Repository navigation
docs(service-analytics): the source comments state the ruled deny for a deployment with no security service - #22299
Conversation
… a deployment with no security service Comments only. The read-admission module header, the admitObjectRead and getReadableFields docs on AnalyticsServiceConfig, the assertReadAdmitted, assertFieldsReadable and member-gate docs, the field-read-admission member gate header and the row-scope refusal doc each equated "no provider wired" with "a deployment with no security service" and said such a deployment keeps its analytics behaviour. AnalyticsServicePlugin always wires the providers, and on ObjectKernel and LiteKernel a never-registered `security` lookup throws, so the bridges take UNUSABLE and refuse, fail-closed. A comment-stripped transpile of each file is byte-identical to the base. Claude-Session: https://claude.ai/code/session_0115N1oNnQS5WqofZ2DzaT3q Co-authored-by: Claude <noreply@anthropic.com>
…ted API doc comments The edited JSDoc ships: after a rebuild the new phrases occur in dist/index.d.ts and dist/index.d.cts (and the class-member ones in dist/index.js and dist/index.cjs), and the published 17.6.0 tarball carries the old sentences in the same files. Claude-Session: https://claude.ai/code/session_0115N1oNnQS5WqofZ2DzaT3q Co-authored-by: Claude <noreply@anthropic.com>
📓 Docs Drift CheckThis PR changes 1 package(s): ⛔ 3 release-owned page(s) name something this change touched. These are read-only:
What this run could not see
Coarse fallback — 10 page(s) merely mention a changed package (the pre-#9192 predicate, kept for the deliberately-wide backstop): Which tree this was computed onThis run read A worktree cut from an older # while this PR is open — GitHub drops the merge commit once it closes
git fetch origin 8627ba999a1b8dafecc316ad1ae0bc053159c565 && git checkout 8627ba999a1b8dafecc316ad1ae0bc053159c565
# afterwards, rebuild it from the two parents, which stay fetchable
git fetch origin 238222d8cd412ca77c816fa1f849c991ed84f251 7fb9cee9875bccc483711810842f9030d55313f1 && git checkout -B drift-repro 238222d8cd412ca77c816fa1f849c991ed84f251 && git merge --no-ff 7fb9cee9875bccc483711810842f9030d55313f1
node scripts/docs-audit/affected-docs.mjs --json 238222d8cd412ca77c816fa1f849c991ed84f251
|
Part of #22279
Clause-②: no
This is the source-comment half of #22279: comments only, plus the patch changeset their published text needs. The release-owned text is in the docs-only PR #22296. The card stays open until both PRs have merged.
Why
Maintainer ruling B on #22235 (
6056824332, 「同意」, 2026-10-08), verbatim: "B — deny, as measured, becomes the declaration. On a deployment with no security service the analytics read bridges deny, fail-closed, as they do today; the bridge comments and the header ofadmission-bridge-resolution.test.tssay so; the "absent admits" sentence in the released text is corrected by a docs card, since that text is release-owned."PR #22276 (
58707166f) rewrote the bridge comments inplugin.tsand the test header to that ruling. The comments here are the ones its acceptance notes listed outside its fence. Each one equated "no provider wired" with "a deployment with no security service" and said such a deployment keeps its analytics behaviour. ThroughAnalyticsServicePlugina provider is always wired, either the host's own or the bridge. OnObjectKernelandLiteKernelthe lookup of asecurityservice that was never registered throws, so the bridges take UNUSABLE and refuse the query, fail-closed.The new text follows the
plugin.tswording onmain. ⛔ It does not say the ABSENT branch denies. ABSENT is described as reached only by a context that answers the lookup with nothing (the package's test doubles do, and no in-repo kernel does). Whether ABSENT itself should deny is not ruled.What changed (comments only)
Line positions are at base
58707166f.read-admission.ts:51-65. The ABSENT bullet is replaced by three bullets: the declared deny on a deployment with no security service, the ABSENT context, and a host that constructsAnalyticsServicewith no provider. The lead-in "but closed is a claim about a WIRED provider" goes.:59-65)analytics-service.tsAnalyticsServiceConfig.admitObjectReaddoc,:842-845analytics-service.tsAnalyticsServiceConfig.getReadableFieldsdoc,:862-866analytics-service.tsassertReadAdmitteddoc,:1899-1901(the card's:1897-1899)field-read-admission.tsassertCallerMembersJudgeableheader,:338-341:339-341)analytics-service.ts[#20917]field-level read gate doc,:1922"A no-op when no provider is wired (no security service)". It documentsassertFieldsReadablebut sits detached, directly above the member-shape gate's doc.analytics-service.tsassertCallerMembersResolvabledoc,:1935"that gate is a no-op with no security service"analytics-service.tsassertDatasetFieldsJudgeabledoc,:2061"which stands down with no security service"read-scope-refusal.tsreadScopeUnresolvedErrordoc,:96-99: "a deployment with no security service … is reported loudly at init, and it must keep running unscoped exactly as before"The four added sites (bounded in-place fix, declared here)
The card listed four sites, taken from PR #22276's acceptance notes. A census of the package's
src/for the same claim,git grep -n -i 'no .?security.? service'outside__tests__, found four more. Three are inanalytics-service.ts, a file this card already holds. The fourth is the row-scope sibling of the read-admission header. All four meet the four conditions: the same defect class as the card, a mechanical rewording to a shape the ruling already fixed, the same gates, and no other claim on the file (read-scope-refusal.tsis in none of the 12 open PRs' file lists, which were read during this run before the edit). Leaving them would keep the claim alive twenty lines below the doc this PR corrects. Reviewer: if you want any of them out, say which and it comes back in a patch round.Proof that only comments moved
For each of the four files,
ts.transpileModulewithremoveComments: truegives byte-identical output for the base file and for this head:(sha256 prefix / bytes.) Positive control: the same comparison over
read-scope-refusal.tswitherr.status = 500changed in memory to501reports the stripped outputs as different.Changeset:
patchfor@objectstack/service-analytics, notskip-changesetAGENTS.md: published means what
files[]ships, and this package ships["dist","README.md","CHANGELOG.md"]. After a rebuild of the package (under the verify lock), the edited JSDoc is in the published output:AnalyticsServiceConfigdocs) is indist/index.d.tsanddist/index.d.cts.admitObjectRead.AnalyticsServicePluginalways wires one" and "no-op with no field reader wired" (class-member docs) are in all four ofdist/index.{js,cjs,d.ts,d.cts}.dist/index.d.tsanddist/index.d.cts.read-scope-refusal.tsphrase "their lookup throws on the never-registered name" is in 0 files, because a non-exported function's doc is not emitted. A runtime string fromplugin.tsis in 2 files.The published
@objectstack/service-analytics@17.6.0tarball carries the old sentences in the same files. "the deployment has no security service, which" and "keeps its pre-existing analytics behaviour" are in itsindex.d.tsandindex.d.cts. "A no-op when no provider is wired: that is a deployment with no security" is in all four. So this diff changes published bytes and takes apatch:.changeset/22279-analytics-absent-security-comments.md.This differs from PR #22276, which carried
skip-changeset. Itsplugin.tscomments sit inside a function body, measured at 0 files underdist/. Here the comments are on an exported interface and on class members, which the build keeps.Verification (head
7fb9cee98)@objectstack/service-analyticswas built under the verify lock: its dependency closure, then the package itself.check-dts-emittedfound "2/2 declared declaration file(s) present".pnpm --filter @objectstack/service-analytics typecheckexits 0.pnpm --filter @objectstack/service-analytics exec vitest run --maxWorkers=2: "Test Files 180 passed (180)", "Tests 4443 passed | 262 skipped (4705)". These are the same counts PR fix(service-analytics): declare the measured deny on a kernel with no security service, pin it on both in-repo kernels, give the reconcile runner an explicit security double #22276 recorded.node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstackderives 58 commands. Each was run with its exit code captured before any pipe. 57 exit 0. 1 is NOT MEASURED:pnpm check:dual-build-cjs-loadsexited 3,PREREQUISITE NOT MET, because 65 workspace packages have nodist/in this worktree. A targeted substitute reading:require('./dist/index.cjs')of this package loads, with 17 exports andAnalyticsServicePlugina function.dispatch-gates --rangives: "58 derived, 57 run, 1 NOT-MEASURED, 0 UNRUN."check:dts-closurereports 75/75 declaration files across 15 built packages.check:sourcemap-no-sources-contentreports 105 maps across 15 packages, none embedding source.check:published-files,check:nul-bytes(10246 tracked files, no raw control bytes),check:doc-authoring,check-empty-changeset("1 declaring changeset(s) added") andcheck:lean-entry-closureall exit 0. Locally,check-changeset-no-majorreads its clause-② level axis as not applicable, because there is nopull_requestpayload. CI reads this body'sClause-②: no.eslint --no-inline-config --format jsonover the 4 touched source files reports 4 files, 0 errors and 0 warnings. The config's only global ignores arenode_modules,dist,build,.nextand.turbo, so all 4 files are in scope. The config never enables type-aware linting (noparserOptions.projectineslint.config.mjs), so this diff cannot change the verdict on a file it does not touch. The repo-widepnpm lintis left to CI.Acceptance notes
plugin.tsandread-admission.ts, and any change in behaviour.admission-absence-report.test.ts:199, the other the tier label atcaller-member-column-reference-gate.test.ts:109. Test names are outside this comments-only fence. Noted, not filed. Carrier: none.Generated by Claude Code