You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
security (P0 suspect): a non-system caller who resolves no permission set — an unauthenticated one included — is admitted to aggregate any object at an analytics door, object admission and row scope skipped #21061
Filing gate: ① a product defect with a measured reach:, under the possible-data-disclosure exception. P0 suspect, for the emergency triage path. ⚠️ Disclosure discipline: this card names doors, caller classes, codes and statuses only. Every reading is private.
reach:measured at a public door on a stock showcase boot (pnpm dev --fresh, no configuration). #20995's dev measured it during that card's reach step (os-dev-report5924254306 on #20995, out_of_scope_findings F1). The readings are in the dev's private scratch space, and this seat has read them. Filed by the domain:services execution seat (#6021, session_01XY5uCwTjZj7884yYtyur4H). ⛔ Not a claim.
What was measured (by class)
The caller class. A non-system caller whose permission-set resolution returns no set. Measured members of the class:
an unauthenticated request carried as the guest envelope;
a picker context on a deployment with no guest set registered;
on an embedder that disables the baseline, a signed-in user.
The baseline fallback covers only callers with a user id.
The door. The analytics query door (cube read) answers this caller 200 with aggregates over any object on the stock boot, platform identity objects included.
On the same boot the generic record doors answer the unauthenticated caller 401, and so does the analytics dataset door.
So the cube-read door does not apply the authentication gate its siblings apply.
Behind it, the security layer skips object admission and the row scope for a caller who resolves no set.
#20995's surface is field masking (the projection answers, the query guards, the result masker). Object admission, the row scope and the door's authentication are other positions:
in plugin-security, the permission-set-dependent admission and RLS paths that return early for an empty set;
the analytics cube-read route's authentication.
Scope for whoever takes it (⛔ not a ruling)
Measure first, privately: confirm on a stock boot which doors admit this caller class, and to which objects. Include the cube read, the SQL echo, and any other analytics face.
The safe side: a caller who resolves no permission set is not granted object-level read by the absence of sets.
Either the door requires the authentication its sibling doors require, or the security layer treats "no set resolved" as no grant for object admission and the row scope.
Which one, or both, is triage's / the owner's call. ⛔ Not a door-specific copy of the admission rule.
Pins: an unauthenticated caller and a zero-set caller are refused at each analytics face, with a signed-in member as the control. No pin states a request recipe in its title.
Reader who acts
Emergency triage (grade, route and P0 confirmation), then the owning seat. plugin-security is domain:services. The analytics route's mount may be domain:cli or domain:services, depending on where its authentication lives.
Dedupe
mcp__github__search_issues, repo-scoped, open and closed, in the act that filed this card:
Filing gate: ① a product defect with a measured⚠️ Disclosure discipline: this card names doors, caller classes, codes and statuses only. Every reading is private.
reach:, under the possible-data-disclosure exception. P0 suspect, for the emergency triage path.reach:measured at a public door on a stock showcase boot (pnpm dev --fresh, no configuration). #20995's dev measured it during that card's reach step (os-dev-report5924254306on #20995,out_of_scope_findingsF1). The readings are in the dev's private scratch space, and this seat has read them. Filed by thedomain:servicesexecution seat (#6021,session_01XY5uCwTjZj7884yYtyur4H). ⛔ Not a claim.What was measured (by class)
The baseline fallback covers only callers with a user id.
200with aggregates over any object on the stock boot, platform identity objects included.401, and so does the analytics dataset door.maskingRule's describe and the result masker mask it — which one a public door serves is not measured #20995) closes the masked-field half only: grouping or filtering by a field whose masking rule applies is now refused403for this class. Grouping by any other field, and the object admission itself, are unchanged.Why it is not closed by #20995
#20995's surface is field masking (the projection answers, the query guards, the result masker). Object admission, the row scope and the door's authentication are other positions:
plugin-security, the permission-set-dependent admission and RLS paths that return early for an empty set;Scope for whoever takes it (⛔ not a ruling)
Reader who acts
Emergency triage (grade, route and P0 confirmation), then the owning seat.
plugin-securityisdomain:services. The analytics route's mount may bedomain:cliordomain:services, depending on where its authentication lives.Dedupe
mcp__github__search_issues, repo-scoped, open and closed, in the act that filed this card:/analytics/queryor/analytics/sqlrequest writes inferred and augmented cubes into the shared registry before admission, so a refused request still changes every member'smeta#20381, [finding] service-analytics read scope: compileScopedFilterToSql applies no whole-day upper bound and binds a temporal comparand as written, so an RLS $lte on a bare day drops the rest of that day in NativeSQL analytics #20733, finding: the #7929 read-scope disclosure is NOT analytics-only — an RLS$fieldfilter injected by the security middleware discloses the same policy column on the ordinary CRUD path, and predates #7598 #7988, 降级 analytics shim 把 ExecutionContext 丢在门口 ——/analytics/query在没装 service-analytics 的装配里不注入 RLS/租户谓词,契约字段where也被静默忽略 #3891 and security(analytics): read-scope 自动桥是插件顺序依赖的 — security 晚注册则 analytics RLS 静默全关 #3618 are other analytics or RLS defects, all closed.access: privatecredential-bearing identity objects that the sets themselves declare deny-by-design #20027 (closed, the shipped sets' blanket on identity objects), a different mechanism.maskingRule's describe and the result masker mask it — which one a public door serves is not measured #20995 (this caller class's field masking, PR fix(plugin-security)!: a caller who resolves no permission set is served a masked field masked and may not query on it #21051 in review).Dedupe words:
zero permission sets object admission·sessionless caller admission·no-set caller row scope·analytics cube read unauthenticatedGenerated by Claude Code