Files
sim/apps
Theodore Li 7f4cc38fb7 improvement(tables): show the lock chip only when a table is actually locked (#5967)
* improvement(tables): show the lock chip only when a table is actually locked

- The header chip rendered whenever an admin had the flag on, so an unlocked
  table permanently carried a "Lock settings" entry. Header space is for
  state: the chip now appears only once something is locked and names the
  mode. The admin route to the panel on an unlocked table is the breadcrumb
  dropdown, which already had it
- Keep the Append-only name when the schema is locked too. Append-only
  describes the row semantics and a schema lock doesn't change them; the
  detail line calls out the locked columns instead

* improvement(tables): resolve the lock flag server-side and record lock changes fully

- Drop NEXT_PUBLIC_TABLE_LOCKS. A feature flag's gating lives in AppConfig,
  which has no client counterpart, so mirroring it into a public env var meant
  AppConfig couldn't control the UI at all and org/user clauses could never
  reach the client — only global on/off. The page now resolves the flag with
  session context and passes it down, per the add-feature-flag skill. Embedded
  renders default to false, failing closed; enforcement of stored locks is
  unaffected either way
- Record the previous locks alongside the new ones and name the transitions in
  the audit description, so the log answers who locked what without expanding
  metadata. Forward the request for IP / user-agent capture

* fix(tables): resolve the lock flag with the same context on both gates

The page passed userId/orgId while the PATCH gate resolved the flag with no
context, so an org- or user-targeted rollout would show the settings panel and
then 403 on save — the rollout path the previous commit exists to enable.

Both now key on the workspace's host organization rather than the viewer's
active one, matching the convention getWorkspaceHostContextForViewer
documents: active-org describes the account, not the workspace host. The
route's lookup runs only when a lock is actually being turned on.
2026-07-25 17:47:11 -04:00
..