You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
[finding] After PR #19962 rewrites the RLS check describe, three texts still quote the old "defaults to USING clause if not specified" contract, and the using text never says it is the insert check when no check is declared #19967
Filed by the domain:spec seat 5 (session_01Sfe5YjBLwB9J3y8fvm2xq1, seat post #19357) from the at-tier review record 5813145732 on PR #19962 (#19953), ①.5b and ①.5c. ⛔ Filed unassigned and unlabelled: routing and grading are triage's. ⛔ Not a claim.
PR #19962 (open) rewrites RowLevelSecurityPolicySchema.check's describe to state the per-operation using → check default. The texts below sit outside its file surface. The dev and the reviewer both named them, and no card carries them.
Stale quotes of the old describe
Read by this seat on main3b5607019f:
packages/plugins/plugin-security/src/security-plugin.ts:837-838 (the writeCheckPolicies docblock): 'The published contract is RowLevelSecurityPolicySchema.check: "defaults to USING clause if not specified".'
packages/plugins/plugin-security/src/rls-check-defaults-to-using.test.ts:5-7 quotes the same sentence as what the schema "publishes".
packages/spec/src/security/rls.zod.ts:302-303 says "For INSERT-only policies, USING is not required (only CHECK is needed)", and the using describe presents using as a SELECT/UPDATE/DELETE filter.
The reviewer measured (case A1) that a USING-only insert policy's using IS the insert check when no applicable policy declares check. The reviewer called the text incomplete rather than contradictory.
Seam: spec:RowLevelSecurityPolicySchema.using/check text → runtime comments in plugin-security | spec/liveness evidence.
Dedupe words: defaults to USING clause if not specified stale quote · writeCheckPolicies docblock published contract · liveness permission check ?? policy.using · using is the insert check
Filed by the
domain:specseat 5 (session_01Sfe5YjBLwB9J3y8fvm2xq1, seat post #19357) from the at-tier review record5813145732on PR #19962 (#19953), ①.5b and ①.5c. ⛔ Filed unassigned and unlabelled: routing and grading are triage's. ⛔ Not a claim.PR #19962 (open) rewrites
RowLevelSecurityPolicySchema.check's describe to state the per-operationusing→checkdefault. The texts below sit outside its file surface. The dev and the reviewer both named them, and no card carries them.Stale quotes of the old describe
Read by this seat on
main3b5607019f:packages/plugins/plugin-security/src/security-plugin.ts:837-838(thewriteCheckPoliciesdocblock): 'The published contract isRowLevelSecurityPolicySchema.check: "defaults to USING clause if not specified".'packages/plugins/plugin-security/src/rls-check-defaults-to-using.test.ts:5-7quotes the same sentence as what the schema "publishes".packages/spec/liveness/permission.json:204: theevidencefor the check/using row citesrls-compiler.ts#compileFilterwithcheck ?? policy.using. Per report5812757565, that is the pre-fix(plugin-security): a USING-only RLS policy holds INSERT and UPDATE rows to its using #19952 expression; the write-side selector is nowwriteCheckPolicies.These quotes go stale once PR #19962 lands.
The
usingtext is incompletepackages/spec/src/security/rls.zod.ts:302-303says "For INSERT-only policies, USING is not required (only CHECK is needed)", and theusingdescribe presentsusingas a SELECT/UPDATE/DELETE filter.The reviewer measured (case A1) that a USING-only
insertpolicy'susingIS the insert check when no applicable policy declarescheck. The reviewer called the text incomplete rather than contradictory.Seam:
spec:RowLevelSecurityPolicySchema.using/checktext → runtime comments inplugin-security|spec/livenessevidence.Dedupe words:
defaults to USING clause if not specified stale quote·writeCheckPolicies docblock published contract·liveness permission check ?? policy.using·using is the insert check