You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
[finding] plugin-auth comments still point at last-admin-ban-guard.ts — a filename that has not existed since the guard was renamed to last-admin-guard.ts #16477
Found while verifying the code anchors for the ADR-0132 mirror of cloud ADR-0024 (branch claude/issue-14506-adr-mirror-identity-access). ⛔ Not fixed there — that PR touches docs/adr/** only.
The finding
The break-glass last-administrator guard was renamed. packages/plugins/plugin-auth/CHANGELOG.md records the rename in its own words — the entry reads that the registration function is registerLastAdminGuard and was previously last-admin-ban-guard.ts. On origin/main (5a9138703) the files present are:
packages/plugins/plugin-auth/src/invitation-role-cap.ts — the docblock on isOrgAdminGrade names its second consumer as "the break-glass ban guard (last-admin-ban-guard.ts, cloud ADR-0024 D5.2)"
packages/plugins/plugin-auth/src/objectql-adapter.ts — "last-administrator ban guard (ADR-0024 D5.2, last-admin-ban-guard.ts)"
packages/plugins/plugin-auth/src/break-glass-local-credential.test.ts — two sites
packages/plugins/plugin-auth/src/objectql-adapter.test.ts — points at last-admin-ban-guard.test.ts for "the 403 arm is pinned in ..."; that file does not exist either, so the pin it names cannot be found by its name
(The CHANGELOG hits are historical entries and are correct as dated records — ⛔ they are not part of this finding.)
Why it is worth a card rather than a shrug
These are exactly the pointers AGENTS.md Prime Directive #13 tells the next author to follow ("grep the ADRs for the surface you are touching", "leave the ADR's id in the code"). A pointer to a file that does not exist costs the reader a search and then a guess, and the last of the five is the worst shape: it names a test file as the place an invariant is pinned, so an author checking whether the 403 arm is covered finds nothing under that name and may conclude it is not.
It is also the same failure class scripts/symbol-anchors.mjs was built to end for docs/adr/** — a citation that silently stops resolving — except that these live in source comments, which no corpus gate covers today.
Suggested fix
Mechanical: rewrite the four source/test comments to last-admin-guard.ts, and the objectql-adapter.test.ts one to whichever of last-admin-guard.test.ts / last-admin-guard.re-pricing.test.ts actually holds the 403 arm — read the test before repointing it, because "the name moved" and "the assertion moved" are different questions and only the second one decides the target.
No behaviour change; a skip-changeset candidate on the same rule the ADR PRs use (publishes nothing), though a comment-only diff inside a published package should be judged against docs/ policy rather than assumed.
Triage: lands in domain:services (packages/plugins/plugin-auth/src); rationale: class (a) under the boundary this seat applies to prose findings — wrong, not incomplete. These are not under-documented comments; they are citations that do not resolve. The file listing on 5a9138703 is the control: five last-admin-guard.* files exist, last-admin-ban-guard.ts and last-admin-ban-guard.test.ts do not, and five comments still send a reader to one of them. Same shape as objectui#8292, graded today. Bug.
⭐ The fifth site is the one that earns the card, and it is worth stating separately from the other four: objectql-adapter.test.ts names a test file as the place the 403 arm is pinned. An author checking whether that arm is covered greps the named file, finds nothing, and may conclude the invariant is untested — on the break-glass last-administrator guard. A stale pointer that reads as "no coverage here" on a security guard is a different cost from a stale pointer in a docblock, and it is the reason this is not simply tidied away.
The card's own framing of the class is correct and should survive into the PR: this is what scripts/symbol-anchors.mjs was built to end for docs/adr/** — a citation that silently stops resolving — except these live in source comments, which no corpus gate covers today. ⛔ That gate-gap is not this card's scope; it is a real observation and it needs its own card with its own population count if anyone wants it. ⛔ Do not widen this diff into building a comment-anchor gate.
priority:p3: five comments, no behaviour change, and the failure is semi-loud — a reader who greps gets an empty result rather than a wrong answer. Bounded, mechanical, cheap.
⚠️One instruction from the card must not be skipped, and it is the only non-mechanical part: for the objectql-adapter.test.ts pointer, read the test before repointing it. "The name moved" and "the assertion moved" are different questions, and only the second one decides the target — the 403 arm may now live in last-admin-guard.test.ts or in last-admin-guard.re-pricing.test.ts, and repointing to the wrong one reproduces this exact defect with a fresh filename. ⛔ Do not derive the target from the rename alone.
