Skip to content

#20802 analytics half (domain:services): the cube read and the analytics read scope answer { relation: { field: value } } as the engine seam now serves it — as the caller, capped, one answer on every face #20887

Description

@objectstack-fleet

Filing gate: ④ a coordination node, the per-layer child of #20802. It carries the half of ruling 5907789183 (maintainer 「20802 同意」) that lives in packages/services/service-analytics. Reader: the domain:services seat, which claims it once it is queued.

Filed by the domain:engine execution seat 1 (session_01DEvba2nBuD4tWzfq8r8NFY, os-support-ai), which landed the engine half. ⛔ Filed bare: routing and grading belong to triage. ⛔ Not a claim.

Why now

What the ruling asks of this half (verbatim, 5907789183)

"The same answer on every face: CRUD (engine.find, POST /api/v1/data/:object/query) and the analytics cube read the same form the same way once the seam serves it; the analytics read-scope refusal of the nested form aligns with the seam's permission rule."

What exists today (re-check at origin/main)

  • The cube read flattens the form into a dotted member (profile.verified), resolved through the cube's declared join.
    git grep -n "Nested relation (e.g." origin/main -- packages/services/service-analytics/src/strategies/filter-normalizer.ts → 1
    Whether that answers the engine's rows, runs as the caller with the related object's row scope and field permissions, and is bounded, is this card's to measure.
  • The read scope refuses the form.
    git grep -n 'non-$ key means a nested relation' origin/main -- packages/services/service-analytics/src/read-scope-sql.ts → 1

Scope for whoever takes it (⛔ not a ruling)

  • For one dataset, the cube read answers the form with the same rows the engine answers:
    • single-valued and multi-valued relations;
    • a related field the caller cannot read is refused loudly, never emptied;
    • past the cap, refused, never truncated.
      Measure the NativeSQL and ObjectQL strategies both.
  • The read scope's refusal is either lifted to serve the form under the same permission rule, or kept with words that name the served route. The seat that claims this card says which, and why.
  • ⛔ No driver change (D4 (b)). ⛔ No second copy of the permission rule.

Dedupe

mcp__github__search_issues, repo-scoped, open and closed, in the act that filed this card:

Dedupe words: 20802 analytics half · cube read nested relation filter as the caller · read scope nested relation refusal served


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions