Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
19 changes: 19 additions & 0 deletions .changeset/21913-principal-less-producers.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
---
"@objectstack/service-settings": minor
"@objectstack/service-messaging": patch
"@objectstack/service-datasource": minor
"@objectstack/plugin-webhooks": patch
---

Platform plumbing in these four packages now passes the explicit system opt-in (`{ isSystem: true }`) on its data-engine calls. Until now it reached the engine with no principal and no opt-in, and the security middleware let that through only because of its principal-less hand-off.

Clause-②: yes (widening)

- **Why `yes (widening)`:** two exported option types gain an optional `context` that an adapter must forward as-is. They are `SettingsEngine.find` / `.insert` (`@objectstack/service-settings`) and `SecretStoreEngineLike.delete` (`@objectstack/service-datasource`), so both packages take a `minor`. An implementation written against the old types still type-checks, and nothing accepted or refused at any door changes.
- **service-settings:** `SettingsService` reads and writes its own `sys_setting` rows under the opt-in: `loadRows`, plus the existence probe and insert in `upsertRow` (the update already used it). The `sys_setting_audit` writer does too.
- **service-datasource:** the `sys_metadata` helpers behind runtime datasources use the opt-in. They cover boot restore, cluster convergence, and persist and delete behind the admin doors. So do the `sys_secret` binder's `bind`, `unbind` and `resolve`.
- **plugin-webhooks:** the auto-enqueuer's subscription refresh and the redeliver guard's subscription lookup use the opt-in.
- **service-messaging:** two paths use the opt-in. One is the dispatcher's claim path: `claim`, `claimDigest` and the visibility-timeout reap on both outboxes. The other is the emit fan-out: the `sys_notification` row, the recipient's address and locale reads, the preference reads, the inbox row and the delivered receipt.
- **A user reference that names no user is still refused.** The engine skips its dangling-reference check for an `isSystem` write, so each producer that writes a user reference checks it first. The checked references are the `actor_id` of `sys_notification`, `sys_inbox_message` and `sys_setting_audit`, and the `user_id` of a user-scope `sys_setting` row. An unknown id is refused with the engine's own answer: `VALIDATION_FAILED`, one `reference_not_found` finding, and the same message. A write that names no user is unchanged.
- What each call reads and writes is otherwise unchanged. None of the gates the middleware runs before its hand-off applies to these objects.
- ⛔ No new export on any package entry, and no new elevation API.
38 changes: 19 additions & 19 deletions content/docs/permissions/tenant-audit-census.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -122,7 +122,7 @@ are reported as `undecidable` rather than assumed either way.

The same holds twice over for the context. An options argument spelled as a
literal can be read; one spelled `options`, `{ ...opts }`, or handed through a
forwarding shim cannot, and **67 of the 233 sites are spelled that way**. A
forwarding shim cannot, and **60 of the 233 sites are spelled that way**. A
context resolved from an inline literal or a local `const` can be tested for
`isSystem`; one arriving from a helper call cannot.

Expand Down Expand Up @@ -150,8 +150,8 @@ now **0**: nothing on this surface threads a context that provably lacks the fla

**"No tenant context" counted sites it had not read.** An options argument the
walker could not parse was folded into the same bucket as one it had read and
found empty. That published **84 sites "carrying no tenant context at all"**
when 17 said so and 67 were simply unread — an over-claim in the *alarming*
found empty. That published **69 sites "carrying no tenant context at all"**
when 9 said so and 60 were simply unread — an over-claim in the *alarming*
direction, on the very figure this page tells other cards to cite. `carries` is
now three-valued, and an unreadable argument can never contribute to the
provable count.
Expand Down Expand Up @@ -188,9 +188,9 @@ reproduce them. Where it disagrees, it disagrees on the page:
| carried figure | where it survives | this census |
| :--- | :--- | ---: |
| 175 write call sites | quoted in the merged changeset | **233** |
| 24 carrying no tenant context | quoted in the merged changeset | **9** provable and tenancy-enabled; **34** more whose options argument is unreadable |
| 24 carrying no tenant context | quoted in the merged changeset | **2** provable and tenancy-enabled; **33** more whose options argument is unreadable |
| 127 of 175 statically decidable, 48 runtime-parameter-name sites | restated on the `isSystem`-scoping card | **155 of 233** decidable, **78** undecidable |
| 135 (77%) silenced by the `isSystem` guard before the posture gate | the lost issue body — **no surviving corroboration** | **not reproduced**: 114 decidably elevated, 0 decidably not, 102 undecidable |
| 135 (77%) silenced by the `isSystem` guard before the posture gate | the lost issue body — **no surviving corroboration** | **not reproduced**: 121 decidably elevated, 0 decidably not, 103 undecidable |
| 141 and 132, two independent re-derivations | the card that filed this work | — |

**The differences are not reconciled, and deliberately so.** The old census's
Expand All @@ -207,14 +207,14 @@ would report a smaller number and would not say so.

The fourth row is the one worth flagging to anyone citing it. **The 135 / 77%
figure has no surviving corroboration anywhere in the tree.** This census reads
114 of 233 (49%) as decidably elevated, with 102 more whose elevation is a
121 of 233 (52%) as decidably elevated, with 103 more whose elevation is a
run-time fact — so the claim is neither confirmed nor refuted, and the honest
answer is that a static reading cannot settle it.

⇒ **Cite `9 / 233`, and say what it is**: the sites whose options argument was
⇒ **Cite `2 / 233`, and say what it is**: the sites whose options argument was
READ and holds no tenant context, against a decidably tenancy-enabled object.
That is the control's provable yield surface. ⛔ Do not cite it as "the sites
without tenant context" — **34 further sites** have an options argument this
without tenant context" — **33 further sites** have an options argument this
cannot read, and they are neither in nor out.

{/* BEGIN GENERATED: tenant-audit-census (scripts/tenant-audit-census.mjs) — DO NOT EDIT */}
Expand All @@ -228,14 +228,14 @@ cannot read, and they are neither in nor out.
| …whose object name is chosen at run time | 78 |
| …against an object with tenancy ENABLED | 154 |
| …against an object that declares tenancy off | 1 |
| threading a tenant context | 149 |
| PROVABLY carrying none (options read, no context key) | **17** |
| …of those, against a decidably tenancy-enabled object | **9** |
| options argument UNREADABLE — may or may not carry one | 67 |
| …of those, against a decidably tenancy-enabled object | 34 |
| threading a decidably ELEVATED (`isSystem`) context | 114 |
| threading a tenant context | 164 |
| PROVABLY carrying none (options read, no context key) | **9** |
| …of those, against a decidably tenancy-enabled object | **2** |
| options argument UNREADABLE — may or may not carry one | 60 |
| …of those, against a decidably tenancy-enabled object | 33 |
| threading a decidably ELEVATED (`isSystem`) context | 121 |
| threading a context that is decidably NOT elevated | 0 |
| threading a context whose elevation is a run-time fact | 102 |
| threading a context whose elevation is a run-time fact | 103 |

| how the instrument reached the site | count |
| :--- | ---: |
Expand Down Expand Up @@ -297,13 +297,13 @@ holds still. They are required to be HERE and to say WHEN they were true;
their values are not compared. The reasoning, and the measurement behind it,
are in `scripts/check-tenant-audit-census.mjs`.

Measured on 2026-10-05 at `3d34c6efd`.
Measured on 2026-10-06 at `3832674ac`.

| corpus scale (not enforced) | count |
| :--- | ---: |
| tracked non-test sources scanned | 607 |
| engine-shaped types recognised | 69 |
| tracked non-test sources scanned | 609 |
| engine-shaped types recognised | 70 |
| declared objects in the registry | 116 |
| same-named calls subtracted as non-engine | 158 |
| same-named calls subtracted as non-engine | 159 |

{/* END GENERATED: tenant-audit-census */}
46 changes: 24 additions & 22 deletions docs/audits/2026-08-tenant-audit-write-call-sites.counts.md
Original file line number Diff line number Diff line change
Expand Up @@ -38,14 +38,14 @@ silent, and `node scripts/tenant-audit-census.mjs --write` is the resolution.
| Object name chosen at run time | 78 |
| Against a tenancy-enabled object | 154 |
| Against an object declaring tenancy off | 1 |
| Threading a tenant context | 149 |
| Provably carrying none | 17 |
| …and decidably tenancy-enabled | 9 |
| Options argument unreadable | 67 |
| …and decidably tenancy-enabled | 34 |
| Threading a decidably elevated context | 114 |
| Threading a tenant context | 164 |
| Provably carrying none | 9 |
| …and decidably tenancy-enabled | 2 |
| Options argument unreadable | 60 |
| …and decidably tenancy-enabled | 33 |
| Threading a decidably elevated context | 121 |
| Threading a decidably non-elevated context | 0 |
| Threading a context of undecidable elevation | 102 |
| Threading a context of undecidable elevation | 103 |

## Subtractions the census could NOT defend — enforced

Expand Down Expand Up @@ -90,14 +90,14 @@ holds still. They are required to be HERE and to say WHEN they were true;
their values are not compared. The reasoning, and the measurement behind it,
are in `scripts/check-tenant-audit-census.mjs`.

Measured on 2026-10-05 at `3d34c6efd`.
Measured on 2026-10-06 at `3832674ac`.

| corpus scale (not enforced) | count |
| :--- | ---: |
| tracked non-test sources scanned | 607 |
| engine-shaped types recognised | 69 |
| tracked non-test sources scanned | 609 |
| engine-shaped types recognised | 70 |
| declared objects in the registry | 116 |
| same-named calls subtracted as non-engine | 158 |
| same-named calls subtracted as non-engine | 159 |

## Every site

Expand Down Expand Up @@ -208,24 +208,26 @@ Measured on 2026-10-05 at `3d34c6efd`.
| `packages/services/service-automation/src/suspended-run-store.ts` | `delete` | `sys_automation_run` | enabled | elevated | 3 |
| `packages/services/service-automation/src/suspended-run-store.ts` | `insert` | `sys_automation_run` | enabled | elevated | 2 |
| `packages/services/service-automation/src/suspended-run-store.ts` | `update` | `sys_automation_run` | enabled | elevated | 2 |
| `packages/services/service-datasource/src/datasource-admin-plugin.ts` | `delete` | `sys_metadata` | enabled | PROVABLY NONE | 1 |
| `packages/services/service-datasource/src/datasource-admin-plugin.ts` | `insert` | `sys_metadata` | enabled | PROVABLY NONE | 1 |
| `packages/services/service-datasource/src/datasource-admin-plugin.ts` | `update` | `sys_metadata` | enabled | PROVABLY NONE | 2 |
| `packages/services/service-datasource/src/datasource-secret-binder.ts` | `delete` | `sys_secret` | enabled | PROVABLY NONE | 1 |
| `packages/services/service-datasource/src/datasource-secret-binder.ts` | `insert` | `sys_secret` | enabled | PROVABLY NONE | 1 |
| `packages/services/service-datasource/src/datasource-admin-plugin.ts` | `delete` | `sys_metadata` | enabled | elevated | 1 |
| `packages/services/service-datasource/src/datasource-admin-plugin.ts` | `insert` | `sys_metadata` | enabled | elevated | 1 |
| `packages/services/service-datasource/src/datasource-admin-plugin.ts` | `update` | `sys_metadata` | enabled | elevated | 2 |
| `packages/services/service-datasource/src/datasource-secret-binder.ts` | `delete` | `sys_secret` | enabled | elevated | 1 |
| `packages/services/service-datasource/src/datasource-secret-binder.ts` | `insert` | `sys_secret` | enabled | elevated | 1 |
| `packages/services/service-job/src/db-job-adapter.ts` | `insert` | `sys_job` | enabled | elevated | 1 |
| `packages/services/service-job/src/db-job-adapter.ts` | `update` | `sys_job` | enabled | elevated | 3 |
| `packages/services/service-job/src/db-job-adapter.ts` | `insert` | `sys_job_run` | enabled | elevated | 1 |
| `packages/services/service-job/src/db-job-adapter.ts` | `update` | `sys_job_run` | enabled | elevated | 1 |
| `packages/services/service-messaging/src/inbox-channel.ts` | `insert` | `objectName` | undecidable | options unreadable | 1 |
| `packages/services/service-messaging/src/inbox-channel.ts` | `insert` | `receiptObject` | undecidable | PROVABLY NONE | 1 |
| `packages/services/service-messaging/src/inbox-channel.ts` | `insert` | `objectName` | undecidable | context, elevation undecidable | 1 |
| `packages/services/service-messaging/src/inbox-channel.ts` | `insert` | `receiptObject` | undecidable | context, elevation undecidable | 1 |
| `packages/services/service-messaging/src/messaging-service.ts` | `insert` | `RECEIPT_OBJECT` | undecidable | PROVABLY NONE | 1 |
| `packages/services/service-messaging/src/messaging-service.ts` | `update` | `RECEIPT_OBJECT` | undecidable | options unreadable | 1 |
| `packages/services/service-messaging/src/messaging-service.ts` | `insert` | `sys_notification` | enabled | options unreadable | 1 |
| `packages/services/service-messaging/src/messaging-service.ts` | `insert` | `sys_notification` | enabled | context, elevation undecidable | 1 |
| `packages/services/service-messaging/src/sql-http-outbox.ts` | `insert` | `this.objectName` | undecidable | options unreadable | 1 |
| `packages/services/service-messaging/src/sql-http-outbox.ts` | `update` | `this.objectName` | undecidable | options unreadable | 5 |
| `packages/services/service-messaging/src/sql-http-outbox.ts` | `update` | `this.objectName` | undecidable | context, elevation undecidable | 2 |
| `packages/services/service-messaging/src/sql-http-outbox.ts` | `update` | `this.objectName` | undecidable | options unreadable | 3 |
| `packages/services/service-messaging/src/sql-outbox.ts` | `insert` | `this.objectName` | undecidable | options unreadable | 1 |
| `packages/services/service-messaging/src/sql-outbox.ts` | `update` | `this.objectName` | undecidable | options unreadable | 4 |
| `packages/services/service-messaging/src/sql-outbox.ts` | `update` | `this.objectName` | undecidable | context, elevation undecidable | 3 |
| `packages/services/service-messaging/src/sql-outbox.ts` | `update` | `this.objectName` | undecidable | options unreadable | 1 |
| `packages/services/service-queue/src/db-queue-adapter.ts` | `delete` | `sys_job_queue` | enabled | context, elevation undecidable | 2 |
| `packages/services/service-queue/src/db-queue-adapter.ts` | `insert` | `sys_job_queue` | enabled | context, elevation undecidable | 1 |
| `packages/services/service-queue/src/db-queue-adapter.ts` | `update` | `sys_job_queue` | enabled | context, elevation undecidable | 6 |
Expand All @@ -235,7 +237,7 @@ Measured on 2026-10-05 at `3d34c6efd`.
| `packages/services/service-settings/src/settings-service-plugin.ts` | `delete` | `sys_secret` | enabled | elevated | 1 |
| `packages/services/service-settings/src/settings-service-plugin.ts` | `insert` | `sys_secret` | enabled | options unreadable | 1 |
| `packages/services/service-settings/src/settings-service-plugin.ts` | `update` | `sys_secret` | enabled | options unreadable | 1 |
| `packages/services/service-settings/src/settings-service-plugin.ts` | `insert` | `sys_setting_audit` | enabled | PROVABLY NONE | 1 |
| `packages/services/service-settings/src/settings-service-plugin.ts` | `insert` | `sys_setting_audit` | enabled | elevated | 1 |
| `packages/services/service-settings/src/settings-service.ts` | `insert` | `this.objectName` | undecidable | options unreadable | 1 |
| `packages/services/service-settings/src/settings-service.ts` | `update` | `this.objectName` | undecidable | options unreadable | 1 |
| `packages/services/service-storage/src/attachment-lifecycle.ts` | `update` | `sys_file` | enabled | elevated | 3 |
Expand Down
18 changes: 15 additions & 3 deletions packages/plugins/plugin-webhooks/src/auto-enqueuer.ts
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,16 @@ import {
type LegacyDefinitionCredentialKey,
} from './webhook-legacy-cleartext.js';

/**
* [#21913] The execution context the subscription cache refresh
* ({@link AutoEnqueuer.refresh}) reads `sys_webhook` under: the explicit system
* opt-in. It is the platform reading its own delivery configuration on a boot
* and timer path that has no caller, so it may not rely on a missing principal
* to pass the security middleware's principal-less hand-off, which ADR-0096 D5
* closes.
*/
const SYSTEM_CTX = { isSystem: true } as const;

/**
* The authored trigger vocabulary, taken from the spec rather than restated
* here — this file both validates authored triggers and maps events onto them,
Expand Down Expand Up @@ -378,9 +388,11 @@ export class AutoEnqueuer {
private async doRefresh(): Promise<void> {
let rows: any[];
try {
rows = await this.engine.find(this.subscriptionsObject, {
where: { active: true },
});
rows = await this.engine.find(
this.subscriptionsObject,
{ where: { active: true } },
{ context: SYSTEM_CTX },
);
} catch (err) {
this.logger?.warn?.(
`[webhook-auto-enqueuer] failed to load ${this.subscriptionsObject}`,
Expand Down
20 changes: 17 additions & 3 deletions packages/plugins/plugin-webhooks/src/redeliver-guard.ts
Original file line number Diff line number Diff line change
Expand Up @@ -59,6 +59,18 @@ import {
resolveWebhookSecret,
} from './webhook-secret.js';

/**
* [#21913] The execution context the guard reads `sys_webhook` under: the
* explicit system opt-in. The guard runs inside the messaging service's
* redeliver path, after the delivery row has been read under the requesting
* caller's organization, and reads the subscription that row belongs to only
* for its existence, name and secret posture — the inputs of the refusal
* reason it returns. What it reads and returns is unchanged by the opt-in; it
* may simply no longer rely on a missing principal to pass the security
* middleware's principal-less hand-off, which ADR-0096 D5 closes.
*/
const SYSTEM_CTX = { isSystem: true } as const;

/** The delivery-row fields this guard reads. Structural — no messaging import. */
export interface RedeliverGuardRow {
/** Producer domain; only `'webhook'` rows are this guard's business. */
Expand All @@ -79,9 +91,11 @@ export function createWebhookRedeliverGuard(
return async (row) => {
if (row.source !== 'webhook') return undefined;

const subscription = (await engine.findOne(subscriptionsObject, {
where: { id: row.refId },
})) as Record<string, unknown> | null;
const subscription = (await engine.findOne(
subscriptionsObject,
{ where: { id: row.refId } },
{ context: SYSTEM_CTX },
)) as Record<string, unknown> | null;

if (!subscription) {
return (
Expand Down
Loading
Loading