Skip to content

spec(security): retire rowLevelSecurity[].tags (1 key); no mainstream platform tags a row-level policy #20321

Description

@objectstack-fleet

Filing gate: ① a declared≠enforced family, filed as one sweep card per family under ruling A′ item ④ on #18900 (5727134555). This is triage's standing request 5857165909 on the seat post. Family rls-tags, seat verdict RETIRE.

  • reach: the declared authoring door. packages/spec parses this key and publishes it in the reference docs. The liveness ledger row cited below records it as not enforced, and the census re-measured the reader side (§5 cross-check C11, with a lit control).
  • The criterion is the maintainer's: 「每族该问的是:主流平台有没有这个能力 —— 有 ⇒ 补消费端(一次做对);没有 ⇒ 退役,而不是看仓里有没有人读」.
  • The maintainer's one word, per ruling A′ ④: RETIRE (the seat's proposal) or ENFORCE (build the consumer once, correctly).

Census by the domain:spec execution seat 1 (session_01Rjy9MeetSfq34PKn81CRiN, seat post #6017), 2026-09-27. ⛔ Filed bare: routing and grading belong to triage. ⛔ Not a claim. This family's rank is 16 of 16, the last one. The sibling family cards are #20273, #20274, #20281, #20282, #20287–#20289, #20294, #20295, #20299–#20301, #20312, #20313 and #20318.

Capability: Free-form tags on a row-level security policy for governance or compliance reporting

key ledger status ledger row what the ledger cites
permission.rowLevelSecurity.tags dead (verified 2026-08-10) packages/spec/liveness/permission.json:225 note: CORRECTED 2026-07-30 (was live with no evidence): no reader in either repo — governance/compliance reporting never consumes policy tags. RE-TESTED AND UPHELD 2026-08-10 (#7427) under the previews ruling (#7131), same measurement as this block's label: at …

Mainstream evidence:

  • Salesforce sharing rules, Dataverse security roles and PostgreSQL RLS policies have no tag attribute. A ServiceNow ACL has none either (whether its generic record tags apply to ACL records is UNVERIFIED, and they would be a list feature, not a policy attribute).
  • Compliance reporting in those platforms keys on the rule itself (name, object, criteria).

Verdict: RETIRE — the mainstream lacks it, or it duplicates a capability already delivered here; one batch for the family.

Reader that must exist / disposition: none; this is a retirement with a retiredKey tombstone on RowLevelSecurityPolicySchema.

User-visible risk (1): Benign organisational metadata that nothing reads (ledger).

Acceptance: Every key listed is retired by the spec-property-retirement route: a retiredKey tombstone with its prescription (the ledger row STAYS, status dead, as for every tombstone), an ADR-0087 D2 conversion or D3 entry, docs regenerated; authoring the key becomes a tsc + parse error; pnpm check:liveness green.

Lane: domain:spec (objectstack)

File surface: packages/spec/src/security/rls.zod.ts:499 · packages/spec/liveness/permission.json

Dedupe: areas\.description \| flow\.description \| hook\.(label\|description) \| rowLevelSecurity\.(label\|description\|tags) \| view\.label\b \| HookPreview → 3 open hits. None carries a key of this family:

四轴:

  • 实际业务需求: 主流平台的行级策略都没有标签,合规报表按规则本身统计。
  • 项目长远合理性: 安全面越窄越好审计。一个无人消费的自由标签只会稀释策略 schema。
  • 防 AI 写错: AI 可能用 tags 表达「仅限某角色」之类的意图,这比无效更糟。退役消除这种误读。
  • 创业阶段不扩散: 单键退役,可与本发布的其他退役合批。

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:accessPermissions that actually hold — RLS/FLS, sharing model, write-path guardsbugSomething isn't workingdomain:specpriority:p3

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions