Low priority. An edge carries only two task uuids and a link type, no titles or content.
What happens
Any signed-in user can list every task dependency edge in the instance through OpenRegister's objects API. That includes edges between tasks in projects the user is not a member of. Every other project-scoped schema (task, column, projectPhase, plannedTimeEntry) limits reads to project members.
Why
Read at development 6fa5ef5.
lib/Settings/planninq_register.json:1119 sets dependency.authorization.read to {"group": "authenticated"} with no match clause.
- Compare
task at :51, which matches project against projects whose members contain $userId.
- The
dependency schema has no project property, so the task pattern cannot be copied as is.
- Writes are fine.
create, update and delete are admin only in the schema, and lib/Service/DependencyService.php:112 checks project membership before it writes.
Fix direction
- Add a
project property to dependency. DependencyService::create() already resolves the shared project id, so it can store it.
- Scope
read with the same $lookup on project membership that task uses.
- Back-fill
project on existing edges in a repair step.
Live check
- As user A, create an edge between two tasks in a project that user B is not a member of.
- As B, call
GET /apps/openregister/api/objects/planninq/dependency. Expected today: A's edge is listed.
Matrix rows
plt-rbac in openspec/parity/capabilities.json (PR #645). The row names OpenRegister as owner because it enforces the rule, but the rule itself lives in this repo.
Related: #250 (security backlog).
Low priority. An edge carries only two task uuids and a link type, no titles or content.
What happens
Any signed-in user can list every task dependency edge in the instance through OpenRegister's objects API. That includes edges between tasks in projects the user is not a member of. Every other project-scoped schema (task, column, projectPhase, plannedTimeEntry) limits reads to project members.
Why
Read at development 6fa5ef5.
lib/Settings/planninq_register.json:1119setsdependency.authorization.readto{"group": "authenticated"}with nomatchclause.taskat:51, which matchesprojectagainst projects whosememberscontain$userId.dependencyschema has noprojectproperty, so the task pattern cannot be copied as is.create,updateanddeleteareadminonly in the schema, andlib/Service/DependencyService.php:112checks project membership before it writes.Fix direction
projectproperty todependency.DependencyService::create()already resolves the shared project id, so it can store it.readwith the same$lookupon project membership thattaskuses.projecton existing edges in a repair step.Live check
GET /apps/openregister/api/objects/planninq/dependency. Expected today: A's edge is listed.Matrix rows
plt-rbacinopenspec/parity/capabilities.json(PR #645). The row names OpenRegister as owner because it enforces the rule, but the rule itself lives in this repo.Related: #250 (security backlog).