Skip to content

feat(console): scoped-invitation placement — invite straight into a unit and positions (framework ADR-0105 D8) - #2868

Merged
os-zhuang merged 1 commit into
mainfrom
claude/adr-0105-d8-invitation-ux
Jul 27, 2026
Merged

feat(console): scoped-invitation placement — invite straight into a unit and positions (framework ADR-0105 D8)#2868
os-zhuang merged 1 commit into
mainfrom
claude/adr-0105-d8-invitation-ux

Conversation

@os-zhuang

Copy link
Copy Markdown
Contributor

The D8 issuance UX over the gated engine seam. Framework side: objectstack-ai/objectstack#3663 (engine: carrier + issuance gate + accept-time apply) and objectstack-ai/objectstack#3674 (the delegable-scope read surface this narrows with). Tracking: objectstack-ai/objectstack#3541.

Why it's here and not in cloud

I originally scoped this as a cloud PR (cloud#874's "scoped-invitations UX"). It isn't: cloud has no invite UI at all — every organization-management screen (OrganizationsPage, MembersPage, InvitationsPage, InviteMemberDialog) already lives open in app-shell. Cloud sells the runtime that entitles the feature, not the console screens. Putting the picker here is consistent with where org management already is, and it stays inert without the entitled runtime (see below).

What

  • @object-ui/authinviteMember accepts optional businessUnitId / positions, passed through better-auth's invitation additionalFields; new describeDelegableScope() reads GET /api/v1/security/my-delegable-scope (DelegableScope type exported).
  • InviteMemberDialog — an optional Placement section listing only the units the issuer may place into and the positions they may hand out. Positions appear once a unit is chosen: an unanchored assignment is refused server-side, so offering it first would mislead.

The property that matters

The narrowing is convenience, not the boundary. The server authorizes the pair against the issuer's adminScope (ADR-0090 D12) at issuance and rejects the whole invitation when it's out of scope. So the UI is free to be helpful without being load-bearing — and it fails toward less, not more:

  • caller has no delegable authority ⇒ section hidden;
  • deployment exposes no delegated-administration runtime (endpoint 501 ⇒ null) ⇒ section hidden;
  • placement travels only when both halves are chosen — a unit with no positions isn't a placement, and sending a half-intent would get an otherwise fine invitation rejected.

An ordinary invitation is unchanged: with no placement chosen the request body is byte-identical to before.

Verification

  • New InviteMemberDialog.placement.test.tsx — 5 cases: hidden with no authority, hidden with no surface, options are exactly the delegable ones (and positions gate on a chosen unit), a complete placement reaches inviteMember, a half-chosen one does not.
  • vitest run packages/auth packages/app-shell232 files, 1955 tests, all passing.
  • turbo lint clean for both packages; changeset included (minor ×2).

Follow-up

End-to-end HTTP verification against a real group-posture boot belongs with cloud's ee-group-showcase (it already boots the enterprise runtime that registers the invitation-placement service): plant admin invites into their own subtree → accepted → sys_user_position lands; out-of-subtree issuance → 403.

🤖 Generated with Claude Code

https://claude.ai/code/session_015FebXPaaGrLhGKw1LHPbpL


Generated by Claude Code

…nit and positions (framework ADR-0105 D8)

An invitation may now carry placement intent (business unit + positions),
applied when it is accepted, so a plant admin's invitee arrives already in
the right unit and role instead of waiting on a platform admin.

- @object-ui/auth: inviteMember accepts optional businessUnitId/positions
  (better-auth invitation additionalFields); new describeDelegableScope()
  reads GET /api/v1/security/my-delegable-scope.
- InviteMemberDialog: optional Placement section listing ONLY the units the
  issuer may place into and the positions they may hand out; positions
  appear once a unit is chosen (an unanchored assignment is refused
  server-side, so offering it first would mislead).

The narrowing is convenience, not the boundary — the server authorizes the
pair against the ISSUER's adminScope at issuance and rejects the whole
invitation when out of scope. So the section is HIDDEN when the caller has
no delegable authority or the deployment exposes no delegated-administration
runtime (501 => null): never a form the server would refuse. An ordinary
invitation is byte-identical to before.

Tests: hidden with no authority, hidden with no surface, options are exactly
the delegable ones, a complete placement reaches inviteMember, a half-chosen
one does not. auth + app-shell 1955/1955; lint clean.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015FebXPaaGrLhGKw1LHPbpL
@vercel

vercel Bot commented Jul 27, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated (UTC)
objectui Ignored Ignored Jul 27, 2026 2:17pm

Request Review

@github-actions github-actions Bot added the tests label Jul 27, 2026
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

Metric Value Budget
Main entry (gzip) 28.0 KB 350 KB
Entry file index-D1dkiTX7.js
Status PASS

📦 Bundle Size Report

Package Size Gzipped
app-shell (index.js) 8.20KB 2.97KB
app-shell (runtime-config.js) 7.42KB 2.32KB
app-shell (types.js) 0.01KB 0.04KB
app-shell (urlParams.js) 7.57KB 2.97KB
auth (AuthContext.js) 0.31KB 0.24KB
auth (AuthGuard.js) 1.17KB 0.53KB
auth (AuthProvider.js) 22.10KB 4.37KB
auth (AuthShell.js) 3.49KB 1.40KB
auth (ForgotPasswordForm.js) 12.12KB 3.41KB
auth (LoginForm.js) 17.86KB 5.29KB
auth (PreviewBanner.js) 0.90KB 0.50KB
auth (RegisterForm.js) 6.43KB 2.09KB
auth (SocialSignInButtons.js) 9.60KB 3.89KB
auth (UserMenu.js) 3.40KB 1.22KB
auth (auth-gate-events.js) 1.29KB 0.66KB
auth (authStyles.js) 5.04KB 1.72KB
auth (createAuthClient.js) 35.76KB 9.11KB
auth (createAuthenticatedFetch.js) 4.37KB 1.69KB
auth (index.js) 1.83KB 0.79KB
auth (phone-identifier.js) 1.11KB 0.66KB
auth (types.js) 0.59KB 0.35KB
auth (useAuth.js) 4.91KB 0.87KB
auth (useIsWorkspaceAdmin.js) 1.61KB 0.85KB
collaboration (CommentThread.js) 18.38KB 4.49KB
collaboration (LiveCursors.js) 3.17KB 1.27KB
collaboration (PresenceAvatars.js) 3.65KB 1.42KB
collaboration (PresenceProvider.js) 2.79KB 1.13KB
collaboration (index.js) 1.25KB 0.53KB
collaboration (useCommentSearch.js) 1.98KB 0.88KB
collaboration (useConflictResolution.js) 7.75KB 1.86KB
collaboration (useMentionNotifications.js) 1.81KB 0.68KB
collaboration (usePresence.js) 6.33KB 1.84KB
collaboration (useRealtimeSubscription.js) 7.91KB 2.01KB
components (index.js) 450.91KB 98.17KB
core (index.js) 2.12KB 0.77KB
create-plugin (index.js) 9.28KB 2.98KB
data-objectstack (index.js) 127.29KB 31.96KB
fields (index.js) 218.37KB 53.54KB
i18n (LocalizationContext.js) 1.76KB 0.96KB
i18n (currency.js) 1.22KB 0.64KB
i18n (i18n.js) 4.32KB 1.77KB
i18n (index.js) 2.46KB 0.96KB
i18n (pickLocalized.js) 1.70KB 0.83KB
i18n (provider.js) 5.37KB 1.72KB
i18n (useObjectLabel.js) 25.17KB 5.80KB
i18n (useSafeTranslation.js) 2.87KB 1.28KB
layout (index.js) 38.45KB 10.67KB
mobile (MobileProvider.js) 0.92KB 0.49KB
mobile (ResponsiveContainer.js) 0.94KB 0.38KB
mobile (breakpoints.js) 1.51KB 0.70KB
mobile (createOfflineDataSource.js) 5.61KB 1.74KB
mobile (index.js) 1.50KB 0.62KB
mobile (offlineQueue.js) 3.91KB 1.35KB
mobile (pwa.js) 0.97KB 0.49KB
mobile (serviceWorker.js) 1.48KB 0.62KB
mobile (serviceWorkerSource.js) 3.41KB 1.48KB
mobile (useBreakpoint.js) 1.54KB 0.65KB
mobile (useGesture.js) 4.42KB 1.27KB
mobile (useOfflineSync.js) 1.99KB 0.72KB
mobile (usePullToRefresh.js) 2.53KB 0.85KB
mobile (useResponsive.js) 0.71KB 0.42KB
mobile (useResponsiveConfig.js) 1.36KB 0.63KB
mobile (useSpecGesture.js) 1.77KB 0.77KB
mobile (useTouchTarget.js) 1.01KB 0.54KB
permissions (MePermissionsProvider.js) 6.84KB 2.42KB
permissions (PermissionContext.js) 0.31KB 0.25KB
permissions (PermissionGuard.js) 0.89KB 0.45KB
permissions (PermissionProvider.js) 3.67KB 1.12KB
permissions (evaluator.js) 4.00KB 1.23KB
permissions (index.js) 0.91KB 0.41KB
permissions (store.js) 0.91KB 0.42KB
permissions (useFieldPermissions.js) 1.28KB 0.52KB
permissions (usePermissions.js) 1.55KB 0.71KB
plugin-ai (index.js) 15.71KB 3.79KB
plugin-calendar (index.js) 45.37KB 12.48KB
plugin-charts (index.js) 47.20KB 13.35KB
plugin-chatbot (index.js) 179.53KB 42.79KB
plugin-dashboard (index.js) 109.60KB 28.33KB
plugin-designer (index.js) 210.92KB 42.69KB
plugin-detail (index.js) 215.28KB 52.50KB
plugin-editor (index.js) 2.46KB 1.10KB
plugin-form (index.js) 103.47KB 25.10KB
plugin-gantt (index.js) 162.33KB 39.53KB
plugin-grid (index.js) 178.24KB 46.72KB
plugin-kanban (index.js) 47.82KB 13.18KB
plugin-list (index.js) 98.71KB 23.32KB
plugin-map (index.js) 16.80KB 5.24KB
plugin-markdown (index.js) 13.65KB 4.67KB
plugin-report (index.js) 37.07KB 9.81KB
plugin-timeline (index.js) 25.37KB 7.20KB
plugin-tree (index.js) 8.36KB 2.81KB
plugin-view (index.js) 85.70KB 20.87KB
providers (DataSourceProvider.js) 0.75KB 0.39KB
providers (MetadataProvider.js) 1.37KB 0.59KB
providers (ThemeProvider.js) 1.55KB 0.67KB
providers (UploadProvider.js) 11.71KB 3.53KB
providers (index.js) 0.44KB 0.22KB
providers (types.js) 0.01KB 0.04KB
react-runtime (index.js) 3.19KB 1.38KB
react (LazyPluginLoader.js) 3.77KB 1.33KB
react (SchemaRenderer.js) 18.70KB 6.09KB
react (data-invalidation.js) 5.05KB 2.08KB
react (index.js) 1.00KB 0.55KB
sdui-parser (codegen.js) 4.09KB 1.74KB
sdui-parser (index.js) 2.16KB 0.94KB
sdui-parser (parse.js) 10.04KB 2.82KB
sdui-parser (types.js) 0.29KB 0.24KB
sdui-parser (validate.js) 4.69KB 1.48KB
types (ai.js) 0.20KB 0.17KB
types (api-types.js) 0.20KB 0.18KB
types (app.js) 2.87KB 0.99KB
types (base.js) 0.20KB 0.18KB
types (blocks.js) 0.20KB 0.18KB
types (complex.js) 0.20KB 0.18KB
types (crud.js) 0.20KB 0.18KB
types (data-display.js) 0.20KB 0.18KB
types (data-protocol.js) 0.20KB 0.19KB
types (data.js) 0.20KB 0.18KB
types (designer.js) 0.77KB 0.41KB
types (disclosure.js) 0.20KB 0.18KB
types (feedback.js) 0.20KB 0.18KB
types (field-types.js) 0.20KB 0.18KB
types (form.js) 0.20KB 0.18KB
types (index.js) 1.86KB 0.91KB
types (layout.js) 0.20KB 0.18KB
types (managed-by.js) 0.19KB 0.18KB
types (mobile.js) 0.20KB 0.18KB
types (navigation.js) 0.20KB 0.18KB
types (objectql.js) 0.20KB 0.18KB
types (overlay.js) 0.20KB 0.18KB
types (permissions.js) 0.20KB 0.18KB
types (plugin-scope.js) 0.20KB 0.18KB
types (record-components.js) 0.20KB 0.19KB
types (record-semantics.js) 1.28KB 0.67KB
types (registry.js) 0.20KB 0.18KB
types (reports.js) 0.20KB 0.18KB
types (spec-report.js) 5.04KB 1.93KB
types (system-fields.js) 2.39KB 1.17KB
types (theme.js) 0.20KB 0.18KB
types (ui-action.js) 0.75KB 0.46KB
types (views.js) 0.20KB 0.18KB
types (widget.js) 0.20KB 0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-zhuang
os-zhuang marked this pull request as ready for review July 27, 2026 14:44
@os-zhuang
os-zhuang merged commit b5609cb into main Jul 27, 2026
14 checks passed
@os-zhuang
os-zhuang deleted the claude/adr-0105-d8-invitation-ux branch July 27, 2026 14:44
os-zhuang added a commit that referenced this pull request Jul 28, 2026
…pickers (framework#3697) (#2891)

Follow-on to objectstack-ai/objectstack#3722, which registered a fourth
organization role. Companion to #2868, which shipped the placement half.

#3722 gave ADR-0105 D8's scope-bounded issuance gate its missing caller:
`delegated_admin`, the grade that may reach `/organization/invite-member`
without being an org admin. But the console could not select the role at
all — `MembersPage` and `InviteMemberDialog` each inlined
`type Role = 'owner' | 'admin' | 'member'` — so the capability the
framework grew was unreachable from either screen.

One vocabulary, not two: role names, labels and narrowing rules move
into `@object-ui/auth`'s new `org-roles` module and both screens consume
it. The list still MIRRORS the server rather than deriving from it
(`/auth/config` publishes feature flags but no role vocabulary); the
module says so and points at objectstack-ai/objectstack#3723.

Both pickers now narrow to what the server will accept, mirroring
DIFFERENT gates:

- invite role  ← `beforeCreateInvitation`'s role cap: never above the
  issuer's own grade; a below-admin issuer may invite as `member` only.
  A `delegated_admin` picking "Admin" would have 403'd.
- change role  ← better-auth's `update-member-role`: needs
  `member:["update"]` (owner/admin only), and only an owner may set
  `owner` or re-role an existing owner. An actor who may re-role nobody
  gets no items rather than three that would 403.

Narrowing is convenience, not the boundary — the server re-checks — and
it fails toward less. An ordinary invitation's request body is
byte-identical to before.

Verified: 654 files / 7684 tests passing; lint 0 errors on both
packages; tsc 29/29.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants