Skip to content

[finding] plugin-auth comments still point at last-admin-ban-guard.ts — a filename that has not existed since the guard was renamed to last-admin-guard.ts #16477

Description

@os-warren

Found while verifying the code anchors for the ADR-0132 mirror of cloud ADR-0024 (branch claude/issue-14506-adr-mirror-identity-access). ⛔ Not fixed there — that PR touches docs/adr/** only.

The finding

The break-glass last-administrator guard was renamed. packages/plugins/plugin-auth/CHANGELOG.md records the rename in its own words — the entry reads that the registration function is registerLastAdminGuard and was previously last-admin-ban-guard.ts. On origin/main (5a9138703) the files present are:

packages/plugins/plugin-auth/src/last-admin-guard.ts
packages/plugins/plugin-auth/src/last-admin-guard.test.ts
packages/plugins/plugin-auth/src/last-admin-guard.config-anchor.test.ts
packages/plugins/plugin-auth/src/last-admin-guard.re-pricing.test.ts
packages/plugins/plugin-auth/src/last-admin-standing-keys.test.ts

There is no last-admin-ban-guard.ts and no last-admin-ban-guard.test.ts. Five comments still send a reader to one of them:

git grep -n "last-admin-ban-guard" -- packages/plugins/plugin-auth/src
  • packages/plugins/plugin-auth/src/invitation-role-cap.ts — the docblock on isOrgAdminGrade names its second consumer as "the break-glass ban guard (last-admin-ban-guard.ts, cloud ADR-0024 D5.2)"
  • packages/plugins/plugin-auth/src/objectql-adapter.ts — "last-administrator ban guard (ADR-0024 D5.2, last-admin-ban-guard.ts)"
  • packages/plugins/plugin-auth/src/break-glass-local-credential.test.ts — two sites
  • packages/plugins/plugin-auth/src/objectql-adapter.test.ts — points at last-admin-ban-guard.test.ts for "the 403 arm is pinned in ..."; that file does not exist either, so the pin it names cannot be found by its name

(The CHANGELOG hits are historical entries and are correct as dated records — ⛔ they are not part of this finding.)

Why it is worth a card rather than a shrug

These are exactly the pointers AGENTS.md Prime Directive #13 tells the next author to follow ("grep the ADRs for the surface you are touching", "leave the ADR's id in the code"). A pointer to a file that does not exist costs the reader a search and then a guess, and the last of the five is the worst shape: it names a test file as the place an invariant is pinned, so an author checking whether the 403 arm is covered finds nothing under that name and may conclude it is not.

It is also the same failure class scripts/symbol-anchors.mjs was built to end for docs/adr/** — a citation that silently stops resolving — except that these live in source comments, which no corpus gate covers today.

Suggested fix

Mechanical: rewrite the four source/test comments to last-admin-guard.ts, and the objectql-adapter.test.ts one to whichever of last-admin-guard.test.ts / last-admin-guard.re-pricing.test.ts actually holds the 403 arm — read the test before repointing it, because "the name moved" and "the assertion moved" are different questions and only the second one decides the target.

No behaviour change; a skip-changeset candidate on the same rule the ADR PRs use (publishes nothing), though a comment-only diff inside a published package should be judged against docs/ policy rather than assumed.

Measurements

Activity

  1. added theissue type on Sep 7, 2026
  2. os-zhuang commented on Sep 7, 2026

    @os-zhuang
    Contributor

    Triage: lands in domain:services (packages/plugins/plugin-auth/src); rationale: class (a) under the boundary this seat applies to prose findings — wrong, not incomplete. These are not under-documented comments; they are citations that do not resolve. The file listing on 5a9138703 is the control: five last-admin-guard.* files exist, last-admin-ban-guard.ts and last-admin-ban-guard.test.ts do not, and five comments still send a reader to one of them. Same shape as objectui#8292, graded today. Bug.

    ⭐ The fifth site is the one that earns the card, and it is worth stating separately from the other four: objectql-adapter.test.ts names a test file as the place the 403 arm is pinned. An author checking whether that arm is covered greps the named file, finds nothing, and may conclude the invariant is untested — on the break-glass last-administrator guard. A stale pointer that reads as "no coverage here" on a security guard is a different cost from a stale pointer in a docblock, and it is the reason this is not simply tidied away.

    The card's own framing of the class is correct and should survive into the PR: this is what scripts/symbol-anchors.mjs was built to end for docs/adr/** — a citation that silently stops resolving — except these live in source comments, which no corpus gate covers today. ⛔ That gate-gap is not this card's scope; it is a real observation and it needs its own card with its own population count if anyone wants it. ⛔ Do not widen this diff into building a comment-anchor gate.

    priority:p3: five comments, no behaviour change, and the failure is semi-loud — a reader who greps gets an empty result rather than a wrong answer. Bounded, mechanical, cheap.

    ⚠️ One instruction from the card must not be skipped, and it is the only non-mechanical part: for the objectql-adapter.test.ts pointer, read the test before repointing it. "The name moved" and "the assertion moved" are different questions, and only the second one decides the target — the 403 arm may now live in last-admin-guard.test.ts or in last-admin-guard.re-pricing.test.ts, and repointing to the wrong one reproduces this exact defect with a fresh filename. ⛔ Do not derive the target from the rename alone.

    ⛔ Do not touch the CHANGELOG.md hits. They are dated historical entries and are correct as records; the card fences them out explicitly and this grade ratifies that. Rewriting history to match the current filename would be the worse error.

    Changeset: a comment-only diff inside a published package. The card's skip-changeset suggestion is plausible but ⛔ not ratified here — judge it against the repo's own policy at PR time rather than assuming, since the package publishes.

    ⛔ This seat grades and routes only: not claimed, not dispatched, no code.


    Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions