You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 5297072
Browse filesBrowse the repository at this point in the historyBrowse files
Platform plumbing in these four packages now passes the explicit system opt-in (`{ isSystem: true }`) on its data-engine calls. Until now it reached the engine with no principal and no opt-in, and the security middleware let that through only because of its principal-less hand-off.
9
+
10
+
Clause-②: yes (widening)
11
+
12
+
-**Why `yes (widening)`:** two exported option types gain an optional `context` that an adapter must forward as-is. They are `SettingsEngine.find` / `.insert` (`@objectstack/service-settings`) and `SecretStoreEngineLike.delete` (`@objectstack/service-datasource`), so both packages take a `minor`. An implementation written against the old types still type-checks, and nothing accepted or refused at any door changes.
13
+
-**service-settings:**`SettingsService` reads and writes its own `sys_setting` rows under the opt-in: `loadRows`, plus the existence probe and insert in `upsertRow` (the update already used it). The `sys_setting_audit` writer does too.
14
+
-**service-datasource:** the `sys_metadata` helpers behind runtime datasources use the opt-in. They cover boot restore, cluster convergence, and persist and delete behind the admin doors. So do the `sys_secret` binder's `bind`, `unbind` and `resolve`.
15
+
-**plugin-webhooks:** the auto-enqueuer's subscription refresh and the redeliver guard's subscription lookup use the opt-in.
16
+
-**service-messaging:** two paths use the opt-in. One is the dispatcher's claim path: `claim`, `claimDigest` and the visibility-timeout reap on both outboxes. The other is the emit fan-out: the `sys_notification` row, the recipient's address and locale reads, the preference reads, the inbox row and the delivered receipt.
17
+
-**A user reference that names no user is still refused.** The engine skips its dangling-reference check for an `isSystem` write, so each producer that writes a user reference checks it first. The checked references are the `actor_id` of `sys_notification`, `sys_inbox_message` and `sys_setting_audit`, and the `user_id` of a user-scope `sys_setting` row. An unknown id is refused with the engine's own answer: `VALIDATION_FAILED`, one `reference_not_found` finding, and the same message. A write that names no user is unchanged.
18
+
- What each call reads and writes is otherwise unchanged. None of the gates the middleware runs before its hand-off applies to these objects.
19
+
- ⛔ No new export on any package entry, and no new elevation API.
Copy file name to clipboardExpand all lines: content/docs/permissions/tenant-audit-census.mdx
+19-19Lines changed: 19 additions & 19 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -122,7 +122,7 @@ are reported as `undecidable` rather than assumed either way.
122
122
123
123
The same holds twice over for the context. An options argument spelled as a
124
124
literal can be read; one spelled `options`, `{ ...opts }`, or handed through a
125
-
forwarding shim cannot, and **67 of the 233 sites are spelled that way**. A
125
+
forwarding shim cannot, and **60 of the 233 sites are spelled that way**. A
126
126
context resolved from an inline literal or a local `const` can be tested for
127
127
`isSystem`; one arriving from a helper call cannot.
128
128
@@ -150,8 +150,8 @@ now **0**: nothing on this surface threads a context that provably lacks the fla
150
150
151
151
**"No tenant context" counted sites it had not read.** An options argument the
152
152
walker could not parse was folded into the same bucket as one it had read and
153
-
found empty. That published **84 sites "carrying no tenant context at all"**
154
-
when 17 said so and 67 were simply unread — an over-claim in the *alarming*
153
+
found empty. That published **69 sites "carrying no tenant context at all"**
154
+
when 9 said so and 60 were simply unread — an over-claim in the *alarming*
155
155
direction, on the very figure this page tells other cards to cite. `carries` is
156
156
now three-valued, and an unreadable argument can never contribute to the
157
157
provable count.
@@ -188,9 +188,9 @@ reproduce them. Where it disagrees, it disagrees on the page:
188
188
| carried figure | where it survives | this census |
189
189
| :--- | :--- | ---: |
190
190
| 175 write call sites | quoted in the merged changeset |**233**|
191
-
| 24 carrying no tenant context | quoted in the merged changeset |**9** provable and tenancy-enabled; **34** more whose options argument is unreadable |
191
+
| 24 carrying no tenant context | quoted in the merged changeset |**2** provable and tenancy-enabled; **33** more whose options argument is unreadable |
192
192
| 127 of 175 statically decidable, 48 runtime-parameter-name sites | restated on the `isSystem`-scoping card |**155 of 233** decidable, **78** undecidable |
193
-
| 135 (77%) silenced by the `isSystem` guard before the posture gate | the lost issue body — **no surviving corroboration**|**not reproduced**: 114 decidably elevated, 0 decidably not, 102 undecidable |
193
+
| 135 (77%) silenced by the `isSystem` guard before the posture gate | the lost issue body — **no surviving corroboration**|**not reproduced**: 121 decidably elevated, 0 decidably not, 103 undecidable |
194
194
| 141 and 132, two independent re-derivations | the card that filed this work | — |
195
195
196
196
**The differences are not reconciled, and deliberately so.** The old census's
@@ -207,14 +207,14 @@ would report a smaller number and would not say so.
207
207
208
208
The fourth row is the one worth flagging to anyone citing it. **The 135 / 77%
209
209
figure has no surviving corroboration anywhere in the tree.** This census reads
210
-
114 of 233 (49%) as decidably elevated, with 102 more whose elevation is a
210
+
121 of 233 (52%) as decidably elevated, with 103 more whose elevation is a
211
211
run-time fact — so the claim is neither confirmed nor refuted, and the honest
212
212
answer is that a static reading cannot settle it.
213
213
214
-
⇒ **Cite `9 / 233`, and say what it is**: the sites whose options argument was
214
+
⇒ **Cite `2 / 233`, and say what it is**: the sites whose options argument was
215
215
READ and holds no tenant context, against a decidably tenancy-enabled object.
216
216
That is the control's provable yield surface. ⛔ Do not cite it as "the sites
217
-
without tenant context" — **34 further sites** have an options argument this
217
+
without tenant context" — **33 further sites** have an options argument this
218
218
cannot read, and they are neither in nor out.
219
219
220
220
{/* BEGIN GENERATED: tenant-audit-census (scripts/tenant-audit-census.mjs) — DO NOT EDIT */}
@@ -228,14 +228,14 @@ cannot read, and they are neither in nor out.
228
228
| …whose object name is chosen at run time | 78 |
229
229
| …against an object with tenancy ENABLED | 154 |
230
230
| …against an object that declares tenancy off | 1 |
231
-
| threading a tenant context |149|
232
-
| PROVABLY carrying none (options read, no context key) |**17**|
233
-
| …of those, against a decidably tenancy-enabled object |**9**|
234
-
| options argument UNREADABLE — may or may not carry one |67|
235
-
| …of those, against a decidably tenancy-enabled object |34|
236
-
| threading a decidably ELEVATED (`isSystem`) context |114|
231
+
| threading a tenant context |164|
232
+
| PROVABLY carrying none (options read, no context key) |**9**|
233
+
| …of those, against a decidably tenancy-enabled object |**2**|
234
+
| options argument UNREADABLE — may or may not carry one |60|
235
+
| …of those, against a decidably tenancy-enabled object |33|
236
+
| threading a decidably ELEVATED (`isSystem`) context |121|
237
237
| threading a context that is decidably NOT elevated | 0 |
238
-
| threading a context whose elevation is a run-time fact |102|
238
+
| threading a context whose elevation is a run-time fact |103|
239
239
240
240
| how the instrument reached the site | count |
241
241
| :--- | ---: |
@@ -297,13 +297,13 @@ holds still. They are required to be HERE and to say WHEN they were true;
297
297
their values are not compared. The reasoning, and the measurement behind it,
0 commit comments