You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
plugin-security: the packaged-permission-set lock refusal carries no userMessage, so the console replaces it with "You don't have permission to save this record" and the "Clone it instead" guidance never reaches the admin #21794
Clause A6 of access-security.packaged-permission-set-lifecycle (rev 1) fails in the 17.7 pre-release run #21784 (subject 316be321e, console pin 2e818d0b51ec). An independent verifier (RUNNER rule 7) reproduced it twice (API and UI): CONFIRMED, P3. Predates 17.6.0. Same class as the closed #19397.
Reproduction
Boot the showcase. Admin PATCH /api/v1/data/sys_permission_set/{id of showcase_contributor} {"description":"edit"} → 403 NOT_OVERRIDABLE, message "… Clone it instead (the "Clone" action …)", no userMessage.
In the console, open the same record in Setup → Edit → change Description → Save.
Expected: the form shows the refusal's guidance (clone the set).
Actual: the same 403 on the wire, and the form shows the generic "You don't have permission to save this record."; "Clone it instead" is absent from the page.
Mechanism
packages/plugins/plugin-security/src/packaged-permission-set-lock.ts:269-287 — PackagedPermissionSetLockedError declares no userMessage. The console deliberately substitutes a generic string for an unmarked permission error (objectui form.tsx:2540-2545, the fix(sharing): 共享规则新建页 — 自定义 widget 未国际化,且「接收方」永远无可选项 #3821 contract); marking the error on the producer side is the designed channel (packages/rest/src/error-response.ts:433).
Done when
The lock error carries a userMessage with the clone guidance and a test pins it on the wire envelope.
QA-source: #21784 · access-security.packaged-permission-set-lifecycle · acceptance[5]
Clause A6 of
access-security.packaged-permission-set-lifecycle(rev 1) fails in the 17.7 pre-release run #21784 (subject316be321e, console pin2e818d0b51ec). An independent verifier (RUNNER rule 7) reproduced it twice (API and UI): CONFIRMED, P3. Predates 17.6.0. Same class as the closed #19397.Reproduction
PATCH /api/v1/data/sys_permission_set/{id of showcase_contributor} {"description":"edit"}→403 NOT_OVERRIDABLE, message "… Clone it instead (the "Clone" action …)", nouserMessage.Mechanism
packages/plugins/plugin-security/src/packaged-permission-set-lock.ts:269-287—PackagedPermissionSetLockedErrordeclares nouserMessage. The console deliberately substitutes a generic string for an unmarked permission error (objectuiform.tsx:2540-2545, the fix(sharing): 共享规则新建页 — 自定义 widget 未国际化,且「接收方」永远无可选项 #3821 contract); marking the error on the producer side is the designed channel (packages/rest/src/error-response.ts:433).Done when
The lock error carries a
userMessagewith the clone guidance and a test pins it on the wire envelope.Generated by Claude Code