Skip to content

Commit ab41a8f

Browse files
os-elon-muskclaude
andauthored
fix(scripts): apply the tenant-audit census's engine-door rule to inline type literals (225 -> 227) (#19073)
Fixes #18944 Clause-②: no The census applied its engine-door rule to **named declarations only**. A write call site whose receiver type is an inline type literal had no name for the engine type index to be keyed on, so it was classified `kind: 'other'` and subtracted from the certified population — however plainly its own text stated an ObjectQL write door. The census already **printed** both such sites on every run and called the subtraction "probably WRONG"; it then took the subtraction anyway. A diagnostic that names a subtraction as wrong and still takes it is a deferral, not a report. ## JOB ONE — the crux, answered before the classifier was touched **Both sites PASS. This is a classification repair, not a live violation.** Measured with a probe that calls the census's own exported functions (`resolveReceiver`, `resolveObjectNameArg`, `declaredObjects`, `tenantContextOf`) on the **unmodified** module, i.e. before any edit to the classifier. Sites selected by symbol — file + verb + receiver text — never by the card's line numbers. | site (re-derived by symbol) | object | tenancy | context | elevated | violation? | |---|---|---|---|---|---| | `plugin-auth/src/audience-gate-test-support.ts` · `engine.insert` · re-derived at **:72** | `sys_invitation` | **enabled** | `options.context` | yes | **no** | | `plugin-auth/src/sso-client-secret.ts` · `e.update` · re-derived at **:303** | `sys_sso_provider` | **disabled** (declared opt-out) | `options.context` | yes | **no** | Controls, because a "no" needs one: - **corpus control (HITS)** — both files are in the census corpus on this tree (`collectSources().includes(...)` → `true` for each). A "no violation" from a file the instrument never reads would be void. - **predicate control (HITS)** — the same violation predicate (`tenancy === 'enabled' && carriesTenantContext === false`) lights on **9** other sites of 227, three named in the report (`auth-plugin.ts`, `scim-connection-service.ts`, `datasource-admin-plugin.ts`). The instrument can say "yes"; it said "no" here. - what would have changed the reading: either site dropping its `{ context: { isSystem: true } }` argument (→ `carries: false`), or `sys_invitation` declaring `tenancy.enabled: false`. ⇒ **The figure downstream cards cite does not move.** `9 / 225` becomes `9 / 227`: the numerator is unchanged and the denominator becomes truthful. The repair is to what this page can be read as having examined — ⛔ not to any count that anything cites as a violation. On triage's still-open escalation branch (「被减掉的两个写点里任一个在生产路径上执行过 ⇒ 升 p1」): still **not run**, and it still needs a runtime reading. What this PR adds is that the branch's safety premise is spent for these two sites either way — once placed, neither breaks the rule the population exists to enforce. One of them is nonetheless production-shaped (`migrateLegacySsoClientSecrets`, a boot-path migration), so the branch is reported as open rather than closed. ## The fix `inlineEngineDoorOrOther()` judges a declared type text one more time when no indexed **name** is found in it, by reading the same door rule off the text itself. It calls `typeTextDeclaresEngineDoor` → `memberIsEngineDoor` — the one function that already answers that question for a named declaration — so there is no second spelling of the rule to drift from. Applied at all four `resolveReceiver` returns that carry a declared type text (`fromEntry`, an `as` cast, a member access, a call's return type), not only at the two that happen to fire today. A named engine type still wins and still reports its own name; an inline literal with no **write** door is still a subtraction that says why. ⛔ Not a widening of the definition: it IS the definition, applied where it had only been reported. ## Before / after, with the ablation proof Same tree, same command (`node scripts/tenant-audit-census.mjs`): | | before | after | |---|---:|---:| | write call sites | 225 | **227** | | object name decidable | 149 | 151 | | tenancy enabled | 149 | 150 | | declares tenancy off | 0 | **1** | | threading a tenant context | 141 | 143 | | **provably none AND tenancy-enabled** | **9** | **9** | | options unreadable AND tenancy-enabled | 32 | 32 | | decidably elevated | 106 | 108 | | non-engine calls subtracted | 146 | 144 | | subtractions the census could NOT defend | 3 | **1** | | …of those, type text states an engine door | 2 | **0** | Ablation, through `scripts/ablation-replace.mjs` so the write is verified against the disk rather than against an exit code (anchor: the helper's own guard, replaced with a dead one): ```text anchor hits 1 time(s), as declared anchor 1 -> 0, replacement 0 -> 1 blob 40921ef -> f76872fe8b03 (git hash-object, before -> under mutation) under mutation: census reads 225; anonymous-type 2; undefended 3; doorShaped 2 under mutation: check-tenant-audit-census.mjs EXIT=1 committed : | write call sites on the application surface | **227** | census : | write call sites on the application surface | **225** | restore: git checkout HEAD -- PATH (the explicit-HEAD form, absolute path) blob after restore 40921ef blob at HEAD 40921ef git diff HEAD empty ``` Predicted direction before running it: reverting the classifier turns the gate red. Observed: exactly that — and the census reverts to the pre-fix reading in every one of the eleven rows above. So the artefacts in this PR are held to the fixed classifier, and the file that was edited is the file that ran. ## Both artefacts AND the prose Both generated artefacts were rewritten by the census's own tooling (`node scripts/tenant-audit-census.mjs --write`), ⛔ never by hand. The page's **hand-written** prose was re-read against the new numbers. One claim was **falsified** by the placement and is corrected: > exactly two opt out (`sys_api_key`, `sys_sso_provider`), and no write call site > on this surface targets either. One now does — the legacy client-secret migration writes `sys_sso_provider` under an elevated context, which is why the generated `declares tenancy off` row reads **1** rather than 0. `sys_api_key` still has no write site on this surface (measured: no site in `--json` names it). Nine further hand-written figures moved and are updated (the gate holds every one of them: 23 prose figures). Two things stated rather than rewritten on a guess: - **"18 classifier cases, 6 of which red against the old reading"** — could not be verified. The generator's self-test reports 44 cases before this change and 49 after, and the gate's own reports 24; none is 18, so the claim counts some subset this PR cannot identify. It is left as written and its sentence is narrowed to the two over-claims it was written for, rather than being silently extended over the third instance this PR adds. - **the `(47%)` → `(48%)` parenthetical** is hand-written and unenforced (the gate requires digits-then-`%`, not a value). 108/227 = 47.58%, so floor gives 47 and nearest gives 48. Both surviving data points on the page (77% and 47%) round the same way under either rule, so the convention is undetermined from the page itself; nearest-integer was used and is flagged here for the seat. ## Verification Gate families derived from the **real** change set after the final commit: `node scripts/pm/dispatch-gates.mjs --commands --repo objectstack-ai/objectstack` derived at `6c23858e5`, the final commit (3 paths vs merge base `0ec81857a`; the tool's own repo+commit declaration is in its stderr, and the list is byte-identical to the derivation taken before the last commit). **All 62 commands it printed were run on that HEAD, each exit code captured before any pipe: 62 run, 62 exit 0.** Five of them first refused as `PREREQUISITE NOT MET` in a fresh worktree — `@objectstack/spec`, `@objectstack/lint`, `@objectstack/formula`, then `@objectstack/client-react` were not built — so those packages' closures were built and the families were re-run rather than reported unmeasured. The per-command table is in the report comment on #18944. NOT MEASURED, and named rather than counted as passes: the 14 families that apply only once a changeset exists (this PR declares none, see below), the 11 that declare a whole-root population no path narrows, the 2 that take a value from the workflow, the 2 path-scheduled CI jobs (`Test Core`, `Build Docs`) and the 52 artifact-roster families whose `silent` verdict is a fact about a list rather than about these paths. `scripts/check-tenant-audit-census.mjs` is this census's gate and it judges: ```text ✓ check-tenant-audit-census: OK -- 227 write call sites certified (151 decidable; 9 tenancy-enabled sites PROVABLY carry no tenant context, 32 more unreadable), 23 prose figures held to the census, every write call site placed and every `UNTYPED_RECEIVERS` row matched. ``` ⛔ No gate was weakened: no ratchet raised, no floor lowered, no ledger row deleted, no test skipped. The `doorShaped` diagnostic is **kept** — now 0 by construction — as the alarm for this hole reopening, and five new self-test cases pin the rule in both directions. ## Changeset No changeset, and the `skip-changeset` label is **owed but not applied by this PR** — label management was withheld by this dispatch. Measured, not assumed: no package directory contains any of the three files (30 manifests inspected; the repo-root manifest is `private: true`), so nothing any package's `files[]` ships can move. Positive control: `packages/spec` is published and its `files[]` is non-empty, so the instrument can say "shipped" when it is. An empty-frontmatter changeset is explicitly not an option here (the gate rejects newly added ones). ## Acceptance notes - **to file (class (a), pre-existing, ⛔ not fixed here)** — the census aborts with a `ts-parse` refusal (exit 3) on a receiver whose inline type literal separates its members by a **newline only**: `declaredTypesIn` collapses whitespace, so the separator is lost and the synthetic `type CensusReceiver = ...` re-parse fails with "';' expected". Reproduced directly; control lit (the semicolon-separated form of the same literal returns `true`). Live on `main` through the `anonymous-type` arm, which has called `typeTextDeclaresEngineDoor` on the same collapsed text since PR #18943; this PR widens the same call to brace-free type texts that mention a write verb. No such receiver exists in the corpus today (573 sources, exit 0). - noted, not filed: `NON_ENGINE_REASONS` is exported and read by nothing — its keys are produced by `nonEngineReason` and its descriptions are documentation only, so its docblock's "closed set of seven" is closed by review, not by a gate. True today. Successor: the next author of this classifier. - noted, not filed: the module docblock's "There are 45 of them" for erased (`any`) receivers reads 44 on this tree (18 + 15 + 11), a pre-existing one-off drift in a comment, untouched here. --- _Generated by [Claude Code](https://claude.ai/code/session_019srGWGCBBCBHqcDoRZpQRh)_ --------- Co-authored-by: Claude <noreply@anthropic.com>
1 parent 6f8d751 commit ab41a8f

3 files changed

Lines changed: 212 additions & 49 deletions

File tree

‎content/docs/permissions/tenant-audit-census.mdx‎

Lines changed: 64 additions & 27 deletions
Original file line numberDiff line numberDiff line change
@@ -71,6 +71,16 @@ as an engine when it declares a write door whose first parameter is named
7171
`IDataEngine` door signature. Interfaces that extend one inherit it; aliases that
7272
narrow one (`Partial<Pick<IDataEngine, …>>`) carry it.
7373

74+
**That rule is read off the TYPE, not off the type's name.** The engine type
75+
index is keyed on declaration names, so a receiver whose declared type is an
76+
inline type literal has no name to look up — and for two sites, both writing
77+
under `{ context: { isSystem: true } }`, that alone subtracted a real engine
78+
write from this population while the census printed the type text and said the
79+
subtraction was probably wrong. The same door rule is now read off the type text
80+
itself, so an unnamed type that states a write door places its site. That is
81+
what moved this page's population from 225 to 227; nothing about the two sites
82+
changed, only whether this instrument could see them.
83+
7484
**The expensive failure direction is a keyword.** Sites whose receiver the author
7585
typed `any` have no type to read, and there are 44 of them — just under a fifth
7686
of the population, concentrated in exactly the seed and bootstrap paths this
@@ -86,7 +96,12 @@ Tenancy itself is enabled *by default* — `isTenancyDisabled()` reads
8696
`tenancy.enabled === false` and nothing else — so the object registry only has to
8797
find the opt-outs. Across 117 declared objects — the dated, ⛔ unenforced
8898
corpus-scale figure below — exactly two opt out (`sys_api_key`,
89-
`sys_sso_provider`), and no write call site on this surface targets either.
99+
`sys_sso_provider`), and exactly one write call site on this surface targets
100+
either — `plugin-auth`'s legacy client-secret migration writes
101+
`sys_sso_provider` under an elevated context. That is the
102+
`declares tenancy off` row below reading **1** rather than 0: the object is
103+
outside this control's reach by its own declaration, not by the census failing
104+
to see the write.
90105

91106
A **declared object** here is a top-level object declaration in a
92107
`*.object.ts(x)` file — `export const X = ObjectSchema.create({ name: … })` —
@@ -106,7 +121,7 @@ are reported as `undecidable` rather than assumed either way.
106121

107122
The same holds twice over for the context. An options argument spelled as a
108123
literal can be read; one spelled `options`, `{ ...opts }`, or handed through a
109-
forwarding shim cannot, and **67 of the 225 sites are spelled that way**. A
124+
forwarding shim cannot, and **67 of the 227 sites are spelled that way**. A
110125
context resolved from an inline literal or a local `const` can be tested for
111126
`isSystem`; one arriving from a helper call cannot.
112127

@@ -140,12 +155,28 @@ direction, on the very figure this page tells other cards to cite. `carries` is
140155
now three-valued, and an unreadable argument can never contribute to the
141156
provable count.
142157

143-
⭐ Both are the same shape as the failure this artefact exists for, wearing
144-
opposite hats: one scored an unread thing as *nothing to report*, the other
145-
scored an unread thing as *a finding*. `node
146-
scripts/check-tenant-audit-census.mjs --self-test` pins all of it — 18 classifier
147-
cases, 6 of which red against the old reading, driven from the gate's own
148-
self-test rather than from a flag on the generator.
158+
**A door rule keyed on names read an unnamed door as no door.** Two receivers
159+
typed with an inline type literal that spells `insert` / `update` with an
160+
`object: string` first parameter were subtracted from the population — by the
161+
same instrument that printed their type text on every run and called the
162+
subtraction probably wrong. Placing them moved the population **225 → 227** and
163+
the elevated count **106 → 108**. ⭐ It moved the provable yield surface
164+
(`9`) **not at all**: both sites thread an elevated context, and one of them
165+
targets a tenancy-opt-out object. The repair is to the denominator and to what
166+
this page can be read as having examined — ⛔ not to the count anything cites as
167+
a violation. It is pinned in **both** directions, because a rule that placed
168+
every inline literal would be the same failure mirrored: an unnamed type that
169+
states a write door places its site, one that states none is still a subtraction
170+
that says why, and an indexed type name beside an inline literal still wins and
171+
reports itself.
172+
173+
⭐ All three are the same shape as the failure this artefact exists for, wearing
174+
different hats: one scored an unread thing as *nothing to report*, one scored an
175+
unread thing as *a finding*, and one scored a thing it had read and printed as
176+
outside its own population. `node
177+
scripts/check-tenant-audit-census.mjs --self-test` pins the first two — 18
178+
classifier cases, 6 of which red against the old reading — driven from the
179+
gate's own self-test rather than from a flag on the generator.
149180

150181
## ⭐ Deviations from the carried figures, untrimmed
151182

@@ -155,10 +186,10 @@ reproduce them. Where it disagrees, it disagrees on the page:
155186

156187
| carried figure | where it survives | this census |
157188
| :--- | :--- | ---: |
158-
| 175 write call sites | quoted in the merged changeset | **225** |
189+
| 175 write call sites | quoted in the merged changeset | **227** |
159190
| 24 carrying no tenant context | quoted in the merged changeset | **9** provable and tenancy-enabled; **32** more whose options argument is unreadable |
160-
| 127 of 175 statically decidable, 48 runtime-parameter-name sites | restated on the `isSystem`-scoping card | **149 of 225** decidable, **76** undecidable |
161-
| 135 (77%) silenced by the `isSystem` guard before the posture gate | the lost issue body — **no surviving corroboration** | **not reproduced**: 106 decidably elevated, 0 decidably not, 102 undecidable |
191+
| 127 of 175 statically decidable, 48 runtime-parameter-name sites | restated on the `isSystem`-scoping card | **151 of 227** decidable, **76** undecidable |
192+
| 135 (77%) silenced by the `isSystem` guard before the posture gate | the lost issue body — **no surviving corroboration** | **not reproduced**: 108 decidably elevated, 0 decidably not, 102 undecidable |
162193
| 141 and 132, two independent re-derivations | the card that filed this work | — |
163194

164195
**The differences are not reconciled, and deliberately so.** The old census's
@@ -169,17 +200,17 @@ at any commit.
169200

170201
Two structural facts do plausibly widen this reading against any hand or regex
171202
one, and both are counted in the generated tables below: the 44 sites reached
172-
through an erased (`any`) receiver, and the 40 that name their object through a
203+
through an erased (`any`) receiver, and the 41 that name their object through a
173204
`const` rather than inline. An instrument that read either the way a person does
174205
would report a smaller number and would not say so.
175206

176207
The fourth row is the one worth flagging to anyone citing it. **The 135 / 77%
177208
figure has no surviving corroboration anywhere in the tree.** This census reads
178-
106 of 225 (47%) as decidably elevated, with 102 more whose elevation is a
209+
108 of 227 (48%) as decidably elevated, with 102 more whose elevation is a
179210
run-time fact — so the claim is neither confirmed nor refuted, and the honest
180211
answer is that a static reading cannot settle it.
181212

182-
⇒ **Cite `9 / 225`, and say what it is**: the sites whose options argument was
213+
⇒ **Cite `9 / 227`, and say what it is**: the sites whose options argument was
183214
READ and holds no tenant context, against a decidably tenancy-enabled object.
184215
That is the control's provable yield surface. ⛔ Do not cite it as "the sites
185216
without tenant context" — **32 further sites** have an options argument this
@@ -191,29 +222,29 @@ cannot read, and they are neither in nor out.
191222

192223
| what | count |
193224
| :--- | ---: |
194-
| write call sites on the application surface | **225** |
195-
| …whose object name is statically decidable | 149 |
225+
| write call sites on the application surface | **227** |
226+
| …whose object name is statically decidable | 151 |
196227
| …whose object name is chosen at run time | 76 |
197-
| …against an object with tenancy ENABLED | 149 |
198-
| …against an object that declares tenancy off | 0 |
199-
| threading a tenant context | 141 |
228+
| …against an object with tenancy ENABLED | 150 |
229+
| …against an object that declares tenancy off | 1 |
230+
| threading a tenant context | 143 |
200231
| PROVABLY carrying none (options read, no context key) | **17** |
201232
| …of those, against a decidably tenancy-enabled object | **9** |
202233
| options argument UNREADABLE — may or may not carry one | 67 |
203234
| …of those, against a decidably tenancy-enabled object | 32 |
204-
| threading a decidably ELEVATED (`isSystem`) context | 106 |
235+
| threading a decidably ELEVATED (`isSystem`) context | 108 |
205236
| threading a context that is decidably NOT elevated | 0 |
206237
| threading a context whose elevation is a run-time fact | 102 |
207238

208239
| how the instrument reached the site | count |
209240
| :--- | ---: |
210-
| receiver carried a readable engine type | 181 |
241+
| receiver carried a readable engine type | 183 |
211242
| receiver erased, placed by the object NAME | 18 |
212243
| receiver erased, placed by an `object: string` PARAMETER | 15 |
213244
| receiver erased, placed by an `UNTYPED_RECEIVERS` row | 11 |
214245

215-
| object name spelled inline | 109 |
216-
| object name spelled through a `const` | 40 |
246+
| object name spelled inline | 110 |
247+
| object name spelled through a `const` | 41 |
217248
| object name is an `object: string` parameter | 19 |
218249
| object name is some other run-time expression | 57 |
219250

@@ -232,8 +263,14 @@ must not be spelled the same way as «read it, not an engine».
232263

233264
| what | count |
234265
| :--- | ---: |
235-
| write calls subtracted with no defensible reason | **3** |
236-
| …whose declared type text states an engine door anyway | **2** |
266+
| write calls subtracted with no defensible reason | **1** |
267+
| …whose declared type text states an engine door anyway | **0** |
268+
269+
⛔ The second row is **0 by construction**, not a tally that happens to be low.
270+
An inline type literal stating a write door has no name for the engine type index
271+
to be keyed on, so the door rule is read off the type text itself and the site is
272+
PLACED — it is in the population above rather than subtracted here. A non-zero
273+
value on that row means a door-shaped receiver reached the subtraction anyway.
237274

238275
Every one of them is listed, by receiver and by the type text that could not be
239276
placed, in [`docs/audits/2026-08-tenant-audit-write-call-sites.counts.md`](https://github.com/objectstack-ai/objectstack/blob/main/docs/audits/2026-08-tenant-audit-write-call-sites.counts.md).
@@ -253,13 +290,13 @@ holds still. They are required to be HERE and to say WHEN they were true;
253290
their values are not compared. The reasoning, and the measurement behind it,
254291
are in `scripts/check-tenant-audit-census.mjs`.
255292

256-
Measured on 2026-09-18 at `d4cb05cbf`.
293+
Measured on 2026-09-18 at `30def652e`.
257294

258295
| corpus scale (not enforced) | count |
259296
| :--- | ---: |
260297
| tracked non-test sources scanned | 573 |
261298
| engine-shaped types recognised | 63 |
262299
| declared objects in the registry | 117 |
263-
| same-named calls subtracted as non-engine | 146 |
300+
| same-named calls subtracted as non-engine | 144 |
264301

265302
{/* END GENERATED: tenant-audit-census */}

‎docs/audits/2026-08-tenant-audit-write-call-sites.counts.md‎

Lines changed: 18 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -33,17 +33,17 @@ silent, and `node scripts/tenant-audit-census.mjs --write` is the resolution.
3333

3434
| Measure | Value |
3535
|---|---:|
36-
| Write call sites | 225 |
37-
| Object name statically decidable | 149 |
36+
| Write call sites | 227 |
37+
| Object name statically decidable | 151 |
3838
| Object name chosen at run time | 76 |
39-
| Against a tenancy-enabled object | 149 |
40-
| Against an object declaring tenancy off | 0 |
41-
| Threading a tenant context | 141 |
39+
| Against a tenancy-enabled object | 150 |
40+
| Against an object declaring tenancy off | 1 |
41+
| Threading a tenant context | 143 |
4242
| Provably carrying none | 17 |
4343
| …and decidably tenancy-enabled | 9 |
4444
| Options argument unreadable | 67 |
4545
| …and decidably tenancy-enabled | 32 |
46-
| Threading a decidably elevated context | 106 |
46+
| Threading a decidably elevated context | 108 |
4747
| Threading a decidably non-elevated context | 0 |
4848
| Threading a context of undecidable elevation | 102 |
4949

@@ -62,13 +62,17 @@ must not be spelled the same way as «read it, not an engine».
6262

6363
| what | count |
6464
| :--- | ---: |
65-
| write calls subtracted with no defensible reason | **3** |
66-
| …whose declared type text states an engine door anyway | **2** |
65+
| write calls subtracted with no defensible reason | **1** |
66+
| …whose declared type text states an engine door anyway | **0** |
67+
68+
⛔ The second row is **0 by construction**, not a tally that happens to be low.
69+
An inline type literal stating a write door has no name for the engine type index
70+
to be keyed on, so the door rule is read off the type text itself and the site is
71+
PLACED — it is in the population above rather than subtracted here. A non-zero
72+
value on that row means a door-shaped receiver reached the subtraction anyway.
6773

6874
| file | receiver | verb | why | declared type | door | n |
6975
|---|---|---|---|---|---|---:|
70-
| `packages/plugins/plugin-auth/src/audience-gate-test-support.ts` | `engine` | `insert` | anonymous-type | `{ insert: (name: string, data: any, options?: any) => Promise<unknown> } \| null` | ⚠️ yes | 1 |
71-
| `packages/plugins/plugin-auth/src/sso-client-secret.ts` | `e` | `update` | anonymous-type | `{ find(object: string, query: unknown): Promise<Record<string, unknown>[]>; update(object: string, data: unknown, options?: unknown): Promise<unknown>; }` | ⚠️ yes | 1 |
7276
| `packages/plugins/plugin-hono-server/src/adapter.ts` | `this.app` | `delete` | type-not-in-corpus | `Hono` | no | 1 |
7377

7478
## Corpus scale — present and dated, ⛔ NOT enforced
@@ -80,14 +84,14 @@ holds still. They are required to be HERE and to say WHEN they were true;
8084
their values are not compared. The reasoning, and the measurement behind it,
8185
are in `scripts/check-tenant-audit-census.mjs`.
8286

83-
Measured on 2026-09-18 at `d4cb05cbf`.
87+
Measured on 2026-09-18 at `30def652e`.
8488

8589
| corpus scale (not enforced) | count |
8690
| :--- | ---: |
8791
| tracked non-test sources scanned | 573 |
8892
| engine-shaped types recognised | 63 |
8993
| declared objects in the registry | 117 |
90-
| same-named calls subtracted as non-engine | 146 |
94+
| same-named calls subtracted as non-engine | 144 |
9195

9296
## Every site
9397

@@ -112,6 +116,7 @@ Measured on 2026-09-18 at `d4cb05cbf`.
112116
| `packages/plugins/plugin-auth/src/admin-user-endpoints.ts` | `insert` | `sys_audit_log` | enabled | elevated | 1 |
113117
| `packages/plugins/plugin-auth/src/admin-user-endpoints.ts` | `update` | `sys_user` | enabled | elevated | 1 |
114118
| `packages/plugins/plugin-auth/src/adopt-membership.ts` | `update` | `SystemObjectName.MEMBER` | undecidable | PROVABLY NONE | 1 |
119+
| `packages/plugins/plugin-auth/src/audience-gate-test-support.ts` | `insert` | `sys_invitation` | enabled | elevated | 1 |
115120
| `packages/plugins/plugin-auth/src/auth-manager.ts` | `update` | `sys_account` | enabled | options unreadable | 1 |
116121
| `packages/plugins/plugin-auth/src/auth-manager.ts` | `update` | `sys_session` | enabled | options unreadable | 3 |
117122
| `packages/plugins/plugin-auth/src/auth-manager.ts` | `update` | `sys_two_factor` | enabled | options unreadable | 1 |
@@ -133,6 +138,7 @@ Measured on 2026-09-18 at `d4cb05cbf`.
133138
| `packages/plugins/plugin-auth/src/reconcile-membership.ts` | `insert` | `sys_member` | enabled | context, elevation undecidable | 1 |
134139
| `packages/plugins/plugin-auth/src/scim-connection-service.ts` | `insert` | `sys_scim_connection_credential` | enabled | PROVABLY NONE | 1 |
135140
| `packages/plugins/plugin-auth/src/session-tombstone.ts` | `update` | `objectName` | undecidable | options unreadable | 1 |
141+
| `packages/plugins/plugin-auth/src/sso-client-secret.ts` | `update` | `sys_sso_provider` | disabled | elevated | 1 |
136142
| `packages/plugins/plugin-email/src/attachment-reclaim.ts` | `update` | `sys_email` | enabled | elevated | 1 |
137143
| `packages/plugins/plugin-email/src/bootstrap-declared-email-templates.ts` | `insert` | `object` | undecidable | elevated | 1 |
138144
| `packages/plugins/plugin-email/src/bootstrap-declared-email-templates.ts` | `update` | `object` | undecidable | elevated | 2 |

0 commit comments

Comments
 (0)