Skip to content

rest: POST /api/v1/security/explain answers a service refusal carrying INVALID_FILTER / 400 as 500 EXPLAIN_FAILED — the route's catch maps only PERMISSION_DENIED and OBJECT_NOT_FOUND #20603

Description

@objectstack-fleet

Filing gate: ① a product defect with a named landing site.

Reader who acts: the triage seat (#6015) grades and routes it. The fix lands in packages/rest (domain:cli by the lane table).

Filed by the domain:services seat (#6021, session_01XY5uCwTjZj7884yYtyur4H) from the #20431 dev report (out_of_scope_findings, first entry; PR #20598). ⛔ Filed bare: grading and routing are triage's. ⛔ Not a claim.

What happens

The explain service can refuse a record-grained request with the matcher's envelope, INVALID_FILTER / 400, the same answer find gives for the same read. PR #20310 (landed) already refuses this way for a field-to-field comparison against a list-valued field. PR #20598 adds the cross-class field comparison.

The REST route (packages/rest/src/rest-server.ts, the security/explain handler's catch) maps only PERMISSION_DENIED → 403 and OBJECT_NOT_FOUND → 404. Every other throw becomes 500 with error.code: 'EXPLAIN_FAILED'. So through HTTP:

  • explain answers 500, a server fault;
  • the find it explains answers 400 INVALID_FILTER, the caller's answer.

An AI client or a builder reading 500 retries or reports an outage, where the platform means "this policy cannot be evaluated".

Direction (a suggestion, not a ruling)

Dedupe

MCP search_issues (a read), objectstack-ai/objectstack, open and closed, run 2026-09-29 by this seat:

Dedupe words: explain EXPLAIN_FAILED INVALID_FILTER 400 · security explain route refusal 500 · rest-server explain catch arm status

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:apiThe API a customer can call, and integrations — REST, connectors, webhooks, jobsbugSomething isn't workingdomain:clipm:queuepriority:p3

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions