You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
core: effective-map super-user entries never carry transfer (or a super-read wildcard's plain bits) — current_user.can(obj, 'transfer') is false for admin_full_access where enforcement answers true via modifyAllRecords #20134
Filing gate: ① a defect with a named landing site: packages/core/src/security/effective-object-permissions.ts, seedSuperUserRestrictedObjects and foldWildcardSuperUser. Finding class (a).
The domain:engine execution seat 1 (session_01Bvd69VPa6puiNzzPUroDBx) filed this from its #20083 dev's out-of-scope findings (os-dev-report on #20083, PR #20132). ⛔ Filed bare: routing and grading are triage's. ⛔ Not a claim.
What happens
Measured by the #20083 dev, identically at base 7b27bd00c7 and at PR #20132's head:
The super-user seed initialises each entry all-false, and the fold lifts only read / create / edit / delete.
So current_user.can(X, 'transfer') is false for admin_full_access and for a walled organization_admin on every object, where checkObjectPermission('transfer', X, sets) is true through modifyAllRecords: 63 fixture cells, 78 on a booted showcase.
A super-read wildcard that also carries plain bits (for example viewAllRecords + allowEdit) loses those plain bits the same way.
This fails closed: a can()-gated transfer control is hidden or refused for a subject the server lets transfer.
Suggested shape (⛔ not a ruling)
Seed and fold every bit checkObjectPermission reads: allowTransfer || modifyAllRecords for transfer, and the wildcard's own plain bits beside its bypass bits.
Filing gate: ① a defect with a named landing site:
packages/core/src/security/effective-object-permissions.ts,seedSuperUserRestrictedObjectsandfoldWildcardSuperUser. Finding class (a).The
domain:engineexecution seat 1 (session_01Bvd69VPa6puiNzzPUroDBx) filed this from its #20083 dev's out-of-scope findings (os-dev-reporton #20083, PR #20132). ⛔ Filed bare: routing and grading are triage's. ⛔ Not a claim.What happens
Measured by the #20083 dev, identically at base
7b27bd00c7and at PR #20132's head:current_user.can(X, 'transfer')isfalseforadmin_full_accessand for a walledorganization_adminon every object, wherecheckObjectPermission('transfer', X, sets)istruethroughmodifyAllRecords: 63 fixture cells, 78 on a booted showcase.viewAllRecords+allowEdit) loses those plain bits the same way.This fails closed: a
can()-gatedtransfercontrol is hidden or refused for a subject the server lets transfer.Suggested shape (⛔ not a ruling)
checkObjectPermissionreads:allowTransfer || modifyAllRecordsfor transfer, and the wildcard's own plain bits beside its bypass bits.*grant, so current_user.can() agrees with checkObjectPermission for a wall-less org admin (#20083) #20132's parity table (all 10 verbs) on the super-user subjects, with 0 under-granted cells.Filing-gate answers
'*'grant, socurrent_user.can()answers false where enforcement answers true (wall-less org admins) #20083 dev.domain:engine). It is sequenced after PR fix(core): the effective object-permission map covers a plain*grant, so current_user.can() agrees with checkObjectPermission for a wall-less org admin (#20083) #20132 (security: the effective object-permission map omits objects covered only by a plain'*'grant, socurrent_user.can()answers false where enforcement answers true (wall-less org admins) #20083), in the same producer, beside the over-grant card filed with it. That is a region order, not aBlocked-by:.closedincluded:can transfer false admin_full_access modifyAllRecords effective permission map missing transfer bit→ 2 hits. [finding] grantsObjectAccess claims to mirror checkObjectPermission but omits allowTransfer AND allowExport, so an export-only or transfer-only grant reads as no object-level CRUD #19515 (closed) isgrantsObjectAccessomittingallowTransfer, a different function, and [permissions] 行级读可见范围无法按业务字段收窄:viewAllRecords 全有/全无两档之间缺共享规则 #4376 is row-level sharing.'*'grant, socurrent_user.can()answers false where enforcement answers true (wall-less org admins) #20083 and finding(plugin-hono-server): /auth/me/permissions never seeds an unrestricted object for a wildcard-only principal, so the Console renders Export where the server answers 403 EXPORT_NOT_PERMITTED #18931 are reached by the sibling query in the over-grant card.Dedupe words:
can transfer admin_full_access false·effective map modifyAllRecords missing·super-user seed all-false transfer