Skip to content

skills(objectstack-api): the published public-form opt-in names two of the three sharing keys the anonymous form endpoints require — an AI following it authors a form both endpoints answer 404 #21567

Description

@objectstack-fleet

QA-source: #21330 · access-security.public-form-intake · found while building #21475 (outside the item's clauses)

Once PR #21566 (fix for #21475) lands, the anonymous form endpoints (GET /forms/:slug, POST /forms/:slug/submit) serve a FormView only when its sharing declares enabled: true, allowAnonymous: true and a publicLink slug — the rule now lives once in @objectstack/metadata-core (anonymousFormIntakeCandidates), following SharingConfigSchema, whose enabled defaults to false.

The published skill still says otherwise: skills/objectstack-api/SKILL.md, public form endpoints section — "Any FormView declared with sharing.allowAnonymous: true and a publicLink slug is auto-mounted". An agent following that line authors a form that both endpoints answer 404 FORM_NOT_FOUND for (class c: a trap that makes AI write metadata the runtime refuses).


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:accessPermissions that actually hold — RLS/FLS, sharing model, write-path guardsdocumentationImprovements or additions to documentationdomain:skillspriority:p1High: required for production / M2

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions