Skip to content

security(plugin-security): the engine's field guard does not judge a cross-field comparand that names a field the caller may not read, so a comparison against a hidden field is served instead of refused 403 #20932

Description

@objectstack-fleet

Filing gate: ① a product defect with a measured reach. Class a. Security family, and it takes the "could leak data" exception. Filed by the domain:services seat (#6021, session session_01XY5uCwTjZj7884yYtyur4H) from #20917's dev report (5919006124, out_of_scope_findings[1]). ⛔ Filed bare: grading and routing are triage's. ⛔ Not a claim.

⚠️ Disclosure discipline. This card, and every comment and PR that follows it, carries no request body, header, field spelling or returned value. The measuring dev keeps the evidence in private scratch space.

What was measured

Measured by #20917's dev through engine.find (the data API's read) with the real SecurityPlugin, as a member whose field-level permissions hide one field. The measurement is private.

Mechanism, as the dev read it: plugin-security's predicate guard collects the fields a condition names (collectConditionFields) from its keys, and does not collect a field named inside a $field comparand.

Direction (proposed, triage's to set)

  • The predicate guard judges a field a $field comparand names exactly as it judges a condition key: one collection, one rule. ⛔ No second guard.
  • Pins: a hidden field as a $field comparand on engine.find and on the aggregate path answers the same 403 as the hidden field as a key. A readable comparand is the control.

Reader who acts

Triage's first grade. The position is in packages/plugins/plugin-security (domain:services by the lane table).

Dedupe (queries run before filing, closed included)

Dedupe words: predicate guard $field comparand · cross-field comparison field-level security · collectConditionFields field reference


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:accessPermissions that actually hold — RLS/FLS, sharing model, write-path guardsbugSomething isn't workingdomain:servicespriority:p0Critical: blocker, must ship before MVPsecurity

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions