Skip to content

Commit faf1d3d

Browse files
committed
fix(plugin-hono-server): drop seedEmail, update erasure ratchet baseline (#6334)
`AuthSessionApi.getSession` declares `user: { id?: string }` and nothing more, so reading `email` off it is the #4127 shape. The canonical resolver reads `sys_user.email` itself (the row it loads anyway for ai_seat), and that column is unique by the auth invariant — same answer, no contract widening. The erasure ratchet baseline drops its `current-user-endpoints.ts` entry: the 6 sites it recorded were the `as any` query options of the hand-copied table reads this PR deletes (ratchet DOWN, as the gate itself instructs). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017uFVNMmTxLpmfQYiuKM1Yx
1 parent 55d9188 commit faf1d3d

2 files changed

Lines changed: 11 additions & 5 deletions

File tree

‎packages/plugins/plugin-hono-server/src/current-user-endpoints.ts‎

Lines changed: 11 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -517,10 +517,17 @@ export function makeExecutionContextResolver(ctx: CurrentUserEndpointsContext) {
517517
// construction: a missing engine or an absent table yields an
518518
// empty-but-valid envelope rather than an exception, so no read
519519
// here needs its own guard.
520-
const grants = await resolveUserAuthzGrants(getObjectQL(), userId, {
521-
tenantId,
522-
seedEmail: session.user.email ? String(session.user.email) : undefined,
523-
});
520+
//
521+
// No `seedEmail`: that option exists for a caller holding an email
522+
// the resolver cannot read back (the API-key path, which has no
523+
// session). Here the resolver's own `sys_user` read — the row it
524+
// loads anyway for the `ai_seat` synthesis — answers it, and
525+
// `sys_user.email` is unique by the auth invariant, so the two
526+
// sources cannot disagree. `AuthSessionApi.getSession` declares
527+
// `user: { id?: string }` and nothing more; reading an undeclared
528+
// `email` off it through `any` is the #4127 shape, and widening
529+
// that contract needs a call site that actually requires it.
530+
const grants = await resolveUserAuthzGrants(getObjectQL(), userId, { tenantId });
524531
// [#2408 / #3361] Open the per-request `Server-Timing` disclosure
525532
// gate for an admin/service principal — the standalone-surface analog
526533
// of the runtime dispatcher's `timedResolveExecutionContext`. The rung

‎scripts/query-options-erasure-baseline.json‎

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -42,7 +42,6 @@
4242
"packages/plugins/plugin-approvals/src/lifecycle-hooks.ts": 4,
4343
"packages/plugins/plugin-auth/src/admin-import-users.ts": 1,
4444
"packages/plugins/plugin-auth/src/auth-manager.ts": 14,
45-
"packages/plugins/plugin-hono-server/src/current-user-endpoints.ts": 6,
4645
"packages/plugins/plugin-sharing/src/share-link-routes.ts": 3,
4746
"packages/plugins/plugin-sharing/src/share-link-service.ts": 5,
4847
"packages/plugins/plugin-webhooks/src/bootstrap-declared-webhooks.ts": 1,

0 commit comments

Comments
 (0)