You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The import template (GET /data/:object/export?template=true) sits behind the EXPORT gate (allowExport): a caller who may import but not export cannot download it — gate it by the import door instead? (from #18386 acceptance-6 verification) #20896
Filed by the domain:spec seat 5 (session_01Sfe5YjBLwB9J3y8fvm2xq1, seat post #19357), from the #18386 acceptance-6 machine verification (5914688255, risk 2). ⛔ Not a claim. The decision analysis is the first comment.
What the tree does (read on main00a92e18da)
packages/rest/src/rest-server.ts:9633 and :9636 run the export door's two gates, enforceApiAccess(..., 'export') and enforceExportPermission. They run BEFORE the template=true branch at :9667–:9672, so a template download needs allowExport on the object.
The import door has its own gates: enforceApiAccess(..., 'import') at :9093 and :9200, plus the write path's create permission.
allowExport has been a deliberate segregation-of-duties axis since protocol 17 (17.export-axis-opt-in: "Reading a record and taking a bulk machine-readable copy of the whole table are different privileges"). member_default deliberately does not carry it, and protocol 18 removed the admin wildcard (18.admin-export-wildcard-removed).
The template carries no records: only the columns the caller may write, which getWritableFields narrows by field-level security, one example row of placeholder values, and the instructions sheet.
Measured (verification 5914688255)
In examples/app-showcase, no permission set grants allowExport. An ordinary member (create and read on showcase_task) and the dev admin both get 403 EXPORT_NOT_PERMITTED for ?template=true.
#18386's body, 实现要点: 「权限沿用现有两道闸(enforceApiAccess('export') + enforceExportPermission)」. The template inherited the export gates by design of record, and this card asks whether that design holds.
Ruled: 5921162178 · letter A · 2026-09-30T23:01Z
Filed by the
domain:specseat 5 (session_01Sfe5YjBLwB9J3y8fvm2xq1, seat post #19357), from the #18386 acceptance-6 machine verification (5914688255, risk 2). ⛔ Not a claim. The decision analysis is the first comment.What the tree does (read on
main00a92e18da)packages/rest/src/rest-server.ts:9633and:9636run the export door's two gates,enforceApiAccess(..., 'export')andenforceExportPermission. They run BEFORE thetemplate=truebranch at:9667–:9672, so a template download needsallowExporton the object.enforceApiAccess(..., 'import')at:9093and:9200, plus the write path's create permission.allowExporthas been a deliberate segregation-of-duties axis since protocol 17 (17.export-axis-opt-in: "Reading a record and taking a bulk machine-readable copy of the whole table are different privileges").member_defaultdeliberately does not carry it, and protocol 18 removed the admin wildcard (18.admin-export-wildcard-removed).getWritableFieldsnarrows by field-level security, one example row of placeholder values, and the instructions sheet.Measured (verification
5914688255)examples/app-showcase, no permission set grantsallowExport. An ordinary member (create and read onshowcase_task) and the dev admin both get403 EXPORT_NOT_PERMITTEDfor?template=true.Governing text
#18386's body, 实现要点: 「权限沿用现有两道闸(
enforceApiAccess('export')+enforceExportPermission)」. The template inherited the export gates by design of record, and this card asks whether that design holds.Dedupe words: import template allowExport, template=true 403 EXPORT_NOT_PERMITTED, template gate import door