Skip to content

Commit 59679e1

Browse files
committed
docs(qa): fix the D11 table row separation
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
1 parent 87dd227 commit 59679e1

1 file changed

Lines changed: 0 additions & 1 deletion

File tree

‎docs/qa/platform-checklist/FOLLOW-UPS.md‎

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,6 @@ gaps. The one security-sensitive finding (D1) has since been fixed in #6683.
2525
| D8 | **Lookup cascade scope is existence-only server-side** — `assertReferencesResolve` accepts any EXISTING id regardless of `lookupFilters` scope (a cross-account contact that exists is accepted on direct POST). May be by-design (filters = UI courtesy) — needs a maintainer ruling: declared ≠ enforced, or documented courtesy. | packages/objectql/src/engine.ts (assertReferencesResolve) | records-forms.cascading-multilevel-and-clear (knownGap) | integrity/design — needs ruling |
2626
| D9 | **`expand` discloses a record the caller is 403'd from reading** — the `#2850` expand waiver keys on the wrong axis, so it fires for *every* referenced object including ones the caller holds no grant on. | packages/plugins/plugin-security/src/security-plugin.ts (`expandSkipCrud`) | api-backend.query-contract-matrix clause 4 | **SECURITY — write-up below (§1a)** |
2727
| D10 | **Encrypted settings are echoed in plaintext on read** — storage is correct (`sys_secret`, aes-256-gcm) but the REST read decrypts and returns the secret verbatim, and repeats it in `cascadeChain`. | packages/services/service-settings/src/{settings-service.ts,settings-routes.ts} | platform-core.settings-hub-roundtrip clause 7 | **SECURITY (admin-gated) — write-up below (§1a)** |
28-
2928
| D11 | **By-id WRITE is not gated by record visibility** — a low-privilege user PATCHes records they cannot read (404 by id, absent from list) on three objects. Two conformance rows claim this is `enforced`. | packages/plugins/plugin-security/src/security-plugin.ts (by-id write pre-image gate, `assertControlledByParentWrite`) | access-security.rls-both-sides c5 + owd-sharing-matrix c4 (one cause, two items) | **SECURITY — write-up below (§1a)** |
3029

3130
### §1a — Security-sensitive write-ups (delivered 2026-08-11, per the maintainer ruling on #7463)

0 commit comments

Comments
 (0)