Skip to content

fix(auth): LoginForm's registerUrl has no default, so an absent URL renders no sign-up link (objectui#11634) - #11652

Merged
objectstack-fleet[bot] merged 3 commits into
mainfrom
claude/issue-11634-loginform-register-default
Oct 5, 2026
Merged

objectstack-fleet[bot] merged 3 commits into
mainfrom
claude/issue-11634-loginform-register-default

Conversation

@objectstack-fleet

Copy link
Copy Markdown
Contributor

Fixes #11634

Clause-②: no

What changed

  • LoginForm (packages/auth/src/LoginForm.tsx) no longer defaults registerUrl to '/register'. The "Don't have an account? Sign up" row renders only when the caller passes a URL, and the prop's doc comment now says so. The prop's type is unchanged (registerUrl?: string). No null arm is added, per the triage ruling on the card (comment 5986895176).
  • .changeset/11634-loginform-register-default.md: '@object-ui/auth': minor. It states the behaviour change: a caller that left the prop out and relied on the default now passes registerUrl="/register" to keep the link.
  • Pins: packages/auth/src/__tests__/LoginForm.test.tsx and a new apps/console/src/pages/auth/__tests__/LoginPage.sign-up-gate-11634.test.tsx.

Why

When /auth/config reports emailPassword.disableSignUp: true, both console login pages pass registerUrl as undefined. The destructuring default turned that undefined back into '/register', so a deployment with sign-up turned off still offered "Sign up".

Callers and examples (measured on origin/main)

  • The console app's LoginPage (its LoginFormCard) passes signUpDisabled ? undefined : registerUrl, where registerUrl is '/register' or '/register?redirect=…'. It already passes the URL whenever sign-up is on, so it is unchanged.
  • @object-ui/app-shell's DefaultLoginPage (mounted by examples/console-starter) passes signUpDisabled ? undefined : '/register'. It is unchanged for the same reason.
  • These render LoginForm with no registerUrl: packages/auth/README.md (the AuthGuard fallback and the forms example), the AuthShell doc comment example, and skills/objectui/guides/auth-permissions.md. None of them states or expects a sign-up link; the skills guide lists "email/password fields, social login buttons, forgot password link". They now render no sign-up link, and none needs the URL to stay correct, so none is edited. The skills guide is on the governed surface in any case.
  • No story, no apps/site page and no content/docs/** page renders LoginForm or states the '/register' default, so no docs page changes.
  • LoginForm's own @example already passes registerUrl="/register", so it is still correct.
  • The test socialButtonLabels-10900.test.tsx renders LoginForm with no registerUrl. It asserts only the social-button labels, so it is unaffected.

One existing pin was re-judged (not deleted). LoginForm — SSO-only (enforced) mode › "hides the password form + sign-up and shows a break-glass link when features.ssoEnforced" rendered with no registerUrl and asserted no "Sign up". Without a default, that assertion holds whatever the enforced guard does. It now passes registerUrl: '/register', so it measures the !ssoEnforced guard. Ablation leg B below shows it goes red when that guard is removed.

New pins

  • LoginForm: registerUrl left out, or passed as undefined, renders no link and no "Don't have an account?" text. registerUrl="/x" renders the link with href /x.
  • Console LoginPage: disableSignUp: true renders no "Sign up" link. disableSignUp: false renders it with href /register. The test uses the mock AuthClient that LoginPage.dev-admin-hint.test.tsx already uses, so it adds no production seam. The dev-admin hint comes from the same config read that sets the sign-up gate, so the test waits for it before it judges the link.

Verification at b906a13 (branch head, after one merge of origin/main at e398a54)

Each command was run from the repo root, with its exit code captured before any pipe.

Gate Exit Reading
pnpm exec vitest run packages/auth/ 0 28 files, 285 tests passed
pnpm exec vitest run apps/console/src/pages/auth/ 0 9 files, 52 tests passed
pnpm exec vitest run packages/app-shell/src/console/auth/ 0 3 files, 14 tests passed
pnpm --filter @object-ui/auth type-check 0 tsc --noEmit && tsc -p tsconfig.test.json; --listFiles on the test project includes LoginForm.test.tsx. @object-ui/auth has no workspace dependencies, so its build closure is empty.
pnpm --filter @object-ui/auth lint 0 0 errors, 26 warnings. The one in LoginForm.tsx (hasSocialProviders unused) was already on main.
eslint on the 3 changed source files 0 --format json shows 3 files, 0 errors
check-changeset-presence / check-changeset-no-major / check-changeset-fixed / check-changeset-overwrite 0 / 0 / 0 / 0 presence: "3 source file(s) of 2 released package(s) changed, and this change declares 1 changeset(s)"
check:changeset-claims / check:pending-changeset-literals 0 / 0 "No pending changeset names a file this change touches."
check:new-line-citations 0 "0 new citation(s)"
check:control-bytes / check:test-path-roots 0 / 0 OK
check:vi-mock-specifiers / -inherit / -override-shape 0 / 0 / 0 OK

Narrowed lint. The repo-wide pnpm lint belongs to CI. Locally I linted the 3 changed .ts/.tsx files, which eslint.config.js puts in the **/*.{ts,tsx} population (the 2 tests are also in the **/*.test.{ts,tsx} / **/__tests__/** blocks). --format json reported 3 files. eslint.config.js sets no parserOptions.project and no projectService, so linting is not type-aware and this diff cannot change the verdict on any untouched file.

NOT MEASURED: console type-check (tsc --noEmit over apps/console, the only program that compiles the new console test). Reason: that program resolves every @object-ui/* import through the package's built dist types, so it needs the console's whole workspace build closure, and that build was not run here. CI runs it. The new file follows the pattern of the existing LoginPage.dev-admin-hint.test.tsx and is lint-clean.

Ablation (from the committed head, trap restore, ablation-replace.mjs: the anchor must hit, and the restore is checked against the HEAD blob)

  • Leg A, '/register' default put back (on-disk count of the default line: 0 → 1 during the mutation → 0 after). 3 tests failed and 25 passed: renders no sign-up link when registerUrl is left out, … is passed as undefined (both "expected a href=/register … to be null"), and the console renders no sign-up link when the server reports disableSignUp: true. The console red also shows the console test reaches the src of @object-ui/auth (vitest alias), not a stale dist.
  • Leg B, !ssoEnforced dropped from the sign-up row guard (guard count 1 → 0 → 1). 1 test failed and 25 passed: the re-judged enforced-mode pin.
  • After each leg the blob was back to HEAD's (c62cd03ca3a4) and git diff HEAD was empty.

Live before/after

Backend: objectstack main at 27991556, examples/app-showcase, objectstack dev --seed-admin --fresh, from a separate objectstack worktree (port 4634). Console: this worktree's Vite dev server (port 5634) proxied to that backend. Route /login (the dev server's basename is /; it is the same LoginPage route the card reached at /_console/login). Each context was a fresh Chromium context: wait for network idle and the identifier field, wait 4 s more, then count a[href$="/register"].

Boot GET /api/v1/auth/config emailPassword Tree a[href$="/register"] per context
OS_DISABLE_SIGNUP=true {"enabled":true,"disableSignUp":true,…} before: '/register' default put back (the base line) [1,1,1], each /register "Sign up"
OS_DISABLE_SIGNUP=true same after: branch head [0,0,0], no "Don't have an account?"
sign-up on (OS_DISABLE_SIGNUP unset) {"enabled":true,"disableSignUp":false,…} after: branch head [1,1,1], each /register "Sign up"

In every context the dev-admin banner rendered and the page's own /auth/config response carried the disableSignUp value above, so the config was applied before the link was counted.

Acceptance notes

  • Sibling with the same shape: forgotPasswordUrl still defaults to '/forgot-password', so undefined brings that link back too. No caller passes undefined to switch it off: both login pages pass "/forgot-password", and AuthPublicConfig has no flag that turns password reset off. Nothing pulls on it, so it is noted here and not filed. Out of scope for this card.
  • Transient link while config loads (read from the code, not measured live): the sign-up row sits outside LoginForm's config-loading gate. The console app's page starts signUpDisabled at false, and DefaultLoginPage starts it at undefined, which falls to '/register'. So on a sign-up-off boot both pages show the link until their config read resolves, and then drop it. The steady state is what this card judged. DefaultLoginPage's comment says its undefined start avoids this flicker, but undefined falls to the URL arm. This is polish, not filed.
  • packages/auth/README.md does not document registerUrl before or after this change. The behaviour change is stated in the changeset.

Session: https://claude.ai/code/session_015W8GBu6sBiqus2L2xjMsAL


Generated by Claude Code

claude added 3 commits October 5, 2026 08:01
…enders no sign-up link (objectui#11634)

Both console login pages pass `registerUrl={undefined}` when the server
reports `emailPassword.disableSignUp`. LoginForm destructured
`registerUrl = '/register'`, so that undefined brought the default back and
a sign-up-disabled deployment still showed "Don't have an account? Sign up".

The default is dropped: the link renders only for a passed URL. The prop's
type is unchanged and no second "off" value is added (triage ruling).

Tests: LoginForm pins absent/undefined -> no link and a passed URL -> that
href; the enforced-mode pin now passes registerUrl so it still measures the
enforced guard; a console LoginPage pin covers disableSignUp true/false.

Claude-Session: https://claude.ai/code/session_015W8GBu6sBiqus2L2xjMsAL
Co-authored-by: Claude <noreply@anthropic.com>
…osing its '/register' default (objectui#11634)

States the behaviour change for a caller that left `registerUrl` out and
relied on the default, and what it now passes to keep the link.

Claude-Session: https://claude.ai/code/session_015W8GBu6sBiqus2L2xjMsAL
Co-authored-by: Claude <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

Metric Value Budget
Eager closure (gzip, 331 chunks) 3317.4 KB 3330.4 KB
Main entry chunk (gzip) 151.8 KB 350 KB
Entry file index-BefVqGby.js —
Status PASS —

The eager closure is every chunk the entry reaches through static imports — what the browser fetches and parses before the app renders. The entry chunk on its own is a small fraction of it.


📦 Bundle Size Report

Package Size Gzipped
app-shell (consoleActionDispatch.js) 0.20KB 0.19KB
app-shell (index.js) 17.22KB 6.37KB
app-shell (runtime-config.js) 22.52KB 7.86KB
app-shell (types.js) 0.01KB 0.04KB
app-shell (urlParams.js) 10.11KB 3.87KB
auth (ActiveOrganizationStorage.js) 27.95KB 10.04KB
auth (AuthContext.js) 0.31KB 0.24KB
auth (AuthGuard.js) 2.07KB 1.00KB
auth (AuthProvider.js) 40.22KB 10.61KB
auth (AuthShell.js) 3.49KB 1.40KB
auth (ForgotPasswordForm.js) 12.21KB 3.45KB
auth (LoginForm.js) 18.15KB 5.40KB
auth (PreviewBanner.js) 0.90KB 0.50KB
auth (RegisterForm.js) 6.72KB 2.24KB
auth (SocialSignInButtons.js) 9.70KB 3.93KB
auth (UserMenu.js) 3.39KB 1.21KB
auth (auth-gate-events.js) 1.29KB 0.66KB
auth (authStyles.js) 5.04KB 1.72KB
auth (createAuthClient.js) 40.70KB 10.94KB
auth (createAuthenticatedFetch.js) 8.54KB 3.46KB
auth (index.js) 3.63KB 1.64KB
auth (invitation-status.js) 1.22KB 0.70KB
auth (org-roles.js) 6.66KB 2.78KB
auth (phone-identifier.js) 1.11KB 0.66KB
auth (types.js) 0.59KB 0.35KB
auth (useAuth.js) 5.30KB 1.02KB
auth (useWorkspaceAdminStatus.js) 11.08KB 4.58KB
collaboration (CommentThread.js) 27.11KB 7.97KB
collaboration (LiveCursors.js) 3.17KB 1.27KB
collaboration (PresenceAvatars.js) 6.28KB 2.60KB
collaboration (PresenceProvider.js) 2.79KB 1.13KB
collaboration (index.js) 1.68KB 0.73KB
collaboration (useCollaborationTranslation.js) 6.50KB 2.52KB
collaboration (useCommentSearch.js) 1.98KB 0.88KB
collaboration (useConflictResolution.js) 7.75KB 1.86KB
collaboration (useMentionNotifications.js) 1.81KB 0.68KB
collaboration (usePresence.js) 6.33KB 1.84KB
collaboration (useRealtimeSubscription.js) 7.91KB 2.01KB
components (index.js) 574.98KB 137.97KB
core (index.js) 10.00KB 3.96KB
create-plugin (index.js) 27.94KB 9.51KB
data-objectstack (index.js) 232.57KB 64.51KB
fields (index.js) 262.75KB 66.62KB
i18n (LocalizationContext.js) 1.76KB 0.96KB
i18n (builtinAggregateLabels.js) 0.86KB 0.49KB
i18n (currency.js) 2.59KB 1.22KB
i18n (fallbackInterpolation.js) 6.25KB 2.77KB
i18n (i18n.js) 8.87KB 3.64KB
i18n (index.js) 5.24KB 2.27KB
i18n (pickLocalized.js) 9.86KB 3.95KB
i18n (provider.js) 39.35KB 12.88KB
i18n (translateFn.js) 0.20KB 0.18KB
i18n (useDisplayLocale.js) 3.52KB 1.76KB
i18n (useObjectLabel.js) 35.66KB 9.49KB
i18n (useSafeTranslation.js) 7.14KB 2.92KB
layout (index.js) 39.47KB 11.25KB
mobile (MobileProvider.js) 0.92KB 0.49KB
mobile (ResponsiveContainer.js) 0.94KB 0.38KB
mobile (breakpoints.js) 1.51KB 0.70KB
mobile (createOfflineDataSource.js) 5.61KB 1.75KB
mobile (index.js) 1.99KB 0.87KB
mobile (offlineQueue.js) 3.91KB 1.35KB
mobile (pwa.js) 0.97KB 0.49KB
mobile (serviceWorker.js) 1.48KB 0.62KB
mobile (serviceWorkerSource.js) 3.41KB 1.48KB
mobile (useBreakpoint.js) 1.54KB 0.65KB
mobile (useGesture.js) 6.96KB 1.98KB
mobile (useOfflineSync.js) 1.99KB 0.72KB
mobile (usePullToRefresh.js) 6.62KB 2.45KB
mobile (useResponsive.js) 0.72KB 0.42KB
mobile (useSpecGesture.js) 5.52KB 2.10KB
mobile (useTouchTarget.js) 1.01KB 0.54KB
permissions (MePermissionsProvider.js) 13.86KB 5.00KB
permissions (PermissionContext.js) 0.31KB 0.25KB
permissions (PermissionGuard.js) 0.89KB 0.45KB
permissions (PermissionProvider.js) 6.52KB 2.26KB
permissions (discardProofCache.js) 1.04KB 0.55KB
permissions (evaluator.js) 8.33KB 3.07KB
permissions (index.js) 0.93KB 0.41KB
permissions (store.js) 0.91KB 0.42KB
permissions (useFieldPermissions.js) 1.28KB 0.53KB
permissions (usePermissions.js) 4.83KB 2.27KB
plugin-ai (index.js) 16.04KB 3.92KB
plugin-calendar (index.js) 53.17KB 15.46KB
plugin-charts (index.js) 84.26KB 23.05KB
plugin-chatbot (index.js) 198.22KB 46.97KB
plugin-dashboard (index.js) 143.58KB 38.81KB
plugin-designer (index.js) 231.41KB 48.84KB
plugin-detail (index.js) 247.21KB 65.03KB
plugin-editor (index.js) 2.23KB 1.05KB
plugin-form (index.js) 177.09KB 45.89KB
plugin-gantt (index.js) 179.16KB 45.06KB
plugin-grid (index.js) 235.92KB 64.87KB
plugin-kanban (index.js) 50.06KB 15.74KB
plugin-list (index.js) 116.72KB 29.10KB
plugin-map (index.js) 25.60KB 8.62KB
plugin-markdown (index.js) 13.88KB 4.80KB
plugin-report (index.js) 44.12KB 12.29KB
plugin-timeline (index.js) 38.80KB 11.71KB
plugin-tree (index.js) 14.51KB 5.15KB
plugin-view (index.js) 90.23KB 22.73KB
providers (DataSourceProvider.js) 0.75KB 0.39KB
providers (MetadataProvider.js) 1.37KB 0.59KB
providers (ThemeProvider.js) 1.90KB 0.85KB
providers (UploadProvider.js) 11.81KB 3.58KB
providers (index.js) 0.45KB 0.23KB
providers (types.js) 0.01KB 0.04KB
react-runtime (index.js) 5.62KB 2.34KB
react (LazyPluginLoader.js) 4.47KB 1.63KB
react (SchemaRenderer.js) 120.63KB 39.56KB
react (data-invalidation.js) 5.05KB 2.08KB
react (index.js) 4.50KB 2.06KB
react (schema-input.js) 4.31KB 2.07KB
react (spec-input.js) 0.20KB 0.18KB
sdui-parser (body-dialect.js) 4.50KB 1.99KB
sdui-parser (codegen.js) 9.45KB 3.76KB
sdui-parser (dashboard-widget-options.js) 3.08KB 1.30KB
sdui-parser (index.js) 7.30KB 3.12KB
sdui-parser (input-type.js) 2.84KB 1.40KB
sdui-parser (parse.js) 25.28KB 7.80KB
sdui-parser (provenance.js) 3.84KB 1.90KB
sdui-parser (types.js) 0.28KB 0.23KB
sdui-parser (validate.js) 23.87KB 7.83KB
types (ai.js) 4.39KB 2.17KB
types (api-types.js) 0.20KB 0.18KB
types (app.js) 4.12KB 1.61KB
types (authoring-nodes.js) 0.20KB 0.19KB
types (base.js) 0.20KB 0.18KB
types (blocks.js) 0.20KB 0.18KB
types (cloud.js) 0.20KB 0.18KB
types (complex.js) 4.44KB 2.07KB
types (crud.js) 0.20KB 0.18KB
types (dashboard-filter-alias.js) 6.23KB 2.74KB
types (dashboard-widget-layout.js) 2.06KB 0.96KB
types (data-display.js) 3.75KB 1.85KB
types (data-protocol.js) 0.20KB 0.19KB
types (data.js) 0.20KB 0.18KB
types (designer.js) 1.85KB 0.85KB
types (disclosure.js) 0.20KB 0.18KB
types (error-code.js) 1.54KB 0.88KB
types (expression.js) 0.20KB 0.18KB
types (feedback.js) 0.20KB 0.18KB
types (field-types.js) 1.13KB 0.65KB
types (form.js) 0.20KB 0.18KB
types (http-inflight.js) 8.87KB 3.73KB
types (http-retry.js) 4.32KB 2.02KB
types (icon-key-migration.js) 4.26KB 1.63KB
types (index.js) 5.78KB 2.70KB
types (layout.js) 0.20KB 0.18KB
types (managed-by.js) 0.19KB 0.18KB
types (mobile.js) 5.00KB 2.39KB
types (navigation.js) 0.20KB 0.18KB
types (node-slots.js) 7.18KB 2.34KB
types (objectql.js) 0.20KB 0.18KB
types (overlay.js) 0.20KB 0.18KB
types (permissions.js) 2.52KB 1.31KB
types (plugin-scope.js) 0.20KB 0.18KB
types (record-components.js) 0.20KB 0.19KB
types (record-semantics.js) 1.28KB 0.67KB
types (registry.js) 0.20KB 0.18KB
types (reports.js) 0.20KB 0.18KB
types (select-option.js) 0.20KB 0.19KB
types (spec-report.js) 4.99KB 1.96KB
types (spec-ui-namespace.js) 0.20KB 0.19KB
types (strict-authoring-face.js) 19.93KB 7.25KB
types (system-fields.js) 3.33KB 1.54KB
types (theme.js) 6.28KB 2.87KB
types (ui-action.js) 8.11KB 3.32KB
types (views.js) 0.20KB 0.18KB
types (widget.js) 0.20KB 0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

@objectstack-fleet

Copy link
Copy Markdown
Contributor Author

ACCEPT: PR objectui#11652, head b906a13. It lands when every check on this head is green

domain:ui execution seat 1 @ objectui · session_015W8GBu6sBiqus2L2xjMsAL (os-steve) · 2026-10-05T08:55Z. Reviewed against GitHub and origin/main, not against the report's prose (report 5991240028).

  • Shape. The PR is a draft against main, and its assignee is os-steve. Its first line is Fixes #11634, the only line with a closing keyword next to an issue number. Clause-②: no is on its own line. The diff is 4 files, +126/−6. No path is governed.
  • The resumption. The first run was lost to the container restart. This run reviewed its one pushed commit (050fc0d) and kept it unchanged. It added the changeset (1895044) and one merge of origin/main (b906a13, at e398a54). No pushed commit was rewritten, and every reading was re-taken.
  • The ruling, as written. The '/register' default is gone, and the prop stays registerUrl?: string (no null arm). The prop doc now says that leaving it out, or passing undefined, renders no link. The @example already passes registerUrl="/register" explicitly, so it stays correct and is unchanged. Neither console LoginPage.tsx changes: both pass an explicit URL whenever sign-up is on.
  • File surface. apps/console/src/pages/auth/__tests__/LoginPage.sign-up-gate-11634.test.tsx sits outside the claim's listed surface. It is the console pin Zone 3 asked for, built on the existing mock-AuthClient seam. It is a test file only and is declared in the report, so it is accepted.
  • Tests.
    • New LoginForm pins: no link when the prop is left out or undefined, and a link to /x when /x is passed. A console LoginPage pin covers disableSignUp: true (no link) and false (link).
    • The SSO-enforced pin that used to render without registerUrl now passes it, so its "no Sign up" assertion measures the !ssoEnforced guard rather than the missing URL. The re-judgement is commented in place.
    • Ablations: putting the default back turns the 3 new-behaviour cases red; dropping !ssoEnforced turns the re-judged pin red.
  • Live, both directions (objectstack main 27991556, OS_DISABLE_SIGNUP=true). Before: [1,1,1] sign-up links in three fresh contexts. After: [0,0,0]. With sign-up on, after: [1,1,1].
  • Changeset, sentence by sentence. It is @object-ui/auth: minor, as the claim graded it. The mechanism, the behaviour-change paragraph with its caller migration (registerUrl="/register"), the in-tree callers sentence and the Clause-②: no line all match the diff.

Gate deviation, accepted because the landing gates on it: the console's tsc --noEmit (the one program that compiles the new console pin) was not run locally, because it needs the console's full dist closure. CI Type Check runs it on this head.

Left as noted, not filed (zero pull or unmeasured; both are in the PR's Acceptance notes):

  • forgotPasswordUrl keeps its '/forgot-password' default. No caller passes undefined to switch that link off.
  • Both login pages can show the sign-up link until their config read resolves.

Landing: on all-green checks on this head, ready, then auto-merge into the merge queue.


Generated by Claude Code

@objectstack-fleet
objectstack-fleet Bot marked this pull request as ready for review October 5, 2026 09:06
@objectstack-fleet
objectstack-fleet Bot enabled auto-merge October 5, 2026 09:06
@objectstack-fleet
objectstack-fleet Bot added this pull request to the merge queue Oct 5, 2026
Merged via the queue into main with commit f1a177c Oct 5, 2026
45 checks passed
@objectstack-fleet
objectstack-fleet Bot deleted the claude/issue-11634-loginform-register-default branch October 5, 2026 09:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

2 participants