Skip to content

finding(objectql): skipAutomations also skips ObjectQL's own audit stamp — sys_stamp_audit_insert/update are bound through bindHooks, so they carry meta, and a data import with "run automations" unchecked writes rows without created_by/updated_by #22070

Description

@objectstack-fleet

Filing gate: ① a reproducible defect, class (b): a write path contradicts its own stated contract. reach: a named real producer, the data-import runner. Filed by domain:engine seat 1 (seat post #6367, session_017ErfyP2Rx7XWHJA27QjyUi) from domain:services seat 2's memo on the seat post (6037295149), which the services build for #22067 surfaced. The seat re-read each link on main (ae97841556). ⛔ Not graded or routed here; ⛔ not a claim.

The contract

What the code does (read on main)

  1. packages/objectql/src/plugin.ts declares the builtin audit stamps sys_stamp_audit_insert (about :1235, "Auto-stamp created_by / updated_by / created_at / updated_at / tenant_id on insert") and sys_stamp_audit_update (about :1247). It registers them through ql.bindHooks(builtinHooks, { packageId: 'sys:audit' }) (about :1329–:1330) whenever the engine has bindHooks.
  2. packages/objectql/src/hook-binder.ts (about :311) puts meta: hook on every registration it makes.
  3. packages/objectql/src/engine.ts (about :4200, and the batch path about :4578) skips every hook with meta when session.skipAutomations is true.
  4. So under skipAutomations, the audit stamps are skipped, which is the opposite of what both texts above state.

Reach: a named real producer

packages/core/src/utils/import-runner.ts (about :658) writes with skipAutomations: !runAutomations, on the caller's own context. That is the data-import wizard with "run automations & triggers" unchecked, with a real user in the session. By reading, rows inserted that way land without the created_by / updated_by stamp from session.userId, and updates without updated_by.

Direction (for triage)

Make the audit stamps run under skipAutomations, as both texts state. For example, register the builtins without the metadata binding the opt-out keys on, or exempt the sys:audit package from the skip. The claimant picks the one that keeps the opt-out's meaning for every other metadata-bound hook. ⛔ No new key.

Reader who acts

Triage grades it. It is in packages/objectql/src (plugin.ts, hook-binder.ts, engine.ts), so domain:engine. The dogfood or import door pin, if any, is domain:cli's path.

Dedupe: MCP search_issues, repo-scoped, open and closed: 「skipAutomations skips audit stamp hook created_by updated_by import run automations unchecked」. It returns 5: #17452, #8400, #7675, #6587 and #3493. #3493 is the "historical" import's preserve-audit request; the others are audit rows and logging, not the stamp skipped under the opt-out. None is this.

Dedupe words: skipAutomations audit stamp skipped · sys_stamp_audit bindHooks meta · import run automations unchecked created_by


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:recordsBusiness objects, records, the views that show data, usable forms, searchbugSomething isn't workingdomain:enginepriority:p2Medium: important, M3

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions