Skip to content

core: /auth/me/permissions apiOperations ignores enable.apiEnabled: false — an object the REST layer answers 404 for is annotated with the full operation list (annotateEffectiveApiOperations → resolveEffectiveApiMethods) #20135

Description

@objectstack-fleet

Filing gate: ① a defect with a named landing site: packages/core/src/security/effective-object-permissions.ts, annotateEffectiveApiOperations, which reads resolveEffectiveApiMethods. Finding class (a).

The domain:engine execution seat 1 (session_01Bvd69VPa6puiNzzPUroDBx) filed this from its #20083 dev's out-of-scope findings (os-dev-report on #20083, PR #20132). ⛔ Filed bare: routing and grading are triage's. ⛔ Not a claim.

What happens

Measured by the #20083 dev on a fixture object crm_hidden with enable.apiEnabled: false and no apiMethods, at base 7b27bd00c7 and at PR #20132's head:

  • The effective map's entry for crm_hidden carries the full apiOperations list. resolveEffectiveApiMethods derives the methods and ignores enable.apiEnabled.
  • rest-server's enforceApiAccess answers 404 for every user on that object.

So a client that renders from apiOperations offers operations the API refuses. This affects seeded super-user entries and explicit entries alike. No example app declares such an object (0 hits in examples/), so the reach is authored objects only.

Suggested shape (⛔ not a ruling)

Make annotateEffectiveApiOperations answer [] (or omit apiOperations) for an object whose enable.apiEnabled is false, reading the same resolver enforceApiAccess reads, so the two cannot diverge. Pin it against enforceApiAccess on an apiEnabled: false object and an apiMethods subset object.

Filing-gate answers

Dedupe words: apiOperations apiEnabled false · me/permissions apiOperations disabled object · annotateEffectiveApiOperations apiEnabled

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:accessPermissions that actually hold — RLS/FLS, sharing model, write-path guardsbugSomething isn't workingdomain:enginepriority:p1High: required for production / M2security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions