You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
security(analytics): the native-SQL analytics path never runs engine read middlewares, so object-scoped read gates (comment threads, activity rows measured; attachments, approval payloads unmeasured) do not apply there #21080
Filing gate: ① a product defect with a measured reach:, under the possible-data-disclosure exception. This is the family card that #20833's ACCEPT (5924729189, Q1) decided to file. ⚠️ Disclosure discipline: doors, caller classes, files, functions, codes and statuses only. The door's request shape and every reading are private.
reach:measured on a real org-bound boot by #20833's dev (os-dev-report5924706600 on #20833, open question Q1 and its finding). The readings are in the dev's private scratch space, and this seat has read them. Filed by the domain:services execution seat (#6021, session_01XY5uCwTjZj7884yYtyur4H). ⛔ Not a claim.
What was measured (by class)
The caller: a signed-in member whose permission sets admit the gated object at object level, and who may not read some of the parent records the gated rows hang off.
The door: an analytics dataset read served by the native-SQL strategy on a SQL driver.
What it serves: grouped and counted results over every row of the gated object, the rows about parents this caller cannot read included.
Comment threads: a grouped read shows a thread the generic data door lists as empty for the same caller.
A count over the object equals the system total, not the count the data door serves this caller.
NOT MEASURED:
the attachment read gate (service-storage) and the approval payload redaction (plugin-approvals) on this path, which share the mechanism;
whether a multi-organization boot adds the organization predicate on this path.
The position (source read at origin/main)
packages/services/service-analytics/src/strategies/native-sql-strategy.ts compiles the query to SQL and executes it through the driver's raw-SQL seam (executeRawSql). No engine operation runs, so no engine middleware does.
It applies only the security service's answers: object admission (read-admission.ts, canReadObject) and the read filter (read-scope-sql.ts, getReadFilter).
The gates it misses are engine middlewares, registered per object:
packages/plugins/plugin-audit/src/comment-access-hooks.ts, the comment thread read gate;
Direction (the dev's recommendation, accepted for filing; ⛔ not a ruling)
Measure first, privately: each unmeasured gate above on this path, and the multi-organization predicate.
One change in the door's own package covers every such gate by construction: the analytics door serves an object that carries an engine read middleware only through the engine path, or refuses the bypassing path for it.
⛔ No per-object list in service-analytics, and ⛔ no second registration per gate.
The open design question is how the strategy learns that an object carries an engine read gate. The per-object registrations are visible inside the engine, and the global ones are not object-keyed. Whether that takes an engine-side answer (domain:engine) is triage's call.
Pins: for each gated object, the analytics read for a caller who cannot read some parents agrees with the generic data door's answer for the same caller, with an unrestricted reader as the control. No pin title states a request.
Reader who acts
Triage (grade and route). service-analytics is domain:services. An engine-side answer, if the design needs one, is domain:engine's.
Filing gate: ① a product defect with a measured⚠️ Disclosure discipline: doors, caller classes, files, functions, codes and statuses only. The door's request shape and every reading are private.
reach:, under the possible-data-disclosure exception. This is the family card that #20833's ACCEPT (5924729189, Q1) decided to file.reach:measured on a real org-bound boot by #20833's dev (os-dev-report5924706600on #20833, open question Q1 and its finding). The readings are in the dev's private scratch space, and this seat has read them. Filed by thedomain:servicesexecution seat (#6021,session_01XY5uCwTjZj7884yYtyur4H). ⛔ Not a claim.What was measured (by class)
service-storage) and the approval payload redaction (plugin-approvals) on this path, which share the mechanism;The position (source read at
origin/main)packages/services/service-analytics/src/strategies/native-sql-strategy.tscompiles the query to SQL and executes it through the driver's raw-SQL seam (executeRawSql). No engine operation runs, so no engine middleware does.read-admission.ts,canReadObject) and the read filter (read-scope-sql.ts,getReadFilter).packages/plugins/plugin-audit/src/comment-access-hooks.ts, the comment thread read gate;packages/services/service-storage/src/attachment-access-hooks.ts, the attachment read gate;packages/plugins/plugin-approvals/src/payload-redaction-middleware.ts, which is global and post-result (find and findOne only).canHandledeclines forms it cannot serve as the engine would ([spec]service-analytics' read-scope / Cube filter compilers still refuse$field, so a CEL field-to-field RLS rule 400s on those faces #7598, #20802 analytics half (domain:services): the cube read and the analytics read scope answer{ relation: { field: value } }as the engine seam now serves it — as the caller, capped, one answer on every face #20887). A declined query routes to the ObjectQL strategy, which hands it to the engine with the caller's context, so the engine's middlewares run.Direction (the dev's recommendation, accepted for filing; ⛔ not a ruling)
service-analytics, and ⛔ no second registration per gate.domain:engine) is triage's call.Reader who acts
Triage (grade and route).
service-analyticsisdomain:services. An engine-side answer, if the design needs one, isdomain:engine's.Card links:
Part of, its ACCEPT).objectstack-ai/cloud#2485's member grant stays withheld until then.Dedupe
mcp__github__search_issues, repo-scoped, open and closed, in the act that filed this card:$fieldfilter injected by the security middleware discloses the same policy column on the ordinary CRUD path, and predates #7598 #7988 (closed) are other native-path or read-scope defects: the field gate, scope placeholders, the SQL echo and policy-column disclosure.Dedupe words:
analytics native sql middleware bypass·engine read middleware analytics·comment thread visibility analytics·activity read gate analyticsGenerated by Claude Code