Skip to content

Commit 21eab0e

Browse files
committed
fix(liveness,contract): position ledger rename + externalSharingModel classification + downstream fixture
Liveness: GOVERNED kind role→position; liveness/role.json→position.json (flat, parent dropped); permission ledger rowLevelSecurity.positions; object ledger gains externalSharingModel as 'authorable' with the P1 shape-only rationale and the #2696 pointer. Downstream-contract sharing fixture moves to the position recipient. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012oLzaP8n7A3YKFmgaHWC8H
1 parent db01bdb commit 21eab0e

6 files changed

Lines changed: 27 additions & 28 deletions

File tree

‎packages/downstream-contract/src/additional-domains.fixtures.ts‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -50,7 +50,7 @@ export const DcSharingRule: SharingRuleInput = {
5050
object: 'dc_account',
5151
condition: 'record.stage == "customer"',
5252
accessLevel: 'read',
53-
sharedWith: { type: 'role', value: 'dc_manager' },
53+
sharedWith: { type: 'position', value: 'dc_manager' },
5454
active: true,
5555
};
5656

‎packages/spec/liveness/object.json‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -248,6 +248,10 @@
248248
"searchableFields": {
249249
"status": "live",
250250
"note": "objectql `$search` executor (ADR-0061: expandSearchToFilter in engine.find) + objectui list/lookup/command-palette; canonical searchable-field source."
251+
},
252+
"externalSharingModel": {
253+
"status": "authorable",
254+
"note": "[ADR-0090 D11] P1 lands the SPEC SHAPE only (validated external<=internal at authoring). Runtime consumption (audience-aware evaluator branch) is scheduled with the principal-taxonomy semantics phase; tracked on the ADR-0090 tracking issue (#2696)."
251255
}
252256
}
253257
}

‎packages/spec/liveness/permission.json‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -139,10 +139,10 @@
139139
"status": "live",
140140
"evidence": "packages/plugins/plugin-security/src/rls-compiler.ts"
141141
},
142-
"roles": {
142+
"positions": {
143143
"status": "live",
144144
"evidence": "packages/plugins/plugin-security/src/rls-compiler.ts",
145-
"note": "flat match — no subordinate rollup."
145+
"note": "flat match — no subordinate rollup (ADR-0090 D3 rename)."
146146
},
147147
"enabled": {
148148
"status": "live",
Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,19 @@
1+
{
2+
"type": "position",
3+
"_note": "PositionSchema (ADR-0090 D3; formerly RoleSchema). Flat capability-distribution group.",
4+
"props": {
5+
"name": {
6+
"status": "live",
7+
"evidence": "packages/core/src/security/resolve-authz-context.ts:210",
8+
"note": "sys_position.name keys position-bound permission-set resolution and ctx.positions."
9+
},
10+
"label": {
11+
"status": "live",
12+
"note": "display (admin nav/forms, security-plugin.ts)."
13+
},
14+
"description": {
15+
"status": "live",
16+
"note": "display."
17+
}
18+
}
19+
}

‎packages/spec/liveness/role.json‎

Lines changed: 0 additions & 24 deletions
This file was deleted.

‎packages/spec/scripts/liveness/check-liveness.mts‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -53,7 +53,7 @@ const repoRoot = resolve(specRoot, '../..');
5353
const ledgerRoot = join(specRoot, 'liveness');
5454

5555
// Governed metadata types, rolled out highest-frequency / highest-risk first.
56-
const GOVERNED = ['object', 'field', 'flow', 'action', 'hook', 'permission', 'role', 'agent', 'tool', 'skill', 'dataset', 'page'];
56+
const GOVERNED = ['object', 'field', 'flow', 'action', 'hook', 'permission', 'position', 'agent', 'tool', 'skill', 'dataset', 'page'];
5757

5858
// ADR-0010 provenance/lock overlay fields — system-stamped, on every type; auto-live.
5959
const FRAMEWORK_FIELDS = new Set([

0 commit comments

Comments
 (0)