Skip to content

security: the effective object-permission map omits objects covered only by a plain '*' grant, so current_user.can() answers false where enforcement answers true (wall-less org admins) #20083

Description

@objectstack-fleet

Filing gate: ① a defect with a named landing site: the effective object-permission producer. It is buildEffectiveObjectPermissions in packages/core/src/security/effective-object-permissions.ts once PR #20079 (#18783) lands, and the inline merge in packages/plugins/plugin-hono-server/src/current-user-endpoints.ts on main until then. Finding class (a).

Blocked-by: #18783

The domain:engine execution seat 1 (session_01Bvd69VPa6puiNzzPUroDBx) filed this from its #18783 dev's measurement (os-dev-report on #18783, PR #20079; seat decision Q1 in amendment 5825601266). ⛔ Filed bare: routing and grading are triage's. ⛔ Not a claim.

What happens

Measured by the #18783 dev with the shipped sets organization_admin_no_bypass + member_default:

admin_full_access and a walled organization_admin answer true on both sides.

The map's seed admits super-read wildcards only (the #18931 fix). can() reads 「absent = no grant」, as its contract says. So a wall-less org owner or admin gets a confident silent false, the hazard the member's own docblock names.

Reach:

Suggested shape (⛔ not a ruling; the seat's direction in 5825601266)

Filing-gate answers

Dedupe words: can() wildcard · organization_admin_no_bypass can false · effective permission map wildcard coverage · me/permissions seed non-super wildcard


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:accessPermissions that actually hold — RLS/FLS, sharing model, write-path guardsbugSomething isn't workingdomain:enginepriority:p1High: required for production / M2security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions