Skip to content

docs(auth): write down the X-Tenant-ID edge contract and its unstamped-first-request gap - #5706

Merged
os-sales merged 2 commits into
mainfrom
claude/issue-5279-tenant-header-edge-contract
Aug 22, 2026
Merged

docs(auth): write down the X-Tenant-ID edge contract and its unstamped-first-request gap#5706
os-sales merged 2 commits into
mainfrom
claude/issue-5279-tenant-header-edge-contract

Conversation

@os-sales

Copy link
Copy Markdown
Collaborator

Fixes #5279

Documentation only. The header createAuthenticatedFetch stamps had no written contract, and the shape of the missing information was actively misleading.

Why this card existed at all

X-Tenant-ID's only non-CORS consumer lives in the cloud repository. A search confined to this repo and the framework (objectstack) finds zero readers and reads as "nothing consumes this stamp". #5279 was filed on exactly that reading, held on it, and was only discharged when a cloud-side reading came back non-empty (packages/service-tenant/src/tenant-context.ts, packages/tenant-router/src/spec/turso-multi-tenant.zod.ts).

That makes the missing documentation an active hazard rather than a gap: the next person to grep reaches the same false conclusion and deletes a live routing input. So the decisive facts go where a grep-then-delete reader looks first — the stamping site itself — and the full contract goes in the package README, which ships to npm.

What is documented

packages/auth/README.md gains "The X-Tenant-ID edge contract":

Question Answer written down
What it means A routing hint carrying the better-auth activeOrganizationId. Not an identity claim, not an authorization input, not what scopes rows
Who stamps it createAuthenticatedFetch, from ActiveOrganizationStorage, whenever that holds a value — not gated on the URL being an /api/ call, suppressed by sameOriginOnly for cross-origin URLs, overwrites a caller-supplied value
Who writes the storage AuthProvider only, at four moments (organization load, org switch, delete/leave, sign-out)
Who reads the header The cloud edge — cited from #5279, since that repo is not readable from here. Its configuration contract is readable here and is quoted from it
Who does not read it The framework. resolveAuthzContext takes tenantId from the API-key principal or session.activeOrganizationId and from no header, pinned by packages/verify/src/harness.org-context.test.ts
What a reader may assume May route on it; may not treat it as identity, may not assume the row scoping came from it, may not assume it is present

The configuration half is not paraphrased from the cloud repo — it is measured from the contract this package actually resolves. TenantRoutingConfigSchema from @objectstack/spec/cloud (17.1.0, the version @object-ui/auth resolves), parsed on an empty config:

enabled:               false
identificationSources: ["subdomain", "header", "jwt_claim"]
tenantHeaderName:      "X-Tenant-ID"
jwtOrganizationClaim:  "organizationId"

Two things a client author needs from that: the header name is configurable (X-Tenant-ID is a default, not a constant), and the header is one of six identification sources ranked second, behind subdomain — on a subdomain-routed deployment it is not what picks the tenant.

The negative half is stated with its own evidence, because "the framework ignores it" is the half that reads as "nobody uses it": the CORS allow-list comment (X-Tenant-ID / X-Environment-Id route "a request to its environment") and plugin-sharing's record that trusting x-tenant-id as identity was a vulnerability.

The unstamped-first-request gap

Its own section. ActiveOrganizationStorage is filled only after AuthProvider's async getSession -> listOrganizations -> getActiveOrganization chain resolves, so early-boot requests carry no tenant header at all. Documented:

Three pins, so the prose cannot drift

packages/auth/src/__tests__/createAuthenticatedFetch.test.tsx gains one case per wire-level statement the README makes: no active organization means no header at all (.has() false, not empty-string); the stamp is not gated on /api/ the way Authorization is; the active organization overwrites a caller-supplied X-Tenant-ID.

The middle one is labelled in the test body as recorded, not endorsed — it makes today's asymmetry visible so that gating the stamp becomes a deliberate, red-test change rather than a silent one, and the question is filed for triage rather than answered here.

Scope

Deliberately not in this PR, per the card:

Verification

Run at f3e0d6313, the head of this branch.

Scope is narrowed to @object-ui/auth, and the narrowing is proven rather than asserted: every .ts edit is comment-only, so the change can have no runtime effect. Demonstrated by compiling both revisions of createAuthenticatedFetch.ts with removeComments and diffing — byte-identical, 2750 bytes each — and by the package's other 20 emitted dist/*.js files being hash-identical across the rebuild. The instrument was self-checked: re-spelling one header literal in a scratchpad copy makes the same comparison go red, so a green reading is a measurement, not a no-op.

Gate Result
pnpm --filter @object-ui/auth build pass
pnpm --filter @object-ui/auth type-check (tsc --noEmit && tsc -p tsconfig.test.json) pass
pnpm --filter @object-ui/auth lint pass — 29 problems (0 errors, 29 warnings), every warning pre-existing in AuthProvider.tsx
pnpm exec vitest run packages/auth/ Test Files 18 passed (18) / Tests 190 passed (190). The three new cases were confirmed to actually execute by a --reporter=verbose run of the edited file (Tests 13 passed (13), each new title printed), not inferred from the file-level count
node scripts/check-control-bytes.mjs check-control-bytes: OK (scanned 4754 tracked text file(s); skipped 85 binary)
node scripts/check-changeset-presence.mjs 2 source file(s) of 1 released package(s) changed, and this change declares 1 changeset(s)
node scripts/check-changeset-fixed.mjs All workspace packages are in the changeset fixed group.
node scripts/check-changeset-no-major.mjs No changeset declares a major bump.
node scripts/check-doc-snippet-types.mjs narrowed, declared — see below

check-doc-snippet-types is the gate this diff most obviously reaches: its declared scan surface is every page under content/docs plus every packages/<name>/README.md. It refuses to run against an unbuilt tree (The snippet program was NOT run: the packages it resolves against are not built) and wants 14 packages built first, so it was not run in full here — CI runs it on a built tree.

What replaces it is a measurement rather than a hope, because the narrowing is provable. The gate compiles only the fence languages in its own exported TS_FENCE_LANGUAGESts, tsx, typescript — so the population was read from the gate itself and applied to both revisions of the file:

Revision fenced blocks in the compiled population
before 11 10
after 13 10, byte-lengths identical and in the same order

The two blocks this PR adds are http and text — the header example and the parsed-config dump are not compilable programs, and marking them as fragments would have been a worse answer than writing them as TypeScript. The set of blocks the gate compiles is therefore unchanged by this diff, so its verdict on this file is unchanged. The extractor was self-checked: planting one ts block in a scratchpad copy takes the population from 10 to 11, so the zero-delta reading is a measurement and not a broken probe.

The rest of the farm is CI's run, as always.


Generated by Claude Code

…d-first-request gap (#5279)

The header `createAuthenticatedFetch` stamps had no written contract, and the
shape of the missing information was actively misleading: its only non-CORS
consumer lives in the cloud repository, so a search confined to this repo and
the framework returns zero readers and reads as "nothing consumes this stamp".
#5279 was filed on exactly that reading and held until a cloud-side reading came
back non-empty. Without the contract written down, the next person to grep
reaches the same false conclusion and deletes a live routing input.

packages/auth/README.md gains "The X-Tenant-ID edge contract": what the header
means (a routing hint carrying the better-auth activeOrganizationId, not an
identity claim, not an authorization input, not what scopes rows), who stamps it
and under exactly which condition, who reads it, and what a reader may and may
not assume. The framework half is stated as a negative with its pin —
resolveAuthzContext takes tenantId from the API-key principal or
session.activeOrganizationId and from no header — next to plugin-sharing's
record that trusting x-tenant-id as identity was a vulnerability. The
configuration half is quoted from the contract this package can actually
resolve, TenantRoutingConfigSchema in @objectstack/spec/cloud, where X-Tenant-ID
is the default of a configurable tenantHeaderName and `header` ranks second of
six identification sources behind `subdomain`.

The unstamped-first-request gap gets its own section: ActiveOrganizationStorage
is filled only after AuthProvider's async organization chain resolves, so
early-boot requests carry no tenant header at all. What a reader observes is
documented as absent, never present-and-empty, with the five situations that
open the window and the instruction to fall through to the next identification
source rather than fail closed. The gap is recorded, deliberately not closed:
the cloud readers observe today's behaviour.

The stamping site carries the decisive facts inline, because the source is what
a grep-then-delete reader reads first.

Three cases in createAuthenticatedFetch.test.tsx pin the statements the prose
makes about the wire, so the documentation cannot drift away from the behaviour
unnoticed.

Documentation only. Proven: with comments stripped, the emitted JS for
createAuthenticatedFetch.ts is byte-identical before and after (2750 bytes
both), and the package's other 20 dist JS files are hash-identical.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012u2pRjcqAYtoEjgr3wwhnK
@github-actions github-actions Bot added documentation Improvements or additions to documentation tests labels Aug 22, 2026
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

Metric Value Budget
Eager closure (gzip, 52 chunks) 3913.6 KB 3990.2 KB
Main entry chunk (gzip) 152.3 KB 350 KB
Entry file index-spBIKF4m.js
Status PASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

Package Size Gzipped
app-shell (index.js) 10.04KB 3.72KB
app-shell (runtime-config.js) 12.80KB 4.47KB
app-shell (types.js) 0.01KB 0.04KB
app-shell (urlParams.js) 10.06KB 3.86KB
auth (AuthContext.js) 0.31KB 0.24KB
auth (AuthGuard.js) 1.17KB 0.53KB
auth (AuthProvider.js) 29.34KB 7.05KB
auth (AuthShell.js) 3.49KB 1.40KB
auth (ForgotPasswordForm.js) 12.21KB 3.45KB
auth (LoginForm.js) 18.15KB 5.39KB
auth (PreviewBanner.js) 0.90KB 0.50KB
auth (RegisterForm.js) 6.65KB 2.22KB
auth (SocialSignInButtons.js) 9.61KB 3.89KB
auth (UserMenu.js) 3.41KB 1.23KB
auth (auth-gate-events.js) 1.29KB 0.66KB
auth (authStyles.js) 5.04KB 1.72KB
auth (createAuthClient.js) 40.21KB 10.80KB
auth (createAuthenticatedFetch.js) 9.63KB 3.74KB
auth (index.js) 2.77KB 1.22KB
auth (invitation-status.js) 1.22KB 0.70KB
auth (org-roles.js) 6.66KB 2.78KB
auth (phone-identifier.js) 1.11KB 0.66KB
auth (types.js) 0.59KB 0.35KB
auth (useAuth.js) 5.02KB 0.89KB
auth (useIsWorkspaceAdmin.js) 3.04KB 1.45KB
collaboration (CommentThread.js) 26.08KB 7.56KB
collaboration (LiveCursors.js) 3.17KB 1.27KB
collaboration (PresenceAvatars.js) 6.49KB 2.64KB
collaboration (PresenceProvider.js) 2.79KB 1.13KB
collaboration (index.js) 1.68KB 0.73KB
collaboration (useCollaborationTranslation.js) 6.05KB 2.52KB
collaboration (useCommentSearch.js) 1.98KB 0.88KB
collaboration (useConflictResolution.js) 7.75KB 1.86KB
collaboration (useMentionNotifications.js) 1.81KB 0.68KB
collaboration (usePresence.js) 6.33KB 1.84KB
collaboration (useRealtimeSubscription.js) 7.91KB 2.01KB
components (index.js) 506.90KB 113.84KB
core (index.js) 4.92KB 1.97KB
create-plugin (index.js) 10.08KB 3.26KB
data-objectstack (index.js) 160.15KB 44.52KB
fields (index.js) 238.40KB 59.89KB
i18n (LocalizationContext.js) 1.76KB 0.96KB
i18n (currency.js) 1.22KB 0.64KB
i18n (i18n.js) 4.28KB 1.75KB
i18n (index.js) 3.44KB 1.39KB
i18n (pickLocalized.js) 7.62KB 3.26KB
i18n (provider.js) 23.13KB 7.63KB
i18n (useDisplayLocale.js) 2.85KB 1.45KB
i18n (useObjectLabel.js) 33.40KB 8.71KB
i18n (useSafeTranslation.js) 7.77KB 3.13KB
layout (index.js) 38.95KB 10.97KB
mobile (MobileProvider.js) 0.92KB 0.49KB
mobile (ResponsiveContainer.js) 0.94KB 0.38KB
mobile (breakpoints.js) 1.51KB 0.70KB
mobile (createOfflineDataSource.js) 5.61KB 1.75KB
mobile (index.js) 1.55KB 0.62KB
mobile (offlineQueue.js) 3.91KB 1.35KB
mobile (pwa.js) 0.97KB 0.49KB
mobile (serviceWorker.js) 1.48KB 0.62KB
mobile (serviceWorkerSource.js) 3.41KB 1.48KB
mobile (useBreakpoint.js) 1.54KB 0.65KB
mobile (useGesture.js) 6.96KB 1.98KB
mobile (useOfflineSync.js) 1.99KB 0.72KB
mobile (usePullToRefresh.js) 2.53KB 0.85KB
mobile (useResponsive.js) 0.72KB 0.42KB
mobile (useResponsiveConfig.js) 1.37KB 0.63KB
mobile (useSpecGesture.js) 4.32KB 1.64KB
mobile (useTouchTarget.js) 1.01KB 0.54KB
permissions (MePermissionsProvider.js) 9.53KB 3.38KB
permissions (PermissionContext.js) 0.31KB 0.25KB
permissions (PermissionGuard.js) 0.89KB 0.45KB
permissions (PermissionProvider.js) 4.64KB 1.50KB
permissions (evaluator.js) 5.12KB 1.74KB
permissions (index.js) 0.93KB 0.41KB
permissions (store.js) 0.91KB 0.42KB
permissions (useFieldPermissions.js) 1.28KB 0.53KB
permissions (usePermissions.js) 1.93KB 0.88KB
plugin-ai (index.js) 15.75KB 3.80KB
plugin-calendar (index.js) 46.62KB 12.83KB
plugin-charts (index.js) 64.65KB 18.32KB
plugin-chatbot (index.js) 181.41KB 43.22KB
plugin-dashboard (index.js) 128.41KB 32.95KB
plugin-designer (index.js) 212.30KB 42.80KB
plugin-detail (index.js) 242.34KB 60.98KB
plugin-editor (index.js) 2.46KB 1.10KB
plugin-form (index.js) 125.63KB 30.64KB
plugin-gantt (index.js) 164.10KB 39.87KB
plugin-grid (index.js) 200.79KB 54.26KB
plugin-kanban (index.js) 52.93KB 14.60KB
plugin-list (index.js) 111.80KB 27.20KB
plugin-map (index.js) 20.06KB 6.62KB
plugin-markdown (index.js) 13.72KB 4.69KB
plugin-report (index.js) 43.49KB 11.93KB
plugin-timeline (index.js) 26.68KB 7.66KB
plugin-tree (index.js) 8.50KB 2.88KB
plugin-view (index.js) 84.61KB 20.74KB
providers (DataSourceProvider.js) 0.75KB 0.39KB
providers (MetadataProvider.js) 1.37KB 0.59KB
providers (ThemeProvider.js) 1.90KB 0.85KB
providers (UploadProvider.js) 11.66KB 3.50KB
providers (index.js) 0.45KB 0.23KB
providers (types.js) 0.01KB 0.04KB
react-runtime (index.js) 5.62KB 2.34KB
react (LazyPluginLoader.js) 3.77KB 1.33KB
react (SchemaRenderer.js) 43.66KB 14.77KB
react (data-invalidation.js) 5.05KB 2.08KB
react (index.js) 1.33KB 0.69KB
react (schema-input.js) 2.32KB 1.24KB
react (spec-input.js) 0.20KB 0.18KB
sdui-parser (codegen.js) 5.41KB 2.34KB
sdui-parser (index.js) 4.77KB 2.16KB
sdui-parser (input-type.js) 2.84KB 1.40KB
sdui-parser (parse.js) 10.76KB 3.17KB
sdui-parser (provenance.js) 3.66KB 1.82KB
sdui-parser (types.js) 0.29KB 0.24KB
sdui-parser (validate.js) 6.92KB 2.40KB
types (ai.js) 0.20KB 0.17KB
types (api-types.js) 0.20KB 0.18KB
types (app.js) 2.87KB 0.99KB
types (base.js) 0.20KB 0.18KB
types (blocks.js) 0.20KB 0.18KB
types (complex.js) 0.20KB 0.18KB
types (crud.js) 0.20KB 0.18KB
types (dashboard-filter-alias.js) 6.23KB 2.74KB
types (data-display.js) 0.20KB 0.18KB
types (data-protocol.js) 0.20KB 0.19KB
types (data.js) 0.20KB 0.18KB
types (designer.js) 1.87KB 0.85KB
types (disclosure.js) 0.20KB 0.18KB
types (error-code.js) 1.54KB 0.88KB
types (feedback.js) 0.20KB 0.18KB
types (field-types.js) 0.20KB 0.18KB
types (form.js) 0.20KB 0.18KB
types (http-inflight.js) 8.87KB 3.73KB
types (http-retry.js) 4.32KB 2.02KB
types (index.js) 3.59KB 1.79KB
types (layout.js) 0.20KB 0.18KB
types (managed-by.js) 0.19KB 0.18KB
types (mobile.js) 2.59KB 1.31KB
types (navigation.js) 0.20KB 0.18KB
types (objectql.js) 0.20KB 0.18KB
types (overlay.js) 0.20KB 0.18KB
types (permissions.js) 0.20KB 0.18KB
types (plugin-scope.js) 0.20KB 0.18KB
types (record-components.js) 0.20KB 0.19KB
types (record-semantics.js) 1.28KB 0.67KB
types (registry.js) 0.20KB 0.18KB
types (reports.js) 0.20KB 0.18KB
types (spec-report.js) 5.05KB 1.93KB
types (system-fields.js) 3.33KB 1.54KB
types (theme.js) 0.20KB 0.18KB
types (ui-action.js) 3.40KB 1.71KB
types (views.js) 0.20KB 0.18KB
types (widget.js) 0.20KB 0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

Copy link
Copy Markdown
Collaborator Author

Seat review — accepted on its merits. HELD only on #5705, which is a red base, not this diff.

Fence held exactly: packages/auth/README.md, the stamping site, a test, a changeset. No content/docs/**, no apps/site/** — the brief routed the edge contract to package-local docs precisely so #5668 could not touch it, and that is where it went. No governed surfaces.

Three things I want on the record:

  1. It did not claim a measurement it could not make. objectstack-ai/cloud is unreachable from this session (add_repo returned no access), so the cloud readers are cited as the recorded reading rather than re-derived. What it measured instead is the part that is reachable, at runtime rather than by file-read: TenantRoutingConfigSchema.parse({}) against the version @object-ui/auth actually resolves → tenantHeaderName: 'X-Tenant-ID', and header ranking second of six identification sources behind subdomain. That is the [finding] 响应式词汇的两个零消费表面:useResponsiveConfig 生产零调用者(page.components[].responsive 因此实际未生效)、MobileComponentConfig 零消费者 #4773 lesson applied without being told.

  2. The narrowing is proven with a falsified instrument. Both revisions of createAuthenticatedFetch.ts compiled with removeComments → byte-identical (2750 bytes each), then self-checked by re-spelling a header literal in a scratchpad copy until the comparison went red. Worth being precise about why that is valid here: --removeComments proves program semantics unchanged; it does not license a shipped-bytes claim, and none was made — the bundle report shows auth (createAuthenticatedFetch.js) moving 6.35 → 9.63 KB, which is comment text surviving this package's build. Two gauges, two different questions, both read. (auth now joins core and react on the list of packages whose shipped .js moves on a prose-only change.)

  3. The check-doc-snippet-types narrowing is declared, not skipped. The gate refuses to run on an unbuilt tree, so instead of hoping, the agent read the gate module's own TS_FENCE_LANGUAGES and applied it to both revisions: 11 → 13 fenced blocks, but 10 → 10 in the compiled population, identical byte-lengths in identical order; the two added fences are http and text. Self-checked by planting a ts block to move 10 → 11.

The inline comment at the stamping site is the part that will still be earning its keep in a year — it names the exact failure this card was filed on:

DO NOT DELETE THIS ON THE STRENGTH OF A GREP. … a search confined to this repo plus the framework finds zero consumers and reads as "dead stamp" — which is the false premise objectui#5279 was filed on.

The isApiCall asymmetry it noticed was recorded, not acted on"recorded as the behaviour that ships, not endorsed" — and routed to #5702, where I have labelled it needs-user-decision. That is the right handling of a behaviour question found mid-fence.

Held pending #5705 (main red: console.ai.pendingDrafts missing from eight locale packs). Nothing about this PR needs to change; it merges when the base is green.


Generated by Claude Code

@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

Metric Value Budget
Eager closure (gzip, 52 chunks) 3914.3 KB 3990.2 KB
Main entry chunk (gzip) 152.3 KB 350 KB
Entry file index-DvF64ISu.js
Status PASS

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

Package Size Gzipped
app-shell (index.js) 10.04KB 3.72KB
app-shell (runtime-config.js) 12.80KB 4.47KB
app-shell (types.js) 0.01KB 0.04KB
app-shell (urlParams.js) 10.06KB 3.86KB
auth (AuthContext.js) 0.31KB 0.24KB
auth (AuthGuard.js) 1.17KB 0.53KB
auth (AuthProvider.js) 29.34KB 7.05KB
auth (AuthShell.js) 3.49KB 1.40KB
auth (ForgotPasswordForm.js) 12.21KB 3.45KB
auth (LoginForm.js) 18.15KB 5.39KB
auth (PreviewBanner.js) 0.90KB 0.50KB
auth (RegisterForm.js) 6.65KB 2.22KB
auth (SocialSignInButtons.js) 9.61KB 3.89KB
auth (UserMenu.js) 3.41KB 1.23KB
auth (auth-gate-events.js) 1.29KB 0.66KB
auth (authStyles.js) 5.04KB 1.72KB
auth (createAuthClient.js) 40.21KB 10.80KB
auth (createAuthenticatedFetch.js) 9.63KB 3.74KB
auth (index.js) 2.77KB 1.22KB
auth (invitation-status.js) 1.22KB 0.70KB
auth (org-roles.js) 6.66KB 2.78KB
auth (phone-identifier.js) 1.11KB 0.66KB
auth (types.js) 0.59KB 0.35KB
auth (useAuth.js) 5.02KB 0.89KB
auth (useIsWorkspaceAdmin.js) 3.04KB 1.45KB
collaboration (CommentThread.js) 26.08KB 7.56KB
collaboration (LiveCursors.js) 3.17KB 1.27KB
collaboration (PresenceAvatars.js) 6.49KB 2.64KB
collaboration (PresenceProvider.js) 2.79KB 1.13KB
collaboration (index.js) 1.68KB 0.73KB
collaboration (useCollaborationTranslation.js) 6.05KB 2.52KB
collaboration (useCommentSearch.js) 1.98KB 0.88KB
collaboration (useConflictResolution.js) 7.75KB 1.86KB
collaboration (useMentionNotifications.js) 1.81KB 0.68KB
collaboration (usePresence.js) 6.33KB 1.84KB
collaboration (useRealtimeSubscription.js) 7.91KB 2.01KB
components (index.js) 506.90KB 113.84KB
core (index.js) 4.92KB 1.97KB
create-plugin (index.js) 10.08KB 3.26KB
data-objectstack (index.js) 160.15KB 44.52KB
fields (index.js) 238.40KB 59.89KB
i18n (LocalizationContext.js) 1.76KB 0.96KB
i18n (currency.js) 1.22KB 0.64KB
i18n (i18n.js) 4.28KB 1.75KB
i18n (index.js) 3.44KB 1.39KB
i18n (pickLocalized.js) 7.62KB 3.26KB
i18n (provider.js) 23.13KB 7.63KB
i18n (useDisplayLocale.js) 2.85KB 1.45KB
i18n (useObjectLabel.js) 33.40KB 8.71KB
i18n (useSafeTranslation.js) 7.77KB 3.13KB
layout (index.js) 38.95KB 10.97KB
mobile (MobileProvider.js) 0.92KB 0.49KB
mobile (ResponsiveContainer.js) 0.94KB 0.38KB
mobile (breakpoints.js) 1.51KB 0.70KB
mobile (createOfflineDataSource.js) 5.61KB 1.75KB
mobile (index.js) 1.55KB 0.62KB
mobile (offlineQueue.js) 3.91KB 1.35KB
mobile (pwa.js) 0.97KB 0.49KB
mobile (serviceWorker.js) 1.48KB 0.62KB
mobile (serviceWorkerSource.js) 3.41KB 1.48KB
mobile (useBreakpoint.js) 1.54KB 0.65KB
mobile (useGesture.js) 6.96KB 1.98KB
mobile (useOfflineSync.js) 1.99KB 0.72KB
mobile (usePullToRefresh.js) 2.53KB 0.85KB
mobile (useResponsive.js) 0.72KB 0.42KB
mobile (useResponsiveConfig.js) 1.37KB 0.63KB
mobile (useSpecGesture.js) 4.32KB 1.64KB
mobile (useTouchTarget.js) 1.01KB 0.54KB
permissions (MePermissionsProvider.js) 9.53KB 3.38KB
permissions (PermissionContext.js) 0.31KB 0.25KB
permissions (PermissionGuard.js) 0.89KB 0.45KB
permissions (PermissionProvider.js) 4.64KB 1.50KB
permissions (evaluator.js) 5.12KB 1.74KB
permissions (index.js) 0.93KB 0.41KB
permissions (store.js) 0.91KB 0.42KB
permissions (useFieldPermissions.js) 1.28KB 0.53KB
permissions (usePermissions.js) 1.93KB 0.88KB
plugin-ai (index.js) 15.75KB 3.80KB
plugin-calendar (index.js) 46.62KB 12.83KB
plugin-charts (index.js) 64.65KB 18.32KB
plugin-chatbot (index.js) 181.41KB 43.22KB
plugin-dashboard (index.js) 128.41KB 32.95KB
plugin-designer (index.js) 212.30KB 42.80KB
plugin-detail (index.js) 242.34KB 60.98KB
plugin-editor (index.js) 2.46KB 1.10KB
plugin-form (index.js) 125.63KB 30.64KB
plugin-gantt (index.js) 164.10KB 39.87KB
plugin-grid (index.js) 200.79KB 54.26KB
plugin-kanban (index.js) 52.93KB 14.60KB
plugin-list (index.js) 111.80KB 27.20KB
plugin-map (index.js) 20.06KB 6.62KB
plugin-markdown (index.js) 13.72KB 4.69KB
plugin-report (index.js) 43.49KB 11.93KB
plugin-timeline (index.js) 26.68KB 7.66KB
plugin-tree (index.js) 8.50KB 2.88KB
plugin-view (index.js) 84.61KB 20.74KB
providers (DataSourceProvider.js) 0.75KB 0.39KB
providers (MetadataProvider.js) 1.37KB 0.59KB
providers (ThemeProvider.js) 1.90KB 0.85KB
providers (UploadProvider.js) 11.66KB 3.50KB
providers (index.js) 0.45KB 0.23KB
providers (types.js) 0.01KB 0.04KB
react-runtime (index.js) 5.62KB 2.34KB
react (LazyPluginLoader.js) 3.77KB 1.33KB
react (SchemaRenderer.js) 43.66KB 14.77KB
react (data-invalidation.js) 5.05KB 2.08KB
react (index.js) 1.33KB 0.69KB
react (schema-input.js) 2.32KB 1.24KB
react (spec-input.js) 0.20KB 0.18KB
sdui-parser (codegen.js) 5.41KB 2.34KB
sdui-parser (index.js) 4.77KB 2.16KB
sdui-parser (input-type.js) 2.84KB 1.40KB
sdui-parser (parse.js) 10.76KB 3.17KB
sdui-parser (provenance.js) 3.66KB 1.82KB
sdui-parser (types.js) 0.29KB 0.24KB
sdui-parser (validate.js) 6.92KB 2.40KB
types (ai.js) 0.20KB 0.17KB
types (api-types.js) 0.20KB 0.18KB
types (app.js) 2.87KB 0.99KB
types (base.js) 0.20KB 0.18KB
types (blocks.js) 0.20KB 0.18KB
types (complex.js) 0.20KB 0.18KB
types (crud.js) 0.20KB 0.18KB
types (dashboard-filter-alias.js) 6.23KB 2.74KB
types (data-display.js) 0.20KB 0.18KB
types (data-protocol.js) 0.20KB 0.19KB
types (data.js) 0.20KB 0.18KB
types (designer.js) 1.87KB 0.85KB
types (disclosure.js) 0.20KB 0.18KB
types (error-code.js) 1.54KB 0.88KB
types (feedback.js) 0.20KB 0.18KB
types (field-types.js) 0.20KB 0.18KB
types (form.js) 0.20KB 0.18KB
types (http-inflight.js) 8.87KB 3.73KB
types (http-retry.js) 4.32KB 2.02KB
types (index.js) 3.59KB 1.79KB
types (layout.js) 0.20KB 0.18KB
types (managed-by.js) 0.19KB 0.18KB
types (mobile.js) 2.59KB 1.31KB
types (navigation.js) 0.20KB 0.18KB
types (objectql.js) 0.20KB 0.18KB
types (overlay.js) 0.20KB 0.18KB
types (permissions.js) 0.20KB 0.18KB
types (plugin-scope.js) 0.20KB 0.18KB
types (record-components.js) 0.20KB 0.19KB
types (record-semantics.js) 1.28KB 0.67KB
types (registry.js) 0.20KB 0.18KB
types (reports.js) 0.20KB 0.18KB
types (spec-report.js) 5.05KB 1.93KB
types (system-fields.js) 3.33KB 1.54KB
types (theme.js) 0.20KB 0.18KB
types (ui-action.js) 3.40KB 1.71KB
types (views.js) 0.20KB 0.18KB
types (widget.js) 0.20KB 0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@os-sales
os-sales marked this pull request as ready for review August 22, 2026 13:12
@os-sales
os-sales added this pull request to the merge queue Aug 22, 2026
Merged via the queue into main with commit 934a532 Aug 22, 2026
23 checks passed
@os-sales
os-sales deleted the claude/issue-5279-tenant-header-edge-contract branch August 22, 2026 13:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation tests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Confirm whether X-Tenant-ID has a reader: the framework derives the tenant from the session, not the header

2 participants