Conversation
Contributor
Reviewer's GuideConsolidates all transitional organization-scoped legacy-or-grant authorization behind File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
vecchp
force-pushed
the
perm/grant-members-dual
branch
from
September 2, 2026 16:21
922651f to
927dcce
Compare
vecchp
force-pushed
the
perm/perm-single-seam
branch
from
September 2, 2026 16:26
14b5e69 to
96351b9
Compare
vecchp
force-pushed
the
perm/grant-members-dual
branch
from
September 2, 2026 16:32
927dcce to
250ce68
Compare
vecchp
force-pushed
the
perm/perm-single-seam
branch
from
September 2, 2026 16:32
96351b9 to
4864f7e
Compare
vecchp
force-pushed
the
perm/grant-members-dual
branch
from
September 2, 2026 18:46
250ce68 to
86cdc2c
Compare
vecchp
force-pushed
the
perm/perm-single-seam
branch
from
September 2, 2026 18:46
4864f7e to
872841c
Compare
vecchp
pushed a commit
that referenced
this pull request
Sep 2, 2026
…eferrals) + refresh merge guide RFC 0003 designs the §5 cutover shape for the last legacy org-scoped template (CASEWORKER): guardian-at-creation rows are rule-4 violations; the target is org-role CHANGE/DELETE org-scoped (can_obj, never read-side visible) with shared/foreign rows per-record via the object arm, then guardian teardown after parity tests. Option A recommended; sub-decisions (whitelist entries, sharing edges, referral own_org_or, sibling rows, teardown order) are left to the cutover PRs, mirroring RFC 0002's structure. Merge guide rewritten for the real stack: audit fix links folded/deleted (#2421-#2424), single-seam #2433, provisioning #2434, and the remaining post-stack work.
vecchp
force-pushed
the
perm/grant-members-dual
branch
from
September 2, 2026 18:55
86cdc2c to
e0b6a76
Compare
vecchp
force-pushed
the
perm/perm-single-seam
branch
from
September 2, 2026 18:55
872841c to
8a94e7f
Compare
vecchp
pushed a commit
that referenced
this pull request
Sep 2, 2026
…eferrals) + refresh merge guide RFC 0003 designs the §5 cutover shape for the last legacy org-scoped template (CASEWORKER): guardian-at-creation rows are rule-4 violations; the target is org-role CHANGE/DELETE org-scoped (can_obj, never read-side visible) with shared/foreign rows per-record via the object arm, then guardian teardown after parity tests. Option A recommended; sub-decisions (whitelist entries, sharing edges, referral own_org_or, sibling rows, teardown order) are left to the cutover PRs, mirroring RFC 0002's structure. Merge guide rewritten for the real stack: audit fix links folded/deleted (#2421-#2424), single-seam #2433, provisioning #2434, and the remaining post-stack work.
vecchp
force-pushed
the
perm/grant-members-dual
branch
from
September 2, 2026 19:03
e0b6a76 to
797a71e
Compare
vecchp
force-pushed
the
perm/perm-single-seam
branch
from
September 2, 2026 19:03
8a94e7f to
f631590
Compare
vecchp
pushed a commit
that referenced
this pull request
Sep 2, 2026
…eferrals) + refresh merge guide RFC 0003 designs the §5 cutover shape for the last legacy org-scoped template (CASEWORKER): guardian-at-creation rows are rule-4 violations; the target is org-role CHANGE/DELETE org-scoped (can_obj, never read-side visible) with shared/foreign rows per-record via the object arm, then guardian teardown after parity tests. Option A recommended; sub-decisions (whitelist entries, sharing edges, referral own_org_or, sibling rows, teardown order) are left to the cutover PRs, mirroring RFC 0002's structure. Merge guide rewritten for the real stack: audit fix links folded/deleted (#2421-#2424), single-seam #2433, provisioning #2434, and the remaining post-stack work.
vecchp
force-pushed
the
perm/grant-members-dual
branch
from
September 2, 2026 19:10
797a71e to
de505f4
Compare
vecchp
force-pushed
the
perm/perm-single-seam
branch
from
September 2, 2026 19:10
f631590 to
85d69d4
Compare
vecchp
pushed a commit
that referenced
this pull request
Sep 2, 2026
…eferrals) + refresh merge guide RFC 0003 designs the §5 cutover shape for the last legacy org-scoped template (CASEWORKER): guardian-at-creation rows are rule-4 violations; the target is org-role CHANGE/DELETE org-scoped (can_obj, never read-side visible) with shared/foreign rows per-record via the object arm, then guardian teardown after parity tests. Option A recommended; sub-decisions (whitelist entries, sharing edges, referral own_org_or, sibling rows, teardown order) are left to the cutover PRs, mirroring RFC 0002's structure. Merge guide rewritten for the real stack: audit fix links folded/deleted (#2421-#2424), single-seam #2433, provisioning #2434, and the remaining post-stack work.
vecchp
force-pushed
the
perm/grant-members-dual
branch
from
September 2, 2026 19:25
de505f4 to
9aec14a
Compare
vecchp
force-pushed
the
perm/perm-single-seam
branch
from
September 2, 2026 19:25
85d69d4 to
e8f2d3b
Compare
vecchp
pushed a commit
that referenced
this pull request
Sep 2, 2026
…eferrals) + refresh merge guide RFC 0003 designs the §5 cutover shape for the last legacy org-scoped template (CASEWORKER): guardian-at-creation rows are rule-4 violations; the target is org-role CHANGE/DELETE org-scoped (can_obj, never read-side visible) with shared/foreign rows per-record via the object arm, then guardian teardown after parity tests. Option A recommended; sub-decisions (whitelist entries, sharing edges, referral own_org_or, sibling rows, teardown order) are left to the cutover PRs, mirroring RFC 0002's structure. Merge guide rewritten for the real stack: audit fix links folded/deleted (#2421-#2424), single-seam #2433, provisioning #2434, and the remaining post-stack work.
vecchp
force-pushed
the
perm/grant-members-dual
branch
from
September 8, 2026 15:30
9aec14a to
29f27bc
Compare
The audit's structural finding: the dual read was one adapter per consumer (HasOrgPermOrGrant, HasPermOrGrant, report_org_for_user, get_user_permitted_org_dual), each re-deriving 'legacy OR grant' with no shared seam — which is how C-0/C-8 class misses happened (consumers the sweep forgot). This collapses them: - common/permissions/selectors.py: permitted_org(user, perm, *, org_id) — the ONE org-scoped seam. Legacy arm = permissioned_queryset (single-join EXISTS) .first(), one query on the common path; grant arm = can() (can() never implies existence, so the org is re-fetched). has_authority_anywhere = has_perm OR can_anywhere for the member queries' global tier. - accounts/extensions.py: HasOrgPerm IS the dual extension now (delegates to permitted_org); HasOrgPermOrGrant deleted. Schema directives revert from @hasOrgPermOrGrant back to @hasOrgPerm (less FE churn). HasPermOrGrant's checker delegates to has_authority_anywhere. - reports/permissions.py + accounts/permissions.py: the two org-fetching helpers delegate to permitted_org. Role-backing a template no longer must coincide with cutting every consumer over: every consumer shares the seam, and the legacy arm is deleted from permitted_org once at phase 5. The predicate's read path stays pure-grant (scopes/visible/can unchanged); only this transitional org-scoped check is dual. schema.graphql regenerated. 1131 affected-apps passed; ruff + mypy strict clean. Member-query pinned query counts preserved (permitted_org keeps the legacy path to a single .first()).
vecchp
force-pushed
the
perm/perm-single-seam
branch
from
September 8, 2026 15:33
e8f2d3b to
2b3d34c
Compare
vecchp
pushed a commit
that referenced
this pull request
Sep 8, 2026
…eferrals) + refresh merge guide RFC 0003 designs the §5 cutover shape for the last legacy org-scoped template (CASEWORKER): guardian-at-creation rows are rule-4 violations; the target is org-role CHANGE/DELETE org-scoped (can_obj, never read-side visible) with shared/foreign rows per-record via the object arm, then guardian teardown after parity tests. Option A recommended; sub-decisions (whitelist entries, sharing edges, referral own_org_or, sibling rows, teardown order) are left to the cutover PRs, mirroring RFC 0002's structure. Merge guide rewritten for the real stack: audit fix links folded/deleted (#2421-#2424), single-seam #2433, provisioning #2434, and the remaining post-stack work.
Contributor
Author
|
Closing: refactor of the |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What & why
The audit's structural finding (D-1 / the "cleaner design"): the dual read was one
adapter per consumer (
HasOrgPermOrGrant,HasPermOrGrant,report_org_for_user,get_user_permitted_org_dual), each re-deriving "legacy ORgrant" — which is exactly how the C-0/C-8-class misses happened (the sweep forgot a
consumer). This collapses them into one seam:
common/permissions/selectors.py—permitted_org(user, perm, *, org_id):the single org-scoped transition seam. Legacy arm =
permissioned_queryset(single-join EXISTS)
.first()— one query on the common path (pinned member-querycounts preserved); grant arm =
can()(can()never implies existence, so the orgis re-fetched by pk). Plus
has_authority_anywhere(has_permORcan_anywhere)for the member queries' global tier.
accounts/extensions.py—HasOrgPermis the dual extension now(delegates to
permitted_org);HasOrgPermOrGrantis deleted. Schema directivesrevert from
@hasOrgPermOrGrantback to@hasOrgPerm(less FE/codegen churnat every future slice).
HasPermOrGrant's checker delegates tohas_authority_anywhere.reports/permissions.py/accounts/permissions.py—report_org_for_userand
get_user_permitted_org_dualdelegate topermitted_org.Role-backing a template no longer has to coincide with cutting every consumer over —
every consumer reads the seam, so a domain can land independently, and the legacy
arm is deleted once, from
permitted_org, at phase 5. The read predicate(
scopes/visible/can) stays pure-grant; only this transitional org-scoped checkis dual.
Changes
common/permissions/selectors.py—permitted_org+has_authority_anywhereaccounts/extensions.py—HasOrgPermdual; deleteHasOrgPermOrGrantaccounts/permissions.py,reports/permissions.py— delegate to the seamteams/schema.py,reports/schema.py,accounts/schema.py—@hasOrgPermschema.graphql— regeneratedVerification
Summary by Sourcery
Centralize the §5.3 dual-read authorization logic so all organization-scoped consumers transition consistently from legacy permissions to grants.
Enhancements:
@hasOrgPermschema directive.Chores: