Repository navigation
security(auth): the identity import hands runImport a protocol without getMetaItem, so its reference cells skip the target's exposure ask (census row 9 of #22661) #22800
Description
Activity
- addedbugSomething isn't workingSomething isn't workingarea:accessPermissions that actually hold — RLS/FLS, sharing model, write-path guardsPermissions that actually hold — RLS/FLS, sharing model, write-path guards
on Oct 11, 2026 objectstack-fleet commented
on Oct 11, 2026 ContributorAuthorMore actionsRelease:
session_01JfJfBUC3cQ6hhgm9MQK76T(domain:engineseat 1, #6367,os-project-manager) · 2026-10-11T14:33Z · reason: seat 1 dispatches serially, so cards whose regions do not meet its serial queue go to seat 2 to be developed in parallel · destination:domain:engineseat 2 (#20966, 🟢os-steve,session_01ADzJtzYTLUfgrRZHxkagkX), which claims it afresh at its own pick.- Whose instruction: the maintainer, who invoked this seat. Words: 「当前任务处理完,后续改为串行派发」 and 「seat 2 上线了,哪些卡他可以并行开发你和他沟通一下」. Where: this seat's session chat, 2026-10-11 (recorded on [PM seat] domain:engine — 🟢 os-project-manager #6367).
- Seat 1 never claimed this card: no
Claim:fromsession_01JfJfBUC3cQ6hhgm9MQK76Tis on it, and it carries no assignee. Its state stayspm:queue. - Serial notes for the taker: a derived sub-issue of security(data, analytics): a lookup target's exposure declaration is not judged when the data door's
$expand, or the dataset door's dimension-label pass, reads it — detail withheld pending maintainer #22661 (census row 9). The fix point is inpackages/plugins/plugin-auth(domain:services, declared on [PM seat] domain:services — 🟢 os-project-manager · session_01CBAfsWMSfM3EToQGVStEcp #6021 at dispatch). It adds row 9 topackages/core/src/security/second-object-read-exposure.pin.test.ts, the same file security(runtime):callData's engine fallback hands a caller'swheretoql.findafter judging only the addressed object, so a nested-relation condition skips the target's exposure ask (census row 10 of #22661) #22823 edits, so the two run one after the other, not side by side. - Parent: at landing, the landing record names security(data, analytics): a lookup target's exposure declaration is not judged when the data door's
$expand, or the dataset door's dimension-label pass, reads it — detail withheld pending maintainer #22661's row 9. Seat 1 ticks the parent's checklist (6102873261) and closes security(data, analytics): a lookup target's exposure declaration is not judged when the data door's$expand, or the dataset door's dimension-label pass, reads it — detail withheld pending maintainer #22661 when rows 9 and 10 have both landed.
Generated by Claude Code
objectstack-fleet commented
on Oct 11, 2026 ContributorAuthorMore actionsClaim: PM loop round 1 · 2026-10-11T14:49Z
Session:session_01ADzJtzYTLUfgrRZHxkagkX
Account:os-steve(the seat's linked user asGET /useranswers it; always the card's assignee)
Branch:claude/issue-22800-identity-import-exposure
Worktree:objectstack-issue-22800
Domain:domain:engine
Seat:domain:engine#2(seat post #20966); taken at this seat's own pick after seat 1's release 6110107168
File surface (read onorigin/maineed637c09f; stop on a breach and explain it in the report):- cross-lane
domain:services(declared on [PM seat] domain:services — 🟢 os-project-manager · session_01CBAfsWMSfM3EToQGVStEcp #6021 at this claim):packages/plugins/plugin-auth/src/admin-import-users.ts, the run protocol handed torunImportgains thegetMetaItemmemberdepsalready holds; and its tests inplugin-auth. packages/core/src/security/second-object-read-exposure.pin.test.ts: census row 9 moves from open to decided.- read only:
packages/core/src/utils/import-runner.ts(servesReferenceTarget). ⛔ No edit there. - one changeset.
Container & model:S,mode:subagent,model: default(dispatch-gates --tier: no path-derived mandate; a security judgement, so not the floor tier)
Clause-②: no - Narrowing: an identity-import reference cell whose target's declaration refuses
listanswers as a target the caller cannot read, as every otherrunImportcaller already does (security(import): an import's reference resolution matches a lookup cell against a target whose exposure refuses reads (census row 7 of #22661) #22739). It owes one contract-review-tier review before the queue.
Responsibility:plugin-auth's identity import, which builds its run protocol withoutgetMetaItem, sorunImport'sservesReferenceTargetanswers served without asking | the one exposure decisionservesReferenceTargetasks for every otherrunImportcaller (security(import): an import's reference resolution matches a lookup cell against a target whose exposure refuses reads (census row 7 of #22661) #22739, PR fix(core)!: an import's reference resolution asks the lookup target its declared exposure before matching a cell (#22739) #22770) | a platform administrator using the identity import; whether any ofsys_user's reference targets refuseslistis NOT MEASURED, and the card's first step measures it
Thread-read: 6110107168
Serial constraints cleared: security(import): an import's reference resolution matches a lookup cell against a target whose exposure refuses reads (census row 7 of #22661) #22739 (PR fix(core)!: an import's reference resolution asks the lookup target its declared exposure before matching a cell (#22739) #22770,c74d843997) landed the gate this card wires. None of the 11 open PRs touchesadmin-import-users.tsor the census pin file. security(runtime):callData's engine fallback hands a caller'swheretoql.findafter judging only the addressed object, so a nested-relation condition skips the target's exposure ask (census row 10 of #22661) #22823 (census row 10, same pin file) runs after this card, on this seat's serial line. This seat's [finding] import: a sandbox's own fault (CPU budget, wall-clock ceiling) reaches an import row as its debug wrapper, where the data doors answerInternal server error#22741 editsimport-runner.ts'stoFailedResult, which this card only reads. Epic [epic] ADR-0131 — total organization ownership: no NULL organization_id (v18 line) #15194'splugin-authterritory (catalog reads inauth-manager,ensure-default-organization,last-admin-guard,auto-org-admin-grant) does not includeadmin-import-users.ts.
- cross-lane
This card carries census row 9 of #22661 (part of #22661). It was found by the contract review of PR #22770 (6106439614, ①.7 and ③), and ruled in this seat's ACCEPT on #22739 (6106456351). ⛔ Classes, positions and functions only.
Filing class: ① a product defect, class (a). Reach: a named real producer, by source reading on
origin/mainc74d843997; not measured at the door.Reader who acts: the
domain:enginelane, seat 1 (#6367), which owns #22661's derived sub-issues. The fix lands inpackages/plugins/plugin-auth(domain:services), so the claim declares the cross-domain path.The gap
runImport'sresolveRef(packages/core/src/utils/import-runner.ts) asks a lookup target its declared exposure through the protocol's optionalgetMetaItem. A protocol without that member is not judged. That is the capability-gate shape PR fix(core)!: an import's reference resolution asks the lookup target its declared exposure before matching a cell (#22739) #22770 landed.packages/plugins/plugin-auth/src/admin-import-users.ts) builds its run protocol withoutgetMetaItem, so its reference cells are matched without the ask.deps.getMetaItemand hands it to the prepare step a few lines earlier (around:456). So "no declaration to judge" is a choice at this door, not a fact of it.$expand, or the dataset door's dimension-label pass, reads it — detail withheld pending maintainer #22661's family refused "reads run under the system identity" as an exemption at the data door.Why
p3sys_user's own reference fields' targets. Whether any of them declares an exposure that refuseslistis NOT MEASURED.p3.Direction (not a ruling)
getMetaItem(thedepsmember it already holds), soservesReferenceTargetjudges its targets like every otherrunImportcaller. ⛔ No second rule.sys_user's reference fields name, and whether any refuseslist. If none does, state the null and pin the wiring anyway, so a future refusing declaration is judged.runImportcaller without the member, rides the parent's close-out.Duplicate check
read判定:调用方读不到的那一行,要不要答得和一个不存在的 id 完全一样(#21771 裁决 A 是否延伸到 explain 的 read) #22795 (REST paging since 2026-09-01, plus recent windows). A local grep over titles and bodies.admin-import-users: 8, all closed (lint: theapproval-approvers-may-resolve-emptyremedy tells authors the admin bulk import does not writesys_user.manager_id; it has since PR #18046 #22683, [ruling row 7] the user bulk import must admitmanager_id, resolved in a second pass keyed on the importer's identity key — split from #16678 #18028, ApproverType's.describe()still offersmanagerunqualified, so the generated reference page sells a rung whose column has no product write surface #17579, [finding]admin-import-users'sfindData(args: any)annotation opts it out of theImportProtocolLikecontract #16952 just declared — the one implementor the class actually bit stays unchecked #17422, [finding]ImportProtocolLike's three methods takeargs: any, so the exported extension point never declares which query dialectrunImportsends — and an in-repo implementor froze on the undeclared one #16952, [finding] plugin-auth: 5 more first-sibling-pays dynamic imports charged to a case's own testTimeout — census attached, same shape as the durability-swallow-repair flake #15916, [finding] plugin-authdurability-swallow-repair.test.ts:673times out at 10 s on a coldTest Core (6/6)shard — a dynamic import charged to the test's own budget (red twice on PR #15791, green on main) #15852, [finding] plugin-authdurability-swallow-repair.test.ts:673times out at 10000 ms on the PR-CI Test Core (6/6) shard — three unrelated PRs red on it in one hour while merge-group runs of the same shard passed #15603).plugin-authand exposure orapiEnabled: 3. Two are closed (QA run · surface:api (89/89) · 251a7dd4 · 2026-10-04 · 68 PASS / 7 PARTIAL / 14 FAIL / 0 BLOCKED / 0 NOT-RUN #21720, [finding] packages/core/PHASE2_IMPLEMENTATION.md's fenced TypeScript blocks are in no tsc program — a block that has NEVER compiled survived two sweeps, and the gate #15931 proposed would not have caught it #18715), and the third is thedomain:cliseat post.plugin-auth187.Generated by Claude Code