Commit e238c79
* fix(plugin-auth): report the refused admin-audit writes two `catch {}` sites swallowed
Two tier-1 DARK durability swallows on plugin-auth's admin surface (#12981
batch 6): an administrative action landed, its audit row was refused, and the
endpoint answered 200 with nothing recorded anywhere. Control flow is unchanged
at both sites — an admin operation must never fail over its own audit — but the
refusal is no longer silent.
Both catches were doing two jobs and were only right about one. plugin-audit
UNINSTALLED means no sys_audit_log object, so nothing ever claimed the action
would be audited and silence is correct. A REFUSED write is the other thing
entirely, and it wore the same catch. Each site now asks
getSchema('sys_audit_log') — the registry that owns the answer — rather than
reading the driver's error text, which would decide the same question by
guessing. getSchema is declared optional on AdminUserDataEngine and
IdentityImportEngine, so it is additive; where it is absent the site cannot
measure the difference and therefore reports.
What was hiding in the silence: sys_account is in plugin-audit's SKIP_OBJECTS,
so the row refused in writeAdminAudit was the only record that a password was
administratively reset; and the run-level import row is a shape plugin-audit's
actionFor structurally cannot emit, so the per-row create rows kept the trail
looking complete while who ran the import and under which policy was gone.
Both sinks are re-exported from index.ts and declare no error, so the LEVEL
stays warn and remains #13398's question; only the SILENCE is repaired here.
Each seam is pinned, plus absence-asserting cases so a seam that warns
unconditionally cannot pass.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016ZC5rNQj3WEet5HAmmAkMs
* test(plugin-auth): silence an unused engine-double parameter in the batch 6 pins
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016ZC5rNQj3WEet5HAmmAkMs
* chore: ratchet the engine-double ledger for the batch 6 pin (1 -> 2 pinned)
Coverage grew, which is the direction the shrink-only ledger wants; the gate's
own verdict line asked for --write.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016ZC5rNQj3WEet5HAmmAkMs
---------
Co-authored-by: Claude <noreply@anthropic.com>
1 parent 6c3f9f5 commit e238c79
5 files changed
Lines changed: 415 additions & 21 deletions
File tree
- .changeset
- packages/plugins/plugin-auth/src
- scripts
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
89 | 89 | | |
90 | 90 | | |
91 | 91 | | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
92 | 105 | | |
93 | 106 | | |
94 | 107 | | |
| |||
510 | 523 | | |
511 | 524 | | |
512 | 525 | | |
513 | | - | |
514 | | - | |
515 | | - | |
516 | | - | |
517 | | - | |
518 | | - | |
519 | | - | |
520 | | - | |
521 | | - | |
522 | | - | |
523 | | - | |
524 | | - | |
525 | | - | |
526 | | - | |
527 | | - | |
528 | | - | |
529 | | - | |
| 526 | + | |
| 527 | + | |
| 528 | + | |
| 529 | + | |
| 530 | + | |
| 531 | + | |
| 532 | + | |
| 533 | + | |
| 534 | + | |
| 535 | + | |
| 536 | + | |
| 537 | + | |
| 538 | + | |
| 539 | + | |
| 540 | + | |
| 541 | + | |
| 542 | + | |
| 543 | + | |
| 544 | + | |
| 545 | + | |
| 546 | + | |
| 547 | + | |
| 548 | + | |
| 549 | + | |
| 550 | + | |
| 551 | + | |
| 552 | + | |
| 553 | + | |
| 554 | + | |
| 555 | + | |
| 556 | + | |
| 557 | + | |
| 558 | + | |
| 559 | + | |
| 560 | + | |
| 561 | + | |
| 562 | + | |
| 563 | + | |
| 564 | + | |
| 565 | + | |
| 566 | + | |
| 567 | + | |
| 568 | + | |
| 569 | + | |
| 570 | + | |
| 571 | + | |
| 572 | + | |
| 573 | + | |
| 574 | + | |
| 575 | + | |
530 | 576 | | |
531 | 577 | | |
532 | 578 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
116 | 116 | | |
117 | 117 | | |
118 | 118 | | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
| 136 | + | |
119 | 137 | | |
120 | 138 | | |
121 | 139 | | |
| |||
376 | 394 | | |
377 | 395 | | |
378 | 396 | | |
| 397 | + | |
| 398 | + | |
| 399 | + | |
| 400 | + | |
| 401 | + | |
| 402 | + | |
379 | 403 | | |
380 | 404 | | |
381 | 405 | | |
| |||
389 | 413 | | |
390 | 414 | | |
391 | 415 | | |
392 | | - | |
393 | | - | |
394 | | - | |
| 416 | + | |
| 417 | + | |
| 418 | + | |
| 419 | + | |
| 420 | + | |
| 421 | + | |
| 422 | + | |
| 423 | + | |
| 424 | + | |
| 425 | + | |
| 426 | + | |
| 427 | + | |
| 428 | + | |
| 429 | + | |
| 430 | + | |
| 431 | + | |
| 432 | + | |
| 433 | + | |
| 434 | + | |
| 435 | + | |
| 436 | + | |
| 437 | + | |
| 438 | + | |
| 439 | + | |
| 440 | + | |
395 | 441 | | |
396 | 442 | | |
397 | 443 | | |
| |||
0 commit comments