Skip to content

[rebuild of #19354] feat(spec): ISecurityService gains the effective-object-permission reader — the packages/spec half of objectstack-ai/objectstack#18783, split out under 强制条款② #19578

Description

@os-steve

REBUILD of card #19354, whose original is unreachable. Filed by the domain:spec seat 4 (session_01AmH9bKvGoLjiY86Q4Z3og2, seat post #18917) on 2026-09-21, under the maintainer's instruction to rebuild the cards lost when the os-sam account was banned.

⛔ The original is not deleted and ⛔ nothing here overrules it. GET and PATCH on …/issues/19354 both answer 404; a card this seat filed answers 200 on the same path, so it is ⛔ not a token or rate problem.

⚠️ This card had fallen out of every listing, which is why it was nearly lost

The ban does not only break the single-issue read: the card disappears from GET /issues?labels=… as well. Measured at rebuild time — the domain:spec · pm:queue listing returned 93 cards at 2026-09-21T03:45Z and 80 now; of the 17 that left, eleven closed or moved legitimately and six are simply unreadable: #19354, #19368, #19377, #19389, #19410, #19421.

⇒ nothing would ever have surfaced this card again. Its body below is reproduced from a read this seat took at 2026-09-21T03:45Z, before the ban — ⛔ not reconstructed, ⛔ not summarised. Its original labels were priority:p2 · pm:queue · domain:spec, and this rebuild carries them; ⛔ a re-grade is triage's, not this seat's.

Rebuild ledger for the ban: #19384#19541 (closed not_planned under ruling #208) · #19474#19542 (live, PR #19517) · #19389#19568 · #19377 → ⛔ not rebuilt, already closed completed with its PR merged · and this batch: #19354, #19368, #19410, #19421.


The original card, reproduced verbatim below, ⛔ not rewritten

Split out of #18783 by the triage seat (session_01KYzNJPin9Ar4oMMkSh4S9h) at 2026-09-20T13:51Z, answering the domain:engine seat's pm:retriage (issuecomment-5749198306) with option B — split, the shape that seat listed and declined to choose itself.

Why this half exists separately

The ruled work (batch #156 item 5 letter A, issuecomment-5725678115, maintainer 「同意」) is, verbatim:

ISecurityService gains an effective-object-permission reader, threaded through the engine so evaluateOptionVisibility populates EvalContext.permissions; a census of every current_user-bound predicate evaluation site comes first

That sentence names two landing surfaces. The first one is packages/spec:

packages/spec/src/contracts/security-service.ts:245:export interface ISecurityService {

Both limbs of the spec-lane test hit, re-read on origin/main by the triage seat rather than taken from the requesting seat:

limb verdict
path — the diff touches packages/spec/src/** HIT
declaration — adding a reader to a published interface widens the public surface HIT

SKILL.md:640「双肢命中即 spec 车道」 · references/lanes/spec.md:12packages/spec 恒归本席,不论谁需要它」 · SKILL.md:290「新 packages/spec 工作恒归 spec 座位」 · references/core-rules.md:62「新 spec 工作由 spec 席收口」.

⚠️ 本段的一条引用于 2026-09-20T13:54Z 被更正,原文留在这里而不是抹掉。 初版引的是 SKILL.md:234「新 packages/spec 工作恒由 domain:spec 席收口,不论谁需要它;已派发卡 ⛔ 不因触 spec 转席。」—— 那一行已于提交 912083757(2026-09-20T12:43:45Z,PR #19321)退役,origin/main 上 grep 零命中。⛔ 本席写这张卡时读的是本地检出,而它停在旧 main 上,于是把一条死行号当成了现行章程。⇒ 判词不变:该规则的两半都活在上面新列的三个载体里;变的只是引用指向哪一行。⚠️ 同样被那次提交改掉的还有锚定规则本身,现读为「每个包恰属一个域;domain:* = 修复落地包的域;Seam: 卡归 spec 席,默认纵向派发」,与本卡的拆法同向。

⚠️ The exception that would have kept it in the engine lane — 「已派发卡 ⛔ 不因触 spec 转席」 — does not apply: #18783 is un-dispatched, and 「定车道与改路由限未派发卡」 is exactly the window pm:retriage exists for. Raising it before dispatch was the cheap moment; after dispatch it would have been too late.

Scope of THIS card

⚠️ Two constraints carried over from #18783, ⛔ neither re-derived here

  1. The engine does not hold what the reader must return. ExecutionContext.permissions carries permission-set NAMES, ⛔ not object bits. That is why this is a new reader rather than a re-projection of something already threaded.
  2. A hard serial pair, from both ends. evaluateOptionVisibility sits at packages/objectql/src/validation/rule-validator.ts:2150; checkPredicate, which formula/objectql: relationship traversal in predicates — a validation rule or visibility predicate reads one hop through a lookup (record.crm_account.type); replaces the removed os.lookup declaration (#18318, batch #148) #18682 must change, sits at :2713the same file. ⇒ formula/objectql: relationship traversal in predicates — a validation rule or visibility predicate reads one hop through a lookup (record.crm_account.type); replaces the removed os.lookup declaration (#18318, batch #148) #18682 and the engine half are ⛔ not parallelisable. Recorded on formula/objectql: relationship traversal in predicates — a validation rule or visibility predicate reads one hop through a lookup (record.crm_account.type); replaces the removed os.lookup declaration (#18318, batch #148) #18682 as well by the engine seat, so the constraint is visible from both ends.

⛔ Not in dispute

The ruling itself — letter A, and the census-first ordering — is untouched by this split. A split moves work between seats; it ⛔ never re-opens the direction.

Refs: #18783 (the engine half, now blocked on this) · #18545 · #18682 · issuecomment-5725678115 (the ruling)


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions