You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
[Decision] authz: after #21516, a composition that serves authenticated requests without registering the security objects answers 503, not "zero capabilities" — keep it loud (A), or read an unregistered authz object as "not provisioned" (B)? #21599
Filing gate: ② a decision only the maintainer can make. It touches the region of a maintainer-ruled security predicate (2026-08-30, 第 5 场总监席决裁批 #9). Filed by the director seat, summon #32 (session_016tKoy8NJa35Yih1FdzrVmn), from PR #21545's at-tier contract review (record 5969221098, finding R2, "escalate to the maintainer; not blocking"). ⛔ Not a claim.
What did not change. The deliberately tested shape ABSENT_AUTHZ_TABLES (notifications.hono.integration.test.ts): a wired engine whose authz objects are registered but whose tables were never created. It still answers zero capabilities, quietly, through the missing-table path.
Measured:
shipped boots are unaffected: the CLI depends on @objectstack/plugin-security, and serve and bootStack compose it;
An unregistered authz object is a composition error. tryFind keeps its one predicate.
A host serving authenticated requests without the security model gets a 503 that names the unavailable authz store. Registered-but-unprovisioned keeps the quiet zero-capability answer.
B. Read "unregistered" as "not provisioned"
tryFind also treats an OBJECT_NOT_FOUND attributed on the read's own authz object as "not provisioned", so zero capabilities, quiet. That is a second recognised case, in the region the source forbids a second predicate.
The lean host quietly denies every action again, and a missing security model looks like an empty grant table.
Business meaning:
A: a building with no security desk installed reports "security system offline". It does not pretend every visitor was checked and refused.
B: a missing security desk is treated the same as a desk with an empty guest list.
四维分析
os-decision-facets
① 项目长远合理性: 注册表是对象存在与否的唯一事实来源。「未注册」表示这个组合根本没有安全模型,和「已注册但表未建」(08-30 裁决的安静分支)不是一回事。A 让两者各有其答案;B 把配置错误伪装成「零授权」,并且要在明令禁止第二谓词的地方加第二种认定。
A: this card closes completed, citing the ruling. Optionally, one sentence is added beside the predicate's comment saying an unregistered authz object stays loud, by this ruling. That rides any next change to that file.
B: a domain:engine / security card amends the predicate region, with pins for both directions plus the new case, and an at-tier contract review.
Dedupe: MCP search_issues, scoped to this repo, for 「resolve-authz-context tryFind isMissingTableError unregistered security objects AuthzStoreUnavailableError zero capabilities OBJECT_NOT_FOUND」 → 2 hits, both closed and on other subjects (#15353, #15350).
Ruled: 5974491232 · letter A · 2026-10-03T23:14Z
Filing gate: ② a decision only the maintainer can make. It touches the region of a maintainer-ruled security predicate (2026-08-30, 第 5 场总监席决裁批 #9). Filed by the director seat, summon #32 (
session_016tKoy8NJa35Yih1FdzrVmn), from PR #21545's at-tier contract review (record5969221098, finding R2, "escalate to the maintainer; not blocking"). ⛔ Not a claim.维护者速读
#21516 让引擎拒绝「注册表里没有的对象名」,已于今天合入(PR #21545)。
副作用:
影响面:正式发布的启动方式都不受影响,CLI 和 bootStack 都自带安全插件。只有 5 个测试夹具为此补注册了这组对象。
选项:
推荐 A。请回一个字母(A / B)。
Background
The ruled predicate.
packages/core/src/security/resolve-authz-context.ts,tryFind. The 2026-08-30 ruling (verbatim in the source):tryFind仅对未被判定为「表未 provision」的读失败抛AuthzStoreUnavailableError(SERVICE_UNAVAILABLE / 503)」;The source also says "⛔ Do NOT add a second predicate here". The predicate is
isMissingTableError.What [finding] [security] An in-process engine verb passes an object name the registry does not resolve to the driver as a raw table name, so a sandboxed body reads a protected table by a name the data door refuses #21516 changed. The engine's in-process verbs now refuse an unregistered name with
OBJECT_NOT_FOUNDbefore any driver is asked. So an authz read of an object the composition never registered no longer reaches the driver's missing-table error.isMissingTableErrordoes not recogniseOBJECT_NOT_FOUND, sotryFindraises the 503.What did not change. The deliberately tested shape
ABSENT_AUTHZ_TABLES(notifications.hono.integration.test.ts): a wired engine whose authz objects are registered but whose tables were never created. It still answers zero capabilities, quietly, through the missing-table path.Measured:
@objectstack/plugin-security, andserveand bootStack compose it;Options
tryFindkeeps its one predicate.tryFindalso treats anOBJECT_NOT_FOUNDattributed on the read's own authz object as "not provisioned", so zero capabilities, quiet. That is a second recognised case, in the region the source forbids a second predicate.Business meaning:
四维分析
os-decision-facets
Prior rulings read: isMissingTableError / tryFind / AuthzStoreUnavailableError / 2026-08-30 批 #9 → the ruling quoted above; #21516 triage
5964437602("refuse"); thread: 0.推荐:A。 终态句:两年后,「对象是否存在」只问注册表,「表是否建好」只问驱动,安全路径对两者各给一个诚实的答案。只看①选 A;②③④ 是否翻转:否(②零拉动、③响亮、④零改动,均同向)。
回退: B,前提是你认为「未注册」应等同「未开通」。届时须修订 08-30 裁决的谓词描述,而不是在旁边另加一个谓词。
置信缺口: 仓外的嵌入式或精简组合(cloud 的测试宿主等)是否有不装安全插件、却处理已登录请求的情况,未实测。
After the ruling
completed, citing the ruling. Optionally, one sentence is added beside the predicate's comment saying an unregistered authz object stays loud, by this ruling. That rides any next change to that file.domain:engine/ security card amends the predicate region, with pins for both directions plus the new case, and an at-tier contract review.Related
#21516 · PR #21545 · the 2026-08-30 ruling (第 5 场总监席决裁批 #9) ·
notifications.hono.integration.test.ts(ABSENT_AUTHZ_TABLES).Dedupe: MCP
search_issues, scoped to this repo, for 「resolve-authz-context tryFind isMissingTableError unregistered security objects AuthzStoreUnavailableError zero capabilities OBJECT_NOT_FOUND」 → 2 hits, both closed and on other subjects (#15353, #15350).Generated by Claude Code