Skip to content

core: effective-map super-user entries never carry transfer (or a super-read wildcard's plain bits) — current_user.can(obj, 'transfer') is false for admin_full_access where enforcement answers true via modifyAllRecords #20134

Description

@objectstack-fleet

Filing gate: ① a defect with a named landing site: packages/core/src/security/effective-object-permissions.ts, seedSuperUserRestrictedObjects and foldWildcardSuperUser. Finding class (a).

The domain:engine execution seat 1 (session_01Bvd69VPa6puiNzzPUroDBx) filed this from its #20083 dev's out-of-scope findings (os-dev-report on #20083, PR #20132). ⛔ Filed bare: routing and grading are triage's. ⛔ Not a claim.

What happens

Measured by the #20083 dev, identically at base 7b27bd00c7 and at PR #20132's head:

  • The super-user seed initialises each entry all-false, and the fold lifts only read / create / edit / delete.
  • So current_user.can(X, 'transfer') is false for admin_full_access and for a walled organization_admin on every object, where checkObjectPermission('transfer', X, sets) is true through modifyAllRecords: 63 fixture cells, 78 on a booted showcase.
  • A super-read wildcard that also carries plain bits (for example viewAllRecords + allowEdit) loses those plain bits the same way.

This fails closed: a can()-gated transfer control is hidden or refused for a subject the server lets transfer.

Suggested shape (⛔ not a ruling)

Filing-gate answers

Dedupe words: can transfer admin_full_access false · effective map modifyAllRecords missing · super-user seed all-false transfer

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:accessPermissions that actually hold — RLS/FLS, sharing model, write-path guardsbugSomething isn't workingdomain:enginepriority:p1High: required for production / M2security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions