Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -118,7 +118,7 @@ async function boot(ctx: any, options: Record<string, unknown> = {}) {
return plugin;
}

describe('[#10036] the "nothing is enforced" warning must fire when SecurityPlugin.start() bailed', () => {
describe('the "nothing is enforced" warning must fire when SecurityPlugin.start() bailed', () => {
// ── The state the warning describes, constructed for real ───────────────
//
// SecurityPlugin registers `security.permissions` / `security.rls` /
Expand Down
8 changes: 4 additions & 4 deletions packages/qa/dogfood/test/armed.ts
Original file line number Diff line number Diff line change
Expand Up @@ -133,9 +133,9 @@ export async function assertArmed(probes: readonly ArmingProbe[]): Promise<void>
if (!Array.isArray(probes) || probes.length === 0) {
throw new Error(
'assertArmed(): the arming declaration is EMPTY, which asserts nothing. An empty ' +
'declaration would certify every fixture that forgot to write one — the exact defect ' +
'class this helper exists to close (#8074). Name at least one control, or do not call ' +
'assertArmed at all and say in the fixture header why no precondition applies.',
'declaration would certify every fixture that forgot to write one — the exact defect class this ' +
'helper exists to close, a fixture that passes while the control it measures is not engaged. Name ' +
'at least one control, or do not call assertArmed at all and say in the fixture header why no precondition applies.',
);
}

Expand All @@ -159,7 +159,7 @@ export async function assertArmed(probes: readonly ArmingProbe[]): Promise<void>

if (disarmed.length > 0) {
throw new Error(
`[#8074] this fixture is DISARMED: ${disarmed.length} of ${probes.length} control(s) it ` +
`assertArmed(): this fixture is DISARMED: ${disarmed.length} of ${probes.length} control(s) it ` +
'measures are not engaged on the booted stack, so its assertions would pass without ' +
'testing anything.\n\n' +
`${disarmed.join('\n\n')}\n\n` +
Expand Down
6 changes: 3 additions & 3 deletions packages/qa/dogfood/test/build-shaped-artifact.ts
Original file line number Diff line number Diff line change
Expand Up @@ -189,7 +189,7 @@ export function buildShapedArtifact(stack: Record<string, unknown>): BuildShaped
`declares ${expected.length} (${expected.join(', ') || 'none'}). Either a callable was ` +
`dropped, or \`lowerCallables\` grew a slot \`callableSlots\` in ` +
`packages/qa/dogfood/test/build-shaped-artifact.ts does not know about — fix the walk, ` +
`never the assertion (#6293).`,
`never the assertion.`,
);
}

Expand Down Expand Up @@ -222,7 +222,7 @@ export function buildShapedArtifact(stack: Record<string, unknown>): BuildShaped
`without a sound — ${dropped.join(', ')}. An entry it does not recognise is deleted ` +
`rather than handed to the schema, so the artifact would parse green carrying nothing ` +
`where these were. Most likely the entry is a headless husk (an object with an effect ` +
`and no handler), which is what a plain \`JSON.stringify\` of the stack leaves (#6293).`,
`and no handler), which is what a plain \`JSON.stringify\` of the stack leaves.`,
);
}
}
Expand Down Expand Up @@ -262,7 +262,7 @@ export function buildShapedArtifact(stack: Record<string, unknown>): BuildShaped
if (leftover.length > 0) {
throw new Error(
`build-shaped artifact: ${leftover.length} value(s) are still functions after lowering and ` +
`would be dropped by JSON.stringify without a sound: ${leftover.join(', ')} (#6293).`,
`would be dropped by JSON.stringify without a sound: ${leftover.join(', ')}.`,
);
}

Expand Down
2 changes: 1 addition & 1 deletion packages/qa/dogfood/test/enterprise-organizations.ts
Original file line number Diff line number Diff line change
Expand Up @@ -181,7 +181,7 @@ export async function probeOrganizations(
'problem — the package publishes no entry Node can load, and the importer\'s ' +
'message below is the authority on what it has to publish'
: `declare ${pkg} in ${root}'s own package.json and install it — being ` +
'reachable as somebody else\'s transitive dependency is not enough (#4719)';
'reachable as somebody else\'s transitive dependency is not enough';
if (declared) {
throw new Error(
`${MULTI_ORG_ENV}=1 declares that ${pkg} (enterprise, ADR-0105 D12) is ` +
Expand Down
12 changes: 6 additions & 6 deletions packages/qa/dogfood/test/expression-conformance.ledger.ts
Original file line number Diff line number Diff line change
Expand Up @@ -141,7 +141,7 @@ export const EXPRESSION_SURFACE: ExprSurface[] = [
},
{
id: 'sharing-condition',
summary: 'sharing-rule `condition` → criteria_json (ADR-0058 D3, closes #1887)',
summary: 'sharing-rule `condition` → criteria_json (ADR-0058 D3: compiled from the authored CEL, a faithful lowering rather than a divergent hand-written filter)',
dialect: 'cel', mode: 'compile', state: 'enforced', failPolicy: 'fail-closed',
enforcement: 'plugin-sharing/bootstrap-declared-sharing-rules.ts celToFilter → compileCelToFilter; matched by sharing-rule-service findMatchingRecords',
covers: ['security/sharing.zod.ts:CriteriaSharingRuleSchema.condition'],
Expand Down Expand Up @@ -290,7 +290,7 @@ export const EXPRESSION_SURFACE: ExprSurface[] = [
// from the schema.
dialect: 'settings-visibility', mode: 'interpret', state: 'enforced', failPolicy: 'fail-closed',
enforcement:
'service-settings `evaluateVisibility` (visibility-eval.ts), called from `SettingsService.validatePatch` — a closed grammar: single root `data`, one-level member access, `|| && !`, `=== !== == != >= <= > <`, parens, and string/number/bool/null literals, optionally `${…}`-wrapped, as a bare string or a `{dialect, source}` envelope. Fail-closed since #7310: a predicate outside the grammar REFUSES the save (SettingsValidationError, HTTP 400) instead of skipping the specifier — `visible` gates every other check on the key (`required`, `options`, `pattern`, `valueDomain`, the value window), so skipping it switched all of them off at once. The console evaluates the same string client-side through `new Function(...)`. Since #7327 the spec DECLARES that same grammar (`SettingsVisibilityInputSchema`), so it is refused at publish/parse too',
'service-settings `evaluateVisibility` (visibility-eval.ts), called from `SettingsService.validatePatch` — a closed grammar: single root `data`, one-level member access, `|| && !`, `=== !== == != >= <= > <`, parens, and string/number/bool/null literals, optionally `${…}`-wrapped, as a bare string or a `{dialect, source}` envelope. Fail-closed: a predicate outside the grammar REFUSES the save (SettingsValidationError, HTTP 400) instead of skipping the specifier — `visible` gates every other check on the key (`required`, `options`, `pattern`, `valueDomain`, the value window), so skipping it switched all of them off at once. The console evaluates the same string client-side through `new Function(...)`. The spec DECLARES that same grammar (`SettingsVisibilityInputSchema`) rather than CEL, so it is refused at publish/parse too',
covers: ['system/settings-manifest.zod.ts:SpecifierSchema.visible', 'system/settings-manifest.zod.ts:SettingsManifestSchema.visible'],
// Proof is the producer/consumer pin rather than a runtime fixture: the
// failure mode this surface actually has is the two sides disagreeing about
Expand All @@ -300,7 +300,7 @@ export const EXPRESSION_SURFACE: ExprSurface[] = [
},
{
id: 'cel-action-param-option-visible',
summary: "action param option-list per-option gating (params[].options[].visibleWhen, #5016)",
summary: "action param option-list per-option gating (params[].options[].visibleWhen, the same per-option key a field's option list declares)",
// Same key, same evaluator and same binding environment as the per-option
// `visibleWhen` on a FIELD's option list — which is why it is `cel`,
// `interpret` and `fail-soft-log` like `cel-field-rule` rather than
Expand All @@ -316,7 +316,7 @@ export const EXPRESSION_SURFACE: ExprSurface[] = [
},
{
id: 'cel-bulk-action-visible',
summary: "selection-bar bulk action per-record eligibility (bulkActionDefs[].visible, objectui#3067)",
summary: "selection-bar bulk action per-record eligibility (bulkActionDefs[].visible)",
dialect: 'cel', mode: 'interpret', state: 'enforced', failPolicy: 'fail-closed',
enforcement: 'console (objectui) partitionBulkRows (plugin-grid/bulkEligibility.ts) → evalRowPredicate → @objectstack/formula celEngine (interpret), evaluated ONCE PER SELECTED RECORD with that record bound: the button is offered when at least one selected record passes, and the run covers only those — the rest are reported as skipped in the dialog. Faults hide the record (fallback:false, warnOnError) rather than acting on one the predicate was written to exclude; UI gating only, write enforcement stays with permissions/hooks',
// Reached the ledger in #4457, not #3067: the key existed and was evaluated
Expand All @@ -340,14 +340,14 @@ export const EXPRESSION_SURFACE: ExprSurface[] = [
},
{
id: 'cel-row-crud-visible',
summary: 'built-in row Edit/Delete per-record visibility (RowCrudActionOverride.visibleWhen, objectui#2614)',
summary: 'built-in row Edit/Delete per-record visibility (RowCrudActionOverride.visibleWhen)',
dialect: 'cel', mode: 'interpret', state: 'enforced', failPolicy: 'fail-closed',
enforcement: 'console (objectui) RowActionMenu BuiltinRowActionItem + data-table DataTableBuiltinRowActionItem → useRowPredicate → @objectstack/formula celEngine (interpret); FALSE/fault hides the row button (UI gating only — write enforcement stays with permissions/hooks)',
covers: ['data/object.zod.ts:RowCrudActionOverrideSchema.visibleWhen'],
},
{
id: 'cel-row-crud-disabled',
summary: 'built-in row Edit/Delete per-record disabling (userActions.{edit,delete}.disabledWhen, objectui#2614)',
summary: 'built-in row Edit/Delete per-record disabling (userActions.{edit,delete}.disabledWhen)',
dialect: 'cel', mode: 'interpret', state: 'enforced', failPolicy: 'fail-soft-log',
enforcement: 'console (objectui) RowActionMenu BuiltinRowActionItem + data-table DataTableBuiltinRowActionItem → useRowPredicate → @objectstack/formula celEngine (interpret); TRUE renders the button disabled, a fault leaves it enabled (server hooks are the real boundary)',
covers: ['data/object.zod.ts:RowCrudActionOverrideSchema.disabledWhen'],
Expand Down
2 changes: 1 addition & 1 deletion packages/qa/dogfood/test/fixtures/attachments-fixture.ts
Original file line number Diff line number Diff line change
Expand Up @@ -137,7 +137,7 @@ export const attachmentsFixtureStack = defineStack({
type: 'app',
name: 'Attachments Permission Matrix Fixture',
description:
'Three-object app exercising the #2755 attachment permission matrix: parent visibility, uploader/editor delete, enable.files gate.',
'Three-object app exercising the non-admin attachment permission matrix: parent visibility, uploader/editor delete, enable.files gate.',
},
objects: [AttCase, AttSecret, AttNoFiles, AttReadonly],
});
2 changes: 1 addition & 1 deletion packages/qa/dogfood/test/fixtures/comments-fixture.ts
Original file line number Diff line number Diff line change
Expand Up @@ -136,7 +136,7 @@ export const commentsFixtureStack = defineStack({
type: 'app',
name: 'Comments Permission Matrix Fixture',
description:
'Four-object app exercising the #4630 comment permission matrix: thread visibility, author/parent-editor writes, the enable.feeds gate.',
'Four-object app exercising the record-level comment permission matrix: thread visibility, author/parent-editor writes, the enable.feeds gate.',
},
objects: [CmtOpen, CmtPrivate, CmtReadonly, CmtNoFeeds],
});
Original file line number Diff line number Diff line change
Expand Up @@ -56,7 +56,7 @@ export const emailTemplateFixtureStack = defineStack({
version: '0.0.0',
type: 'app',
name: 'Email Template Materialization Fixture',
description: 'Single-object app that authors one email template to prove stack `emailTemplates:` entries materialize into the sys_email_template rows sendTemplate reads (ADR-0054, #4509).',
description: 'Single-object app that authors one email template to prove stack `emailTemplates:` entries materialize into the sys_email_template rows sendTemplate reads (ADR-0054).',
},
objects: [EtNote],
emailTemplates: [etPasswordReset],
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -98,7 +98,7 @@ export const durableSuspendStack = defineStack({
version: '0.0.0',
type: 'app',
name: 'Durable Suspend Fixture',
description: 'Single-object app whose screen flow suspends, persists, and resumes after a cold boot (#4470).',
description: 'Single-object app whose screen flow suspends, persists, and resumes after a cold boot.',
},
objects: [SuspendNote],
flows: [flowDurableSuspend],
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -66,7 +66,7 @@ export const flowFunctionEffectStack = defineStack({
version: '0.0.0',
type: 'app',
name: 'Flow Function Effect Fixture',
description: "Proves a flow function's declared effect reaches the run summary (#4396).",
description: "Proves a flow function's declared effect reaches the run summary.",
},
objects: [FxInvoice],
flows: [sweepFlow('fxn_pure_sweep', 'scoreInvoices'), sweepFlow('fxn_writing_sweep', 'syncBilling')],
Expand Down
2 changes: 1 addition & 1 deletion packages/qa/dogfood/test/fixtures/flow-runas-fixture.ts
Original file line number Diff line number Diff line change
Expand Up @@ -122,7 +122,7 @@ export const runasFixtureStack = defineStack({
version: '0.0.0',
type: 'app',
name: 'Flow runAs Fixture',
description: 'Owner-isolated single-object app exercising flow.runAs identity enforcement (#1888).',
description: 'Owner-isolated single-object app exercising flow.runAs identity enforcement.',
},
objects: [RunAsNote],
flows: [runasSystemTouch, runasUserTouch, runasSystemRead, runasUserRead],
Expand Down
2 changes: 1 addition & 1 deletion packages/qa/dogfood/test/fixtures/label-scope-fixture.ts
Original file line number Diff line number Diff line change
Expand Up @@ -52,7 +52,7 @@ export const labelScopeStack = defineStack({
version: '0.0.0',
type: 'app',
name: 'Label Scope Fixture',
description: 'Deal → vendor lookup exercising the #3602 label read-scope leak.',
description: 'Deal → vendor lookup exercising the dimension-label read scope: a vendor the reader cannot read is shown by raw id, never by name.',
},
objects: [Vendor, Deal],
});
Expand Down
4 changes: 2 additions & 2 deletions packages/qa/dogfood/test/fixtures/rls-owner-fixture.ts
Original file line number Diff line number Diff line change
Expand Up @@ -54,7 +54,7 @@ export const rlsFixtureStack = defineStack({
version: '0.0.0',
type: 'app',
name: 'RLS Owner Fixture',
description: 'Owner-isolated single-object app exercising the #1994 by-id-write invariant.',
description: 'Owner-isolated single-object app exercising the cross-owner by-id-write invariant: a caller that cannot read a record must not be able to write it.',
},
objects: [RlsNote],
});
Expand Down Expand Up @@ -102,7 +102,7 @@ export const ownerScopedMemberSet: PermissionSet = PermissionSetSchema.parse({
*/
export const readOnlyScopedMemberSet: PermissionSet = PermissionSetSchema.parse({
name: FIXTURE_MEMBER_SET,
label: 'RLS Fixture Member — owner-scoped reads only (#1994 hole)',
label: 'RLS Fixture Member — owner-scoped reads only (no write policy: the by-id-write hole shape)',
objects: noteCrud,
rowLevelSecurity: [{ ...RLS.ownerPolicy('rls_note', 'created_by'), operation: 'select' }],
});
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -52,7 +52,7 @@ export const webhookFixtureStack = defineStack({
version: '0.0.0',
type: 'app',
name: 'Webhook Materialization Fixture',
description: 'Single-object app that authors one webhook to prove stack `webhooks:` entries materialize into dispatchable sys_webhook rows (ADR-0054, #3461).',
description: 'Single-object app that authors one webhook to prove stack `webhooks:` entries materialize into dispatchable sys_webhook rows (ADR-0054).',
},
objects: [WmTask],
webhooks: [wmTaskChanged],
Expand Down
2 changes: 1 addition & 1 deletion packages/qa/dogfood/test/search-conformance.ledger.ts
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ export const SEARCH_SURFACE: ConformanceRow[] = [
},
{
id: 'search-fields-override',
summary: '`$searchFields` per-query narrowing — validated against the allowed set, can never widen it; a name outside the set is 400 INVALID_FIELD at the REST ingress (#4254), not silently dropped',
summary: '`$searchFields` per-query narrowing — validated against the allowed set, can never widen it; a name outside the set is 400 INVALID_FIELD at the REST ingress, not silently dropped',
surface: 'spec/api/query.zod.ts:$searchFields',
state: 'enforced',
enforcement: 'spec/data/search-fields.ts resolveSearchFields (intersection) + metadata-protocol/src/protocol.ts assertSearchFieldsAreSearchable (ingress gate)',
Expand Down
2 changes: 1 addition & 1 deletion packages/qa/dogfood/test/showcase-security.ts
Original file line number Diff line number Diff line change
Expand Up @@ -63,7 +63,7 @@ export function showcaseAppDefaultSecurity(extraObjectGrants?: ObjectGrants): Se
// which reads as a security regression rather than a missing declaration.
throw new Error(
'[dogfood] the showcase stack declares no `isDefault` permission set — the CLI wiring ' +
'these fixtures model cannot be reproduced (#5491)',
'these fixtures model cannot be reproduced, and the platform baseline alone grants a member no object access',
);
}
const appDefault = PermissionSetSchema.parse(declaredDefault) as PermissionSet;
Expand Down
2 changes: 1 addition & 1 deletion packages/qa/downstream-contract/src/stack.ts
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ export const ContractStack = defineStack({
version: '1.0.0',
type: 'app',
name: 'Downstream Contract',
description: 'Frozen third-party consumer gating spec backward compatibility (#2035).',
description: 'Frozen third-party consumer gating spec backward compatibility: a spec change that needs this fixture edited to stay green is breaking.',
},
objects: [Account],
views: [AccountViews],
Expand Down
53 changes: 0 additions & 53 deletions scripts/doc-authoring-prose-id.baseline.json
Original file line number Diff line number Diff line change
Expand Up @@ -247,9 +247,6 @@
"#5973": 1,
"#6428": 1
},
"packages/qa/dogfood/test/armed.ts": {
"#8074": 2
},
"packages/qa/dogfood/test/authz-conformance.matrix.ts": {
"#10145": 1,
"#10243": 1,
Expand Down Expand Up @@ -298,56 +295,6 @@
"#9083": 2,
"#9377": 1
},
"packages/qa/dogfood/test/build-shaped-artifact.ts": {
"#6293": 3
},
"packages/qa/dogfood/test/enterprise-organizations.ts": {
"#4719": 1
},
"packages/qa/dogfood/test/expression-conformance.ledger.ts": {
"#1887": 1,
"#2614": 2,
"#3067": 1,
"#5016": 1,
"#7310": 1,
"#7327": 1
},
"packages/qa/dogfood/test/fixtures/attachments-fixture.ts": {
"#2755": 1
},
"packages/qa/dogfood/test/fixtures/comments-fixture.ts": {
"#4630": 1
},
"packages/qa/dogfood/test/fixtures/email-template-materialization-fixture.ts": {
"#4509": 1
},
"packages/qa/dogfood/test/fixtures/flow-durable-suspend-fixture.ts": {
"#4470": 1
},
"packages/qa/dogfood/test/fixtures/flow-function-effect-fixture.ts": {
"#4396": 1
},
"packages/qa/dogfood/test/fixtures/flow-runas-fixture.ts": {
"#1888": 1
},
"packages/qa/dogfood/test/fixtures/label-scope-fixture.ts": {
"#3602": 1
},
"packages/qa/dogfood/test/fixtures/rls-owner-fixture.ts": {
"#1994": 2
},
"packages/qa/dogfood/test/fixtures/webhook-materialization-fixture.ts": {
"#3461": 1
},
"packages/qa/dogfood/test/search-conformance.ledger.ts": {
"#4254": 1
},
"packages/qa/dogfood/test/showcase-security.ts": {
"#5491": 1
},
"packages/qa/downstream-contract/src/stack.ts": {
"#2035": 1
},
"packages/services/service-analytics/src/analytics-service.ts": {
"#3867": 1,
"#5222": 1,
Expand Down
Loading