|
22 | 22 | * |
23 | 23 | * ⭐ WHAT THE ESCALATION BUYS, driven rather than argued (see the arms below): |
24 | 24 | * `manage_sharing` is an ORG-scoped capability (ADR-0111 D6) that an ordinary |
25 | | - * tenant admin may grant. Holding it with no organization resolved is refused |
| 25 | + * tenant admin may grant. (Since #20515 a grant scoped to an organization no |
| 26 | + * longer applies to a resolution with no organization at all, so the arms below |
| 27 | + * hold it through a GLOBAL grant — the one way an org-less caller still holds |
| 28 | + * it.) Holding it with no organization resolved is refused |
26 | 29 | * by `assertResolvableAdminScope` precisely because an unscoped answer "would |
27 | 30 | * expose every tenant's rules". The D4 name-read was the bypass: it satisfied |
28 | 31 | * that gate, `adminOrgScope` then returned the UNFILTERED `where`, and |
@@ -100,10 +103,14 @@ function authzTables(shape: 'name-only' | 'genuine') { |
100 | 103 | ] |
101 | 104 | : []; |
102 | 105 | const userSets: Array<Record<string, unknown>> = [ |
103 | | - // The ORG-scoped capability both shapes hold — the precondition, not the |
104 | | - // axis under test. Scoped to `HOME_ORG`, so it can never be mistaken for |
105 | | - // the unscoped grant that confers standing. |
106 | | - { user_id: USER, permission_set_id: PS_SHARING, organization_id: HOME_ORG }, |
| 106 | + // The `manage_sharing` capability both shapes hold — the precondition, not |
| 107 | + // the axis under test. GLOBAL (no organization): this caller resolves with |
| 108 | + // NO organization, and an organization-less resolution applies only global |
| 109 | + // grants (#20515), so an org-scoped grant here would simply not be held and |
| 110 | + // every arm below would be vacuous. It is still `sharing_admin`, never |
| 111 | + // `admin_full_access`, so it cannot be mistaken for the grant that confers |
| 112 | + // standing. |
| 113 | + { user_id: USER, permission_set_id: PS_SHARING, organization_id: null }, |
107 | 114 | ]; |
108 | 115 | if (shape === 'genuine') { |
109 | 116 | userSets.push({ user_id: USER, permission_set_id: PS_ADMIN, organization_id: null }); |
|
0 commit comments