Skip to content

[P0][security] Role parent dead — manager-rollup unimplemented #1886

Description

@os-zhuang

Part of the metadata liveness audit umbrella #1878 (P0 security cluster).

Problem

Role parent is dead. team-graph.ts:27 does not walk it, so the documented "managers see subordinates' data" rollup is unimplemented. A role hierarchy authored via parent confers no inherited visibility — managers do not actually gain access to their reports' records.

Decision required (enforce or remove)

  • Enforce: have the team/role graph walk parent so the manager-rollup (and any role_and_subordinates sharing recipient — see the SharingRule issue) resolves through the hierarchy.
  • Remove: drop parent from RoleSchema if hierarchical visibility is out of scope, and remove the "managers see subordinates" claim from the docs.

Evidence

  • docs/audits/2026-06-security-identity-property-liveness.md
  • team-graph.ts:27 (does not walk parent)

Note: closely related to the SharingRuleSchema issue (its role_and_subordinates recipient depends on this hierarchy walk).

Activity

  1. os-zhuang commented on Jun 27, 2026

    @os-zhuang
    ContributorAuthor

    Triage (2026-06-27, for 11.0 epic #2364): enforcement STILL-DEAD (authoring-live only). role.parent is shown in RolePreview but plugin-sharing/team-graph.ts expandRoleUsers explicitly does NOT walk a hierarchy; org rollup uses sys_business_unit.parent_department_id. 11.0 action: implement manager-rollup walk or remove role.parent (breaking) and point at the BU hierarchy.

  2. os-zhuang commented on Jun 27, 2026

    @os-zhuang
    ContributorAuthor

    11.0 resolution: REMOVE THE FEATURE (owner decision) — part of the breaking-change batch (#2364, ADR-0049). Hierarchy is delegated to sys_business_unit (ADR-0057); manager-rollup is not implemented.

    Cascade (removes a feature, supersedes ADR-0056 D6):

    • Remove parent from the role schema (spec/src/identity/role.zod.ts) + role.form.ts
    • plugin-sharing: gut RoleGraphService (no sys_role.parent to walk — childRoles() → []/deprecated) ; role_and_subordinates sharing recipient degrades to plain role — update sys-sharing-rule.object.ts description
    • Delete/rewrite plugin-sharing/src/role-graph.test.ts + the hierarchy cases in role.test.ts
    • Update packages/spec/liveness/role.json (drop parent)
    • gen:api-surface + major changeset; changelog note (ADR-0056 D6 superseded)
    • Cross-repo follow-up (separate): objectui RolePreview.tsx reads d.parent — must drop it there too

    Risk: medium-high (feature removal across spec + plugin-sharing + tests + an ADR).

  3. os-zhuang commented on Jun 27, 2026

    @os-zhuang
    ContributorAuthor

    Resolved-pending-confirmation — assessment in cloud#645. The premise here is stale: role.parent is not dead — it powers the open, explicit role_and_subordinates sharing recipient (RoleGraphService in plugin-sharing; used by examples + dogfood). The automatic "superior sees subordinate" permission rollup is a separate, enterprise feature, already implemented & enforced in cloud @objectstack/security-enterprise (HierarchyScopeResolver: own_and_reports via sys_user.manager_id, unit/unit_and_below via BU tree; license-gated; e2e-tested) — per cloud ADR-0016 (强制免费, 治理收费). It rolls up by manager-chain / BU, not role.parent (by design).

    So: keep role.parent (open, explicit sharing); the auto-rollup is paid via manager/BU. Recommend closing this as resolved-per-ADR-0016 once the boundary is confirmed in cloud#645. Optional: a one-line docs note clarifying "manager sees reports" = enterprise own_and_reports (or an explicit role_and_subordinates rule), not an automatic role grant.

  4. os-zhuang commented on Jun 27, 2026

    @os-zhuang
    ContributorAuthor

    Closing as resolved per cloud ADR-0016 (assessment: cloud#645).

    Decision: keep role.parent — it's live in the open edition via the explicit role_and_subordinates sharing recipient. The "superior auto-sees subordinates" permission rollup is the enterprise feature, already implemented & enforced in @objectstack/security-enterprise (own_and_reports via manager-chain + unit_and_below via BU tree), license-gated. Enforce-or-remove → enforced (enterprise) + role path stays open-explicit. No open-framework change needed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    priority:p0Critical: blocker, must ship before MVPsecurity

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions