Filing gate: ① a defect with a named landing site: the effective object-permission producer. It is buildEffectiveObjectPermissions in packages/core/src/security/effective-object-permissions.ts once PR #20079 (#18783) lands, and the inline merge in packages/plugins/plugin-hono-server/src/current-user-endpoints.ts on main until then. Finding class (a).
Blocked-by: #18783
The domain:engine execution seat 1 (session_01Bvd69VPa6puiNzzPUroDBx) filed this from its #18783 dev's measurement (os-dev-report on #18783, PR #20079; seat decision Q1 in amendment 5825601266). ⛔ Filed bare: routing and grading are triage's. ⛔ Not a claim.
What happens
Measured by the #18783 dev with the shipped sets organization_admin_no_bypass + member_default:
admin_full_access and a walled organization_admin answer true on both sides.
The map's seed admits super-read wildcards only (the #18931 fix). can() reads 「absent = no grant」, as its contract says. So a wall-less org owner or admin gets a confident silent false, the hazard the member's own docblock names.
Reach:
Suggested shape (⛔ not a ruling; the seat's direction in 5825601266)
Filing-gate answers
Dedupe words: can() wildcard · organization_admin_no_bypass can false · effective permission map wildcard coverage · me/permissions seed non-super wildcard
Generated by Claude Code
Filing gate: ① a defect with a named landing site: the effective object-permission producer. It is
buildEffectiveObjectPermissionsinpackages/core/src/security/effective-object-permissions.tsonce PR #20079 (#18783) lands, and the inline merge inpackages/plugins/plugin-hono-server/src/current-user-endpoints.tsonmainuntil then. Finding class (a).Blocked-by: #18783
The
domain:engineexecution seat 1 (session_01Bvd69VPa6puiNzzPUroDBx) filed this from its #18783 dev's measurement (os-dev-reporton #18783, PR #20079; seat decision Q1 in amendment 5825601266). ⛔ Filed bare: routing and grading are triage's. ⛔ Not a claim.What happens
Measured by the #18783 dev with the shipped sets
organization_admin_no_bypass+member_default:/auth/me/permissions→objects, and from PR feat(objectql,plugin-security,core): the server answers current_user.can() in an option's visibleWhen #20079 onISecurityService.getEffectiveObjectPermissions) has no entry for an app object (crm_account) covered only by a plain'*'grant without bypass bits;current_user.can('crm_account', 'edit')evaluates tofalse;PermissionEvaluator.checkObjectPermission('update', 'crm_account', sets)answerstrue.admin_full_accessand a walledorganization_adminanswertrueon both sides.The map's seed admits super-read wildcards only (the #18931 fix).
can()reads 「absent = no grant」, as its contract says. So a wall-less org owner or admin gets a confident silentfalse, the hazard the member's own docblock names.Reach:
toEvalPermissions(/auth/me/permissions.objects), objectui'scan()).can()-gated option is refused for that population. That direction fails closed; before PR feat(objectql,plugin-security,core): the server answers current_user.can() in an option's visibleWhen #20079 the gate was unenforced for everyone.visibleWhenlines calling.can(inexamples//packages/, against a control of 35visibleWhenlines inexamples/.Suggested shape (⛔ not a ruling; the seat's direction in 5825601266)
buildEffectiveObjectPermissions, so the one map the route and the member share becomes true tocheckObjectPermission.'*'fallback inside formula'scan(). That is consumer-side tolerance, it changescan()'s published 「absent = no grant」 rule, and it stays inexact when another set's'*'should widen a PRESENT entry./auth/me/permissionsresponse change (more entries) against its consumers.canis bound but unwalked in-repo — the nearest call site needs an ISecurityService addition the #18545 ruling does not decide #18783's body. Whether to merge the two is triage's call.Filing-gate answers
canis bound but unwalked in-repo — the nearest call site needs an ISecurityService addition the #18545 ruling does not decide #18783 dev.packages/coreisdomain:engine. The route (plugin-hono-server) isdomain:cli, andplugin-securityisdomain:services. Triage routes it.closedincluded:can wildcard permission set organization admin no bypass effective object permissions missing entry→ 2 hits, both read. finding(plugin-hono-server): /auth/me/permissions never seeds an unrestricted object for a wildcard-only principal, so the Console renders Export where the server answers 403 EXPORT_NOT_PERMITTED #18931 (closed) is the same route's super-user seeding for Export, the precedent this card extends. P0: organization_admin wildcard VAMA is contained only by the tenant wall — wall-less postures yield env-wide superusers (ADR-0105 F2 → D4) #3540 (closed) is the wall-less VAMA containment.Dedupe words:
can() wildcard·organization_admin_no_bypass can false·effective permission map wildcard coverage·me/permissions seed non-super wildcardGenerated by Claude Code