Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 10 additions & 0 deletions .changeset/20596-plugin-auth-provenance-anchors.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
---
'@objectstack/plugin-auth': patch
---

Provenance comments in `plugin-auth` were re-anchored

Comment and docblock lines under `src/` that cited tracker numbers which no
longer resolve on GitHub now cite the commit in this repository's history that
decided the matter, and say in their own words what was decided. Comments
only: no type, schema, export, log or refusal text, or runtime behaviour changes.
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@
* declaration without the constraint. That population is real and reachable:
* `syncDeclaredIndexes` logs a plain UNIQUE whose CREATE fails on existing
* duplicates onto the durability channel and lets the boot continue
* (#14902 / #15479), deliberately, so one dirty table cannot take a deployment
* (commit 61821e54c / #15479), deliberately, so one dirty table cannot take a deployment
* down. `SYS_ACCOUNT_NO_UNIQUE` below is that deployment, spelled as a fixture
* — the same shape with the unique index absent.
*
Expand Down Expand Up @@ -51,7 +51,7 @@ const SYSTEM = { context: { isSystem: true } } as never;

/**
* `sys_account` as a deployment whose declared `(provider_id, account_id)`
* UNIQUE was never physically created — the #14902 / #15479 population. Only
* UNIQUE was never physically created — the commit 61821e54c / #15479 population. Only
* the columns the probe reads are spelled.
*/
const SYS_ACCOUNT_NO_UNIQUE = {
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,7 @@ import { keysetWalk } from '@objectstack/types';
*
* ⚠️ "Declared" is not "present". `syncDeclaredIndexes` logs a plain UNIQUE
* whose CREATE fails on existing duplicates onto the durability channel and
* lets the boot continue (#14902 / #15479) — deliberately, so one dirty table
* lets the boot continue (commit 61821e54c / #15479) — deliberately, so one dirty table
* cannot take a deployment down. A database that ever held duplicates therefore
* carries the declaration and not the constraint, and can still hold the class
* today.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,7 @@
* who is a platform admin under ADR-0068 (`isPlatformAdminUser`, the same
* predicate every shaded `/admin/*` mount trusts) sending a body the vendor's
* own handler would EVALUATE. Every other caller and every other body shape
* is DELEGATED through `AuthManager.handleRequest` — the #12029 gate-then-
* is DELEGATED through `AuthManager.handleRequest` — commit 6dd3e6968's gate-then-
* delegate seam — so the vendor's native bytes stand: an anonymous caller
* still gets the enveloped 401, a plain member still gets its own
* `200 {"error":null,"success":false}` negative (pinned by the non-admin
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
// Copyright (c) 2026 ObjectStack. Licensed under the Apache-2.0 license.
//
// #11477 — ORDERING PIN: on `/admin/remove-user` the break-glass guard must run
// commit 6dd3e6968 — ORDERING PIN: on `/admin/remove-user` the break-glass guard must run
// AFTER authorization, and the whole `/admin/*` family must agree on that order.
//
// ── The defect this pins, and why a pin is half the fix ─────────────────────
Expand Down
4 changes: 2 additions & 2 deletions packages/plugins/plugin-auth/src/auth-email-locale.test.ts
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@
* caller's own `Accept-Language` first (only when it names a locale in
* `AUTH_EMAIL_TEMPLATE_LOCALES`), and the deployment default second. The
* 2026-08-13 ruling had made the deployment default the whole answer and
* rejected `Accept-Language` outright. #14762 then added the rung ABOVE both,
* rejected `Accept-Language` outright. Commit 35e94c96b then added the rung ABOVE both,
* per the #14788 option-D ruling of 2026-09-03: the recipient's own
* `sys_user.locale` (#13881) when the account holds one.
*
Expand Down Expand Up @@ -479,7 +479,7 @@ describe('#14319 — authEmailLocaleFromRequest', () => {
});
});

// ── #14762 — the stored rung ───────────────────────────────────────────────
// ── commit 35e94c96b — the stored rung ─────────────────────────────────────

/**
* #14788 was ruled option D on 2026-09-03 (maintainer verbatim 「同意」):
Expand Down
16 changes: 8 additions & 8 deletions packages/plugins/plugin-auth/src/auth-manager.test.ts
Original file line number Diff line number Diff line change
Expand Up @@ -1553,7 +1553,7 @@ describe('AuthManager', () => {
});
});

// #10366 — the localhost-wildcard trio is a DEVELOPMENT convenience and is
// commit bbe643c08 — the localhost-wildcard trio is a DEVELOPMENT convenience and is
// gated on `NODE_ENV !== 'production'`. Before the gate the condition tested
// only emptiness, so a production deployment whose trusted-origin list
// resolved empty silently CSRF-trusted every `localhost` / `*.localhost`
Expand Down Expand Up @@ -2530,7 +2530,7 @@ describe('AuthManager', () => {
expect(sms.sent[0].body).toContain('verification code');
});

// ── #14762 — the recipient's own `sys_user.locale` as the top rung ──────
// ── commit 35e94c96b — the recipient's own `sys_user.locale` as the top rung
//
// #14788 was ruled option D on 2026-09-03: `sys_user.locale` when set →
// the request's `Accept-Language` → the deployment default. There is no
Expand Down Expand Up @@ -2651,7 +2651,7 @@ describe('AuthManager', () => {

// ── #14641 — the SMS INVITE path gets the same rung ──────────────────
//
// Its OWN describe, sibling to #14762 above rather than nested inside it:
// Its OWN describe, sibling to commit 35e94c96b's above, not nested inside it:
// the reporter path is what the next reader greps, and these pins answer
// for #14641, not for the card that gave the OTP send its rung.
describe("#14641 — the invitation SMS reads the invitee's own locale", () => {
Expand Down Expand Up @@ -2858,7 +2858,7 @@ describe('AuthManager', () => {
expect(data.acceptUrl).toBe('http://localhost:3000/_console/accept-invitation/tok456');
});

// #11741 — the invitation producer HOLDS an organization (the invitation
// commit b706af987 — the invitation producer HOLDS an organization (the invitation
// row's own organizationId), so it threads that exact value into
// SendTemplateInput for the sys_email.organization_id stamp. Auth mail
// that genuinely has no organization (password reset / verification /
Expand Down Expand Up @@ -4086,15 +4086,15 @@ describe('AuthManager', () => {
expect(written).toEqual(['hash:current', 'hash:old1']); // prepend + trim to 2
});

// ---- #8676: the same control, against an engine that actually STRIPS ----
// ---- commit d6e80b28b: the same control, against an engine that actually STRIPS ----
//
// ⚠️ Every test above uses `makeEngine`, which hands back the stored object
// untouched. That is a faithful model of a strip-less engine — and it is
// precisely why those tests carry NO information about #8676: once
// precisely why those tests carry NO information about commit d6e80b28b: once
// `sys_account.password` and `previous_password_hashes` are `internal:
// true`, the REAL engine omits both from this read, with no `isSystem`
// carve-out and in spite of the explicit projection (#7728's design;
// measured against a real ObjectQL engine + stub driver on #8676, which
// measured against a real ObjectQL engine + stub driver for commit d6e80b28b, which
// returned `{"id":"a1"}` for the exact query at `assertPasswordNotReused`).
// `compareList` then empties, the loop never runs, `PASSWORD_REUSE` is
// never thrown, and the method's own `catch { return undefined }` means
Expand Down Expand Up @@ -4188,7 +4188,7 @@ describe('AuthManager', () => {
});

it('⛔ the recovery is LOAD-BEARING: drop the accessor and the control provably dies', async () => {
// The falsification arm. This is the pre-#8676 shape — a stripping
// The falsification arm. This is the shape before commit d6e80b28b — a stripping
// engine with no privileged accessor — and it is what every assertion
// in this block would look like if the recovery were removed. Pinned so
// the four tests above can never pass vacuously: if the strip stopped
Expand Down
Loading
Loading