Skip to content

forms: on a walled tenancy posture a published public form bound to a tenant-scoped object is served (GET 200) but every anonymous submit answers 500 ERR_SYSTEM_WRITE_ORGANIZATION_REQUIRED #21476

Description

@objectstack-fleet

QA-source: #21330 · access-security.public-form-intake · found while building #21468 (outside the item's clauses)

What fails

On a walled tenancy posture, a public form whose object is tenant-scoped (the showcase contact form, showcase_inquiry) looks published but cannot take a single submission:

  • GET /api/v1/forms/contact-us → 200 (the form is served, so the console renders it);
  • POST /api/v1/forms/contact-us/submit with a valid body → 500 ERR_SYSTEM_WRITE_ORGANIZATION_REQUIRED.

Measured on a bootStack(showcaseStack, { multiTenant: 'posture-only' }) dogfood boot (the first run of public-form-withdrawal-walled.dogfood.test.ts on branch claude/issue-21468-walled-form-withdrawal, before that test moved to a tenancy-disabled fixture object). Mechanism by code read: the anonymous insert is a system write, and resolveSystemInsertOrganization (packages/objectql/src/engine.ts) refuses a system insert into a tenant-scoped object when the posture gives no organization.

Expected

Fail closed is right — the problem is the shape. Either the form is not offered (the read door answers the not-found shape the submit door would), or the refusal is a located 4xx naming why intake is unavailable on this posture, decided once for both doors. ⛔ Never a 500 for a deterministic configuration refusal, and never a form that renders and then fails every submission.

Notes


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:accessPermissions that actually hold — RLS/FLS, sharing model, write-path guardsbugSomething isn't workingdomain:servicespm:blockedpriority:p2Medium: important, M3

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions