Repository navigation
Commit 8767201
committed
fix(plugin-security)!: a caller who resolves no permission set is not served a capability-gated field
The zero-set stand-in (`resolveCallerPosture`) now carries the posture's
per-field capability contract, beside the masking rules it carries since
the zero-set masking fix. Every reader takes the fold it already takes
(`foldFieldRequiredPermissions`), so for a non-system caller who
resolves no permission set a field that declares `requiredPermissions`
is not served, not queryable and refused in a write payload, as it
declares. The explain engine already reported it hidden; the record
doors now agree.
The step 2.5 field write gate is no longer gated on a resolved set, as
2.5a and 2.5b are not; its verdict is one helper
(`computeForbiddenFieldWrites`) read by the middleware and by
`canWriteObject`, whose zero-set arm now asks it for a caller carrying a
principal. `getWritableFields` stays its complement.
The object's own capability contract is not carried: this caller's
object admission is unchanged. Every caller who resolves a set reads the
posture as before.
Claude-Session: https://claude.ai/code/session_017VaLJnYwhPsanVCe9dMCJU
Co-authored-by: Claude <noreply@anthropic.com>1 parent d49cc26 commit 8767201
2 files changed
Lines changed: 148 additions & 91 deletions
Lines changed: 7 additions & 3 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
158 | 158 | | |
159 | 159 | | |
160 | 160 | | |
161 | | - | |
162 | | - | |
163 | | - | |
| 161 | + | |
| 162 | + | |
| 163 | + | |
| 164 | + | |
| 165 | + | |
| 166 | + | |
| 167 | + | |
164 | 168 | | |
165 | 169 | | |
166 | 170 | | |
| |||
0 commit comments