Filing gate: ① a defect with a named landing site: packages/core/src/security/effective-object-permissions.ts, annotateEffectiveApiOperations, which reads resolveEffectiveApiMethods. Finding class (a).
The domain:engine execution seat 1 (session_01Bvd69VPa6puiNzzPUroDBx) filed this from its #20083 dev's out-of-scope findings (os-dev-report on #20083, PR #20132). ⛔ Filed bare: routing and grading are triage's. ⛔ Not a claim.
What happens
Measured by the #20083 dev on a fixture object crm_hidden with enable.apiEnabled: false and no apiMethods, at base 7b27bd00c7 and at PR #20132's head:
- The effective map's entry for
crm_hidden carries the full apiOperations list. resolveEffectiveApiMethods derives the methods and ignores enable.apiEnabled.
rest-server's enforceApiAccess answers 404 for every user on that object.
So a client that renders from apiOperations offers operations the API refuses. This affects seeded super-user entries and explicit entries alike. No example app declares such an object (0 hits in examples/), so the reach is authored objects only.
Suggested shape (⛔ not a ruling)
Make annotateEffectiveApiOperations answer [] (or omit apiOperations) for an object whose enable.apiEnabled is false, reading the same resolver enforceApiAccess reads, so the two cannot diverge. Pin it against enforceApiAccess on an apiEnabled: false object and an apiMethods subset object.
Filing-gate answers
Dedupe words: apiOperations apiEnabled false · me/permissions apiOperations disabled object · annotateEffectiveApiOperations apiEnabled
Filing gate: ① a defect with a named landing site:
packages/core/src/security/effective-object-permissions.ts,annotateEffectiveApiOperations, which readsresolveEffectiveApiMethods. Finding class (a).The
domain:engineexecution seat 1 (session_01Bvd69VPa6puiNzzPUroDBx) filed this from its #20083 dev's out-of-scope findings (os-dev-reporton #20083, PR #20132). ⛔ Filed bare: routing and grading are triage's. ⛔ Not a claim.What happens
Measured by the #20083 dev on a fixture object
crm_hiddenwithenable.apiEnabled: falseand noapiMethods, at base7b27bd00c7and at PR #20132's head:crm_hiddencarries the fullapiOperationslist.resolveEffectiveApiMethodsderives the methods and ignoresenable.apiEnabled.rest-server'senforceApiAccessanswers 404 for every user on that object.So a client that renders from
apiOperationsoffers operations the API refuses. This affects seeded super-user entries and explicit entries alike. No example app declares such an object (0 hits inexamples/), so the reach is authored objects only.Suggested shape (⛔ not a ruling)
Make
annotateEffectiveApiOperationsanswer[](or omitapiOperations) for an object whoseenable.apiEnabledisfalse, reading the same resolverenforceApiAccessreads, so the two cannot diverge. Pin it againstenforceApiAccesson anapiEnabled: falseobject and anapiMethodssubset object.Filing-gate answers
'*'grant, socurrent_user.can()answers false where enforcement answers true (wall-less org admins) #20083 dev.domain:engine, the owner ofpackages/core's producer). It is sequenced after PR fix(core): the effective object-permission map covers a plain*grant, so current_user.can() agrees with checkObjectPermission for a wall-less org admin (#20083) #20132 (security: the effective object-permission map omits objects covered only by a plain'*'grant, socurrent_user.can()answers false where enforcement answers true (wall-less org admins) #20083), in the same file.closedincluded:apiOperations apiEnabled false me/permissions annotateEffectiveApiOperations resolveEffectiveApiMethods→ 2 hits, both closed: OBJECT_API_METHOD_NOT_ALLOWED names an operation its ownallowedarray contains — the refusal reports the conjunct that PASSED #15416 (a refusal naming a passing conjunct) andreconcileManagedApiMethodsstrips declared verbs with only a console.warn — a declared≠enforced split can live indefinitely unseen (found via cloud#1225) #7521 (reconcileManagedApiMethodswarn-only). Neither coversapiEnabledinapiOperations.reconcileManagedApiMethodsstrips declared verbs with only a console.warn — a declared≠enforced split can live indefinitely unseen (found via cloud#1225) #7521).Dedupe words:
apiOperations apiEnabled false·me/permissions apiOperations disabled object·annotateEffectiveApiOperations apiEnabled