Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
18 changes: 18 additions & 0 deletions .changeset/21908-principal-less-producers-final.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
---
"@objectstack/service-messaging": patch
"@objectstack/service-storage": patch
"@objectstack/service-settings": patch
"@objectstack/metadata-protocol": patch
---

The remaining platform producers in these four packages now pass the explicit system opt-in (`{ isSystem: true }`) on their data-engine calls. Until now they reached the engine with no principal and no opt-in, and the security middleware let that through only because of its principal-less hand-off.

Clause-②: no

- **service-messaging, the inbox read state.** `listInbox` (and its unread total), the receipt read behind it, and mark-read / mark-all-read take the opt-in inside the service. Their scope is unchanged: every read of a user's rows is keyed on the user id the door derived from the session, the receipt a mark-read inserts is stamped with it, and the receipt it updates is one a user-keyed read returned.
- **service-messaging, `owner_of:` audiences.** The record read takes the opt-in, the same posture as the email lookup beside it. It reads only `id` and the owner fields, and only the owner id leaves the resolver. An `owner_of:` audience on an object whose sharing model is `private` now resolves its owner; before, it resolved to nobody.
- **service-messaging, the rest of the fan-out and the outboxes.** The `role:` and `team:` membership reads, the email and SMS recipient reads, the notification template read, the dedup lookup in `emit()`, and both outboxes' enqueue, ack and list.
- **service-storage.** `StorageMetadataStore.createFile` and `createSession` insert under the opt-in. The organization still reaches the driver beside it, so the stored organization is unchanged, and the file's `owner_id` is still the uploading user.
- **service-settings.** The `sys_secret` store the plugin builds (insert, get, update), and the read that verifies a rotation before the old secret is reaped. A store `update` now writes the `ciphertext` it is given; without a context the engine's read-only strip dropped it. No caller in this repository uses `update`.
- **metadata-protocol.** `SysMetadataRepository.getByHash`, `list`, `history` and the history replay of `watch()`.
- None of the gates the middleware runs before its hand-off applies to these calls. ⛔ No new export on any package entry, and no new elevation API.
2 changes: 1 addition & 1 deletion content/docs/permissions/system-context.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -353,7 +353,7 @@ still holds equal to the census on every pull request:
| — in tests | 1013 | — |
| — in non-test sources | 798 | — |
| Appearances of the bare identifier `isSystem` in non-test sources | 813 | — |
| — parsed as a declaration | 26 | ✅ |
| — parsed as a declaration | 27 | ✅ |
| — parsed as an object-literal / type key (producers and option objects) | 310 | — |
| — parsed as a property **read** | 120 | ✅ |
| — parsed in some other syntactic position (a local, a cast, a conditional) | 9 | ✅ |
Expand Down
30 changes: 15 additions & 15 deletions content/docs/permissions/tenant-audit-census.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -122,7 +122,7 @@ are reported as `undecidable` rather than assumed either way.

The same holds twice over for the context. An options argument spelled as a
literal can be read; one spelled `options`, `{ ...opts }`, or handed through a
forwarding shim cannot, and **60 of the 233 sites are spelled that way**. A
forwarding shim cannot, and **54 of the 233 sites are spelled that way**. A
context resolved from an inline literal or a local `const` can be tested for
`isSystem`; one arriving from a helper call cannot.

Expand Down Expand Up @@ -150,8 +150,8 @@ now **0**: nothing on this surface threads a context that provably lacks the fla

**"No tenant context" counted sites it had not read.** An options argument the
walker could not parse was folded into the same bucket as one it had read and
found empty. That published **69 sites "carrying no tenant context at all"**
when 9 said so and 60 were simply unread — an over-claim in the *alarming*
found empty. That published **62 sites "carrying no tenant context at all"**
when 8 said so and 54 were simply unread — an over-claim in the *alarming*
direction, on the very figure this page tells other cards to cite. `carries` is
now three-valued, and an unreadable argument can never contribute to the
provable count.
Expand Down Expand Up @@ -188,9 +188,9 @@ reproduce them. Where it disagrees, it disagrees on the page:
| carried figure | where it survives | this census |
| :--- | :--- | ---: |
| 175 write call sites | quoted in the merged changeset | **233** |
| 24 carrying no tenant context | quoted in the merged changeset | **2** provable and tenancy-enabled; **33** more whose options argument is unreadable |
| 24 carrying no tenant context | quoted in the merged changeset | **2** provable and tenancy-enabled; **31** more whose options argument is unreadable |
| 127 of 175 statically decidable, 48 runtime-parameter-name sites | restated on the `isSystem`-scoping card | **155 of 233** decidable, **78** undecidable |
| 135 (77%) silenced by the `isSystem` guard before the posture gate | the lost issue body — **no surviving corroboration** | **not reproduced**: 121 decidably elevated, 0 decidably not, 103 undecidable |
| 135 (77%) silenced by the `isSystem` guard before the posture gate | the lost issue body — **no surviving corroboration** | **not reproduced**: 123 decidably elevated, 0 decidably not, 102 undecidable |
| 141 and 132, two independent re-derivations | the card that filed this work | — |

**The differences are not reconciled, and deliberately so.** The old census's
Expand All @@ -207,14 +207,14 @@ would report a smaller number and would not say so.

The fourth row is the one worth flagging to anyone citing it. **The 135 / 77%
figure has no surviving corroboration anywhere in the tree.** This census reads
121 of 233 (52%) as decidably elevated, with 103 more whose elevation is a
123 of 233 (53%) as decidably elevated, with 102 more whose elevation is a
run-time fact — so the claim is neither confirmed nor refuted, and the honest
answer is that a static reading cannot settle it.

⇒ **Cite `2 / 233`, and say what it is**: the sites whose options argument was
READ and holds no tenant context, against a decidably tenancy-enabled object.
That is the control's provable yield surface. ⛔ Do not cite it as "the sites
without tenant context" — **33 further sites** have an options argument this
without tenant context" — **31 further sites** have an options argument this
cannot read, and they are neither in nor out.

{/* BEGIN GENERATED: tenant-audit-census (scripts/tenant-audit-census.mjs) — DO NOT EDIT */}
Expand All @@ -228,14 +228,14 @@ cannot read, and they are neither in nor out.
| …whose object name is chosen at run time | 78 |
| …against an object with tenancy ENABLED | 154 |
| …against an object that declares tenancy off | 1 |
| threading a tenant context | 164 |
| PROVABLY carrying none (options read, no context key) | **9** |
| threading a tenant context | 171 |
| PROVABLY carrying none (options read, no context key) | **8** |
| …of those, against a decidably tenancy-enabled object | **2** |
| options argument UNREADABLE — may or may not carry one | 60 |
| …of those, against a decidably tenancy-enabled object | 33 |
| threading a decidably ELEVATED (`isSystem`) context | 121 |
| options argument UNREADABLE — may or may not carry one | 54 |
| …of those, against a decidably tenancy-enabled object | 31 |
| threading a decidably ELEVATED (`isSystem`) context | 123 |
| threading a context that is decidably NOT elevated | 0 |
| threading a context whose elevation is a run-time fact | 103 |
| threading a context whose elevation is a run-time fact | 102 |

| how the instrument reached the site | count |
| :--- | ---: |
Expand Down Expand Up @@ -297,11 +297,11 @@ holds still. They are required to be HERE and to say WHEN they were true;
their values are not compared. The reasoning, and the measurement behind it,
are in `scripts/check-tenant-audit-census.mjs`.

Measured on 2026-10-06 at `3832674ac`.
Measured on 2026-10-06 at `2bea8b684`.

| corpus scale (not enforced) | count |
| :--- | ---: |
| tracked non-test sources scanned | 609 |
| tracked non-test sources scanned | 612 |
| engine-shaped types recognised | 70 |
| declared objects in the registry | 116 |
| same-named calls subtracted as non-engine | 159 |
Expand Down
30 changes: 15 additions & 15 deletions docs/audits/2026-08-tenant-audit-write-call-sites.counts.md
Original file line number Diff line number Diff line change
Expand Up @@ -38,14 +38,14 @@ silent, and `node scripts/tenant-audit-census.mjs --write` is the resolution.
| Object name chosen at run time | 78 |
| Against a tenancy-enabled object | 154 |
| Against an object declaring tenancy off | 1 |
| Threading a tenant context | 164 |
| Provably carrying none | 9 |
| Threading a tenant context | 171 |
| Provably carrying none | 8 |
| …and decidably tenancy-enabled | 2 |
| Options argument unreadable | 60 |
| …and decidably tenancy-enabled | 33 |
| Threading a decidably elevated context | 121 |
| Options argument unreadable | 54 |
| …and decidably tenancy-enabled | 31 |
| Threading a decidably elevated context | 123 |
| Threading a decidably non-elevated context | 0 |
| Threading a context of undecidable elevation | 103 |
| Threading a context of undecidable elevation | 102 |

## Subtractions the census could NOT defend — enforced

Expand Down Expand Up @@ -90,11 +90,11 @@ holds still. They are required to be HERE and to say WHEN they were true;
their values are not compared. The reasoning, and the measurement behind it,
are in `scripts/check-tenant-audit-census.mjs`.

Measured on 2026-10-06 at `3832674ac`.
Measured on 2026-10-06 at `2bea8b684`.

| corpus scale (not enforced) | count |
| :--- | ---: |
| tracked non-test sources scanned | 609 |
| tracked non-test sources scanned | 612 |
| engine-shaped types recognised | 70 |
| declared objects in the registry | 116 |
| same-named calls subtracted as non-engine | 159 |
Expand Down Expand Up @@ -219,13 +219,13 @@ Measured on 2026-10-06 at `3832674ac`.
| `packages/services/service-job/src/db-job-adapter.ts` | `update` | `sys_job_run` | enabled | elevated | 1 |
| `packages/services/service-messaging/src/inbox-channel.ts` | `insert` | `objectName` | undecidable | context, elevation undecidable | 1 |
| `packages/services/service-messaging/src/inbox-channel.ts` | `insert` | `receiptObject` | undecidable | context, elevation undecidable | 1 |
| `packages/services/service-messaging/src/messaging-service.ts` | `insert` | `RECEIPT_OBJECT` | undecidable | PROVABLY NONE | 1 |
| `packages/services/service-messaging/src/messaging-service.ts` | `insert` | `RECEIPT_OBJECT` | undecidable | context, elevation undecidable | 1 |
| `packages/services/service-messaging/src/messaging-service.ts` | `update` | `RECEIPT_OBJECT` | undecidable | options unreadable | 1 |
| `packages/services/service-messaging/src/messaging-service.ts` | `insert` | `sys_notification` | enabled | context, elevation undecidable | 1 |
| `packages/services/service-messaging/src/sql-http-outbox.ts` | `insert` | `this.objectName` | undecidable | options unreadable | 1 |
| `packages/services/service-messaging/src/sql-http-outbox.ts` | `update` | `this.objectName` | undecidable | context, elevation undecidable | 2 |
| `packages/services/service-messaging/src/sql-http-outbox.ts` | `update` | `this.objectName` | undecidable | options unreadable | 3 |
| `packages/services/service-messaging/src/sql-outbox.ts` | `insert` | `this.objectName` | undecidable | options unreadable | 1 |
| `packages/services/service-messaging/src/sql-http-outbox.ts` | `insert` | `this.objectName` | undecidable | context, elevation undecidable | 1 |
| `packages/services/service-messaging/src/sql-http-outbox.ts` | `update` | `this.objectName` | undecidable | context, elevation undecidable | 4 |
| `packages/services/service-messaging/src/sql-http-outbox.ts` | `update` | `this.objectName` | undecidable | options unreadable | 1 |
| `packages/services/service-messaging/src/sql-outbox.ts` | `insert` | `this.objectName` | undecidable | context, elevation undecidable | 1 |
| `packages/services/service-messaging/src/sql-outbox.ts` | `update` | `this.objectName` | undecidable | context, elevation undecidable | 3 |
| `packages/services/service-messaging/src/sql-outbox.ts` | `update` | `this.objectName` | undecidable | options unreadable | 1 |
| `packages/services/service-queue/src/db-queue-adapter.ts` | `delete` | `sys_job_queue` | enabled | context, elevation undecidable | 2 |
Expand All @@ -235,8 +235,8 @@ Measured on 2026-10-06 at `3832674ac`.
| `packages/services/service-settings/src/settings-service-plugin.ts` | `insert` | `objectName` | undecidable | options unreadable | 1 |
| `packages/services/service-settings/src/settings-service-plugin.ts` | `update` | `objectName` | undecidable | options unreadable | 2 |
| `packages/services/service-settings/src/settings-service-plugin.ts` | `delete` | `sys_secret` | enabled | elevated | 1 |
| `packages/services/service-settings/src/settings-service-plugin.ts` | `insert` | `sys_secret` | enabled | options unreadable | 1 |
| `packages/services/service-settings/src/settings-service-plugin.ts` | `update` | `sys_secret` | enabled | options unreadable | 1 |
| `packages/services/service-settings/src/settings-service-plugin.ts` | `insert` | `sys_secret` | enabled | elevated | 1 |
| `packages/services/service-settings/src/settings-service-plugin.ts` | `update` | `sys_secret` | enabled | elevated | 1 |
| `packages/services/service-settings/src/settings-service-plugin.ts` | `insert` | `sys_setting_audit` | enabled | elevated | 1 |
| `packages/services/service-settings/src/settings-service.ts` | `insert` | `this.objectName` | undecidable | options unreadable | 1 |
| `packages/services/service-settings/src/settings-service.ts` | `update` | `this.objectName` | undecidable | options unreadable | 1 |
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -28,6 +28,7 @@
import { describe, expect, it } from 'vitest';
import { assertEngineDeleteDispatch, assertEngineUpdateDispatch, assertEngineFindOnePredicate } from '@objectstack/metadata-core';
import { ObjectStackProtocolImplementation } from './protocol.js';
import { SysMetadataRepository } from './sys-metadata-repository.js';

interface Row {
id: string;
Expand Down Expand Up @@ -294,3 +295,37 @@ describe('platform-store calls carry the explicit system opt-in (#21911)', () =>
});
});
});

describe('[#21908] row 23 — the repository reads the engine-lane slice left carry the opt-in', () => {
it('SysMetadataRepository.getByHash, list, history and watch’s replay', async () => {
const { engine, calls, historyRows } = makeStubEngine();
const protocol = new ObjectStackProtocolImplementation(engine);
await protocol.saveMetaItem({
type: 'view', name: 'proj_task_grid', item: viewBody('proj_task_grid'), mode: 'publish',
});
// The population the reads below must find, written by the save above.
expect(historyRows.length).toBeGreaterThan(0);
const hash = String(historyRows[0].checksum);
const ref = { type: 'view', name: 'proj_task_grid' } as any;
const repo = new SysMetadataRepository({ engine, organizationId: null });

await expectSystemOptIn(calls, 'getByHash', async () => {
expect(await repo.getByHash(ref, hash)).not.toBeNull();
});
await expectSystemOptIn(calls, 'list', async () => {
const headers: unknown[] = [];
for await (const h of repo.list({ type: 'view' } as any)) headers.push(h);
expect(headers).toHaveLength(1);
});
await expectSystemOptIn(calls, 'history', async () => {
const events: unknown[] = [];
for await (const e of repo.history(ref)) events.push(e);
expect(events.length).toBeGreaterThan(0);
});
await expectSystemOptIn(calls, 'replayFromHistory', async () => {
const it = repo.watch({} as any, 0)[Symbol.asyncIterator]();
expect((await it.next()).done).toBe(false);
await it.return?.();
});
});
});
12 changes: 10 additions & 2 deletions packages/metadata-protocol/src/sys-metadata-repository.ts
Original file line number Diff line number Diff line change
Expand Up @@ -496,7 +496,8 @@ export class SysMetadataRepository implements MetadataRepository {
//
// [#21911, ADR-0096] This read, and every store call of `put`, `delete`,
// `promoteDraft`, `restoreVersion`, `listDrafts` and the two lineage
// counters, carries the explicit system opt-in (`{ ...ctx, isSystem: true }`
// counters — and [#21908] the reads of `getByHash`, `list`, `history` and
// `watch`'s replay — carries the explicit system opt-in (`{ ...ctx, isSystem: true }`
// inside a transaction, so the handle rides along): the repository is
// platform plumbing under a door that already authorized the caller, and
// it scopes its own rows by organization. None of them reaches the data
Expand All @@ -520,13 +521,15 @@ export class SysMetadataRepository implements MetadataRepository {
async getByHash(ref: MetaRef, hash: string): Promise<MetadataItem | null> {
this.assertOpen();
const full = this.fullRef(ref);
// [#21908] The explicit system opt-in, as `get` carries — see its note.
const row = await this.engine.findOne(this.historyTable, {
where: {
organization_id: this.organizationId,
type: full.type,
name: full.name,
checksum: hash,
},
context: { isSystem: true },
});
if (!row) return null;
const rawBody = (row as any).metadata;
Expand Down Expand Up @@ -1189,9 +1192,11 @@ export class SysMetadataRepository implements MetadataRepository {
state: 'active',
};
if (filter.type) where.type = filter.type;
// [#21908] The explicit system opt-in, as `get` carries — see its note.
const rows = await this.engine.find('sys_metadata', {
where,
limit: filter.limit,
context: { isSystem: true },
});
for (const row of rows) {
if (filter.nameContains && !String(row.name).includes(filter.nameContains)) continue;
Expand Down Expand Up @@ -1305,7 +1310,8 @@ export class SysMetadataRepository implements MetadataRepository {
type: full.type,
name: full.name,
};
const rows = await this.engine.find(this.historyTable, { where });
// [#21908] The explicit system opt-in, as `get` carries — see its note.
const rows = await this.engine.find(this.historyTable, { where, context: { isSystem: true } });
rows.sort((a: any, b: any) => {
const va = typeof a.event_seq === 'number' ? a.event_seq : 0;
const vb = typeof b.event_seq === 'number' ? b.event_seq : 0;
Expand Down Expand Up @@ -1378,8 +1384,10 @@ export class SysMetadataRepository implements MetadataRepository {
filter: WatchFilter,
since: number,
): Promise<MetadataEvent[]> {
// [#21908] The explicit system opt-in, as `get` carries — see its note.
const rows = await this.engine.find(this.historyTable, {
where: { organization_id: this.organizationId },
context: { isSystem: true },
});
const out: MetadataEvent[] = [];
for (const row of rows as Array<Record<string, unknown>>) {
Expand Down
Loading
Loading