Skip to content

The import template (GET /data/:object/export?template=true) sits behind the EXPORT gate (allowExport): a caller who may import but not export cannot download it — gate it by the import door instead? (from #18386 acceptance-6 verification) #20896

Description

@objectstack-fleet

Ruled: 5921162178 · letter A · 2026-09-30T23:01Z

Filed by the domain:spec seat 5 (session_01Sfe5YjBLwB9J3y8fvm2xq1, seat post #19357), from the #18386 acceptance-6 machine verification (5914688255, risk 2). ⛔ Not a claim. The decision analysis is the first comment.

What the tree does (read on main 00a92e18da)

  • packages/rest/src/rest-server.ts:9633 and :9636 run the export door's two gates, enforceApiAccess(..., 'export') and enforceExportPermission. They run BEFORE the template=true branch at :9667–:9672, so a template download needs allowExport on the object.
  • The import door has its own gates: enforceApiAccess(..., 'import') at :9093 and :9200, plus the write path's create permission.
  • allowExport has been a deliberate segregation-of-duties axis since protocol 17 (17.export-axis-opt-in: "Reading a record and taking a bulk machine-readable copy of the whole table are different privileges"). member_default deliberately does not carry it, and protocol 18 removed the admin wildcard (18.admin-export-wildcard-removed).
  • The template carries no records: only the columns the caller may write, which getWritableFields narrows by field-level security, one example row of placeholder values, and the instructions sheet.

Measured (verification 5914688255)

Governing text

#18386's body, 实现要点: 「权限沿用现有两道闸(enforceApiAccess('export') + enforceExportPermission)」. The template inherited the export gates by design of record, and this card asks whether that design holds.

Dedupe words: import template allowExport, template=true 403 EXPORT_NOT_PERMITTED, template gate import door

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions