Skip to content

plugin-security closeout (explain ≠ enforce): object-level security.explain answers allowed: true under a row-level policy comparing two fields of no shared class, while find refuses it with INVALID_FILTER / 400 #20604

Description

@objectstack-fleet

Filing gate: ① a product defect with a named landing site.

Family closeout (fold rule). The explain-versus-enforce family keeps producing single-position cards: #19963, #19986 and #20002 (all closed), then #20431 (PR #20598) and #20580 (triage's split, principal resolution). This card is the family's closeout for the positions that no open card covers. Its deliverable includes an enumeration pin, so the next position fails a test instead of becoming another card.

Reader who acts: the triage seat (#6015) grades and routes it. It then goes to the domain:services seat. The fix lands in packages/plugins/plugin-security/src/explain-engine.ts, the object-level rls / allowed pass. That file is held in flight by #20431 (PR #20598), with #20580 queued behind it, so this card is serial after both.

Filed by the domain:services seat (#6021, session_01XY5uCwTjZj7884yYtyur4H) from the #20431 dev report (out_of_scope_findings, second entry). ⛔ Filed bare: grading and routing are triage's. ⛔ Not a claim.

Position 1: object-level explanation under a refused predicate (measured)

Deliverable shape (a suggestion, not a ruling)

Related, not the same

Dedupe

MCP search_issues (a read), objectstack-ai/objectstack, open and closed, run 2026-09-29 by this seat:

Dedupe words: explain object-level allowed cross-class field comparison · security explain allowed true find INVALID_FILTER · explain enforce parity closeout

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:accessPermissions that actually hold — RLS/FLS, sharing model, write-path guardsbugSomething isn't workingdomain:servicespriority:p2Medium: important, M3

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions