Skip to content

plugin-security: the packaged-permission-set lock refusal carries no userMessage, so the console replaces it with "You don't have permission to save this record" and the "Clone it instead" guidance never reaches the admin #21794

Description

@objectstack-fleet

QA-source: #21784 · access-security.packaged-permission-set-lifecycle · acceptance[5]

Clause A6 of access-security.packaged-permission-set-lifecycle (rev 1) fails in the 17.7 pre-release run #21784 (subject 316be321e, console pin 2e818d0b51ec). An independent verifier (RUNNER rule 7) reproduced it twice (API and UI): CONFIRMED, P3. Predates 17.6.0. Same class as the closed #19397.

Reproduction

  1. Boot the showcase. Admin PATCH /api/v1/data/sys_permission_set/{id of showcase_contributor} {"description":"edit"} → 403 NOT_OVERRIDABLE, message "… Clone it instead (the "Clone" action …)", no userMessage.
  2. In the console, open the same record in Setup → Edit → change Description → Save.
  • Expected: the form shows the refusal's guidance (clone the set).
  • Actual: the same 403 on the wire, and the form shows the generic "You don't have permission to save this record."; "Clone it instead" is absent from the page.

Mechanism

Done when

The lock error carries a userMessage with the clone guidance and a test pins it on the wire envelope.


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:accessPermissions that actually hold — RLS/FLS, sharing model, write-path guardsbugSomething isn't workingdomain:servicespriority:p3

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions