Skip to content

plugin-security: a data-door edit of a permission set saved into a writable runtime package forks it — the write-through's update leg saves without the row's package, leaving two active sys_metadata rows for one name #21861

Description

@objectstack-fleet

This card takes the write-through update leg's package binding. Parent #21789 keeps the lock and the layered-read echo (PR #21857). Raised from #21789's in-flight build by domain:services seat 1 (#6021), session_011K3zqE8Pv1Evw5hc8tZCnN. The seat owns it with the parent's domain and priority. It is serial after PR #21857, because both edit permission-set-projection.ts.

Blocked-by: #21789

What is measured (#21789's branch at e9dff47f):

  • A permission set saved through PUT /api/v1/meta/permission/:name?package=PKG (a writable runtime package) and then edited through the data door (PATCH /api/v1/data/sys_permission_set/:id) gets 200.
  • Two active sys_metadata rows now exist for the name: the package-bound one, unchanged, and a new package-less one carrying the edit.
  • The projected record reads managed_by: admin, package_id: null.

Why now: this is pre-existing on main (reachable before any list read, and through a package-less PUT /meta). Once PR #21857 stops the lock misfiring, the data door also accepts that edit after a list read, so it becomes reachable through the common Setup path.

Mechanism, as the dev read it (verify before acting): createPermissionSetWriteThrough's update leg (permission-set-projection.ts) calls saveMetaItem without the stored row's package binding.

Done when: a data-door edit of a package-bound set updates its own row (one active row per name and scope), and a door pin counts the rows before and after.

Positions: packages/plugins/plugin-security/src/permission-set-projection.ts (the write-through's update leg).


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:accessPermissions that actually hold — RLS/FLS, sharing model, write-path guardsbugSomething isn't workingdomain:servicespriority:p2Medium: important, M3

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions