Skip to content

security: the effective permission map folds a super-user '*' over the same set's narrower explicit entries — a walled org admin gets can('sys_position','edit') true where enforcement refuses #20136

Description

@objectstack-fleet

Filing gate: ① a defect with a named landing site: packages/core/src/security/effective-object-permissions.ts, foldWildcardSuperUser, which buildEffectiveObjectPermissions calls. Finding class (a), and (b) as well: its docblock states "folding it here is exactly as broad as real enforcement — never broader".

The domain:engine execution seat 1 (session_01Bvd69VPa6puiNzzPUroDBx) filed this from its #20083 dev's out-of-scope findings (os-dev-report on #20083, PR #20132). ⛔ Filed bare: routing and grading are triage's. ⛔ Not a claim.

What happens

Measured by the #20083 dev, identically at origin/main 7b27bd00c7 and at PR #20132's head, on a unit fixture and on a booted showcase:

  • For a walled organization_admin (+ member_default), the map grants create / edit / delete / import on sys_position, sys_permission_set, sys_position_permission_set, sys_user_permission_set and sys_user_position, and edit on sys_organization.
  • PermissionEvaluator.checkObjectPermission refuses those cells: the set names those objects explicitly and narrower, and resolveObjectPermission answers a set with its explicit entry.
  • 38 over-granted cells in total.
  • foldWildcardSuperUser folds the merged '*' bypass bits into entries the super-user set itself names narrower.

Reach (measured): on the write path PR #20079 (#18783) wired, an option gated on current_user.can('sys_position', 'edit') is ADMITTED for that subject. That fails OPEN. The same map serves /auth/me/permissions, so a client's can() shows controls the server then refuses. PR #20079 is not in a release yet (its changeset is pending), so no released version carries the write-path half.

Suggested shape (⛔ not a ruling)

Filing-gate answers

Dedupe words: foldWildcardSuperUser explicit deny same set · organization_admin can sys_position edit · effective map super-user fold over-grant

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:accessPermissions that actually hold — RLS/FLS, sharing model, write-path guardsbugSomething isn't workingdomain:enginepriority:p1High: required for production / M2security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions