Commit c64e65f
* fix(plugin-security): the app default permission set resolves from the first level that NAMES one (#15298)
`declaredPermissionSets`' docblock stated a short-circuit the code did not
have: it pushed the flattened top level and then every package body
unconditionally, collecting each permission set twice on today's additive
artifact. The duplication was unobservable at the sole (private) call site,
which takes the first `isDefault` set, so this corrects a false written
contract on a security-path reader rather than a live defect.
The reader now walks the discipline its docblock claims — start from the
expression the card replaced (`appDefaultPermissionSetName(config.permissions)`)
and consult `packages[]` only where it came back `undefined`.
The condition is the resolved NAME, never the `permissions` container:
branching on the container re-creates the silent loss the card removed one
shape further along, since a flattened level that carries sets but marks none
of them `isDefault` is legal and hand-authorable.
`resolveArtifactPackageOrder` is called before the top level is consulted, so
its ADR-0112 refusal of a malformed `packages` stays unconditional instead of
depending on which level happened to answer first.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UHvF5hyiZjnCyExFnfQB8m
* chore(changeset): record the plugin-security default-permission-set reader correction (#15298)
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UHvF5hyiZjnCyExFnfQB8m
* docs(plugin-security): say why this reader branches on the answer where the sibling branches on the container (#15298)
`resolveStackCollection` (packages/cli/src/utils/stack-collections.ts, #15006)
landed on main branching on the container, and is right to: it returns a whole
collection, so a present top-level key has already answered. This reader
extracts a distinguished element out of the collection, so "present" and
"answers" are different facts here.
Recording the reason in the docblock so the convergence pass reads two readers
that differ AND say why, rather than two that differ while appearing to agree.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UHvF5hyiZjnCyExFnfQB8m
* chore(changeset): name the #15226 sentence this entry supersedes in the same unreleased batch (#15298)
Both entries are patch bumps on @objectstack/plugin-security and will compile
into one release. Leaving the earlier one as written keeps the record honest;
naming the superseded sentence keeps the compiled notes from carrying a
contradiction.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UHvF5hyiZjnCyExFnfQB8m
---------
Co-authored-by: Claude <noreply@anthropic.com>
1 parent 5964124 commit c64e65f
3 files changed
Lines changed: 192 additions & 36 deletions
File tree
- .changeset
- packages/plugins/plugin-security/src
Lines changed: 57 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
Lines changed: 66 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
259 | 259 | | |
260 | 260 | | |
261 | 261 | | |
| 262 | + | |
| 263 | + | |
| 264 | + | |
| 265 | + | |
| 266 | + | |
| 267 | + | |
| 268 | + | |
| 269 | + | |
| 270 | + | |
| 271 | + | |
| 272 | + | |
| 273 | + | |
| 274 | + | |
| 275 | + | |
| 276 | + | |
| 277 | + | |
| 278 | + | |
| 279 | + | |
| 280 | + | |
| 281 | + | |
| 282 | + | |
| 283 | + | |
| 284 | + | |
| 285 | + | |
| 286 | + | |
| 287 | + | |
| 288 | + | |
| 289 | + | |
| 290 | + | |
| 291 | + | |
| 292 | + | |
| 293 | + | |
| 294 | + | |
| 295 | + | |
| 296 | + | |
| 297 | + | |
| 298 | + | |
| 299 | + | |
| 300 | + | |
| 301 | + | |
| 302 | + | |
| 303 | + | |
| 304 | + | |
| 305 | + | |
| 306 | + | |
| 307 | + | |
| 308 | + | |
| 309 | + | |
| 310 | + | |
| 311 | + | |
262 | 312 | | |
263 | 313 | | |
264 | 314 | | |
| |||
293 | 343 | | |
294 | 344 | | |
295 | 345 | | |
| 346 | + | |
| 347 | + | |
| 348 | + | |
| 349 | + | |
| 350 | + | |
| 351 | + | |
| 352 | + | |
| 353 | + | |
| 354 | + | |
| 355 | + | |
| 356 | + | |
| 357 | + | |
| 358 | + | |
| 359 | + | |
| 360 | + | |
| 361 | + | |
296 | 362 | | |
297 | 363 | | |
Lines changed: 69 additions & 36 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
86 | 86 | | |
87 | 87 | | |
88 | 88 | | |
89 | | - | |
90 | | - | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
91 | 92 | | |
92 | 93 | | |
93 | 94 | | |
| |||
114 | 115 | | |
115 | 116 | | |
116 | 117 | | |
117 | | - | |
118 | | - | |
119 | | - | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
| 138 | + | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
120 | 147 | | |
121 | 148 | | |
122 | 149 | | |
123 | | - | |
124 | | - | |
125 | | - | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
126 | 153 | | |
127 | 154 | | |
128 | 155 | | |
129 | 156 | | |
130 | 157 | | |
131 | 158 | | |
132 | 159 | | |
133 | | - | |
134 | | - | |
135 | | - | |
136 | | - | |
137 | | - | |
138 | | - | |
139 | | - | |
140 | | - | |
141 | | - | |
142 | | - | |
143 | | - | |
144 | | - | |
145 | | - | |
146 | | - | |
147 | | - | |
| 160 | + | |
| 161 | + | |
| 162 | + | |
| 163 | + | |
| 164 | + | |
| 165 | + | |
| 166 | + | |
| 167 | + | |
| 168 | + | |
| 169 | + | |
| 170 | + | |
| 171 | + | |
| 172 | + | |
| 173 | + | |
| 174 | + | |
| 175 | + | |
| 176 | + | |
| 177 | + | |
| 178 | + | |
148 | 179 | | |
149 | | - | |
150 | | - | |
| 180 | + | |
| 181 | + | |
| 182 | + | |
| 183 | + | |
151 | 184 | | |
152 | 185 | | |
153 | | - | |
154 | | - | |
155 | | - | |
156 | | - | |
| 186 | + | |
| 187 | + | |
157 | 188 | | |
158 | | - | |
| 189 | + | |
159 | 190 | | |
160 | | - | |
| 191 | + | |
| 192 | + | |
161 | 193 | | |
162 | | - | |
| 194 | + | |
163 | 195 | | |
164 | 196 | | |
165 | 197 | | |
| |||
191 | 223 | | |
192 | 224 | | |
193 | 225 | | |
194 | | - | |
195 | | - | |
196 | | - | |
| 226 | + | |
| 227 | + | |
| 228 | + | |
| 229 | + | |
197 | 230 | | |
198 | 231 | | |
199 | 232 | | |
200 | 233 | | |
201 | | - | |
| 234 | + | |
202 | 235 | | |
203 | 236 | | |
0 commit comments