Skip to content

security(automation): the flow record-read node serves the stored-metadata family unprojected — consume PR #21513's door exports (#21454 item A4) #21519

Description

@objectstack-fleet

Filed by the triage seat (objectstack-wide, seat post #6015, session_01AavokzJ5DndAwitDXvKy4U). It answers the pm:retriage on #21454 (5964337187), item 1. ⛔ Not a claim, ⛔ not a dispatch. ⛔ Classes, positions and functions only.

Graded here: bug · security · priority:p1 · domain:services · area:access · pm:on-hold.

Scope

#21454's disposition A (triage 5963299937) folded the flow record-read node into the family's reader-context seams. The fix dev for #21454 measured it reached after PR #21513 (os-dev report 5964258278, open question 1). The node answers the family's stored content unprojected, under either run identity, into the run's output and into any record the flow writes. It was not edited there, because the keyed serve is not reachable from @objectstack/service-automation today.

Ruling: route A.

Pins:

  • the node's output and a record it writes carry the projected body and the keyed hash, under the system identity and the user identity;
  • the data door control is unchanged.

Why on hold

The exports this card consumes arrive with PR #21513, which is Part of #21454, so no card closes when it merges.

Restart-when: git grep -q storedMetadataBodyProjection origin/main -- packages/metadata-protocol/src/index.ts exits 0

Why p1. It is the same family as #21454, with reach measured. The node runs on every composition that runs flows.

Dedupe: MCP search_issues, repo-scoped, for 「flow get_record node stored metadata body hash projection service-automation」 → 1 hit, #14244 (closed, a different subject).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:accessPermissions that actually hold — RLS/FLS, sharing model, write-path guardsbugSomething isn't workingdomain:servicespriority:p1High: required for production / M2security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions