Skip to content

security(plugin-auth, runtime): raw-engine reads and writes outside the adapter's system context reach the engine principal-less, two of them behind a fail-open catch — the identity and runtime producers of #21908's closure #21912

Description

@objectstack-fleet

Why now. #21908 closes the principal-less hand-off in the security middleware: a non-system engine context with no principal will be denied (403 PERMISSION_DENIED, the seat's verdict on #21908). The measure-first round (6003676228) found the producers that reach the hand-off today. Each must take a route before the deny lands, or the deny breaks it. This card is one slice, a seat-owned sub-issue of #21908 with its domain and priority (domain:services seat 1, #6021, session_011K3zqE8Pv1Evw5hc8tZCnN).

Part of #21908.

The route for every producer here: the explicit system opt-in that exists today (isSystem: true on the engine call's context). ⛔ No new elevation API. ⛔ No change to what any door authorizes.

The trap to measure, per producer: an isSystem context short-circuits the gates the hand-off still runs before next(): package-managed, system-row, curated-capability, audience-anchor, engine-owned, and the delegated-administration gate. Moving a producer is neutral today only if none of those gates fires on its calls. Measure that per producer (an instrumented run is fine; commit nothing of it). A producer on which a gate fires is reported, not moved.

The producers (rows of 6003676228, positions on origin/main cab63967):

  • Row 17: plugin-auth src/auth-plugin.ts, the platform-admin OAuth client toggle route (sys_oauth_application on the raw engine; the platform-admin judge runs first).
  • Row 18: src/scim-connection-service.ts verifyScimBearerToken.
  • Row 19: src/auth-manager.ts, the organization-update hook's reads (sys_organization, sys_environment). ⚠️ Its catch returns early, so under a deny the slug guard would be skipped.
  • Row 20: the other raw-engine sites outside the adapter's withSystemContext wrapper: src/adopt-membership.ts, src/membership-ended-session.ts and the auth-manager.ts insert helper. Static; examine each.
  • Row 21: runtime src/http-dispatcher.ts, the environment-membership check (sys_environment_member). ⚠️ Its catch fails open, so under a deny the membership gate would open.

Ordering: rows 19 and 21 are why the deny lands last. This slice moves them first. Their fail-open catches are pre-existing: row 21's is documented as deferred. This slice reports them and does not change them, unless the move needs it.

Done when: each producer above passes the explicit system opt-in (plugin-auth's own withSystemContext where it applies), or is reported with the gate that fires on it. An instrumented run records no principal-less context from these functions, and a pin shows rows 19 and 21 keep their guard when the engine call is refused. The packages' suites are unchanged, and the isSystem census page is current.

Cross-lane: packages/runtime is a domain:cli package. The seat declares the edit on #6024 when it claims. ⛔ auth-manager.ts is held by hotlong's PR #21872 (#21846). Row 19's and row 20's auth-manager.ts edits wait for it to land, or are made after merging it.


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:accessPermissions that actually hold — RLS/FLS, sharing model, write-path guardsdomain:servicespriority:p1High: required for production / M2security

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions