Skip to content

docs(qa): record A1 of crud-permission-matrix as a known v18 gap - #21749

Merged
objectstack-fleet[bot] merged 1 commit into
mainfrom
claude/issue-21747-crud-matrix-knowngap
Oct 4, 2026
Merged

objectstack-fleet[bot] merged 1 commit into
mainfrom
claude/issue-21747-crud-matrix-knowngap

Conversation

@objectstack-fleet

Copy link
Copy Markdown
Contributor

Fixes #21747

Clause-②: no

What

In docs/qa/platform-checklist/areas/access-security.json, item access-security.crud-permission-matrix only: one knownGaps entry, revision 4 to 5, one history entry (revision 5, citing #21747 and the maintainer ruling, #21057 comment 5980557328). A1's assertion, the item's priority (P0) and every other item are unchanged. No product change, no run record.

A1 stays a FAIL in the run table, read as known (#21057), and goes green when the v18 ADR-0131 C1 business-unit leg lands.

The knownGaps entry (verbatim)

A1 (acceptance[0], every allowed cell succeeds) is a KNOWN FAIL on 17.x until the v18 ADR-0131 C1 business-unit leg lands (#21057, target:v18, gated by #15193): the seeded sys_business_unit rows carry organization_id null, so the showcase_field_ops_delegate × sys_user_position in-subtree create (bu_west_coast under bu_field_ops) answers 403 PERMISSION_DENIED "outside the delegated subtree" and the delegate's scope resolves to an empty subtree (the gate fails closed: over-refusal, never exposure). Measured discriminator (#21057 comments 5927366808 and 5979438043): once the organization is stamped on the seeded units, the in-subtree create flips to 201 while the out-of-subtree create (bu_hq_finance) stays 403 — so the cause is the unstamped seed, not the gate. Score A1 FAIL in the run table and read it as known (#21057), not new; do NOT re-derive it, do NOT weaken the clause, do NOT stamp the units to make it pass (that would hide the very gap this entry tracks). It turns green when the v18 C1 leg lands — that flip is the signal the gap closes, and this entry is then removed (ruling: #21057 comment 5980557328, ADR-0131 D3/D14)

Discriminator source

Read from #21057 itself, not copied from the card: the dev report comment 5927366808 (boot 2: admin PATCH of organization_id onto bu_field_ops, bu_west_coast and bu_east_coast, then the delegate's in-subtree create answers 201 and the out-of-subtree create on bu_hq_finance stays 403) and comment 5979438043 (reproduced again at 251a7dd, run #21720). The ruling is comment 5980557328.

Validators

  • pnpm check:platform-checklist: exit 0, "check-platform-checklist: OK - 15 areas, 270 items".
  • node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --commands: derived 13 commands for the one changed path. All exit 0: check-ci-filter-parity, check-closing-keyword-parity (and --self-test), check-comment-mask-corpus, check:doc-formula-expressions (after building the lint and formula packages), check:cross-package-test-inputs, check:doc-authoring, check:driver-memory-census, check:gitlink-declared, check:nul-bytes, check:platform-checklist, check:refd-timer-probe, check:watch-hint-literal.
  • NOT MEASURED: the shard-attestation and test-completeness steps (they need CI-only variables), the type-check lanes (no TypeScript touched) and the pending-changeset families (no changeset; docs/qa is not published).

Acceptance notes

  • skip-changeset is not applied here (no labels were in scope for this run); nothing published changes.
  • PR assignee is left to the seat.

🤖 Generated with Claude Code

https://claude.ai/code/session_01VDtqoecgES7ScQYGbFVDRv

@github-actions github-actions Bot added the size/s label Oct 4, 2026
@objectstack-fleet objectstack-fleet Bot added the skip-changeset PR has no user-facing published change; bypasses the changeset gate label Oct 4, 2026
@objectstack-fleet
objectstack-fleet Bot marked this pull request as ready for review October 4, 2026 14:06
@objectstack-fleet
objectstack-fleet Bot enabled auto-merge October 4, 2026 14:07
@objectstack-fleet
objectstack-fleet Bot added this pull request to the merge queue Oct 4, 2026
Merged via the queue into main with commit 8cbba54 Oct 4, 2026
37 checks passed
@objectstack-fleet
objectstack-fleet Bot deleted the claude/issue-21747-crud-matrix-knowngap branch October 4, 2026 14:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/s skip-changeset PR has no user-facing published change; bypasses the changeset gate

Projects

None yet

1 participant