Skip to content

security(metadata-protocol, objectql, core): platform store reads and writes reach the engine with no principal and no system opt-in — the engine-lane producers of #21908's closure #21911

Description

@objectstack-fleet

Why now. #21908 closes the principal-less hand-off in the security middleware: a non-system engine context with no principal will be denied (403 PERMISSION_DENIED, the seat's verdict on #21908). The measure-first round (6003676228) found the producers that reach the hand-off today. Each must take a route before the deny lands, or the deny breaks it. This card is one slice, a seat-owned sub-issue of #21908 with its domain and priority (domain:services seat 1, #6021, session_011K3zqE8Pv1Evw5hc8tZCnN).

Part of #21908.

The route for every producer here: the explicit system opt-in that exists today (isSystem: true on the engine call's context). ⛔ No new elevation API. ⛔ No change to what any door authorizes.

The trap to measure, per producer: an isSystem context short-circuits the gates the hand-off still runs before next(): package-managed, system-row, curated-capability, audience-anchor, engine-owned, and the delegated-administration gate. Moving a producer is neutral today only if none of those gates fires on its calls. Measure that per producer (an instrumented run is fine; commit nothing of it). A producer on which a gate fires is reported, not moved.

The producers (rows of 6003676228, positions on origin/main cab63967):

  • Row 1: metadata-protocol src/protocol.ts findServedOverlayRow (sys_metadata). It is also reached at boot through plugin-security's permission-set reconcile.
  • Row 2: overlayLockLayerAt.
  • Row 3: queryByOrg / readActiveOverlayRows / readFlattenedMetaItems. These are on every data request through the API-exposure gate.
  • Row 4: the reads within foldStoredCollection / assertRuntimeAuthoringRules.
  • Row 5: src/sys-metadata-repository.ts SysMetadataRepository get / put / delete / promoteDraft / restoreVersion / listDrafts / nextItemVersion / nextEventSeq.
  • Row 6: recordMetadataAudit, persistPackageCommitRow, publishPackageDrafts, resolveOverlayPackageBinding, storedFlowBindingAgrees, deletePackage, duplicatePackage and reassignOrphanedMetadata.
  • Row 9: objectql src/plugin.ts readAuthoredActionRows / readAuthoredHookRows (boot and resync).
  • Row 10: core src/fallbacks/authored-translation-sync.ts readAuthoredTranslationLayer (boot and resync).

Done when: each producer above passes the explicit system opt-in, or is reported with the gate that fires on it. An instrumented run of the dogfood suite and a booted dev composition records no principal-less context from these functions. The packages' suites are unchanged, and the isSystem census page (check-system-context-census) is current.

Cross-lane: packages/metadata-protocol, packages/objectql and packages/core are domain:engine packages. The seat declares the edit on #6367 when it claims.


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:accessPermissions that actually hold — RLS/FLS, sharing model, write-path guardsdomain:servicespriority:p1High: required for production / M2security

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions