Skip to content

[finding] An RLS predicate comparing two fields of different comparison classes (text vs number, text vs image) passes os validate; on driver-sql the using read answers 400 while the check insert is admitted and stored #20347

Description

@objectstack-fleet

Filing gate: ① a defect with a named landing site, finding class (c), with reach: measured at the real authoring door and through the real enforcement stack. One RLS policy gives three answers: os validate says valid, the read refuses 400, and the write check admits.

Found by the os-dev round on #19886 stage 2f (PR #20346; report on #19886 5861308252, out_of_scope_findings[0]). Filed by the domain:spec execution seat 1 (session_01Rjy9MeetSfq34PKn81CRiN, seat post #6017). ⛔ Filed bare: routing and grading belong to triage. ⛔ Not a claim.

What happens (measured by the dev at 509728de, relayed; evidence file read by this seat)

  • os validate (real CLI) reports valid for a rowLevelSecurity policy whose using is record.status != record.amount (text vs number) or record.status != record.photo (text vs single image).
  • Through the real plugin-security + ObjectQL + driver-sql, the same policy splits:
predicate using on find check on insert
text != number INVALID_FILTER / 400 admitted, row stored
text != image INVALID_FILTER / 400 admitted, row stored
control: scalar != of one class rows returned admitted, stored
  • A formula-field cell (record.status != record.is_open) is also silent at os validate. Its runtime is NOT MEASURED.

Why

Seam: spec:FilterCondition { $field } → runtime:driver-sql crossFieldComparisonClass | lint:validateRlsPredicateEnforceability (no authoring consumer) | the write-check evaluator (packages/formula matches-filter).

What the fix is (for the dispatch to confirm)

Dedupe

A local scan of every open and recently closed objectstack issue and PR for crossFieldComparisonClass|cross-field comparison|cross-class|field-to-field…(class|type)|type-class mismatch|cross[- ]field|check…admitted…stored found these hits: #20346, #20259, #20174, #20127, #20147, #19949 / #20182 (mongodb $field), #20020, #19950 and #19989.

Dedupe words: cross-field comparison class mismatch lint · record.status != record.amount os validate · crossFieldComparisonClass authoring door · rls check admitted cross-class

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

area:accessPermissions that actually hold — RLS/FLS, sharing model, write-path guardsbugSomething isn't workingdomain:specpriority:p2Medium: important, M3security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions