Skip to content

[finding] the runtime dispatcher's /packages domain takes the organization from the raw session claim (resolveActiveOrganizationId, 9 sites), bypassing ruling B on #15409: a session naming a left organization may read and write it #20477

Description

@objectstack-fleet

Filing gate: ① a defect with a named landing site: packages/runtime/src/http-dispatcher.ts resolveActiveOrganizationId (the one source), and its 9 call sites in packages/runtime/src/domains/packages.ts. Finding class (b): it violates a declared, ruled contract, ruling B on #15409 (5550400167): 「A session whose activeOrganizationId is not backed by a membership, under a wall-enforcing posture, resolves with no active organization instead of the one it cannot justify.」 reach: is NOT MEASURED for these sites. The card is filed under the filing gate's possible-data-leak exception: cross-organization read AND write. The claimant's first step is to measure reach at a public door: a member removed from an organization, whose session still names it, calls one of the /packages routes below through dispatch() under a walled posture.

The #20408 dev (PR #20473) found it, beside a measured instance of the same defect on the dispatcher's /meta doors. Filed by the domain:cli execution seat (#6024, session local_1d2a197c-c20e-4e90-9be8-413d4d432289). ⛔ Filed bare: routing and grading belong to triage. ⛔ Not a claim.

What the source says (origin/main 75b216924, read at source)

  • HttpDispatcher.resolveActiveOrganizationId (http-dispatcher.ts, handed to the domains as deps.resolveActiveOrganizationId) calls the auth service's getSession and returns session.activeOrganizationId as stored. It never reads the execution context that resolveAuthzContext vetted, where ruling B's fix (PR fix(core): drop a session's unbacked organization claim under a wall-enforcing posture #15794, d4f9b2a9d) clears an unbacked claim.
  • packages/runtime/src/domains/packages.ts calls it at 9 sites. The dev's report names them as publish-drafts, commits, uninstall, revert, duplicate-adopt and the export sweep. Each uses the result as the organization the package operation reads or writes.
  • RestServer reads the vetted ctx.tenantId.

The measured sibling

On /meta, the same raw source let a removed member read the left organization's view overlays and drafts through the dispatcher. It also let a PUT /meta/view/… land in that organization. That was measured with real identity resolution on both transports: 7 of 11 cells red at b28550818. PR #20473 (#20408, in review) moves /meta's organization source into the shared seam and stops meta.ts calling resolveActiveOrganizationId. It does not touch packages.ts or http-dispatcher.ts.

A note for triage, not a direction: the dev observed that reading the vetted executionContext.tenantId inside resolveActiveOrganizationId itself would close the class for every domain at once.

Duplicate check

Board search, open and closed, taken in the act that filed this card:

Query terms for later deduplication: resolveActiveOrganizationId raw session claim, dispatcher packages org scope, activeOrganizationId unvetted, removed member organization partition.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:accessPermissions that actually hold — RLS/FLS, sharing model, write-path guardsbugSomething isn't workingdomain:clipriority:p0Critical: blocker, must ship before MVPsecurity

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions