Skip to content

fix(security): drop profile grants on the removed crm_competitor object - #552

Merged
yinlianghui merged 1 commit into
mainfrom
fix/dangling-competitor-grants
Jul 30, 2026
Merged

yinlianghui merged 1 commit into
mainfrom
fix/dangling-competitor-grants

Conversation

@yinlianghui

Copy link
Copy Markdown
Collaborator

Description

main is currently failing pnpm validate with four cross-reference errors — every profile that grants CRUD on crm_competitor points at an object that no longer exists:

✗ Permission 'marketing_user' grants on object 'crm_competitor' which is not defined in objects.
✗ Permission 'sales_manager' grants on object 'crm_competitor' which is not defined in objects.
✗ Permission 'sales_rep'     grants on object 'crm_competitor' which is not defined in objects.
✗ Permission 'system_admin'  grants on object 'crm_competitor' which is not defined in objects.

Reproduced on a clean checkout of main at 7f0b3ef4, so this is not specific to any open PR — but it turns every open PR's Build and Test red until it is fixed.

Root cause — a semantic conflict git could not see

Two merges disagreed on meaning while merging cleanly on text:

Time (UTC) Event
01:50 #547 opened. crm_competitor existed on its base, so granting CRUD on it was correct.
06:50 #551 merged, reverting the demo-only competitor module and removing the crm_competitor object.
07:57 #547 merged — an hour after the object was gone, still carrying the grants.

#551 touched objects, views, navigation and seed data; #547 touched src/profiles/. No file overlapped, so git had nothing to conflict on and GitHub's mergeability check — which is textual — stayed green for both. Neither PR was wrong on its own; only their merge order was.

Changes

Verification

On a clean checkout with this fix applied:

  • pnpm validate — clean: 15 Objects / 309 Fields, 6 Permissions, 12 Positions. The only remaining output is the two pre-existing campaign_enrollment flow-variable warnings, which are expected and documented as safe to ignore.
  • pnpm typecheck — clean.
  • pnpm test — 128/128 passing (11 files).

Type of Change

  • Bug fix (non-breaking change which fixes an issue)

Checklist

  • pnpm validate passes
  • pnpm typecheck passes
  • pnpm test passes
  • Changeset added

Refs #547, refs #551. No new issue filed: this is the mechanical consequence of the two merges above, not a product defect. The removed demo module itself is archived at tag demo-series-2026-07 if it is ever needed again.

main was failing `pnpm validate` with four cross-reference errors — every
profile that granted CRUD on `crm_competitor` was pointing at an object that
no longer exists.

Two merges disagreed semantically while merging cleanly on text: #547 added
competitor grants to four profiles (the object existed on its base), and
d97f3a0 removed the demo-only competitor module. Neither touched the other's
files, so git had nothing to conflict on.

The picklist field `crm_opportunity.competitors` is unrelated and stays — it
never referenced the removed object.

Verified on a clean checkout: validate clean (15 objects, 6 permissions),
typecheck clean, 128/128 tests pass.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@vercel

vercel Bot commented Jul 30, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated (UTC)
hotcrm Ignored Ignored Jul 30, 2026 8:37am

Request Review

@yinlianghui yinlianghui added bug Something isn't working configuration Build and app configuration files labels Jul 30, 2026
@yinlianghui
yinlianghui merged commit 93e4e6c into main Jul 30, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working configuration Build and app configuration files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant