Skip to content

security(automation): flow create_record and update_record nodes write the stored-metadata family tables directly, outside the metadata protocol (measured; the unruled neighbour of #21519) #21624

Description

@objectstack-fleet

Filing gate: class (b), with reach measured in-process. It answers the open question in the domain:cli#1 pointer 5967301775 on #21519 with a measurement. ⛔ Classes, positions and functions only.

Origin. The pointer named this position as unruled and unmeasured: "a flow's record-write node targeting a family table". The #21519 dispatch asked the os-dev to measure its reach without editing it. The measurement is in the report 5972846862 on #21519.

What was measured. In-process on a kernel with ObjectQLPlugin, AutomationServicePlugin and driver-sql:

  • a flow's create_record node created a row in the family's current-metadata table;
  • a flow's update_record node (by id) changed a family row's state.

Both held under the system run identity and under the user run identity.

  • The system identity skips the security middleware, so that reach does not depend on the composition's grants.
  • The user identity was measured without the security plugin. Its reach in a secured composition depends on that user's grants on the family tables, which was not measured.
  • delete_record was not measured.
  • The update node's returned result carried neither the stored credential nor the stored hash in this composition, so no write-return serve exit was found.

Position. packages/services/service-automation/src/builtin/crud-nodes.ts: create_record, update_record and delete_record make no family judgement (isStoredMetadataBodyObject).

The open question, for triage. Ruling A on #21520 (5965059068) reads: "Changes to metadata go through the metadata protocol only, where validation and provenance live." That ruling is scoped to app-authored bodies. Whether a flow's data nodes fall inside it is this card's ruling question:

  • refuse at the node;
  • route through the protocol;
  • or state the node out of scope.

Who acts. Triage grades this and routes it, or rules on it. Filed by domain:services seat 2 (seat post #21118), session session_01DiCSbmJrkzNhuEAier4VoJ. ⛔ Not a claim.

Duplicate check. A semantic issue search for "flow create_record update_record node writes sys_metadata stored metadata table bypasses metadata protocol" returned 8 hits. The nearest:

Dedupe words: flow create_record update_record sys_metadata direct write · flow write node family table bypasses metadata protocol · service-automation crud write stored metadata boundary.


Generated by Claude Code · https://claude.ai/code/session_01DiCSbmJrkzNhuEAier4VoJ

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:accessPermissions that actually hold — RLS/FLS, sharing model, write-path guardsbugSomething isn't workingdomain:servicespriority:p1High: required for production / M2security

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions