Filing gate: ① a defect with named landing sites, both on GOVERNED paths (Tier H). Finding class (a), text an agent reads that is false of what main enforces. Per NORTH-STAR 优先级 rule 4, 「写给 AI 的文档与 skills 说错一句,等于产品缺陷」.
Filed by the domain:spec execution seat 2 (session_01QcAS3qiYYZNezaxZxaUdMV, seat post #18549). It comes from the #19967 dev round (PR #20268, out_of_scope_findings[0]), and the at-tier contract review of PR #20268 judged both sites false ③ (record on that PR). PR #20268 corrects every non-governed site of the same sentences. ⛔ These two were left untouched because they are governed. ⛔ Filed bare: routing and grading are triage's. ⛔ Not a claim.
The sites (origin/main a9fb83ef06)
docs/adr/0066-unified-authorization-model.md:93, item 3: 「Multiple row policies for the same object/operation are OR-combined (any matching policy admits the row)」.
- True for READS:
compileFilter OR-combines the applicable policies' using.
- False as a statement about WRITES: the write
check is chosen once per operation across the applicable policies (writeCheckPolicies: an insert policy's using stands in when no applicable policy declares check), then OR-combined. It is not "any matching policy admits the row".
skills/objectstack-data/rules/security.md:72-75 (a published skill): it calls using the 「read filter」 and check the 「write filter」, and says the plugin 「re-reads the target row through the write filter before single-id update/delete」.
Related, one clause (safe direction; from the same review ①.2)
rls.zod.ts's overview used to say 「Default Deny: If no policy matches, access is denied」. That was false in the DANGEROUS direction: a caller outside every applicable policy is not row-restricted by RLS. PR #20268 corrects it. The same review notes one optional follow-up clause for that text: for an update or delete, the caller's select policies bound the target rows when no write-class using applies. If the skills page states a default posture, it should state this one.
Suggested shape (⛔ not a ruling)
One governed PR: correct the ADR sentence (reads OR-combine; writes choose the check per operation, then OR-combine) and the skill's RLS section, citing the enforcing code. It needs the maintainer's approval as Tier H.
Dedupe: open issues filtered locally for ADR-0066 / security.md with RLS terms → 0 hits.
Filing gate: ① a defect with named landing sites, both on GOVERNED paths (Tier H). Finding class (a), text an agent reads that is false of what
mainenforces. Per NORTH-STAR 优先级 rule 4, 「写给 AI 的文档与 skills 说错一句,等于产品缺陷」.Filed by the
domain:specexecution seat 2 (session_01QcAS3qiYYZNezaxZxaUdMV, seat post #18549). It comes from the #19967 dev round (PR #20268,out_of_scope_findings[0]), and the at-tier contract review of PR #20268 judged both sites false ③ (record on that PR). PR #20268 corrects every non-governed site of the same sentences. ⛔ These two were left untouched because they are governed. ⛔ Filed bare: routing and grading are triage's. ⛔ Not a claim.The sites (
origin/maina9fb83ef06)docs/adr/0066-unified-authorization-model.md:93, item 3: 「Multiple row policies for the same object/operation are OR-combined (any matching policy admits the row)」.compileFilterOR-combines the applicable policies'using.checkis chosen once per operation across the applicable policies (writeCheckPolicies: an insert policy'susingstands in when no applicable policy declarescheck), then OR-combined. It is not "any matching policy admits the row".skills/objectstack-data/rules/security.md:72-75(a published skill): it callsusingthe 「read filter」 andcheckthe 「write filter」, and says the plugin 「re-reads the target row through the write filter before single-idupdate/delete」.usingis its check when nocheckis declared.checkjudges every row an insert or update writes, arrays andmulti: trueincluded (PRs fix(plugin-security, objectql): a row-level check holds for every row of an array insert and a predicate update #19988, fix(plugin-security, objectql)!: a by-id update's row-level check holds for the row it stores #20012).checkonselect/deleteis refused (PR feat(spec)!: refuse acheckon aselect/deleterow-level security policy #20167).Related, one clause (safe direction; from the same review ①.2)
rls.zod.ts's overview used to say 「Default Deny: If no policy matches, access is denied」. That was false in the DANGEROUS direction: a caller outside every applicable policy is not row-restricted by RLS. PR #20268 corrects it. The same review notes one optional follow-up clause for that text: for an update or delete, the caller'sselectpolicies bound the target rows when no write-classusingapplies. If the skills page states a default posture, it should state this one.Suggested shape (⛔ not a ruling)
One governed PR: correct the ADR sentence (reads OR-combine; writes choose the check per operation, then OR-combine) and the skill's RLS section, citing the enforcing code. It needs the maintainer's approval as Tier H.
Dedupe: open issues filtered locally for
ADR-0066/security.mdwith RLS terms → 0 hits.