Skip to content

feat(console): group tenancy posture affordances — org switcher as write context + org attribution (ADR-0105 Phase 1)#2858

Merged
os-zhuang merged 1 commit into
mainfrom
claude/adr-0105-group-tenancy-posture-5womi2
Jul 27, 2026
Merged

feat(console): group tenancy posture affordances — org switcher as write context + org attribution (ADR-0105 Phase 1)#2858
os-zhuang merged 1 commit into
mainfrom
claude/adr-0105-group-tenancy-posture-5womi2

Conversation

@os-zhuang

Copy link
Copy Markdown
Contributor

Closes the remaining Phase 1 console item of framework ADR-0105 (tracking: objectstack-ai/objectstack#3541; engine side landed in objectstack-ai/objectstack#3559).

Why

Under the new group tenancy posture the server widens reads to every organization the member belongs to (organization_id IN accessible_org_ids) while writes land in the ACTIVE organization (engine-stamped, D5). The console's existing presentation — "which org am I in = which org's data I see" — becomes wrong the moment a deployment switches postures, which is why the ADR's Risks section requires these affordances to land with Phase 1, not after.

The switching mechanism is untouched: better-auth organization.setActive → session activeOrganizationId → engine write stamping is already the single channel, client and server agree on it. This PR only changes what the console communicates.

What

  • @object-ui/authAuthPublicConfig.features.tenancyPosture ('single' | 'group' | 'isolated', exported as TenancyPosture) mirrors the server's public auth config key (public-auth-features.ts, non-flag by design: multiOrgEnabled stays the capability gate; this only tells the console how to render org context).
  • useTenancyPosture() (app-shell) — reads the posture from the promise-cached auth config fetch. undefined (older server, unrecognized value, fetch failure) keeps every group affordance off — non-group deployments render pixel-identical to today.
  • WorkspaceSwitcher — under group the dropdown labels the active org "Working organization" with the hint "New records are created here. Views show data from all your organizations."
  • RecordFormPage (create mode) — org-walled objects (they carry organization_id) show a "Creates in <active org>" badge naming the engine's write target.
  • Default list columns (ObjectView, InterfaceListPage, ObjectDataPage) — under group, org-walled objects get a TRAILING organization_id attribution column so cross-org rows are attributable at a glance. Render-time only — never persisted into saved view/page metadata (a saved view must not fossilize a posture-dependent column set); the view-creation prefill path is deliberately left untouched.

Verification

  • turbo build (29 tasks) and turbo lint clean for @object-ui/auth + @object-ui/app-shell and dependents.
  • vitest run packages/app-shell packages/auth — 231 files, 1950 tests, all passing.
  • New coverage: WorkspaceSwitcher.test.tsx (group label + hint; isolated/unknown postures keep today's rendering), ObjectView.defaultColumns.test.tsx + InterfaceListPage.defaults.test.tsx org-attribution cases (append-last, non-walled objects untouched, no dupes, off-flag is a no-op).
  • Changeset included (minor, feature).

Not in this PR

Deeper "all my organizations" console affordances (aggregated cross-org views, org quick-filters) are tracked as Phase 2 in objectstack-ai/objectstack#3541. The three-plants-one-group dogfood acceptance runs against a group-posture backend once this lands.

🤖 Generated with Claude Code

https://claude.ai/code/session_015FebXPaaGrLhGKw1LHPbpL


Generated by Claude Code

…ite context + org attribution (ADR-0105 Phase 1)

Under the group posture the server widens reads to the member's whole
organization set while writes land in the ACTIVE organization, so the
console must stop presenting the active org as a read boundary:

- @object-ui/auth: features.tenancyPosture ('single'|'group'|'isolated',
  exported as TenancyPosture) mirrors the server's public auth config key.
- useTenancyPosture() (app-shell): posture from the cached config fetch;
  undefined/unrecognized keeps every group affordance off, so non-group
  deployments render pixel-identical to today.
- WorkspaceSwitcher: under group, labels the active org 'Working
  organization' and explains the read/write split.
- RecordFormPage (create): org-walled objects show a 'Creates in <org>'
  badge naming the D5 write target.
- Default list columns (ObjectView / InterfaceListPage / ObjectDataPage):
  under group, org-walled objects get a TRAILING organization_id
  attribution column — render-time only, never persisted into saved
  view/page metadata.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015FebXPaaGrLhGKw1LHPbpL
@vercel

vercel Bot commented Jul 27, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated (UTC)
objectui Ignored Ignored Jul 27, 2026 8:47am

Request Review

@github-actions github-actions Bot added the tests label Jul 27, 2026
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

Metric Value Budget
Main entry (gzip) 28.0 KB 350 KB
Entry file index-D2XtTZ66.js
Status PASS

📦 Bundle Size Report

Package Size Gzipped
app-shell (index.js) 8.20KB 2.97KB
app-shell (runtime-config.js) 7.42KB 2.32KB
app-shell (types.js) 0.01KB 0.04KB
app-shell (urlParams.js) 7.57KB 2.97KB
auth (AuthContext.js) 0.31KB 0.24KB
auth (AuthGuard.js) 1.17KB 0.53KB
auth (AuthProvider.js) 21.70KB 4.21KB
auth (AuthShell.js) 3.49KB 1.40KB
auth (ForgotPasswordForm.js) 12.12KB 3.41KB
auth (LoginForm.js) 17.86KB 5.29KB
auth (PreviewBanner.js) 0.90KB 0.50KB
auth (RegisterForm.js) 6.43KB 2.09KB
auth (SocialSignInButtons.js) 9.60KB 3.89KB
auth (UserMenu.js) 3.40KB 1.22KB
auth (auth-gate-events.js) 1.29KB 0.66KB
auth (authStyles.js) 5.04KB 1.72KB
auth (createAuthClient.js) 33.74KB 8.53KB
auth (createAuthenticatedFetch.js) 4.37KB 1.69KB
auth (index.js) 1.83KB 0.79KB
auth (phone-identifier.js) 1.11KB 0.66KB
auth (types.js) 0.59KB 0.35KB
auth (useAuth.js) 4.86KB 0.85KB
auth (useIsWorkspaceAdmin.js) 1.61KB 0.85KB
collaboration (CommentThread.js) 18.38KB 4.49KB
collaboration (LiveCursors.js) 3.17KB 1.27KB
collaboration (PresenceAvatars.js) 3.65KB 1.42KB
collaboration (PresenceProvider.js) 2.79KB 1.13KB
collaboration (index.js) 1.25KB 0.53KB
collaboration (useCommentSearch.js) 1.98KB 0.88KB
collaboration (useConflictResolution.js) 7.75KB 1.86KB
collaboration (useMentionNotifications.js) 1.81KB 0.68KB
collaboration (usePresence.js) 6.33KB 1.84KB
collaboration (useRealtimeSubscription.js) 7.91KB 2.01KB
components (index.js) 450.70KB 98.15KB
core (index.js) 1.86KB 0.63KB
create-plugin (index.js) 9.28KB 2.98KB
data-objectstack (index.js) 127.29KB 31.96KB
fields (index.js) 218.35KB 53.54KB
i18n (LocalizationContext.js) 1.76KB 0.96KB
i18n (currency.js) 1.22KB 0.64KB
i18n (i18n.js) 4.32KB 1.77KB
i18n (index.js) 2.46KB 0.96KB
i18n (pickLocalized.js) 1.70KB 0.83KB
i18n (provider.js) 5.37KB 1.72KB
i18n (useObjectLabel.js) 25.17KB 5.80KB
i18n (useSafeTranslation.js) 2.87KB 1.28KB
layout (index.js) 38.45KB 10.67KB
mobile (MobileProvider.js) 0.92KB 0.49KB
mobile (ResponsiveContainer.js) 0.94KB 0.38KB
mobile (breakpoints.js) 1.51KB 0.70KB
mobile (createOfflineDataSource.js) 5.61KB 1.74KB
mobile (index.js) 1.50KB 0.62KB
mobile (offlineQueue.js) 3.91KB 1.35KB
mobile (pwa.js) 0.97KB 0.49KB
mobile (serviceWorker.js) 1.48KB 0.62KB
mobile (serviceWorkerSource.js) 3.41KB 1.48KB
mobile (useBreakpoint.js) 1.54KB 0.65KB
mobile (useGesture.js) 4.42KB 1.27KB
mobile (useOfflineSync.js) 1.99KB 0.72KB
mobile (usePullToRefresh.js) 2.53KB 0.85KB
mobile (useResponsive.js) 0.71KB 0.42KB
mobile (useResponsiveConfig.js) 1.36KB 0.63KB
mobile (useSpecGesture.js) 1.77KB 0.77KB
mobile (useTouchTarget.js) 1.01KB 0.54KB
permissions (MePermissionsProvider.js) 6.84KB 2.42KB
permissions (PermissionContext.js) 0.31KB 0.25KB
permissions (PermissionGuard.js) 0.89KB 0.45KB
permissions (PermissionProvider.js) 3.67KB 1.12KB
permissions (evaluator.js) 4.00KB 1.23KB
permissions (index.js) 0.91KB 0.41KB
permissions (store.js) 0.91KB 0.42KB
permissions (useFieldPermissions.js) 1.28KB 0.52KB
permissions (usePermissions.js) 1.55KB 0.71KB
plugin-ai (index.js) 15.71KB 3.79KB
plugin-calendar (index.js) 45.37KB 12.48KB
plugin-charts (index.js) 46.90KB 13.26KB
plugin-chatbot (index.js) 179.53KB 42.79KB
plugin-dashboard (index.js) 108.55KB 27.96KB
plugin-designer (index.js) 210.92KB 42.69KB
plugin-detail (index.js) 215.33KB 52.51KB
plugin-editor (index.js) 2.46KB 1.10KB
plugin-form (index.js) 103.53KB 25.12KB
plugin-gantt (index.js) 162.33KB 39.53KB
plugin-grid (index.js) 176.83KB 46.49KB
plugin-kanban (index.js) 47.82KB 13.18KB
plugin-list (index.js) 98.71KB 23.32KB
plugin-map (index.js) 16.80KB 5.24KB
plugin-markdown (index.js) 13.65KB 4.67KB
plugin-report (index.js) 37.07KB 9.81KB
plugin-timeline (index.js) 25.37KB 7.20KB
plugin-tree (index.js) 8.36KB 2.81KB
plugin-view (index.js) 85.70KB 20.87KB
providers (DataSourceProvider.js) 0.75KB 0.39KB
providers (MetadataProvider.js) 1.37KB 0.59KB
providers (ThemeProvider.js) 1.55KB 0.67KB
providers (UploadProvider.js) 11.71KB 3.53KB
providers (index.js) 0.44KB 0.22KB
providers (types.js) 0.01KB 0.04KB
react-runtime (index.js) 3.19KB 1.38KB
react (LazyPluginLoader.js) 3.77KB 1.33KB
react (SchemaRenderer.js) 18.70KB 6.09KB
react (data-invalidation.js) 5.05KB 2.08KB
react (index.js) 1.00KB 0.55KB
sdui-parser (codegen.js) 4.09KB 1.74KB
sdui-parser (index.js) 2.16KB 0.94KB
sdui-parser (parse.js) 10.04KB 2.82KB
sdui-parser (types.js) 0.29KB 0.24KB
sdui-parser (validate.js) 4.69KB 1.48KB
types (ai.js) 0.20KB 0.17KB
types (api-types.js) 0.20KB 0.18KB
types (app.js) 2.87KB 0.99KB
types (base.js) 0.20KB 0.18KB
types (blocks.js) 0.20KB 0.18KB
types (complex.js) 0.20KB 0.18KB
types (crud.js) 0.20KB 0.18KB
types (data-display.js) 0.20KB 0.18KB
types (data-protocol.js) 0.20KB 0.19KB
types (data.js) 0.20KB 0.18KB
types (designer.js) 0.77KB 0.41KB
types (disclosure.js) 0.20KB 0.18KB
types (feedback.js) 0.20KB 0.18KB
types (field-types.js) 0.20KB 0.18KB
types (form.js) 0.20KB 0.18KB
types (index.js) 1.97KB 0.93KB
types (layout.js) 0.20KB 0.18KB
types (managed-by.js) 0.19KB 0.18KB
types (mobile.js) 0.20KB 0.18KB
types (navigation.js) 0.20KB 0.18KB
types (objectql.js) 0.20KB 0.18KB
types (overlay.js) 0.20KB 0.18KB
types (permissions.js) 0.20KB 0.18KB
types (plugin-scope.js) 0.20KB 0.18KB
types (record-components.js) 0.20KB 0.19KB
types (record-semantics.js) 1.28KB 0.67KB
types (registry.js) 0.20KB 0.18KB
types (reports.js) 0.20KB 0.18KB
types (spec-report.js) 5.04KB 1.93KB
types (system-fields.js) 2.39KB 1.17KB
types (theme.js) 0.20KB 0.18KB
types (ui-action.js) 0.75KB 0.46KB
types (views.js) 0.20KB 0.18KB
types (widget.js) 0.20KB 0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-zhuang
os-zhuang marked this pull request as ready for review July 27, 2026 08:55
@os-zhuang
os-zhuang merged commit 8b4bc94 into main Jul 27, 2026
14 checks passed
@os-zhuang
os-zhuang deleted the claude/adr-0105-group-tenancy-posture-5womi2 branch July 27, 2026 08:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants