Repository navigation
Commit 7797102
feat(platform-objects): sys_organization's data door admits update, column-gated by the ADR-0092 D2 whitelist (#16687)
* feat(platform-objects): admit update on sys_organization's data door, column-gated by the ADR-0092 D2 whitelist (#15873)
Ruling (a), decision batch #64, 2026-09-07 — the data door admits `update`
and the identity write guard's per-object whitelist does the column gating.
`enable.apiMethods` becomes ['get', 'list', 'update'] with the
`userActions.edit` affordance the registry reconciler requires; better-auth's
own columns (name / slug / logo / metadata) are readonly per ADR-0092 D4 and
stay refused/stripped by the guard. create / delete still 405; no bulk
(recorded in SINGLE_RECORD_WRITE_ONLY).
Pins: declaration (platform-objects), column gate + D4 partition derived from
the shipped whitelist (plugin-auth), and the real door with the 405 → 403
transition (dogfood).
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ADLdAs2pVcH17h9tZKWMBg
* test(dogfood): mint the door test's organization through better-auth under the walled posture
The plain showcase boot holds no sys_organization row (system-context read
returns []; the admin session has activeOrganizationId null), and
organization/create is denied without an organization wall (#5261) — so the
fixture boots multiTenant: 'posture-only' and creates the org the way the
Setup app does.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ADLdAs2pVcH17h9tZKWMBg
* test(dogfood),spec,changeset: name the two derived surfaces the update grant moves (#15873 contract-review patch round)
Review FAIL was on the accept-set statement, not the code: granting `update`
also derives the update-mode import door (API_METHOD_DERIVATION: import =
any of create/update) and flips /auth/me/permissions for sys_organization
(allowEdit true, apiOperations gains update and import). Both named in the
changeset; pinned on the real door in the dogfood file (import: 200, timezone
lands, name stripped; better-auth-only row refused per row; insert mode 405
naming create; /me/permissions allowEdit true with update+import and a
sibling better-auth table as the clamp control); the SINGLE_RECORD_WRITE_ONLY
sentence now says what is true (bulk not granted; the derived import door
is, column-clamped per row).
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ADLdAs2pVcH17h9tZKWMBg
---------
Co-authored-by: Claude <noreply@anthropic.com>1 parent ba5284e commit 7797102
6 files changed
Lines changed: 724 additions & 5 deletions
File tree
- .changeset
- packages
- platform-objects/src/identity
- plugins/plugin-auth/src
- qa/dogfood/test
- spec/src/data
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
Lines changed: 91 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
Lines changed: 62 additions & 5 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
17 | 17 | | |
18 | 18 | | |
19 | 19 | | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
20 | 41 | | |
21 | 42 | | |
22 | 43 | | |
| |||
31 | 52 | | |
32 | 53 | | |
33 | 54 | | |
34 | | - | |
35 | | - | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
36 | 61 | | |
37 | 62 | | |
38 | 63 | | |
| |||
176 | 201 | | |
177 | 202 | | |
178 | 203 | | |
| 204 | + | |
| 205 | + | |
| 206 | + | |
| 207 | + | |
| 208 | + | |
| 209 | + | |
| 210 | + | |
| 211 | + | |
| 212 | + | |
| 213 | + | |
| 214 | + | |
| 215 | + | |
179 | 216 | | |
180 | 217 | | |
181 | 218 | | |
| 219 | + | |
182 | 220 | | |
183 | 221 | | |
184 | 222 | | |
| |||
187 | 225 | | |
188 | 226 | | |
189 | 227 | | |
| 228 | + | |
190 | 229 | | |
191 | 230 | | |
192 | 231 | | |
| |||
197 | 236 | | |
198 | 237 | | |
199 | 238 | | |
| 239 | + | |
200 | 240 | | |
201 | 241 | | |
202 | 242 | | |
203 | 243 | | |
| 244 | + | |
| 245 | + | |
204 | 246 | | |
205 | 247 | | |
206 | 248 | | |
| 249 | + | |
207 | 250 | | |
208 | 251 | | |
209 | 252 | | |
| |||
333 | 376 | | |
334 | 377 | | |
335 | 378 | | |
336 | | - | |
337 | | - | |
338 | | - | |
| 379 | + | |
| 380 | + | |
| 381 | + | |
| 382 | + | |
| 383 | + | |
| 384 | + | |
| 385 | + | |
| 386 | + | |
| 387 | + | |
| 388 | + | |
| 389 | + | |
| 390 | + | |
| 391 | + | |
| 392 | + | |
| 393 | + | |
| 394 | + | |
| 395 | + | |
339 | 396 | | |
340 | 397 | | |
0 commit comments