You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
security(spec): a capability-gated field (requiredPermissions, no maskingRule) is served stored to a caller who resolves no permission set, while explain reports it hidden; narrowing it moves getReadableFields' contract answer #21063
Filing gate: ① a product defect with a measured reach:. Finding class (b): the field's requiredPermissions describe ("mask on read, deny on write") is not delivered for one caller class. ⚠️ Disclosure discipline: classes and positions only.
reach: the same public doors as #20995, on a real boot, measured by #20995's dev (os-dev-report5924254306, out_of_scope_findings F3). The readings are private; this seat has read them. Filed by the domain:services execution seat (#6021, session_01XY5uCwTjZj7884yYtyur4H). ⛔ Not a claim.
Delivering the field's describe for this class changes a published contract answer. That makes it domain:spec's to rule: either the contract's zero-set answer narrows to exclude capability-gated fields (then plugin-security folds the capability for the class), or the describe is corrected to state the exception. ⛔ Not a silent change of either side.
The four axes for the ruling: the describe and explain already say hidden, and the safe side is narrowing. The contract docblock states the opposite for this class.
Filing gate: ① a product defect with a measured⚠️ Disclosure discipline: classes and positions only.
reach:. Finding class (b): the field'srequiredPermissionsdescribe ("mask on read, deny on write") is not delivered for one caller class.reach:the same public doors as #20995, on a real boot, measured by #20995's dev (os-dev-report5924254306,out_of_scope_findingsF3). The readings are private; this seat has read them. Filed by thedomain:servicesexecution seat (#6021,session_01XY5uCwTjZj7884yYtyur4H). ⛔ Not a claim.What happens (by class)
maskingRule's describe and the result masker mask it — which one a public door serves is not measured #20995's class).requiredPermissions(an ADR-0066 D3 capability gate) and no masking rule.maskingRule's describe and the result masker mask it — which one a public door serves is not measured #20995) masked fields are masked for this class, but the capability fold is deliberately NOT carried into the zero-set stand-in.5924418816explains why: carrying the fold would narrowgetReadableFieldsfor this class. Its zero-set answer ("the full set … for a caller with no permission sets") is stated in the published contract docblock (packages/spec/src/contracts/security-service.ts, andgetMetadataReadableFieldsthere).Why it is a decision for the contract lane
Delivering the field's describe for this class changes a published contract answer. That makes it
domain:spec's to rule: either the contract's zero-set answer narrows to exclude capability-gated fields (thenplugin-securityfolds the capability for the class), or the describe is corrected to state the exception. ⛔ Not a silent change of either side.getMetadataReadableFields' docblock says the middleware skips its whole field gate for a zero-set caller. After PR fix(plugin-security)!: a caller who resolves no permission set is served a masked field masked and may not query on it #21051 that holds for the grant-based gates and not for masking.Reader who acts
Triage, which routes to
domain:specfor the contract question. The implementation then lands inplugin-security(domain:services).Dedupe
mcp__github__search_issues, repo-scoped, open and closed, in the act that filed this card:requiredPermissions在 record 块上到底是对象动作还是 ADR-0066 能力?—— 已发布的record:quick_actions那一半今天是 fail-open #19186, spec(ui):record:details,record:highlightsandrecord:related_listrefuserequiredPermissions/enforceFieldSecurity/redactFieldsby name while objectui's renderers read and honour all three —requiredPermissionsis declared on the siblingrecord:quick_actionsand nowhere else (spec half of objectui#8649) #18159, finding(plugin-hono-server): /auth/me/permissions never seeds an unrestricted object for a wildcard-only principal, so the Console renders Export where the server answers 403 EXPORT_NOT_PERMITTED #18931, A permission set accepts a hierarchyreadScopebesideviewAllRecords: true, never reads it, and emits no diagnostic — the declaration materialises and a capability census counts it as coverage #16870 and others arerequiredPermissionson UI blocks or permission sets, all closed. None is this caller class's capability fold.maskingRule's describe and the result masker mask it — which one a public door serves is not measured #20995 (masking for this class, PR fix(plugin-security)!: a caller who resolves no permission set is served a masked field masked and may not query on it #21051) and security (P0 suspect): a non-system caller who resolves no permission set — an unauthenticated one included — is admitted to aggregate any object at an analytics door, object admission and row scope skipped #21061 (object admission for this class).Dedupe words:
zero permission sets requiredPermissions fold·capability-gated field zero-set·explain fls hidden servedGenerated by Claude Code