You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit e9e24aa
Browse filesBrowse the repository at this point in the historyBrowse files
docs(qa): deliver the two security-sensitive write-ups (D9, D10) per the #7463 ruling
The maintainer ruling on #7463 (2026-08-11) formally requested the private
write-up of the cross-persona data-disclosure finding, on the D1 precedent.
Delivered here as D9, together with D10 from the platform-core run (#7514),
which was held back for the same reason.
D9 expand bypasses the CRUD gate and the OWD scope on the sub-read — a
contributor reads a contact they are 403'd from reading directly, byte
-identical to the admin's response. The #2850 waiver keys on access.default
while objects declare sharingModel, and access is null for every object in
the built artifact, so the waiver fires for every referenced object. The
unit pin asserts only the re-entry tag, never the authorization outcome.
D10 encrypted settings are echoed in plaintext by the namespace read. Storage
is correct (sys_secret, aes-256-gcm); the REST read decrypts and repeats
the secret in cascadeChain. Admin-gated, so defense-in-depth not escalation.
Each carries impact, a 2/2 reproduction, the located root cause, why the
existing pin stayed green, and a non-prescriptive fix shape.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YD9f6FYyMraUWYeJf53V43
Copy file name to clipboardExpand all lines: docs/qa/platform-checklist/FOLLOW-UPS.md
+73Lines changed: 73 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -23,6 +23,79 @@ gaps. The one security-sensitive finding (D1) has since been fixed in #6683.
23
23
| D6 |**`/api/v1/datasources` admin CRUD has no route ledger** — mounted by serve.ts, absent from rest-route-ledger.ts (tranche-3 discipline gap). | packages/services/service-datasource/src/admin-routes.ts | integration-system.datasource-admin-lifecycle (source note) | low — internal discipline |
24
24
| D7 |**Parent-only PATCH does not revalidate a stale dependent child** — `evaluateOptionVisibility` skips fields absent from the payload, so changing only the parent leaves a now-invalid child value in place server-side; integrity rests entirely on the client clear. | packages/objectql/src/validation/rule-validator.ts (`!(name in data) continue`) | records-forms.cascading-multilevel-and-clear (knownGap) | integrity — safe to file |
25
25
| D8 |**Lookup cascade scope is existence-only server-side** — `assertReferencesResolve` accepts any EXISTING id regardless of `lookupFilters` scope (a cross-account contact that exists is accepted on direct POST). May be by-design (filters = UI courtesy) — needs a maintainer ruling: declared ≠ enforced, or documented courtesy. | packages/objectql/src/engine.ts (assertReferencesResolve) | records-forms.cascading-multilevel-and-clear (knownGap) | integrity/design — needs ruling |
26
+
| D9 |**`expand` discloses a record the caller is 403'd from reading** — the `#2850` expand waiver keys on the wrong axis, so it fires for *every* referenced object including ones the caller holds no grant on. | packages/plugins/plugin-security/src/security-plugin.ts (`expandSkipCrud`) | api-backend.query-contract-matrix clause 4 |**SECURITY — write-up below (§1a)**|
27
+
| D10 |**Encrypted settings are echoed in plaintext on read** — storage is correct (`sys_secret`, aes-256-gcm) but the REST read decrypts and returns the secret verbatim, and repeats it in `cascadeChain`. | packages/services/service-settings/src/{settings-service.ts,settings-routes.ts} | platform-core.settings-hub-roundtrip clause 7 |**SECURITY (admin-gated) — write-up below (§1a)**|
28
+
29
+
### §1a — Security-sensitive write-ups (delivered 2026-08-11, per the maintainer ruling on #7463)
30
+
31
+
Held out of the public run cards (#7463, #7514) pending a disclosure decision, and delivered
32
+
here on the D1 precedent. Both were found by real runs against a live server; neither is
33
+
reachable from a unit test, which is why both pins stayed green.
34
+
35
+
#### D9 — `expand` bypasses the CRUD gate and the OWD scope on the sub-read
36
+
37
+
**Impact.** A low-privilege authenticated user reads records they are explicitly denied.
38
+
Not an admin-only weakness: the probing persona held only the `contributor` position.
39
+
40
+
**Reproduction (2/2).** As a user holding only `contributor`:
0 commit comments