You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
objectql: a formula field or a CEL defaultValue that calls current_user.can() gets no permission data — the formula reads a silent null on every read, the default is left unset with a warn (applyFormulaPlan, applyFieldDefaults) #20082
Filing gate: ① a defect with a named landing site: packages/objectql/src/engine.ts, applyFormulaPlan and applyFieldDefaults. Each builds its own current_user object ({ id, positions }) and passes no permissions. Finding class (a).
The domain:engine execution seat 1 (session_01Bvd69VPa6puiNzzPUroDBx) filed this from its #18783 dev's census (os-dev-report on #18783, PR #20079; seat decision Q3 in amendment 5825601266). The two rows are outside ruling A's census of PREDICATE evaluation sites, because they are value expressions, but both are reachable today. ⛔ Filed bare: routing and grading are triage's. ⛔ Not a claim.
What happens
Measured by the #18783 dev at PR #20079's head f3fe6d6cfd, with the new permission resolver registered:
applyFormulaPlan: a formula field whose expression calls current_user.can(obj, verb) reads null on every find / findOne and on the insert echo, with no log line. That is a silent wrong value.
applyFieldDefaults: a CEL defaultValue calling current_user.can() leaves the field unset and warns "Failed to evaluate default expression", with formula's "carries no permission data" refusal.
can() is a published formula capability (PR #18781). PR #20079 wires it for option visibility only.
Filing gate: ① a defect with a named landing site:
packages/objectql/src/engine.ts,applyFormulaPlanandapplyFieldDefaults. Each builds its owncurrent_userobject ({ id, positions }) and passes nopermissions. Finding class (a).Blocked-by: #18783
The
domain:engineexecution seat 1 (session_01Bvd69VPa6puiNzzPUroDBx) filed this from its #18783 dev's census (os-dev-reporton #18783, PR #20079; seat decision Q3 in amendment 5825601266). The two rows are outside ruling A's census of PREDICATE evaluation sites, because they are value expressions, but both are reachable today. ⛔ Filed bare: routing and grading are triage's. ⛔ Not a claim.What happens
Measured by the #18783 dev at PR #20079's head
f3fe6d6cfd, with the new permission resolver registered:applyFormulaPlan: a formula field whose expression callscurrent_user.can(obj, verb)readsnullon everyfind/findOneand on the insert echo, with no log line. That is a silent wrong value.applyFieldDefaults: a CELdefaultValuecallingcurrent_user.can()leaves the field unset and warns "Failed to evaluate default expression", with formula's "carries no permission data" refusal.can()is a published formula capability (PR #18781). PR #20079 wires it for option visibility only.Suggested shape (⛔ not a ruling)
ObjectQL.registerEffectiveObjectPermissionsResolver→toEvalPermissions). Resolve once per operation, not per row. Keep the member docblock's rules: a throw fails closed, and an absent member passes NO map.null. Measure and pin both.references/compile-surfaces.mdif a filter face is touched (not expected).Filing-gate answers
canis bound but unwalked in-repo — the nearest call site needs an ISecurityService addition the #18545 ruling does not decide #18783 dev.domain:engine, the owner ofpackages/objectql), after PR feat(objectql,plugin-security,core): the server answers current_user.can() in an option's visibleWhen #20079 lands (Blocked-by: #18783).closedincluded:formula field defaultValue current_user.can returns null no permission data applyFormulaPlan applyFieldDefaults→ 0 hits;formula field current_user can permissions null→ 0 hits.current_user.can receiver-only EvalContext permissions bound→ 1 hit ([finding] nothing on the server side populates EvalContext.permissions, socanis bound but unwalked in-repo — the nearest call site needs an ISecurityService addition the #18545 ruling does not decide #18783), so the population is reachable.Dedupe words:
formula field can() null·applyFormulaPlan permissions·defaultValue can() unset·applyFieldDefaults permissionsGenerated by Claude Code