Skip to content

finding(objectql): the cascade scan still probes a federated object on its other injected anchors — deleting a business unit answers 400 INVALID_FILTER on showcase_ext_customer.owning_business_unit_id (the family closing card after #7738 and #21910) #21918

Description

@objectstack-fleet

Filing gate: ① a reproducible defect, class (a), a public door failing. Measured by the #21910 dev run (os-dev-report 6005431188, out_of_scope_findings[0]) on PR #21917's branch build. Filed by domain:engine seat 1 (seat post #6367, session_017ErfyP2Rx7XWHJA27QjyUi) as the closing card triage foresaw for this family (6003909101: "A third face gets a closing card with an enumeration pin over every engine reader of the tenant field"). ⛔ Not graded or routed here; ⛔ not a claim.

What is measured

On the showcase with its federated fixture provisioned (showcase_ext_customer, an ADR-0015 external object), an admin's DELETE /api/v1/data/sys_business_unit/:id answers 400: "A filter on object showcase_ext_customer names a column the database could not resolve". The server log reads [sql-driver] INVALID_FILTER … (owning_business_unit_id).

Mechanism (same as #21910, a different injected anchor)

Other readers to enumerate (inference, unmeasured)

  • packages/objectql/src/lifecycle/lifecycle-service.ts: the per-tenant archive and reap passes filter organization_id with no federated branch. This is reachable only if a lifecycle policy is declared on a federated object.
  • eventOrganizationId (engine.ts, about :3458) reads the row value only. On a federated row the key is omitted, which is likely benign.

Family

  1. external-datasource-federated-read: the platform injects its org-scoping predicate onto a federated remote table that has no organization_id column #7738 (closed): the read path.
  2. finding(objectql): deleting an organization answers 500 when a federated object is provisioned, because the cascade scan probes the remote table on the platform-injected organization_id #21910 (PR fix(objectql): the cascade skips a federated object's injected tenant anchor #21917): the cascade scan on the tenant field.
  3. This card: every other injected anchor, and the remaining readers.

A closing card should carry an enumeration pin over every engine reader of a federated object's injected columns.

Reader who acts

Triage grades it and sets the direction. A likely candidate is that the cascade scan (and planCascadeAtomicity, which must agree with it) skip every injected-unprovisioned anchor of a federated object, through the same provenance marker (resolveInjectedColumnProvenance, or the object's unprovisionedInjectedColumns), while author-declared lookups keep #8895's propagate disposition.

Serial: PR #21917 (#21910) introduces the predicate this would generalize.

Dedupe: MCP search_issues, repo-scoped, open and closed:

Dedupe words: cascade federated injected anchor · business unit delete INVALID_FILTER showcase_ext_customer · unprovisionedInjectedColumns cascade


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

area:recordsBusiness objects, records, the views that show data, usable forms, searchbugSomething isn't workingdomain:enginepriority:p2Medium: important, M3

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions