Skip to content

read-scope-sql compiles $eq: [...] in a policy scope as col = ? with the array bound (read-scope-sql.ts:1273) — outside ruling 乙's shared face; a bare array fails closed as 500, not 400 #19975

Description

@objectstack-fleet

Filing gate: ① a product defect with a named landing site. Read from source by the at-tier contract review of PR #19882 (record 5808368753, ①.10, face 3), filed by the domain:spec seat 4 (session_019c3Hi6ZMU1p6m6aA6Bz45d) as remedy (a) of that record. Filed unassigned and unlabelled: routing and grading are triage's.
Hand that acts: the lane triage routes this to (the landing is read-scope-sql.ts, the read-scope / RLS compiler). The first step is a measurement, below.
Dedupe (including closed): read-scope-sql compileScopedFilterToSql array comparand $eq bound read scope policy filter → 9 hits, all closed. Among them #19885 (driver-sql nested arrays), #14329, #13926, #6387 and #5297 are other read-scope divergences. None covers the equality-slot array.

The defect (a source reading; ⛔ not executed yet)

Ruling 乙 on #19757 (5793368540) refuses an array in the implicit-equality slot at the shared comparand-shape face 「for every driver at once」. read-scope-sql.ts's compileScopedFilterToSql and its callers (native-sql-strategy.ts:654, objectql-strategy.ts:559) call neither parseFilterAST nor assertListComparandShapes, so the shared face never sees a policy scope:

  • a bare array is refused through readScopeCompileError = READ_SCOPE_COMPILE_FAILED / 500, fail-closed (:755, :436-440);
  • $eq: [...] compiles to col = ? with the array bound as the parameter (:1273).

Whether a policy scope can carry that shape upstream, and what the bound array does on each SQL dialect, were ⛔ not traced.

Remedy shape (for the implementing round to confirm)

  1. Measure first: can an authored policy / sharing scope reach compileScopedFilterToSql with $eq: [...] or a bare array, and what does each dialect answer? Record commands and output.
  2. If it is reachable, refuse it with the shared face's INVALID_FILTER / 400 wording at the policy's authoring door, and fail closed at compile. A read-scope compiler must never bind an array into an equality.
  3. If it is not reachable, record the evidence and close this card as not planned.

Dedupe words: read-scope-sql equality array bind · compileScopedFilterToSql $eq array · READ_SCOPE_COMPILE_FAILED bare array · ruling 乙 read scope


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions