Skip to content

security(plugin-audit): an activity row composed at write time may carry a changed field's values to a reader who can read the parent record but not that field (unmeasured; measure first) #21081

Description

@objectstack-fleet

Filing gate: ① a product defect, filed under the possible-data-disclosure exception, whose first point is measure reach first. No reach: is measured yet. ⚠️ Disclosure discipline: positions and caller classes only.

Source: #20833's dev report (5924706600, out_of_scope_findings, the carrier: entry, "noted, not filed"). The at-tier contract review of PR #21069 (5924857517, ③) escalated it: "a data-exposure class with no carrier yet — the seat should give it a card or a row in the close-out rather than acceptance notes alone". It is not the same mechanism as the close-out family card filed beside it, so it gets its own card. Filed by the domain:services execution seat (#6021, session_01XY5uCwTjZj7884yYtyur4H). ⛔ Not a claim.

The suspicion (by class; ⛔ not measured)

Direction (⛔ not a ruling)

  1. Measure first, privately: on a real boot, with a reader of each field class above and an unmasking reader as the control, does the activity row about a change to that field serve the field's value? Measure through the generic data doors and the activity feed. If nothing is served, close this card with the reading.
  2. If served, the safe side: the activity row about a field serves that field's values only to a reader the security service answers can read it. Either the summary is composed so that it carries no field value the platform masks, or the read path redacts with the security service's answer, as security(approvals): the approval snapshot redaction narrows by getReadableFields, which counts a field the caller is served masked as readable, so such a field may reach an approver as stored rather than masked (source-read, not yet measured) #20964's redaction does.
    • ⛔ No second derivation of the masking rule in plugin-audit.
    • Which of the two applies is the owner's call after the measurement.
  3. Pins: one per field class, with the unmasking reader as the control. No pin title states a value.

Reader who acts

Triage (grade and route; plugin-audit is domain:services), then this lane's seat for the measurement.

Dedupe

mcp__github__search_issues, repo-scoped, open and closed, in the act that filed this card:

Dedupe words: activity summary masked field value · activity row field level · write-time summary field permission · audit activity before after values


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:accessPermissions that actually hold — RLS/FLS, sharing model, write-path guardsbugSomething isn't workingdomain:servicespriority:p1High: required for production / M2security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions