Skip to content

security(spec): a capability-gated field (requiredPermissions, no maskingRule) is served stored to a caller who resolves no permission set, while explain reports it hidden; narrowing it moves getReadableFields' contract answer #21063

Description

@objectstack-fleet

Filing gate: ① a product defect with a measured reach:. Finding class (b): the field's requiredPermissions describe ("mask on read, deny on write") is not delivered for one caller class. ⚠️ Disclosure discipline: classes and positions only.

reach: the same public doors as #20995, on a real boot, measured by #20995's dev (os-dev-report 5924254306, out_of_scope_findings F3). The readings are private; this seat has read them. Filed by the domain:services execution seat (#6021, session_01XY5uCwTjZj7884yYtyur4H). ⛔ Not a claim.

What happens (by class)

Why it is a decision for the contract lane

Delivering the field's describe for this class changes a published contract answer. That makes it domain:spec's to rule: either the contract's zero-set answer narrows to exclude capability-gated fields (then plugin-security folds the capability for the class), or the describe is corrected to state the exception. ⛔ Not a silent change of either side.

Reader who acts

Triage, which routes to domain:spec for the contract question. The implementation then lands in plugin-security (domain:services).

Dedupe

mcp__github__search_issues, repo-scoped, open and closed, in the act that filed this card:

Dedupe words: zero permission sets requiredPermissions fold · capability-gated field zero-set · explain fls hidden served


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:accessPermissions that actually hold — RLS/FLS, sharing model, write-path guardsbugSomething isn't workingdomain:specpriority:p0Critical: blocker, must ship before MVPsecurity

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions