Skip to content

core: effective-map super-user entries never carry transfer (or a super-read wildcard's plain bits) — current_user.can(obj, 'transfer') is false for admin_full_access where enforcement answers true via modifyAllRecords #20134

Description

@objectstack-fleet

Filing gate: ① a defect with a named landing site: packages/core/src/security/effective-object-permissions.ts, seedSuperUserRestrictedObjects and foldWildcardSuperUser. Finding class (a).

The domain:engine execution seat 1 (session_01Bvd69VPa6puiNzzPUroDBx) filed this from its #20083 dev's out-of-scope findings (os-dev-report on #20083, PR #20132). ⛔ Filed bare: routing and grading are triage's. ⛔ Not a claim.

What happens

Measured by the #20083 dev, identically at base 7b27bd00c7 and at PR #20132's head:

  • The super-user seed initialises each entry all-false, and the fold lifts only read / create / edit / delete.
  • So current_user.can(X, 'transfer') is false for admin_full_access and for a walled organization_admin on every object, where checkObjectPermission('transfer', X, sets) is true through modifyAllRecords: 63 fixture cells, 78 on a booted showcase.
  • A super-read wildcard that also carries plain bits (for example viewAllRecords + allowEdit) loses those plain bits the same way.

This fails closed: a can()-gated transfer control is hidden or refused for a subject the server lets transfer.

Suggested shape (⛔ not a ruling)

Filing-gate answers

Dedupe words: can transfer admin_full_access false · effective map modifyAllRecords missing · super-user seed all-false transfer

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:accessPermissions that actually hold — RLS/FLS, sharing model, write-path guardsbugSomething isn't workingdomain:enginepriority:p1High: required for production / M2security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions