Repository navigation
Commit a0176ef
fix(core): mask credential-class fields on every write response (#21816)
Fixes #21787
Clause-②: no
## What changed
Credential-class field values are now masked on every write response, as
on reads.
- The engine masks credential-class fields (`secret`, and `password`
outside the exempt `managedBy` bucket, ADR-0100) on its read path only.
Its write results keep the stored row whole by design, so privileged
server-side writers can read back what they wrote. The rule for what an
external caller receives therefore sits at the write mouths, the same
boundary that already omits `internal: true` fields.
- `omitInternalFieldsFromWriteResponse` (`@objectstack/core`) is the one
helper every generic write mouth already calls: protocol `*Data` faces,
the REST cross-object batch, and the MCP stdio bridge. It now applies
the credential mask first (`maskCredentialFieldsInWriteResponse`, new
export) and then omits `internal` fields, in the same order the engine's
read path uses. The mask reads the same `isMaskedOnReadFieldType`
declaration in `@objectstack/spec/data` that the engine's read mask
reads, so the two cannot drift. It never adds a key, so a field already
removed by field-level security stays absent.
- `callData`'s fallback create and update arms (`@objectstack/runtime`,
used when no protocol service is registered) answered without that
helper. They now call it too.
- Unchanged: engine-level write results, and the echoed-mask write
guard. A client that saves a masked value back leaves the stored
credential as it was. The dogfood test pins this.
## Tests
All runs below are from head `91d3806ab5` or from a commit whose tree
matches it for the files each run covers.
- New `packages/core/src/utils/internal-write-response.test.ts`: the
collector, the mask, the order (mask, then omit), the better-auth
exemption, and a field removed upstream staying absent. 5/5 pass.
- The three existing write-mouth tripwires now also check
credential-class stored values: a `password` plaintext and a `secret:`
handle ref on every stored row, in the protocol, REST and MCP suites.
Each tripwire enumerates its whole surface, so a new write mouth must
register there. Protocol 18/18, REST 14/14, MCP 14/14 (MCP adds a test
that the update echo does not return the caller's own credential in
clear).
- New
`packages/runtime/src/action-execution-calldata-write-response.test.ts`:
the fallback create and update arms. 3/3 pass.
- New
`packages/qa/dogfood/test/write-response-credential-mask.dogfood.test.ts`:
a real boot with a synthetic object holding one `password` and one
`secret` field. Before anything else, the test proves the plaintext and
the handle ref are really stored. It then checks single create, single
update, createMany, updateMany, the per-object batch, the cross-object
batch, and the masked-echo round trip. 8/8 pass.
- Full package suites: core 2225/2225, metadata-protocol 5249 passed and
19 skipped, rest 5074 passed and 327 skipped, mcp 390/390. In runtime,
the `action-execution*`, `http-dispatcher.mcp*` and `domains/mcp` files
pass (157/157). Neighbouring credential and `internal` dogfood suites
pass (97/97 across 8 files).
- Typecheck is clean for core, runtime, metadata-protocol, rest, mcp and
dogfood. A `--listFiles` count confirms the new and edited test files
are inside the compiled programs.
**Ablation**, run through `scripts/ablation-replace.mjs` with a dist
preflight. The single call that applies the credential mask inside the
shared helper was replaced. `@objectstack/core` was rebuilt, and the
preflight showed the marker present in `dist/`.
| Suite | Result with the mask call removed |
|:---|:---|
| core | 2 red |
| protocol tripwire | 8 red (every write face plus the negative control)
|
| REST tripwire | 8 red, including both batch routes |
| MCP tripwire | 3 red |
| runtime fallback | 2 red |
| dogfood | 7 red: every write door, while the arming test stayed green
|
The restore was proven: blob equal to HEAD, `git diff HEAD` empty, and
the core rebuild showed the marker absent from `dist/` with a clean
tree. A first ablation attempt used a preflight marker that the pristine
build also emits, so its preflight reading was void. That run is not
counted; the run above uses a unique marker.
**Gates:** `node scripts/pm/dispatch-gates.mjs --ran` reconciles 78
derived families: 77 run with exit 0, 1 NOT MEASURED.
`check:dual-build-cjs-loads` exited 3 with PREREQUISITE NOT MET because
unrelated packages had no `dist/`. `check:engine-double-contract` asked
for the new pinned double to be recorded, and
`scripts/engine-double-contract.pinned.json` is updated.
**Declared narrowing, left to CI:** the full runtime suite; the
workspace type-check lanes; `main` was not merged back in before
opening.
## Acceptance notes
- **Placement:** the fix is in the shared write-response helper, not the
engine's `maskSecretFields`. That is the boundary the existing ruling
set for the sibling `internal` guarantee: engine write results stay
whole for privileged callers, and every external write mouth applies the
response rules. Masking inside the engine would also mask results that
server-side writers read back.
- **Naming:** `omitInternalFieldsFromWriteResponse` now also masks
credentials, so its name describes less than it does. A rename touches
every write mouth and every tripwire, so it is left out of this PR.
Carrier: none.
- **ADR-0100:** the ADR describes the mask on the read path only.
Whether it should gain a line recording the write-response half is a
maintainer call, because `docs/adr/**` is governed. This PR does not
touch it.
- **Not examined:** outbound record surfaces that are not write
responses, such as event payloads, were not checked against this rule.
---
_Generated by [Claude
Code](https://claude.ai/code/session_018zT8d8NpiQ1ExhuNd5TxY6)_
---------
Co-authored-by: Claude <noreply@anthropic.com>1 parent c4d5713 commit a0176ef
12 files changed
Lines changed: 712 additions & 40 deletions
File tree
- .changeset
- packages
- core/src/utils
- mcp/src
- metadata-protocol/src
- qa/dogfood/test
- rest/src
- runtime/src
- domains
- scripts
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
89 | 89 | | |
90 | 90 | | |
91 | 91 | | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
92 | 103 | | |
93 | 104 | | |
94 | 105 | | |
95 | 106 | | |
96 | 107 | | |
97 | 108 | | |
| 109 | + | |
| 110 | + | |
98 | 111 | | |
99 | 112 | | |
100 | | - | |
| 113 | + | |
| 114 | + | |
101 | 115 | | |
102 | 116 | | |
103 | 117 | | |
| |||
118 | 132 | | |
119 | 133 | | |
120 | 134 | | |
121 | | - | |
122 | | - | |
123 | | - | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
| 138 | + | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
| 149 | + | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
| 153 | + | |
| 154 | + | |
| 155 | + | |
| 156 | + | |
| 157 | + | |
| 158 | + | |
| 159 | + | |
| 160 | + | |
| 161 | + | |
| 162 | + | |
| 163 | + | |
| 164 | + | |
| 165 | + | |
| 166 | + | |
| 167 | + | |
| 168 | + | |
| 169 | + | |
| 170 | + | |
| 171 | + | |
| 172 | + | |
| 173 | + | |
| 174 | + | |
| 175 | + | |
| 176 | + | |
| 177 | + | |
| 178 | + | |
| 179 | + | |
| 180 | + | |
| 181 | + | |
| 182 | + | |
| 183 | + | |
| 184 | + | |
| 185 | + | |
| 186 | + | |
| 187 | + | |
| 188 | + | |
| 189 | + | |
| 190 | + | |
| 191 | + | |
| 192 | + | |
| 193 | + | |
124 | 194 | | |
125 | 195 | | |
126 | 196 | | |
| |||
133 | 203 | | |
134 | 204 | | |
135 | 205 | | |
| 206 | + | |
136 | 207 | | |
137 | 208 | | |
138 | 209 | | |
| |||
Lines changed: 23 additions & 5 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
52 | 52 | | |
53 | 53 | | |
54 | 54 | | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
55 | 59 | | |
56 | 60 | | |
57 | 61 | | |
| |||
60 | 64 | | |
61 | 65 | | |
62 | 66 | | |
| 67 | + | |
| 68 | + | |
63 | 69 | | |
64 | 70 | | |
65 | 71 | | |
| |||
78 | 84 | | |
79 | 85 | | |
80 | 86 | | |
| 87 | + | |
| 88 | + | |
81 | 89 | | |
82 | 90 | | |
83 | 91 | | |
| |||
157 | 165 | | |
158 | 166 | | |
159 | 167 | | |
160 | | - | |
| 168 | + | |
161 | 169 | | |
162 | 170 | | |
163 | 171 | | |
| |||
181 | 189 | | |
182 | 190 | | |
183 | 191 | | |
184 | | - | |
| 192 | + | |
185 | 193 | | |
186 | 194 | | |
187 | | - | |
| 195 | + | |
188 | 196 | | |
189 | 197 | | |
190 | 198 | | |
| |||
207 | 215 | | |
208 | 216 | | |
209 | 217 | | |
| 218 | + | |
| 219 | + | |
| 220 | + | |
| 221 | + | |
| 222 | + | |
| 223 | + | |
| 224 | + | |
| 225 | + | |
| 226 | + | |
| 227 | + | |
210 | 228 | | |
211 | 229 | | |
212 | 230 | | |
| |||
221 | 239 | | |
222 | 240 | | |
223 | 241 | | |
224 | | - | |
| 242 | + | |
225 | 243 | | |
226 | 244 | | |
227 | | - | |
| 245 | + | |
228 | 246 | | |
229 | 247 | | |
230 | 248 | | |
Lines changed: 18 additions & 5 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
56 | 56 | | |
57 | 57 | | |
58 | 58 | | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
59 | 68 | | |
60 | 69 | | |
61 | 70 | | |
62 | 71 | | |
63 | 72 | | |
64 | 73 | | |
65 | 74 | | |
| 75 | + | |
| 76 | + | |
66 | 77 | | |
67 | 78 | | |
68 | 79 | | |
| |||
82 | 93 | | |
83 | 94 | | |
84 | 95 | | |
| 96 | + | |
| 97 | + | |
85 | 98 | | |
86 | 99 | | |
87 | 100 | | |
| |||
241 | 254 | | |
242 | 255 | | |
243 | 256 | | |
244 | | - | |
| 257 | + | |
245 | 258 | | |
246 | 259 | | |
247 | 260 | | |
| |||
276 | 289 | | |
277 | 290 | | |
278 | 291 | | |
279 | | - | |
| 292 | + | |
280 | 293 | | |
281 | 294 | | |
282 | 295 | | |
283 | 296 | | |
284 | | - | |
| 297 | + | |
285 | 298 | | |
286 | 299 | | |
287 | 300 | | |
| |||
305 | 318 | | |
306 | 319 | | |
307 | 320 | | |
308 | | - | |
| 321 | + | |
309 | 322 | | |
310 | 323 | | |
311 | 324 | | |
312 | 325 | | |
313 | | - | |
| 326 | + | |
314 | 327 | | |
315 | 328 | | |
316 | 329 | | |
| |||
0 commit comments