Repository navigation
Commit 0046a41
docs(qa): re-anchor three approvals knownGaps on the sys_account.issuer retirement (#19213)
Fixes #17453
## What this changes
Three `knownGap` texts in
`docs/qa/platform-checklist/areas/approvals.json` cited
`packages/plugins/plugin-auth/src/backfill-account-issuer.ts,
CREDENTIAL_ISSUER`. That module
retired with `sys_account.issuer` when better-auth 1.7.3 rolled the
issuer-scoped account identity
back (#17440, closed 2026-09-12), so the citation names a file that is
not on the tree and a reader
who follows it cannot tell whether the gap is closed or the citation
merely rotted.
The file's convention is explicit — *the gap text stays because it
carries the reason* — so this is
not a path substitution, and there is nothing to substitute anyway:
- `backfill-account-issuer.ts` is gone. Positive control: `ls
packages/plugins/plugin-auth/src/`
lists **176** files, so the empty `grep backfill` is a reading, not a
broken instrument.
- `CREDENTIAL_ISSUER` survives only as history — as a retired symbol
named in
`packages/spec/src/migrations/entries/semantic/18.sys-account-issuer-retired.ts`
(and its copy in
the generated `packages/spec/src/migrations/registry.ts`), and as the
deliberately renamed test
constant `LEGACY_CREDENTIAL_ISSUER` in
`packages/plugins/plugin-auth/src/account-issuer-upgrade-path.test.ts`.
There is no live symbol to re-point the three citations at.
So each text keeps the reason it exists to carry — a password hash alone
was not enough; the failure
was a silent lockout whose `User not found` warn pointed at the
`sys_user` row rather than at the
account — and now records that the trap **retired with the column**,
anchored on the retirement's
own migration entry, which is a durable record rather than a module that
can be deleted.
### The clauses the retirement also falsified
The card's second claim measured true, and this pass fixes it in the
same edit. The governing text
is the repo's own, in
`examples/app-showcase/src/security/seed-approval-demo.ts`:
> 1.7.3 rolled that model back and `sys_account.issuer` retired with it,
so the derivation, its
> failure branch and the whole class of silent lockout behind it are
gone. `(provider_id, account_id)`
> is the key, and `internalAdapter.createAccount` supplies both.
Withdrawn accordingly:
| text | falsified clause | now reads |
|---|---|---|
| `approvals.per-group-signoff` | "the issuer READ OFF the dev admin's
own credential row rather than re-spelled" | the seed provisions the
account through better-auth's own `$context`; there is no issuer to read
|
| `approvals.viewer-gating-submitter-side` | "derives that issuer from
the dev admin's own credential row and stamps it"; "pins both the issuer
and the sign-in" | nothing is derived or stamped; the dogfood test pins
the account under the key sign-in resolves on and asserts nothing still
writes the retired field |
| `approvals.ooo-delegation-reroute` | "(issuer derived from the dev
admin's own row)" | delegate B is constructible with nothing about her
issuer to get right |
Each of the three items bumps `revision` and appends a `history` entry,
per the checklist's
change lifecycle (`docs/qa/platform-checklist/README.md`).
## One bounded in-place fix, declared
`approvals.ooo-delegation-reroute`'s **steps** carried the same dead
requirement one field below the
gap text it points at: *"provision B as a real login (see knownGaps: the
credential account's issuer
must be local:credential)"*. Left alone it would have contradicted the
rewritten `knownGap` three
lines above it and still sent a runner looking for a column that no
longer exists — a replayed
instruction, not prose. It is corrected to "a stock boot already does
it, see knownGaps".
It is declared here because it sits outside the three texts the dispatch
named, and it is inside
every other boundary: same file (the declared file surface), same defect
class, mechanical, no new
verification surface, and no other claim holds this file.
## Measurements
Base `origin/main` @ `24d622b94`; gates re-run on the final commit.
The three citations were at `:23`, `:259`, `:662` — no drift from the
card.
`node scripts/pm/dispatch-gates.mjs --commands` prescribes 12 commands
for this surface. All 12 are
green (`EXIT=0`), including `pnpm check:platform-checklist`. Two needed
prerequisites first
(`pnpm install` in the fresh worktree; `turbo run build
--filter=@objectstack/formula
--filter=@objectstack/lint` for `check:doc-formula-expressions`) — their
first `exit 3` was
`PREREQUISITE NOT MET`, not a finding.
The zero-headroom surface did not move. Census line **before** and
**after** the edit are identical:
```
check-platform-checklist: OK — 15 areas, 264 items (264 active, 0 planned); coverage: 38 kinds mapped,
1 waived; traps: 19 documented, 19 in use; provisioning: 5 area recipes, 8 item references resolved
(1 area-qualified), 5/5 recipes referenced; meta-URL spelling: 19 `call` strings scanned against 34
folded spellings; line citations: 0 survive across 20 swept documents; symbol anchors: 600/633 resolved
by `symbol-anchors.mjs` across 20 swept documents against 310 cited sources, 33 on the named #16898
residual, 17 file floors held
```
That is the expected reading rather than luck: the three citations were
**bare paths**, not
`path#symbol` anchors, so they were never in the anchor population the
floors count — and the new
anchor is written bare and without a line number, which also keeps the
`file:line` limb at 0.
No floor and no baseline JSON was touched.
## Acceptance notes
- `docs/qa/platform-checklist/areas/approvals.json` history entries at
revisions 4 and 5 of the three
items still narrate the issuer trap in the past tense ("issuer derived
from the dev admin's own
row"). They are **left alone on purpose**: `history` is the append-only
record of what the item said
when a run was pinned against it, and rewriting it would destroy the
thing that makes old run
records interpretable.
- `scripts/check-platform-checklist.mjs` carries a `bad-citation` ledger
row for this file
(`seed-approval-demo.ts#AUDITOR_DEMO_USER`, `shape: import-only`). It is
a different citation from
the three changed here and is untouched; noted, not filed.
---
_Generated by [Claude
Code](https://claude.ai/code/session_017ef78bLdybu3AffehKkhfk)_
Co-authored-by: Claude <noreply@anthropic.com>1 parent ad192cb commit 0046a41
1 file changed
Lines changed: 13 additions & 10 deletions
0 commit comments