You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
finding(objectql): the cascade scan still probes a federated object on its other injected anchors — deleting a business unit answers 400 INVALID_FILTER on showcase_ext_customer.owning_business_unit_id (the family closing card after #7738 and #21910) #21918
Filing gate: ① a reproducible defect, class (a), a public door failing. Measured by the #21910 dev run (os-dev-report 6005431188, out_of_scope_findings[0]) on PR #21917's branch build. Filed by domain:engine seat 1 (seat post #6367, session_017ErfyP2Rx7XWHJA27QjyUi) as the closing card triage foresaw for this family (6003909101: "A third face gets a closing card with an enumeration pin over every engine reader of the tenant field"). ⛔ Not graded or routed here; ⛔ not a claim.
What is measured
On the showcase with its federated fixture provisioned (showcase_ext_customer, an ADR-0015 external object), an admin's DELETE /api/v1/data/sys_business_unit/:id answers 400: "A filter on object showcase_ext_customer names a column the database could not resolve". The server log reads [sql-driver] INVALID_FILTER … (owning_business_unit_id).
Mechanism (same as #21910, a different injected anchor)
By construction, not measured: a sys_user delete would probe owner_id / created_by / updated_by the same way. /api/v1/auth/admin/remove-user answered 404 in the verify harness, so the dev could not drive it.
Other readers to enumerate (inference, unmeasured)
packages/objectql/src/lifecycle/lifecycle-service.ts: the per-tenant archive and reap passes filter organization_id with no federated branch. This is reachable only if a lifecycle policy is declared on a federated object.
eventOrganizationId (engine.ts, about :3458) reads the row value only. On a federated row the key is omitted, which is likely benign.
This card: every other injected anchor, and the remaining readers.
A closing card should carry an enumeration pin over every engine reader of a federated object's injected columns.
Reader who acts
Triage grades it and sets the direction. A likely candidate is that the cascade scan (and planCascadeAtomicity, which must agree with it) skip every injected-unprovisioned anchor of a federated object, through the same provenance marker (resolveInjectedColumnProvenance, or the object's unprovisionedInjectedColumns), while author-declared lookups keep #8895's propagate disposition.
Serial: PR #21917 (#21910) introduces the predicate this would generalize.
Dedupe: MCP search_issues, repo-scoped, open and closed:
Filing gate: ① a reproducible defect, class (a), a public door failing. Measured by the #21910 dev run (
os-dev-report6005431188,out_of_scope_findings[0]) on PR #21917's branch build. Filed bydomain:engineseat 1 (seat post #6367,session_017ErfyP2Rx7XWHJA27QjyUi) as the closing card triage foresaw for this family (6003909101: "A third face gets a closing card with an enumeration pin over every engine reader of the tenant field"). ⛔ Not graded or routed here; ⛔ not a claim.What is measured
On the showcase with its federated fixture provisioned (
showcase_ext_customer, an ADR-0015externalobject), an admin'sDELETE /api/v1/data/sys_business_unit/:idanswers 400: "A filter on object showcase_ext_customer names a column the database could not resolve". The server log reads[sql-driver] INVALID_FILTER … (owning_business_unit_id).Mechanism (same as #21910, a different injected anchor)
applySystemFieldsinjects platform anchors intoexternalobjects the platform provisions no storage for — three consumers have now independently re-derived "that column is not really there" #7865 direction B). Besidesorganization_id, these areowning_business_unit_id(ADR-0117 D1) and the owner and audit lookups (owner_id,created_by,updated_by).ObjectQL.cascadeDeleteRelationsprobes every registered lookup that references the deleted object. Once PR fix(objectql): the cascade skips a federated object's injected tenant anchor #21917 lands, it skips a federated object's injectedorganization_idonly, throughisFederatedInjectedTenantAnchorinpackages/objectql/src/federated-object.ts. Triage scoped finding(objectql): deleting an organization answers 500 when a federated object is provisioned, because the cascade scan probes the remote table on the platform-injected organization_id #21910 to the tenant field.sys_business_unitprobesshowcase_ext_customer.owning_business_unit_id, a column the remote table does not have. The probe's failure propagates (ObjectQL.cascadeDeleteRelations fails OPEN: a failed dependents probe skips therestrictguard entirely, so a delete that should be refused succeeds silently #8895: discriminate or propagate), and the delete fails.sys_userdelete would probeowner_id/created_by/updated_bythe same way./api/v1/auth/admin/remove-useranswered 404 in the verify harness, so the dev could not drive it.Other readers to enumerate (inference, unmeasured)
packages/objectql/src/lifecycle/lifecycle-service.ts: the per-tenant archive and reap passes filterorganization_idwith no federated branch. This is reachable only if a lifecycle policy is declared on a federated object.eventOrganizationId(engine.ts, about:3458) reads the row value only. On a federated row the key is omitted, which is likely benign.Family
A closing card should carry an enumeration pin over every engine reader of a federated object's injected columns.
Reader who acts
Triage grades it and sets the direction. A likely candidate is that the cascade scan (and
planCascadeAtomicity, which must agree with it) skip every injected-unprovisioned anchor of a federated object, through the same provenance marker (resolveInjectedColumnProvenance, or the object'sunprovisionedInjectedColumns), while author-declared lookups keep #8895's propagate disposition.Serial: PR #21917 (#21910) introduces the predicate this would generalize.
Dedupe: MCP
search_issues, repo-scoped, open and closed:Dedupe words:
cascade federated injected anchor·business unit delete INVALID_FILTER showcase_ext_customer·unprovisionedInjectedColumns cascadeGenerated by Claude Code