You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
finding(objectql): deleting an organization answers 500 when a federated object is provisioned, because the cascade scan probes the remote table on the platform-injected organization_id #21910
Filing gate: ① a reproducible defect, class (a), a public door failing. Measured today by a domain:services dev run (#21868's patch round, PR #21905). Filed by domain:services seat 1 (#6021), session_011K3zqE8Pv1Evw5hc8tZCnN, for triage. ⛔ Not a claim.
What is measured (a booted showcase stack, origin/main866683f96f merged):
Once the showcase's federated fixture is provisioned, POST /api/v1/auth/organization/delete by the organization's owner answers 500 with an empty body. os dev runs that provisioner in the app's onEnable at boot. In the reproduction, a dogfood file that provisions it ran first in the same working directory.
With no fixture database present, the same delete answers 200. That is the only variable between the two runs.
Server lines at the failure:
[reference-cleanup]: the referential integrity check on showcase_ext_customer runs as SYSTEM for the delete of sys_organization, on relation field organization_id.
[sql-driver] INVALID_FILTER: no such column, organization_id.
Delete operation failed, better-auth SERVER_ERROR, and plugin-auth HTTP 500.
Mechanism, as read on origin/main (verify before acting):
ObjectQL's cascade relation scan (packages/objectql/src/engine.ts, the getAllObjects() loop near :16300) walks every registered object's lookup / master_detail fields that reference the deleted object. It has no isFederatedObject check, so it reaches a federated object's platform-injected organization_id lookup and probes the remote table on it.
Reach: every organization delete, on any deployment where a federated object is bound to a remote table with no organization_id column. The showcase app is one such deployment.
Done when: the cascade scan does not treat a federated object's platform-injected organization_id as a reference to sys_organization, and a booted pin deletes an organization with the showcase federated fixture provisioned and gets 200. That door scenario was written for #21868 (PR #21905) and moves here, because it measures this defect first. #8895's propagate disposition for a genuine probe failure stays as ruled.
Observed, not filed (test infrastructure, no runtime reach): five dogfood files run the showcase onEnable provisioner in the package working directory and leave packages/qa/dogfood/.objectstack/data/showcase_external.db behind:
showcase-external-autoconnect
federated-anchor-provenance
federated-phantom-share-grant
federated-rls-injectors
federated-sweep-projections
So whether a later showcase boot on the same runner sees the federated table depends on file order and shard composition. That is why this defect was green locally and red on CI's dogfood shard 3/3. The external-validate and external-import files chdir into a temp directory for this reason.
Positions:packages/objectql/src/engine.ts (the cascade relation scan near :16300 and its probe catch near :16535); isFederatedObject (packages/objectql/src/federated-object.ts).
Filing gate: ① a reproducible defect, class (a), a public door failing. Measured today by a
domain:servicesdev run (#21868's patch round, PR #21905). Filed bydomain:servicesseat 1 (#6021),session_011K3zqE8Pv1Evw5hc8tZCnN, for triage. ⛔ Not a claim.What is measured (a booted showcase stack,
origin/main866683f96fmerged):POST /api/v1/auth/organization/deleteby the organization's owner answers500with an empty body.os devruns that provisioner in the app'sonEnableat boot. In the reproduction, a dogfood file that provisions it ran first in the same working directory.200. That is the only variable between the two runs.[reference-cleanup]: the referential integrity check onshowcase_ext_customerruns as SYSTEM for the delete ofsys_organization, on relation fieldorganization_id.[sql-driver] INVALID_FILTER: no such column,organization_id.Delete operation failed, better-authSERVER_ERROR, and plugin-authHTTP 500.Mechanism, as read on
origin/main(verify before acting):ObjectQL's cascade relation scan (packages/objectql/src/engine.ts, thegetAllObjects()loop near:16300) walks every registered object'slookup/master_detailfields that reference the deleted object. It has noisFederatedObjectcheck, so it reaches a federated object's platform-injectedorganization_idlookup and probes the remote table on it.:16535) passes only a missing TABLE through as benign. That is ObjectQL.cascadeDeleteRelations fails OPEN: a failed dependents probe skips therestrictguard entirely, so a delete that should be refused succeeds silently #8895's discriminate or propagate ruling, and a missing COLUMN propagates by design. So every organization delete fails.buildDriverOptions(near:5520) exempts federated objects from tenant scoping;:8453routes federated targets through the caller's own read.external-datasource-federated-read: the platform injects its org-scoping predicate onto a federated remote table that has no organization_id column #7738 (closed) fixed the read-path face of the same reading. The cascade scan is the face left over.
Reach: every organization delete, on any deployment where a federated object is bound to a remote table with no
organization_idcolumn. The showcase app is one such deployment.Done when: the cascade scan does not treat a federated object's platform-injected
organization_idas a reference tosys_organization, and a booted pin deletes an organization with the showcase federated fixture provisioned and gets200. That door scenario was written for #21868 (PR #21905) and moves here, because it measures this defect first. #8895's propagate disposition for a genuine probe failure stays as ruled.Observed, not filed (test infrastructure, no runtime reach): five dogfood files run the showcase
onEnableprovisioner in the package working directory and leavepackages/qa/dogfood/.objectstack/data/showcase_external.dbbehind:showcase-external-autoconnectfederated-anchor-provenancefederated-phantom-share-grantfederated-rls-injectorsfederated-sweep-projectionsSo whether a later showcase boot on the same runner sees the federated table depends on file order and shard composition. That is why this defect was green locally and red on CI's dogfood shard 3/3. The external-validate and external-import files
chdirinto a temp directory for this reason.Duplicate check (semantic issue search, closed included):
restrictguard entirely, so a delete that should be refused succeeds silently #8895 (closed, the probe's discriminate-or-propagate ruling), external-datasource-federated-read: the platform injects its org-scoping predicate onto a federated remote table that has no organization_id column #7738 (closed, the read-path face) and feat(spec,drivers,objectql,plugin-security):organization_idNOT NULL per cleared table; one predicate for Layer 0 and every driver; bothorWhereNullarms, the__global__sentinel and the #13491 ledger retire (ADR-0131 D1/D8/D9) — protocol 18 #15212 (open, ADR-0131 organization ownership). None is this face.restrictguard entirely, so a delete that should be refused succeeds silently #8895, external-datasource-federated-read: the platform injects its org-scoping predicate onto a federated remote table that has no organization_id column #7738, ObjectQL.delete's single-id cascade is not transactional — a refusal mid-cascade leaves earlier children deleted while the response says the delete failed #7413 and data: a lookup accepts an id that does not exist in the referenced object — including the RBAC permission-set link tables #4441, all closed and none this face.Positions:
packages/objectql/src/engine.ts(the cascade relation scan near:16300and its probe catch near:16535);isFederatedObject(packages/objectql/src/federated-object.ts).Generated by Claude Code