Linkage chore per the multi-repo coordination rule (accepted repo:objectui PR ⇒ file the console bump in the consuming repo).
objectstack-ai/objectui#4108 is merged (objectui main aeb8424, 2026-08-10T10:24:11Z): the list row kebab's built-in Edit/Delete, the grid bulk-delete bar, the non-grid (ListView) bulk delete and the related-list Create/Edit/Delete now AND the caller's own /me/permissions verdict (allowEdit / allowDelete) on top of the layers they already had. Fixes objectui#4096.
Task
Run the standard console refresh (scripts/bump-objectui.sh / pnpm objectui:refresh per repo convention) and land the .objectui-sha + packages/console bump.
Staleness reading (2026-08-10T10:30Z)
Why it matters beyond routine freshness
objectui#4096 is a user-facing permission-affordance repair on a destructive control — Delete rendered one click away from accounts the server answers 403 on. Server-side enforcement was already hard (403, DB unchanged), so nothing is unsafe today, but the bundled console keeps showing the misleading entry until this bump lands.
Standard pin-bump discipline applies: dedicated PR, no riders; .objectui-sha is a shared file — take the whole regen (hono override + lockfile) through the script.
Note for triage: no domain:* / repo:* label applied — routing labels are the triage seat's single-producer territory. Only pm:queue is set here. Single-card cap checked at filing time: #7268 (the previous console-bump card) is closed (2026-08-10T06:45Z) and no other open console-bump card exists.
Linkage chore per the multi-repo coordination rule (accepted
repo:objectuiPR ⇒ file the console bump in the consuming repo).objectstack-ai/objectui#4108 is merged (objectui main
aeb8424, 2026-08-10T10:24:11Z): the list row kebab's built-in Edit/Delete, the grid bulk-delete bar, the non-grid (ListView) bulk delete and the related-list Create/Edit/Delete now AND the caller's own/me/permissionsverdict (allowEdit/allowDelete) on top of the layers they already had. Fixes objectui#4096.Task
Run the standard console refresh (
scripts/bump-objectui.sh/pnpm objectui:refreshper repo convention) and land the.objectui-sha+packages/consolebump.Staleness reading (2026-08-10T10:30Z)
.objectui-shaonorigin/main:8aad9fd50b16750aebdd294392ff79540f17cd32(objectuifix(components): bind the row three ways on the four action renderers (#4075))origin/main:aeb8424evalRowPredicatefault-reason/subject fix (objectui#3792 / [P3] Six flow-node config aliases bypassreadAliasedConfig— no warning, no ledger, no retirement path #3796), theclientValidationwiring (objectui#3561), the object-gridfilterkey fix (objectui#4041) and a dependabot wave.Why it matters beyond routine freshness
objectui#4096 is a user-facing permission-affordance repair on a destructive control — Delete rendered one click away from accounts the server answers
403on. Server-side enforcement was already hard (403, DB unchanged), so nothing is unsafe today, but the bundled console keeps showing the misleading entry until this bump lands.Standard pin-bump discipline applies: dedicated PR, no riders;
.objectui-shais a shared file — take the whole regen (hono override + lockfile) through the script.Note for triage: no
domain:*/repo:*label applied — routing labels are the triage seat's single-producer territory. Onlypm:queueis set here. Single-card cap checked at filing time: #7268 (the previous console-bump card) is closed (2026-08-10T06:45Z) and no other open console-bump card exists.