetch.js) 4.37KB 1.69KB
auth (index.js) 1.83KB 0.79KB
auth (phone-identifier.js) 1.11KB 0.66KB
auth (types.js) 0.59KB 0.35KB
auth (useAuth.js) 4.86KB 0.85KB
auth (useIsWorkspaceAdmin.js) 1.61KB 0.85KB
collaboration (CommentThread.js) 18.38KB 4.49KB
collaboration (LiveCursors.js) 3.17KB 1.27KB
collaboration (PresenceAvatars.js) 3.65KB 1.42KB
collaboration (PresenceProvider.js) 2.79KB 1.13KB
collaboration (index.js) 1.25KB 0.53KB
collaboration (useCommentSearch.js) 1.98KB 0.88KB
collaboration (useConflictResolution.js) 7.75KB 1.86KB
collaboration (useMentionNotifications.js) 1.81KB 0.68KB
collaboration (usePresence.js) 6.33KB 1.84KB
collaboration (useRealtimeSubscription.js) 7.91KB 2.01KB
components (index.js) 450.70KB 98.15KB
core (index.js) 2.12KB 0.77KB
create-plugin (index.js) 9.28KB 2.98KB
data-objectstack (index.js) 127.29KB 31.96KB
fields (index.js) 218.35KB 53.54KB
i18n (LocalizationContext.js) 1.76KB 0.96KB
i18n (currency.js) 1.22KB 0.64KB
i18n (i18n.js) 4.32KB 1.77KB
i18n (index.js) 2.46KB 0.96KB
i18n (pickLocalized.js) 1.70KB 0.83KB
i18n (provider.js) 5.37KB 1.72KB
i18n (useObjectLabel.js) 25.17KB 5.80KB
i18n (useSafeTranslation.js) 2.87KB 1.28KB
layout (index.js) 38.45KB 10.67KB
mobile (MobileProvider.js) 0.92KB 0.49KB
mobile (ResponsiveContainer.js) 0.94KB 0.38KB
mobile (breakpoints.js) 1.51KB 0.70KB
mobile (createOfflineDataSource.js) 5.61KB 1.74KB
mobile (index.js) 1.50KB 0.62KB
mobile (offlineQueue.js) 3.91KB 1.35KB
mobile (pwa.js) 0.97KB 0.49KB
mobile (serviceWorker.js) 1.48KB 0.62KB
mobile (serviceWorkerSource.js) 3.41KB 1.48KB
mobile (useBreakpoint.js) 1.54KB 0.65KB
mobile (useGesture.js) 4.42KB 1.27KB
mobile (useOfflineSync.js) 1.99KB 0.72KB
mobile (usePullToRefresh.js) 2.53KB 0.85KB
mobile (useResponsive.js) 0.71KB 0.42KB
mobile (useResponsiveConfig.js) 1.36KB 0.63KB
mobile (useSpecGesture.js) 1.77KB 0.77KB
mobile (useTouchTarget.js) 1.01KB 0.54KB
permissions (MePermissionsProvider.js) 6.84KB 2.42KB
permissions (PermissionContext.js) 0.31KB 0.25KB
permissions (PermissionGuard.js) 0.89KB 0.45KB
permissions (PermissionProvider.js) 3.67KB 1.12KB
permissions (evaluator.js) 4.00KB 1.23KB
permissions (index.js) 0.91KB 0.41KB
permissions (store.js) 0.91KB 0.42KB
permissions (useFieldPermissions.js) 1.28KB 0.52KB
permissions (usePermissions.js) 1.55KB 0.71KB
plugin-ai (index.js) 15.71KB 3.79KB
plugin-calendar (index.js) 45.37KB 12.48KB
plugin-charts (index.js) 46.99KB 13.28KB
plugin-chatbot (index.js) 179.53KB 42.79KB
plugin-dashboard (index.js) 108.66KB 28.00KB
plugin-designer (index.js) 210.92KB 42.69KB
plugin-detail (index.js) 215.33KB 52.51KB
plugin-editor (index.js) 2.46KB 1.10KB
plugin-form (index.js) 103.53KB 25.12KB
plugin-gantt (index.js) 162.33KB 39.53KB
plugin-grid (index.js) 176.83KB 46.49KB
plugin-kanban (index.js) 47.82KB 13.18KB
plugin-list (index.js) 98.71KB 23.32KB
plugin-map (index.js) 16.80KB 5.24KB
plugin-markdown (index.js) 13.65KB 4.67KB
plugin-report (index.js) 37.07KB 9.81KB
plugin-timeline (index.js) 25.37KB 7.20KB
plugin-tree (index.js) 8.36KB 2.81KB
plugin-view (index.js) 85.70KB 20.87KB
providers (DataSourceProvider.js) 0.75KB 0.39KB
providers (MetadataProvider.js) 1.37KB 0.59KB
providers (ThemeProvider.js) 1.55KB 0.67KB
providers (UploadProvider.js) 11.71KB 3.53KB
providers (index.js) 0.44KB 0.22KB
providers (types.js) 0.01KB 0.04KB
react-runtime (index.js) 3.19KB 1.38KB
react (LazyPluginLoader.js) 3.77KB 1.33KB
react (SchemaRenderer.js) 18.70KB 6.09KB
react (data-invalidation.js) 5.05KB 2.08KB
react (index.js) 1.00KB 0.55KB
sdui-parser (codegen.js) 4.09KB 1.74KB
sdui-parser (index.js) 2.16KB 0.94KB
sdui-parser (parse.js) 10.04KB 2.82KB
sdui-parser (types.js) 0.29KB 0.24KB
sdui-parser (validate.js) 4.69KB 1.48KB
types (ai.js) 0.20KB 0.17KB
types (api-types.js) 0.20KB 0.18KB
types (app.js) 2.87KB 0.99KB
types (base.js) 0.20KB 0.18KB
types (blocks.js) 0.20KB 0.18KB
types (complex.js) 0.20KB 0.18KB
types (crud.js) 0.20KB 0.18KB
types (data-display.js) 0.20KB 0.18KB
types (data-protocol.js) 0.20KB 0.19KB
types (data.js) 0.20KB 0.18KB
types (designer.js) 0.77KB 0.41KB
types (disclosure.js) 0.20KB 0.18KB
types (feedback.js) 0.20KB 0.18KB
types (field-types.js) 0.20KB 0.18KB
types (form.js) 0.20KB 0.18KB
types (index.js) 1.97KB 0.93KB
types (layout.js) 0.20KB 0.18KB
types (managed-by.js) 0.19KB 0.18KB
types (mobile.js) 0.20KB 0.18KB
types (navigation.js) 0.20KB 0.18KB
types (objectql.js) 0.20KB 0.18KB
types (overlay.js) 0.20KB 0.18KB
types (permissions.js) 0.20KB 0.18KB
types (plugin-scope.js) 0.20KB 0.18KB
types (record-components.js) 0.20KB 0.19KB
types (record-semantics.js) 1.28KB 0.67KB
types (registry.js) 0.20KB 0.18KB
types (reports.js) 0.20KB 0.18KB
types (spec-report.js) 5.04KB 1.93KB
types (system-fields.js) 2.39KB 1.17KB
types (theme.js) 0.20KB 0.18KB
types (ui-action.js) 0.75KB 0.46KB
types (views.js) 0.20KB 0.18KB
types (widget.js) 0.20KB 0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-zhuang
os-zhuang merged commit 7b35e4b into main Jul 27, 2026
14 checks passed
@os-zhuang
os-zhuang deleted the fix/dashboard-widget-current-user branch July 27, 2026 09:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant