Skip to content

Commit 90db7d4

Browse files
committed
fix(plugin-sharing,plugin-audit): runtime strings state the decision instead of citing a tracker number
Stage 6 of the services lane's share of the runtime-string burn-down: every ledgered tracker-number occurrence in plugin-sharing/src and the one in plugin-audit's audit-writers.ts. Each rewritten string states what the cited card decided, in words, or drops a citation the sentence already explained. Text only: no status, error code, field, route or control flow moves. The doc-authoring prose-id ledger is recomputed with --census-ledger: four file entries leave it, nothing else moves. Claude-Session: https://claude.ai/code/session_01DiCSbmJrkzNhuEAier4VoJ Co-authored-by: Claude <noreply@anthropic.com>
1 parent aa46322 commit 90db7d4

8 files changed

Lines changed: 34 additions & 28 deletions

File tree

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
---
2+
'@objectstack/plugin-sharing': patch
3+
'@objectstack/plugin-audit': patch
4+
---
5+
6+
Sharing refusals and log lines, and the audit write-failure line, no longer cite tracker numbers; each one states the decision behind it in words
7+
8+
Clause-②: no
9+
10+
Some strings these two packages show to administrators and operators pointed at an issue-tracker number for the reason behind them. The number goes; where the sentence did not already say what was decided, it now does.
11+
12+
- `@objectstack/plugin-sharing`: the orphan-sweep line for record shares says every share on a deleted record goes, whatever its source, so a reused record id cannot inherit it; the same line for share links says a share link is a bearer token, so a reused record id must not inherit it; the write-gate failure line says a failed lookup is a refusal, never an abstention, because an abstention would hand the row to the other write authorities, which may admit it; the authored-row-write probe line says only an app-authored row-level policy that positively admits the row may lift the sharing refusal; the hierarchy-scope line says the resolver contract makes a resolver fail closed on a missing organization. The two sharing-rule refusals (no active organization; deleting a platform-global rule) drop their citations, since each sentence already says why. The `OrphanSweepSubject.issue` member's doc comment now says the member carries that reason in words.
13+
- `@objectstack/plugin-audit`: the missing-table fix in the audit write-failure line says that on a fresh `os dev` boot the table exists in the sibling telemetry file and not in the primary one, so look there before concluding it was never created.
14+
15+
Text only: no status, error code, field, route or control flow moves. A client or log filter that matches the old text (for example a tracker-number suffix) needs the new spelling.

‎packages/plugins/plugin-audit/src/audit-writers.ts‎

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -971,8 +971,9 @@ function auditWriteFailureLine(f: {
971971
'`OS_SKIP_SCHEMA_SYNC` creates it out-of-band instead). (2) Otherwise it was created on a DIFFERENT ' +
972972
'datasource than the one this write reached: its ADR-0057 §3.6 lifecycle class routes it to the ' +
973973
'dedicated `telemetry` datasource whenever one is registered (`os dev` provisions one by default as a ' +
974-
'SIBLING SQLite file) — see framework#5226. Set `OS_TELEMETRY_DB=0` to keep every lifecycle-classed ' +
975-
'object on the primary datasource.'
974+
'SIBLING SQLite file), so on a fresh `os dev` boot the table exists in that sibling file and not in the ' +
975+
'primary one; look there before concluding it was never created. Set `OS_TELEMETRY_DB=0` to keep ' +
976+
'every lifecycle-classed object on the primary datasource.'
976977
: 'Fix: resolve the driver fault quoted at the head of this line on the connection this write ran ' +
977978
'on — every audited write that hits it loses its row until it is resolved.';
978979
return consequence + once + fix;

‎packages/plugins/plugin-sharing/src/record-orphan-cleanup.ts‎

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -118,7 +118,10 @@ export interface OrphanSweepSubject {
118118
table: string;
119119
/** Noun for log messages: `share` → "orphan share sweep", "share rows". */
120120
noun: string;
121-
/** Issue reference appended to the "revoked N rows" warning. */
121+
/**
122+
* Why the rows go, appended to the "revoked N rows" warning. Runtime text
123+
* carries no tracker number, so this states the decision in words.
124+
*/
122125
issue: string;
123126
}
124127

‎packages/plugins/plugin-sharing/src/share-link-service.ts‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -64,7 +64,7 @@ const SYSTEM_CTX = { isSystem: true, positions: [], permissions: [] } as const;
6464
const SHARE_LINK_SWEEP_SUBJECT = {
6565
table: 'sys_share_link',
6666
noun: 'share-link',
67-
issue: '#5190',
67+
issue: 'a share link is a bearer token, so a reused record id must not inherit it',
6868
} as const;
6969

7070
/** URL-safe alphabet (RFC 4648 base64url minus padding). 64 symbols. */

‎packages/plugins/plugin-sharing/src/sharing-rule-service.ts‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -424,7 +424,7 @@ export class SharingRuleService implements ISharingRuleService {
424424
'PERMISSION_DENIED: sharing-rule administration requires an active organization — this ' +
425425
'session carries none. manage_sharing is an ORG-scoped capability (ADR-0111 D6), so with ' +
426426
'no organization resolved there is no tenant whose rules it authorizes, and answering ' +
427-
'unscoped would expose every tenant’s rules (#8158). Select an active organization and ' +
427+
'unscoped would expose every tenant’s rules. Select an active organization and ' +
428428
'retry. Platform operators (manage_platform_settings or the platform_admin position) and ' +
429429
'system contexts are unaffected.',
430430
);
@@ -529,7 +529,7 @@ export class SharingRuleService implements ISharingRuleService {
529529
'PERMISSION_DENIED: deleting a platform-global sharing rule requires platform authority — ' +
530530
'the manage_platform_settings capability or the platform_admin position. Org-scoped ' +
531531
'manage_sharing does not authorize it, because this rule belongs to no organization and ' +
532-
'deleting it revokes every tenant’s grants under it (#7795). It remains listable, ' +
532+
'deleting it revokes every tenant’s grants under it. It remains listable, ' +
533533
'readable and evaluable.',
534534
);
535535
}

‎packages/plugins/plugin-sharing/src/sharing-service.test.ts‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1613,7 +1613,7 @@ describe('[#6428] fail-closed: an unresolvable verdict is DENY, never abstain',
16131613

16141614
expect(logged.length).toBeGreaterThan(0);
16151615
expect(String(logged[0][0])).toContain('fail-closed');
1616-
expect(String(logged[0][0])).toContain('#6428');
1616+
expect(String(logged[0][0])).toContain('an abstention would hand the row to the other write authorities');
16171617
});
16181618

16191619
it('a throwing SHARE lookup denies too — the whole evaluation is covered, not just the first query', async () => {

‎packages/plugins/plugin-sharing/src/sharing-service.ts‎

Lines changed: 8 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -309,7 +309,7 @@ export interface SharingSecurityProbe {
309309
const RECORD_SHARE_SWEEP_SUBJECT = {
310310
table: 'sys_record_share',
311311
noun: 'share',
312-
issue: '#5103',
312+
issue: 'every share on a deleted record goes, whatever its source, so a reused record id cannot inherit it',
313313
} as const;
314314

315315
/**
@@ -734,8 +734,9 @@ export class SharingService implements ISharingService {
734734
): SharingWriteVerdict {
735735
this.logger?.error?.(
736736
`[sharing] the ${verb} gate could not resolve a verdict for '${object}' record `
737-
+ `'${recordId}' (user ${context?.userId ?? 'unknown'}) — DENYING (fail-closed, #6428): `
738-
+ 'a failed lookup is a refusal, never an abstention',
737+
+ `'${recordId}' (user ${context?.userId ?? 'unknown'}) — DENYING (fail-closed): `
738+
+ 'a failed lookup is a refusal, never an abstention, because an abstention would hand the row '
739+
+ 'to the other write authorities, which may admit it',
739740
err instanceof Error ? err : new Error(String(err)),
740741
);
741742
return 'deny';
@@ -954,7 +955,8 @@ export class SharingService implements ISharingService {
954955
this.logger?.warn?.(
955956
`[sharing] the authored-row-write probe for '${object}' record '${recordId}' `
956957
+ `(${operation}, user ${context?.userId ?? 'unknown'}) could not be resolved — `
957-
+ 'ABSTAINING, so the existing refusal stands (fail-closed, #5493)',
958+
+ 'ABSTAINING, so the existing refusal stands (fail-closed: only an app-authored row-level '
959+
+ 'policy that positively admits this row may lift the sharing refusal)',
958960
err instanceof Error ? err : new Error(String(err)),
959961
);
960962
return 'abstain';
@@ -1833,7 +1835,8 @@ export class SharingService implements ISharingService {
18331835
this.logger?.warn?.(
18341836
'[sharing] hierarchy scope NOT widened: an organization wall is in force but the caller ' +
18351837
'context carries no active organization — failing closed to owner-only. ' +
1836-
'"No org" is not "every org" (IHierarchyScopeResolver.resolveOwnerIds, #5973); ' +
1838+
'"No org" is not "every org": the IHierarchyScopeResolver.resolveOwnerIds contract makes a ' +
1839+
'resolver fail closed on a missing organization; ' +
18371840
'the same rule walls Layer 0 (ADR-0095 D1 / ADR-0105 D1).',
18381841
{ userId: me, scope },
18391842
);

‎scripts/doc-authoring-prose-id.baseline.json‎

Lines changed: 0 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -70,9 +70,6 @@
7070
"packages/lint/src/validate-widget-bindings.ts": {
7171
"#2501": 1
7272
},
73-
"packages/plugins/plugin-audit/src/audit-writers.ts": {
74-
"#5226": 1
75-
},
7673
"packages/plugins/plugin-audit/src/objects/sys-activity.object.ts": {
7774
"#11507": 1
7875
},
@@ -137,19 +134,6 @@
137134
"#10424": 1,
138135
"#3545": 6
139136
},
140-
"packages/plugins/plugin-sharing/src/share-link-service.ts": {
141-
"#5190": 1
142-
},
143-
"packages/plugins/plugin-sharing/src/sharing-rule-service.ts": {
144-
"#7795": 1,
145-
"#8158": 1
146-
},
147-
"packages/plugins/plugin-sharing/src/sharing-service.ts": {
148-
"#5103": 1,
149-
"#5493": 1,
150-
"#5973": 1,
151-
"#6428": 1
152-
},
153137
"packages/services/service-analytics/src/analytics-service.ts": {
154138
"#3867": 1,
155139
"#5222": 1,

0 commit comments

Comments
 (0)