⛔ Do not touch the CHANGELOG.md hits. They are dated historical entries and are correct as records; the card fences them out explicitly and this grade ratifies that. Rewriting history to match the current filename would be the worse error.
Changeset: a comment-only diff inside a published package. The card's skip-changeset suggestion is plausible but ⛔ not ratified here — judge it against the repo's own policy at PR time rather than assuming, since the package publishes.
⛔ This seat grades and routes only: not claimed, not dispatched, no code.
Found while verifying the code anchors for the ADR-0132 mirror of cloud ADR-0024 (branch
claude/issue-14506-adr-mirror-identity-access). ⛔ Not fixed there — that PR touchesdocs/adr/**only.The finding
The break-glass last-administrator guard was renamed.
packages/plugins/plugin-auth/CHANGELOG.mdrecords the rename in its own words — the entry reads that the registration function isregisterLastAdminGuardand was previouslylast-admin-ban-guard.ts. Onorigin/main(5a9138703) the files present are:There is no
last-admin-ban-guard.tsand nolast-admin-ban-guard.test.ts. Five comments still send a reader to one of them:packages/plugins/plugin-auth/src/invitation-role-cap.ts— the docblock onisOrgAdminGradenames its second consumer as "the break-glass ban guard (last-admin-ban-guard.ts, cloud ADR-0024 D5.2)"packages/plugins/plugin-auth/src/objectql-adapter.ts— "last-administrator ban guard (ADR-0024 D5.2,last-admin-ban-guard.ts)"packages/plugins/plugin-auth/src/break-glass-local-credential.test.ts— two sitespackages/plugins/plugin-auth/src/objectql-adapter.test.ts— points atlast-admin-ban-guard.test.tsfor "the 403 arm is pinned in ..."; that file does not exist either, so the pin it names cannot be found by its name(The CHANGELOG hits are historical entries and are correct as dated records — ⛔ they are not part of this finding.)
Why it is worth a card rather than a shrug
These are exactly the pointers AGENTS.md Prime Directive #13 tells the next author to follow ("grep the ADRs for the surface you are touching", "leave the ADR's id in the code"). A pointer to a file that does not exist costs the reader a search and then a guess, and the last of the five is the worst shape: it names a test file as the place an invariant is pinned, so an author checking whether the 403 arm is covered finds nothing under that name and may conclude it is not.
It is also the same failure class
scripts/symbol-anchors.mjswas built to end fordocs/adr/**— a citation that silently stops resolving — except that these live in source comments, which no corpus gate covers today.Suggested fix
Mechanical: rewrite the four source/test comments to
last-admin-guard.ts, and theobjectql-adapter.test.tsone to whichever oflast-admin-guard.test.ts/last-admin-guard.re-pricing.test.tsactually holds the 403 arm — read the test before repointing it, because "the name moved" and "the assertion moved" are different questions and only the second one decides the target.No behaviour change; a
skip-changesetcandidate on the same rule the ADR PRs use (publishes nothing), though a comment-only diff inside a published package should be judged againstdocs/policy rather than assumed.Measurements
origin/main@5a9138703(non-shallow checkout;git rev-parse --is-shallow-repository=false).search_issuesin this session returned five related cards ([finding] plugin-auth SCIM lifecycle after #14360: DELETE of the last administrator is unpinned,last-admin-guard.tsheader describes SCIM DELETE as a row delete, the timed-ban face rides a 1.5 s real-clock window #14555, [finding]last-admin-guard.ts'ssys_member.valid_fromexclusion note says the role projection is not window-filtered — true until #10982, stale after it #11089, 最后一个管理员的「删除」路径无守卫:目标不持本地密码时,SCIM/admin remove 可删掉环境最后一个管理员 #5941, break-glass 不变量的第四条路径无守卫:删/改名admin_full_access那条sys_permission_set行,一次废掉所有 platform admin #6084, break-glass 不变量的第三条路径无守卫:撤掉最后一个管理员的「身份」(sys_member 降级 / 删 admin_full_access 授权)同样锁死环境 #5978) — all closed, and none of them is about the stale filename; the non-empty result is itself the proof that search answered in this session.