You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit e13ede8
Browse filesBrowse the repository at this point in the historyBrowse files
fix(rest): the /references door forwards the caller's organization, so the "Used by" panel stops clearing a delete an org-scoped item depends on (#15689)
* fix(rest): forward the caller's organization to the /references door, raw
`GET /api/v1/meta/:type/:name/references` backs the admin "Used by" panel,
whose empty case renders "Nothing in the metadata graph points at this item.
Safe to delete." to an operator about to delete something. The door named no
organization, so `findReferencesToMeta` swept the environment partition only
and an org-scoped `view` pointing at the item was invisible — a false
clearance on a destructive action (the ADR-0110 D3 harm this route's own 501
refusal exists to prevent).
The door now resolves the memoised exec ctx and passes `ctx?.tenantId` RAW.
Not pre-gated on `canonicalMetaUrlType(req.params.type)` the way the sibling
`/meta` doors are: that type is the reference TARGET, while the organization
is spent on the SOURCES, so gating on it would suppress the organization for
exactly the `object` / `flow` / `app` deletes this is about. Raw is safe
because `getMetaItems` applies `organizationIdForMetaRead` to its OWN request
type since #14683 — the per-source-type decision is already the callee's, and
`request.organizationId` has exactly one use inside `findReferencesToMeta`.
Pins in `rest-server-meta-read-org-scope.test.ts` drive real routes over a
real protocol: the org-scoped `view` is now found (red on the base commit),
and the narrowness control proves a non-overridable SOURCE is still read
env-wide with no phantom row resurrected. The `resolveExecCtx` census ledger
moves 76 → 77 sites / 97 → 98 mentions, 23 → 24 locally caught.
No new parameter, response field or contract surface: ADR-0131 D6/D7 retires
this partition in v18, so nothing is built on it.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* chore(docs): re-anchor the system-context census lines the /references door shifted
`check:check-system-context-census --fix` output: the four `rest-server.ts`
elevation-read anchors on the system-context page moved by the same +12 lines
the door's comment added. Pure line rot, no row content changed.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* test(rest): name the filed finding (#15685) in the /references refusal pin
The pin reads the refusal code through both of this route's envelopes because
the two disagree; that disagreement is now a filed card rather than an
unattributed observation in a comment.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
The admin "Used by" panel no longer clears a delete when the caller's own organization is using the item.
6
+
7
+
`GET /api/v1/meta/:type/:name/references` backs that panel, whose empty case reads "Nothing in the metadata graph points at this item. Safe to delete." — advice given to an operator about to delete something. The door supplied no organization, so the reference sweep read the environment partition only: an organization-scoped `view` (or `dashboard`, `report`, `translation`, `email_template`) pointing straight at the object being deleted was invisible, and the panel issued a false clearance. It now passes the caller's organization, and those references are returned.
8
+
9
+
The organization is passed RAW, deliberately, and that is the whole of the change — no new parameter, response field or contract surface. `req.params.type` is the reference TARGET, while the sweep spends the organization on the SOURCES it reads per type; `getMetaItems` applies the `allowOrgOverride` read gate to its own request type, so each source is scoped on its own registry flag. A non-overridable source (`object`, `flow`, `app`, …) is still read environment-wide and no pre-#6190 organization-scoped row is resurrected into a delete clearance. An anonymous or organization-less caller reads exactly what it read before, and no status code or response shape moves.
| 50 |`manage_metadata` bypassed on metadata writes | runtime, rest | Get: schema writes without the capability |`domains/meta.ts:471`, `:874`, `rest-server.ts:5016`, `:6430`, `:6678`, `:7109`, `:7302`|
161
+
| 50 |`manage_metadata` bypassed on metadata writes | runtime, rest | Get: schema writes without the capability |`domains/meta.ts:471`, `:874`, `rest-server.ts:5016`, `:6442`, `:6690`, `:7121`, `:7314`|
162
162
| 51 | The shared metadata-write verdict itself returns `allowed`| metadata-core | Get: the one function all of row 50's doors consult answers yes before any capability is examined |`meta-write-capability.ts:134`|
163
163
| 52 | Anonymous-deny seam satisfied on the domain dispatchers and the package/federation routes | runtime, rest | Get: passes with no `userId`|`domains/actions.ts:421`, `domains/ai.ts:60`, `domains/automation.ts:989`, `domains/meta.ts:232`, `domains/security.ts:78`, `domains/packages.ts:422`, `external-datasource-routes.ts:302`, `package-routes.ts:97`|
164
164
| 53 | MCP principal check satisfied | runtime | Get: MCP surface reachable with no user |`domains/mcp.ts:61`|
0 commit comments