Skip to content

Commit 8b0826f

Browse files
committed
test(plugin-sharing): the org-less manage_sharing arms hold the capability through a global grant
An organization-less resolution no longer applies an organization-scoped grant, so the arms' precondition is now spelled as the one grant an org-less caller still holds. Claude-Session: https://claude.ai/code/session_01N8TPEsoJxPsdSdNKGnNGEN Co-authored-by: Claude <noreply@anthropic.com>
1 parent eafda39 commit 8b0826f

1 file changed

Lines changed: 12 additions & 5 deletions

File tree

‎packages/plugins/plugin-sharing/src/sharing-rule-positions-name-authority.test.ts‎

Lines changed: 12 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,10 @@
2222
*
2323
* ⭐ WHAT THE ESCALATION BUYS, driven rather than argued (see the arms below):
2424
* `manage_sharing` is an ORG-scoped capability (ADR-0111 D6) that an ordinary
25-
* tenant admin may grant. Holding it with no organization resolved is refused
25+
* tenant admin may grant. (Since #20515 a grant scoped to an organization no
26+
* longer applies to a resolution with no organization at all, so the arms below
27+
* hold it through a GLOBAL grant — the one way an org-less caller still holds
28+
* it.) Holding it with no organization resolved is refused
2629
* by `assertResolvableAdminScope` precisely because an unscoped answer "would
2730
* expose every tenant's rules". The D4 name-read was the bypass: it satisfied
2831
* that gate, `adminOrgScope` then returned the UNFILTERED `where`, and
@@ -100,10 +103,14 @@ function authzTables(shape: 'name-only' | 'genuine') {
100103
]
101104
: [];
102105
const userSets: Array<Record<string, unknown>> = [
103-
// The ORG-scoped capability both shapes hold — the precondition, not the
104-
// axis under test. Scoped to `HOME_ORG`, so it can never be mistaken for
105-
// the unscoped grant that confers standing.
106-
{ user_id: USER, permission_set_id: PS_SHARING, organization_id: HOME_ORG },
106+
// The `manage_sharing` capability both shapes hold — the precondition, not
107+
// the axis under test. GLOBAL (no organization): this caller resolves with
108+
// NO organization, and an organization-less resolution applies only global
109+
// grants (#20515), so an org-scoped grant here would simply not be held and
110+
// every arm below would be vacuous. It is still `sharing_admin`, never
111+
// `admin_full_access`, so it cannot be mistaken for the grant that confers
112+
// standing.
113+
{ user_id: USER, permission_set_id: PS_SHARING, organization_id: null },
107114
];
108115
if (shape === 'genuine') {
109116
userSets.push({ user_id: USER, permission_set_id: PS_ADMIN, organization_id: null });

0 commit comments

Comments
 (0)