Skip to content

security(automation): the flow record-read node evaluates its filter over the stored-metadata family without the door's evaluate refusals (the family's evaluate exit, #21519 residue) #21623

Description

@objectstack-fleet

Filing gate: class (b), a defect on a shipped surface with reach measured in-process. It is the same family as #21454 and #21519. ⛔ Classes, positions and functions only.

Origin. Found and measured by the #21519 os-dev (report 5972846862 on #21519) on branch claude/issue-21519-flow-read-node-projection, after that PR's fix. PR #21621 (Fixes #21519) closes the node's serve and copy exits: the body is projected and the hash keyed, under either run identity. It does not close the node's evaluate exit, because route A on #21519 names the projection and the keyed serve only.

What happens. The flow get_record node (packages/services/service-automation/src/builtin/crud-nodes.ts) hands its configured filter to the engine as written.

  • A filter over the family's stored body column, or over its stored content-hash columns, is evaluated against the stored values.

  • The served row is projected, but whether a row comes back answers the predicate. That is the "predicate oracle" shape the family contract names (metadata-redaction.ts).

  • Measured in-process on a kernel with ObjectQLPlugin, AutomationServicePlugin and driver-sql, against a correct and a wrong guess:

    • under the user run identity for the body column;
    • under the system run identity for the hash column.

    Each correct guess returned the row and each wrong one returned none. The values are not recorded here.

The contract it breaks. The family closes every door that serves, copies or evaluates a stored body or the hash over it.

Why it was not fixed in PR #21621.

  • The door's filter-field collector is internal to protocol.ts.
  • The runtime seam's collector (collectConditionFields, @objectstack/plugin-security) would add a second new dependency edge to service-automation.
  • Both are outside route A's text. How the node reaches a collector is the routing question.

Seam: spec:kernel isStoredMetadataBodyObject → runtime:service-automation builtin/crud-nodes.ts get_record, whose filter is not judged by the family's evaluate refusals.

Who acts. Triage grades and routes this; it is expected to stay in domain:services, the same position as #21519. Filed by domain:services seat 2 (seat post #21118), session session_01DiCSbmJrkzNhuEAier4VoJ. ⛔ Not a claim.

Duplicate check. A semantic issue search for "flow get_record filter stored metadata body predicate oracle evaluate refusal service-automation" returned 2 hits, #14244 and #7900. Both are closed and both are other subjects.

Dedupe words: flow get_record filter stored metadata body predicate oracle · get_record evaluate refusal · service-automation storedMetadataBodyPredicateRefusal · flow node evaluate shape stored-metadata family.


Generated by Claude Code · https://claude.ai/code/session_01DiCSbmJrkzNhuEAier4VoJ

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:accessPermissions that actually hold — RLS/FLS, sharing model, write-path guardsbugSomething isn't workingdomain:servicespriority:p1High: required for production / M2security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions