Ruled: 5921156712 · letter D · 2026-09-30T23:01Z
Filed by the domain:services seat (#6021, session session_01XY5uCwTjZj7884yYtyur4H) as a decision card. #20917's dev left an open_questions entry that triage's direction does not settle: report 5919006124 on #20917, accepted in 5919159814, and escalated by the at-tier review 5919318329. #20917 has closed, so this card is the question's anchor. ⛔ Not a claim.
⚠️ Disclosure discipline (security family). This card and its comments carry no request body, header, field spelling or returned value.
The question
PR #20931 (landed as 1571aedc) judges every member an analytics query names against the caller's readable fields, at the analytics door and before either strategy runs. A member of an authored cube whose sql is an expression (for example a CASE WHEN … or a ratio of aggregates) names no single field the gate can attribute.
- What happens today, pinned: the gate stands down on such a member.
- As a result: an expression that reads a field the caller may not read is still answered on the native-SQL strategy. The ObjectQL strategy refuses expression measures outright.
- The permission rule itself is unchanged for every other position.
This is a permission-boundary question, so it is the maintainer's. Four options follow; the analysis is in Chinese in the next comment.
- A. Keep the stand-down: an authored expression is the cube author's declared derived value, like a formula field.
- B. Judge the expression's identifiers against the object's declared fields, and refuse when any is unreadable.
- C. Refuse an expression member for any caller who cannot read at least one field of the object.
- D. Retire raw expressions in a cube member's
sql at the contract (the spec lane), per ADR-0021's "zero raw expressions". A derived value then has to be declared in a form the platform can judge.
Governing text
Generated by Claude Code
Ruled: 5921156712 · letter D · 2026-09-30T23:01Z
Filed by the
domain:servicesseat (#6021, sessionsession_01XY5uCwTjZj7884yYtyur4H) as a decision card. #20917's dev left anopen_questionsentry that triage's direction does not settle: report5919006124on #20917, accepted in5919159814, and escalated by the at-tier review5919318329. #20917 has closed, so this card is the question's anchor. ⛔ Not a claim.The question
PR #20931 (landed as
1571aedc) judges every member an analytics query names against the caller's readable fields, at the analytics door and before either strategy runs. A member of an authored cube whosesqlis an expression (for example aCASE WHEN …or a ratio of aggregates) names no single field the gate can attribute.This is a permission-boundary question, so it is the maintainer's. Four options follow; the analysis is in Chinese in the next comment.
sqlat the contract (thespeclane), per ADR-0021's "zero raw expressions". A derived value then has to be declared in a form the platform can judge.Governing text
5917636106: "the gate judges the underlying fields a member resolves to, not the cube's alias". It does not address a member that resolves to no single field.packages/spec/src/data/analytics.zod.ts: a measure'ssqlis "SQL expression or field reference", and a dimension's is "SQL expression or column reference".docs/adr/0021-analytics-dataset-semantic-layer.md), design principle: "Zero raw SQL / zero raw expressions — every escape hatch is at once a hallucination source, an injection risk, and an un-reviewable blob."Generated by Claude Code