Repository navigation
Commit ea295b1
The "Flow actions" paragraph under "Authorization inside an action" still
carried the honesty clause the contract's TSDoc carried before #15168: that
on the flow face `recordLoadDenied` is "declared but not yet populated" and a
guard on it is "inert (never `true`), never wrong".
That is false on `main`. `dispatchFlowAction` spreads
`actionRecordLoadSignal(subject)` into the context it hands
`automation.execute` (`packages/runtime/src/action-execution.ts:904`), and
both action doors reach it through that one function — the REST `/actions`
route (`packages/runtime/src/domains/actions.ts:732`) and the MCP
`run_action` bridge (`packages/runtime/src/action-execution.ts:1758`), each
passing the whole `ActionSubjectRecordLoad` rather than a bare record.
The direction of the defect is the inverted form of the Prime Directive #10
corollary: not a doc advertising a capability the runtime does not deliver,
but a doc denying one it now does — so an author reading it would not write
the `runAs: 'system'` guard the two-card sequence exists to enable, and no
gate reports it.
The replacement transcribes the sentence that landed on the contract
(`packages/spec/src/contracts/automation-service.ts:56`), adapted to docs
voice by naming the two doors, which that page's readers otherwise cannot
resolve. The surrounding `runAs: 'user'` / `runAs: 'system'` prose and the
`ctx.record.id` table are untouched.
Claude-Session: https://claude.ai/code/session_012zGPuVVX3deAx9LdjK8jCk
Co-authored-by: Claude <noreply@anthropic.com>
1 parent 17ec4b1 commit ea295b1
1 file changed
Lines changed: 6 additions & 5 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
379 | 379 | | |
380 | 380 | | |
381 | 381 | | |
382 | | - | |
383 | | - | |
384 | | - | |
385 | | - | |
386 | | - | |
| 382 | + | |
| 383 | + | |
| 384 | + | |
| 385 | + | |
| 386 | + | |
| 387 | + | |
387 | 388 | | |
388 | 389 | | |
389 | 390 | | |
| |||
0 commit comments