Ruled: 5993018584 · letter A · 2026-10-05T10:54Z
QA-source: #21784 · identity-auth.invitation-scope-gates · acceptance[4]
Clause A5 of identity-auth.invitation-scope-gates and clause A7 of identity-auth.org-membership-team-management fail in the 17.7 pre-release run #21784 (subject 316be321e, console pin 2e818d0b51ec) on one root. It fails closed (the server refuses), so it is a UI-courtesy defect. An independent verifier (RUNNER rule 7) confirmed it: low severity. Predates 17.6.0. The closed #8092 was the same symptom on the workspace members page; it is back on the organization surfaces.
Reproduction
- Boot the showcase. Admin invites a user with role
member; the user signs up and signs in.
- As that member, open the organization's member list in the console.
- Expected: no "Invite User" affordance for a grade that cannot invite (the clause: the UI offers only what the server will accept).
- Actual: "Invite User" is offered; submitting it answers 403 from the server.
Mechanism
- The
invite_user action is gated only on the organization feature (requiresFeature), not on the caller's membership grade.
The verifier found the platform has no way to express that gate today: membership grades are not exposed through the capability channel an action's visibility can read (ADR-0108), so this is a platform gap, not a one-line fix in the action. Re-read by the director seat (ruling 5993018584): the grade IS in an action's visible scope today, as current_user.positions; what is missing is a declarative gate. The capability channel stays grade-free (ADR-0108).
Done when
An action's visibility can depend on the caller's membership grade through a declared key lowered from one reach table (or the grade is projected into the capability channel) (ruled out: ADR-0108), invite_user and the other org-admin affordances use it, and a dogfood test checks a plain member sees none of them.
Generated by Claude Code
Ruled: 5993018584 · letter A · 2026-10-05T10:54Z
QA-source: #21784 · identity-auth.invitation-scope-gates · acceptance[4]
Clause A5 of
identity-auth.invitation-scope-gatesand clause A7 ofidentity-auth.org-membership-team-managementfail in the 17.7 pre-release run #21784 (subject316be321e, console pin2e818d0b51ec) on one root. It fails closed (the server refuses), so it is a UI-courtesy defect. An independent verifier (RUNNER rule 7) confirmed it: low severity. Predates 17.6.0. The closed #8092 was the same symptom on the workspace members page; it is back on the organization surfaces.Reproduction
member; the user signs up and signs in.Mechanism
invite_useraction is gated only on theorganizationfeature (requiresFeature), not on the caller's membership grade.The verifier found the platform has no way to express that gate today: membership grades are not exposed through the capability channel an action's visibility can read (ADR-0108), so this is a platform gap, not a one-line fix in the action.Re-read by the director seat (ruling 5993018584): the grade IS in an action'svisiblescope today, ascurrent_user.positions; what is missing is a declarative gate. The capability channel stays grade-free (ADR-0108).Done when
An action's visibility can depend on the caller's membership grade through a declared key lowered from one reach table
(or the grade is projected into the capability channel)(ruled out: ADR-0108),invite_userand the other org-admin affordances use it, and a dogfood test checks a plain member sees none of them.Generated by Claude Code