Skip to content

[finding] The metadata save door accepts a hook whose sandboxed body targets a stored-metadata table, which the runtime then refuses at bind: authoring answers 200 for a hook that never runs #21565

Description

@objectstack-fleet

Filing gate: ① a defect with a named position, a finding of class (c): authoring accepts what the runtime refuses.

What happens (measured)

With PR #21563 (#21520, ruling A 5965059068), an app-authored hook whose sandboxed body targets one of the two stored-metadata tables is refused at bind. The runtime logs it at error, and the hook never fires.

But the metadata door's save, PUT /api/v1/meta/hook/:name as the administrator, answered 200 for exactly such a runtime-authored hook. Authoring accepts a hook the runtime will never honour, and the author learns it only from a server log.

Why

Ruling A is enforced at the runtime's binding point (packages/runtime/src/sandbox/body-runner.ts, hookBodyRunnerFactory) and at the write seam. Neither the hook's schema (HookSchema's object target, packages/spec) nor the metadata door's save validation (packages/metadata-protocol/src/protocol.ts) consults the boundary.

AGENTS.md Prime Directive 12 says to fix it at the producer and reject it at authoring or publish. The binding refusal is the runtime's floor. The authoring refusal is missing.

Direction (⛔ not a ruling)

The authoring door refuses a hook whose sandboxed body targets either stored-metadata table, loudly, with the same prescription the runtime gives (change metadata through the metadata API). It uses the same predicate the runtime boundary uses. ⛔ No second list of tables.

The position is either a HookSchema refinement (domain:spec) or the save door's validation (protocol.ts, held today by open PR #21473). Pin: PUT /api/v1/meta/hook/:name refuses such a hook, and a hook on an ordinary object saves as before.

Serial: this card depends on PR #21563 landing, because it consumes that boundary's predicate.

Dedupe

MCP search_issues, repo-scoped, open and closed: 「metadata door accepts hook on sys_metadata refused at bind not at save authoring」 gave 10 hits. #21520 (open) is the runtime half and this finding's source; the rest are closed and on other subjects (#21470, #21412, #21207, #20863, #7990, #7529, #9066). None covers this.

Dedupe words: metadata door accepts hook on sys_metadata; hook body target stored-metadata table refused at bind not at save; runtime-authored hook family table 200 then refused.


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:accessPermissions that actually hold — RLS/FLS, sharing model, write-path guardsbugSomething isn't workingdomain:specpriority:p2Medium: important, M3

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions