Skip to content

Commit a54aa9e

Browse files
committed
fix(changeset, spec): cut the write universals an OR-sibling policy falsifies
Measured at the merged head on driver-sql: beside a sibling policy whose check admits, a policy carrying a list comparand is dropped and the sibling alone decides, so the forbidden insert is admitted. Two sentences claimed otherwise and are cut, with no replacement prose: the rest of the 2a changeset's span-1 sentence ("Both shapes now fail the write"), and the 2a entry's acceptanceCriteria universal, the same sentence class this PR's own entry lost in the previous commit. registry.ts regenerated. Claude-Session: https://claude.ai/code/session_01Sfe5YjBLwB9J3y8fvm2xq1 Co-authored-by: Claude <noreply@anthropic.com>
1 parent 5bd2df5 commit a54aa9e

3 files changed

Lines changed: 3 additions & 7 deletions

File tree

‎.changeset/19886-formula-array-comparand-refused.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ Clause-②: no (narrowing)
1515
- a `check` written `record.status != ['closed', 'archived']`, or `!=` against a `current_user` membership array, lowered to `{ status: { $ne: [...] } }` and matched **every** post-image;
1616
- a `check` written `!(record.status == ['closed', 'archived'])` lowered to `{ $not: { status: [...] } }` and did the same.
1717

18-
Every write such a policy was written to refuse was admitted and stored. Both shapes now fail the write. The positive `record.status == ['open', 'pending']` already refused every write (403).
18+
Every write such a policy was written to refuse was admitted and stored. The positive `record.status == ['open', 'pending']` already refused every write (403).
1919

2020
The message withholds the field, the operator and the value, because the filter is usually an access policy the caller did not write, and the comparand may be a resolved membership set.
2121

‎packages/spec/src/migrations/entries/semantic/18.rls-predicate-array-comparand-refused.ts‎

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -42,9 +42,7 @@ export const entry: SemanticMigration = {
4242
acceptanceCriteria:
4343
'Grep the rowLevelSecurity check and using predicates of your permission sets for != or == '
4444
+ 'whose right-hand side is a list literal or a current_user membership array, and for the '
45-
+ 'negation of such an ==, then rewrite each with in or !(... in ...). A check that still '
46-
+ 'carries the shape refuses every write it governs, allowed '
47-
+ 'values included, so one allowed write under each policy finds every such check left. '
45+
+ 'negation of such an ==, then rewrite each with in or !(... in ...). '
4846
+ 'Then re-check what each policy is supposed to refuse rather than assuming the writes it '
4947
+ 'admitted before were right: before this change a != or a negated == against a list '
5048
+ 'admitted every write.',

‎packages/spec/src/migrations/registry.ts‎

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -11603,9 +11603,7 @@ const step18: MigrationStep = {
1160311603
acceptanceCriteria:
1160411604
'Grep the rowLevelSecurity check and using predicates of your permission sets for != or == '
1160511605
+ 'whose right-hand side is a list literal or a current_user membership array, and for the '
11606-
+ 'negation of such an ==, then rewrite each with in or !(... in ...). A check that still '
11607-
+ 'carries the shape refuses every write it governs, allowed '
11608-
+ 'values included, so one allowed write under each policy finds every such check left. '
11606+
+ 'negation of such an ==, then rewrite each with in or !(... in ...). '
1160911607
+ 'Then re-check what each policy is supposed to refuse rather than assuming the writes it '
1161011608
+ 'admitted before were right: before this change a != or a negated == against a list '
1161111609
+ 'admitted every write.',

0 commit comments

Comments
 (0)