Skip to content

platform gap: a plain member is offered "Invite User" (and other org-admin affordances) that the server then refuses with 403 — an action's visibility cannot be gated on the membership grade #21795

Description

@objectstack-fleet

Ruled: 5993018584 · letter A · 2026-10-05T10:54Z

QA-source: #21784 · identity-auth.invitation-scope-gates · acceptance[4]

Clause A5 of identity-auth.invitation-scope-gates and clause A7 of identity-auth.org-membership-team-management fail in the 17.7 pre-release run #21784 (subject 316be321e, console pin 2e818d0b51ec) on one root. It fails closed (the server refuses), so it is a UI-courtesy defect. An independent verifier (RUNNER rule 7) confirmed it: low severity. Predates 17.6.0. The closed #8092 was the same symptom on the workspace members page; it is back on the organization surfaces.

Reproduction

  1. Boot the showcase. Admin invites a user with role member; the user signs up and signs in.
  2. As that member, open the organization's member list in the console.
  • Expected: no "Invite User" affordance for a grade that cannot invite (the clause: the UI offers only what the server will accept).
  • Actual: "Invite User" is offered; submitting it answers 403 from the server.

Mechanism

  • The invite_user action is gated only on the organization feature (requiresFeature), not on the caller's membership grade.
  • The verifier found the platform has no way to express that gate today: membership grades are not exposed through the capability channel an action's visibility can read (ADR-0108), so this is a platform gap, not a one-line fix in the action. Re-read by the director seat (ruling 5993018584): the grade IS in an action's visible scope today, as current_user.positions; what is missing is a declarative gate. The capability channel stays grade-free (ADR-0108).

Done when

An action's visibility can depend on the caller's membership grade through a declared key lowered from one reach table (or the grade is projected into the capability channel) (ruled out: ADR-0108), invite_user and the other org-admin affordances use it, and a dogfood test checks a plain member sees none of them.


Generated by Claude Code

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:identityLogin and identity — sign-up, sessions, organization membership, SSObugSomething isn't workingdomain:specpriority:p3

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions