Skip to content

design(v18): the complete guest model in one ADR — identity, doors, grants channel, organization, public-site binding, disclosure, rate limits, and each declared guest key's fate (ADR-0090 D9 enforce-or-remove) #22146

Description

@objectstack-fleet

Ruled: 6074960686 · letter A (G2: close the three doors, then accept) · 2026-10-09T05:32Z
Ruled: 6056614963 · letter D1 A′ D2b R · 2026-10-08T09:14Z
Ruled: 6054113537 · letter A G2 · 2026-10-08T06:44Z
Blocked-by: #22432
Blocked-by: #22430
Blocked-by: #22431

Filing gate: ② a design card on the maintainer's word. Filed by the director seat (seat post #12708, summon #35, session_01VYToj6PQehTEKNrjGM9akg) after the decision discussion on #21908's second privately held producer row (the anonymous object_operation posture). The maintainer asked 「guest 是不是应该完整的重新设计并开adr」, then stated the demand 「最为一个元数据开发平台,guest 是常见的需求吧?」, and answered the seat's proposal (a domain:spec design card at the priority named, with the interim C on the dispatcher) with 「同意 p1」. That sentence is the named demand this card rests on. ⛔ Not a claim. ⛔ Classes, positions and functions only; the anonymous doors' measured readings stay private where #21158 kept them private.

Reader: the domain:spec seat, in the design-round pattern of #8346 and #8345 (a measurement round first, then a decision request, then the ADR draft). priority:p1 · security · target:v18.

Why one ADR, and why now

The anonymous principal is declared in at least seven places today, two of them declared but not enforced, one of them a maintainer ruling that lives only in a code comment, and one question nobody has answered:

Where What it says State on origin/main
ADR-0056 D2; packages/core/src/security/anonymous-deny.ts (#2567) the platform denies anonymous callers by default, one shared !userId && !isSystem → 401 decision enforced; today's floor
ADR-0090 D9 / D10 the guest builtin position, held implicitly and exclusively by unauthenticated principals; the everyone / guest audience anchors packages suggest and never own; the human / agent / guest principal taxonomy declared, not enforced: a permission set bound to the guest anchor resolves nothing (#21158, closed not_planned on 2026-10-04 for want of demand; its question is folded into this card)
the maintainer's ruling of 2026-08-08, Option A (commit f586f1a89) two named entries: assembleExecutionContext (fail-closed, 401) and assembleExecutionContextOrGuest (a first-class guest envelope), the latter adopted only by surfaces that genuinely serve anonymous principals enforced; written in packages/core/src/security/assemble-execution-context.ts near :30 and :386, in no ADR
ADR-0096 D5 / E1 the principal-less hand-off and strict mode being closed by #21908
ADR-0106 D7 guest-facing metadata disclosure; the fallback permission set enforced
ADR-0121 D6 an authRequired: false endpoint must carry an armed rateLimit; webhook signature keys named as a future vocabulary, not promised enforced
packages/metadata-core/src/anonymous-form-intake.ts (#21967, #21980, #21331) the public form doors' candidates, withdrawal and organization (the deployment's default organization) enforced; a posture of its own
the dispatcher's anonymous object_operation path the docs promise "under the anonymous principal"; the executor threads undefined (packages/runtime/src/endpoint-executor.ts:95) gap; the interim is its own card, ruled C (the guest entry), filed beside this one
"which organization does a guest act in" #21158's open semantics; only the form doors answer for themselves unruled

Every mainstream metadata-driven application platform ships a complete anonymous model as a first-class capability: Salesforce Experience Cloud (a site, a guest user with a guest profile, guest-only sharing rules, secure-guest defaults: private org-wide defaults, no record ownership), ServiceNow (public portal pages and scripted REST executing as the guest user under the same ACLs), Microsoft Power Pages (a site, the Anonymous Users web role, table permissions), Odoo (auth='public' executing as the public user under record rules; auth='none' reserved for infrastructure), Supabase (the anon role under row-level security), Hasura (the unauthorized role, or refusal). The scenarios are the ones this platform's customers have: the pre-login half of a customer portal, public forms, public catalogs (products, positions, locations), token-addressed lookups (order tracking, unsubscribe, confirmation), partner webhooks.

The eight questions the ADR decides (questions, not answers)

  1. Identity and ownership. The guest is a principal (principalKind: 'guest', positions: ['guest']), never the system principal; whether a guest may own a record, and if not, whose record a guest's write becomes.
  2. The closed list of doors that may adopt the guest entry: the anonymous form doors, authRequired: false endpoints of type flow, object_operation reads, anything else; every other surface answers 401.
  3. The grants channel. Whether the guest anchor's bindings become enforced (the security(core, plugin-security): an unauthenticated principal never resolves the permission sets bound to the guest anchor; ADR-0090 D9 is declared and seeded but not enforced #21158 gap closed), how a deployment grants a guest permission set, and what the empty state answers (deny-all).
  4. Organization. Which organization an anonymous request acts in: the deployment default, a per-site mapping, the walled deployment's answer; alignment with ADR-0131.
  5. Public-site binding. Whether a metadata object binds host or path prefix → organization → guest permission set → allowed doors, the way the platforms above bind a site; this is also where question 4 would be answered declaratively.
  6. Disclosure and explain. Whether ADR-0106 D7 and the explain engine's EXTERNAL posture stand unchanged.
  7. Abuse limits. ADR-0121 D6 stands; whether the webhook signature vocabulary (HMAC, timestamp, replay window) enters with this ADR, with its executor.
  8. The fate of every declared guest key under ADR-0049 (enforce or remove) with ADR-0087 conversions: GUEST_POSITION, AUDIENCE_ANCHOR_POSITIONS (packages/spec/src/identity/position.zod.ts:150), the guest value of sys_audience_binding_suggestion, the two named context entries, the fallback permission set's guest reading.

Process

  • Round 1, measurement only, no production change: an AST census of every reader of GUEST_POSITION, 'guest' and principalKind === 'guest' with positions; the anonymous behaviour of every HTTP door measured on a booted showcase (status and what is served), by door class; the hotcrm tree read for any anonymous surface; a comparison table of the five platforms above against the eight questions. Readings that would be exploit recipes stay private, as security(core, plugin-security): an unauthenticated principal never resolves the permission sets bound to the guest anchor; ADR-0090 D9 is declared and seeded but not enforced #21158's did.
  • Round 2: a decision request in the six-item form, the eight questions with options and the four axes, presented by the director seat; the maintainer rules.
  • Round 3: the ADR draft (docs/adr/**, Tier H, the maintainer's approval), then execution cards in the v18 line, each with pins and ADR-0087 dispositions where a key moves.
  • ⛔ No change to packages/spec before the ADR is accepted. ⛔ Round 1 dispatches no build.

Not decided here

The answers. The interim for the dispatcher (the guest entry, ruled C) lands on its own card before #21908's deny and is consistent with any answer this ADR gives: with no grants channel it is deny-all; when the channel lands, the same path serves.

Related: #21158 (folded in) · #21908 · #21967 · #21980 · #21331 · ADR-0056 · ADR-0090 · ADR-0096 · ADR-0106 · ADR-0121 · ADR-0131.

Prior rulings read: guest, anonymous, audience anchor, authRequired, public form → ADR-0090 D9/D10, ADR-0106 D7, ADR-0121 D6, the 2026-08-08 Option A ruling (code comment), #21158's closure 5980599467 (「21158 既然没有需求那就关闭」, superseded by the demand named above), #21967 / #21980 (anonymous intake withdrawal); none designs the model whole.


Generated by Claude Code

Activity

  1. objectstack-fleet commented on Oct 8, 2026

    @objectstack-fleet
    ContributorAuthor

    Claim: PM loop round 1 (round 1 of 3: measurement only, per the card's Process) · 2026-10-08T04:26Z
    Session: session_01LAi5BVvQNiYzepSAcsoFLK
    Account: os-litant (the seat's linked user as GET /user answers it; the card's assignee from this act)
    Branch: claude/issue-22146-guest-model-measure
    Worktree: objectstack-issue-22146
    Domain: domain:spec
    Seat: domain:spec#1 (seat post #6017)
    File surface: ⛔ none written. Measurement round only (the card's Process, round 1: "measurement only, no production change", "⛔ Round 1 dispatches no build"). The branch stays at its base and no PR is opened, in the shape of #8346's round (6041073455). Measured on origin/main 959c209d56:

    • an AST census of every reader of GUEST_POSITION, 'guest' and principalKind === 'guest', with their positions;
    • the anonymous behaviour of every HTTP door, by door class, on a booted showcase (the dev's own temporary server, stopped by the dev);
    • a read of the hotcrm tree (public, a read-only shallow clone in scratch) for any anonymous surface;
    • the five-platform comparison against the eight questions.

    Every probe is a scratch file, deleted after the run. Stop on breach and explain in the report.
    Container & model: L (breadth: census, booted measurement, a second tree, a comparison), mode:subagent, model: opus (--tier: no path-derived mandate; the default tier for a design round with judgment).
    Clause-②: no
    Responsibility: n/a — not a defect card
    Thread-read: none
    Serial constraints cleared: none. The round writes no file. The dispatcher interim (the guest entry, ruled C) is its own card and is not touched here.

    What the round delivers: a measured design note in the os-dev-report, in classes, positions and functions only. Door-level readings that would work as an exploit recipe stay off GitHub, as #21158's did: they go only to this seat's session. Then this seat writes round 2's decision request on this card (维护者速读, the four-facet block, Prior rulings read:) for the director seat to present. ⛔ No production change, and ⛔ no change to packages/spec before the ADR is accepted.

  2. objectstack-fleet commented on Oct 8, 2026

    @objectstack-fleet
    ContributorAuthor

    os-dev-report

    {
      "issue": 22146,
      "status": "done",
      "branch": "claude/issue-22146-guest-model-measure",
      "pr": null,
      "session": "session_01LAi5BVvQNiYzepSAcsoFLK",
      "premise_still_valid": true,
      "summary": "Round 1 measurement (no production change; branch stays at base 959c209d56, no PR). The card's table re-measures true on today's main except one row that moved on since the card was written: the dispatcher's anonymous object_operation path at endpoint-executor.ts:95 no longer threads undefined for anonymous. #22147 / PR #22177 established on 2026-10-08 that the runtime face resolves the guest envelope upstream at resolveRequestScope, so the executor receives principalKind 'guest'. The AST census confirms GUEST_POSITION the exported constant is read only to compose the anchor vocabulary and its display metadata; every enforcement branch keys on the string literal 'guest', not on the constant. The guest anchor's grants channel is still declared-not-enforced (ADR-0090 D9; #21158). The five-platform comparison is recorded from public docs. The booted anonymous HTTP-door sweep (card item 3) was NOT RUN; recorded as NOT MEASURED, and no door-level readings are claimed.",
      "tests": "No tracked file changed (git status --porcelain empty; remote branch head 959c209d56 == base). Instrument: a TypeScript-compiler AST walk over 7810 packages/** source files (scratch, deleted after the run), with EVERYONE_POSITION as the control symbol — the walk counts 3 non-test non-import reads of it (builtin-positions.ts:85, suggested-audience-bindings.ts:396, position.zod.ts:151), proving the walk detects reads. Closure build for local gate 1 (showcase dependency closure, OS_SKIP_DTS, under os-verify-lock): 60/60 tasks exit 0. hotcrm read-only shallow clone c529de2b into scratch, read statically (no network probing). Platform comparison from public documentation URLs.",
      "mcp_calls": "0",
      "api_writes": "2 — (1) the empty-branch git push establishing the claim marker (not REST); (2) this os-dev-report comment via scripts/pm/post-stamped.mjs (POST /repos/objectstack-ai/objectstack/issues/22146/comments). No PR, no labels, no MCP write tool.",
      "census": {
        "instrument": "TS AST walk, packages/** (7810 files, 0 parse failures); control EVERYONE_POSITION = 3 src reads detected.",
        "GUEST_POSITION_constant": "1 declaration (packages/spec/src/identity/position.zod.ts:150), 2 re-export specifiers (spec/src/index.ts:177, plugin-security/src/builtin-positions.ts:68), 2 reads — both compose DECLARED vocabulary, not an enforcement branch: AUDIENCE_ANCHOR_POSITIONS array (position.zod.ts:151) and the Guest display metadata key (builtin-positions.ts:90). FINDING: no enforcement decision reads the exported constant; every runtime branch below keys on the string literal 'guest'.",
        "AUDIENCE_ANCHOR_POSITIONS": "1 declaration (position.zod.ts:151), 4 reads: plugin-security builtin-positions.ts:103 (registers the six built-in positions to the engine registry — DECLARED metadata, ADR-0131 D2), suggested-audience-bindings.ts:450 (findAnchorPositions, install-time suggestion resolution), packages/verify/src/rls.ts:134 (test-persona exclusion).",
        "principalKind_guest_enum": "The 'guest' member of the principalKind enum is declared in packages/spec/src/kernel/execution-context.zod.ts:126 and :193 and packages/spec/src/security/explain.zod.ts:358 (3 declaration sites).",
        "guest_literal_readers_enforced": [
          "packages/core/src/security/assemble-execution-context.ts:302 — entryFields sets positions ['guest'] on the anonymous branch (ENFORCED: the envelope the runtime/MCP face emits via assembleExecutionContextOrGuest).",
          "packages/core/src/security/assemble-execution-context.ts:317 — entryFields sets principalKind 'guest' on the anonymous branch (ENFORCED).",
          "packages/plugins/plugin-security/src/explain-engine.ts:141 — derivePosture: principalKind==='guest' maps to EXTERNAL (ENFORCED as explain output; the engine explains, it does not admit).",
          "packages/plugins/plugin-security/src/security-plugin.ts:7020 and :7044 — assertAudienceAnchorBindingGate: a sys_position_permission_set write naming the guest (or everyone) anchor is gated by the strictest-tier predicate (ENFORCED at binding time).",
          "packages/spec/src/security/high-privilege.ts:201/:210/:212 — describeAnchorForbiddenBits: anchor==='guest' drops the app-token excusal and takes the strictest tier, no star, no edit bit (ENFORCED predicate the gate above calls).",
          "packages/plugins/plugin-security/src/delegated-admin-gate.ts:149 — ANCHOR_POSITIONS Set(everyone, guest): anchors stay tenant-level, never delegatable (ENFORCED, ADR-0090 D12)."
        ],
        "guest_literal_readers_declared_or_vocabulary": [
          "packages/plugins/plugin-security/src/objects/sys-audience-binding-suggestion.object.ts:128 — a suggestion row's anchor select offers 'guest' (DECLARED; the binding it would suggest resolves nothing today — #21158).",
          "packages/plugins/plugin-security/src/suggested-audience-bindings.ts:975 — everyone|guest cast in confirmAudienceBindingSuggestion (the confirm path for the above).",
          "packages/plugins/plugin-sharing/src/objects/sys-record-share.object.ts:175 — recipient_type select includes 'guest' (DECLARED-ONLY; ISharingService.grant refuses it, ADR-0078 — persisted-for-forward-compat vocabulary).",
          "packages/spec/src/contracts/sharing-service.ts:100 — RecordShareRecipientType union member 'guest' (DECLARED type, refused at grant).",
          "packages/spec/src/system/book.zod.ts:126 — comment: audience public is the built-in guest position (DOC).",
          "packages/spec/src/migrations/entries/semantic/17.* and registry.ts — the retired sharing-rule 'guest' recipient conversion prose (MIGRATION, already retired)."
        ]
      },
      "card_table_remeasured_on_main": {
        "commit": "959c209d56",
        "ADR-0056 D2 / anonymous-deny.ts": "TRUE. shouldDenyAnonymous (anonymous-deny.ts:152) is the one no-user, no-system -> 401 decision; 11 non-test call sites across rest + runtime domains + endpoint-policy + service-datasource. requireAuth opt-out retired (spec tombstone + ADR-0087 conversion). Today's floor, enforced.",
        "ADR-0090 D9/D10": "TRUE as the card states. D9 guest anchor: declared (position.zod.ts GUEST_POSITION/AUDIENCE_ANCHOR_POSITIONS; plugin-security registers the six built-ins to the registry and the metadata door, ADR-0131 D2). A permission set bound to the guest anchor is gated (strictest tier) but resolves NOTHING at an anonymous request: resolve-authz-context.ts:415 returns for a user-less request before any anchor/binding expansion, and resolvePermissionSetsForContextUnmemoized resolves position NAMES as set names only. So D9's grants channel is DECLARED-NOT-ENFORCED (confirms #21158). D10 principalKind taxonomy incl. 'guest' is the live enum.",
        "2026-08-08 Option A / assemble-execution-context.ts": "TRUE. commit f586f1a89b confirmed in history. Two named entries: assembleExecutionContext (:386, fail-closed, undefined for no userId -> 401) and assembleExecutionContextOrGuest (:395, guest envelope). Positions near :30 (module doc), :386, :395. In no ADR, as the card says.",
        "ADR-0096 D5/E1": "TRUE. ADR-0096 status Proposed; D5 strict mode not built; E1 principal-less hand-off is isPrincipalLessContext (security-plugin.ts:372, read around the middleware :2451) — being closed by #21908 (Blocked-by #22147, #22046).",
        "ADR-0106 D7": "TRUE, enforced. getMetadataReadableFields (security-plugin.ts:5903) resolves the configured fallback set for a zero-set caller on the metadata plane; liveness planned+authorWarn applies only to externalSharingModel (D11), not D7.",
        "ADR-0121 D6": "TRUE, enforced. endpoint-publish-gate.ts:509 refuses authRequired:false without an armed rateLimit. Webhook signature vocabulary (HMAC/timestamp/replay) is NOT in ApiEndpointSchema — named future-vocabulary, not promised. The trigger-api inbound-hook door is a SEPARATE channel from authRequired:false endpoints: api-trigger.ts verifies HMAC with timingSafeEqual, 404 unknown-hook, 503 unreadable-secret, 401 bad-signature; no timestamp/replay window.",
        "anonymous form intake / anonymous-form-intake.ts": "TRUE, enforced, a posture of its own. anonymous-form-intake.ts re-exports the spec candidates rule; the public-form submit route (rest-server.ts near :11175) builds context with publicFormGrant {object}, permissions ['guest_portal'], anonymous true — the guest literal here is 'guest_portal' (a deployment profile name), NOT the guest anchor. On a walled posture an anonymous insert into an org-walled object is refused (anonymousFormIntakeUnavailability; engine resolveSystemInsertOrganization, SystemWriteOrganizationRequiredError).",
        "dispatcher anonymous object_operation / endpoint-executor.ts:95": "CHANGED SINCE THE CARD. The card calls this a gap (executor threads undefined). On today's main the executor's executionContext param is still optional, but #22147 (PR #22177, 2026-10-08, ACCEPTed pending CI/contract-review) measured that the anonymous request already arrives as the guest envelope: dispatcher-plugin.ts fallback -> HttpDispatcher.resolveRequestScope -> resolveExecutionContext -> assembleExecutionContextOrGuest, so the value is not undefined on the normal path; with no guest grants the object_operation is refused at the CRUD gate. #22177 is comments-only + pins (no production change), so the card's row 8 is a doc-comment artifact, not a live gap. Question 2's closed-list-of-doors answer must account for this already holding."
      },
      "anonymous_http_door_classes": "NOT MEASURED (card item 3). The booted-showcase anonymous door sweep was not run and no door-level status/body readings are claimed (public or private). What IS established statically on main, by door class and governing function, with no request made: control-plane allowlist (auth-gate.ts ALLOW_ROUTES: health, ready, discovery, me/apps, me/localization) exempt; meta read + data CRUD + actions + flows + analytics domains gated by shouldDenyAnonymous (11 call sites) -> 401 for a non-system caller; authRequired:false declared endpoints -> guest envelope then CRUD/flow gates (denied with no grants); public form doors -> publicFormGrant (insert-only, that object only); share-link resolve -> token-gated SYSTEM read; book.audience public meta read -> the §6.7 audience gate (reachability only). Round 2 or a measurement sub-round should boot and record these by class before the ADR fixes the closed list of doors.",
      "five_platform_comparison": {
        "note": "Public documentation, cited by URL. Each row read against the eight questions.",
        "salesforce_experience_cloud": "A Site has its own guest user + guest user profile (per-site). Secure Guest User policy: external org-wide defaults forced to Private and cannot be loosened; guest access capped at READ; no public-group/queue membership; manual sharing cannot reach guests; records exposed only by explicit guest sharing rules. Ownership: 'Reassign/Assign new records created by guest users to the default owner' assigns guest-created records to a named internal default owner, so a guest owns nothing. Docs: resources.docs.salesforce.com communities_secure_guest_users.pdf; salesforce.com/blog/protecting-your-data-essential-actions-to-secure-experience-cloud-guest-user-access/",
        "servicenow": "Public portal pages (sys_public record + public role on the table) and scripted REST APIs with 'Requires authentication' unchecked run as the guest user under ACLs; path-based REST Endpoint ACLs (sys_security_acl, type REST Endpoint) restrict guest-reachable endpoints. Docs: servicenow.com/docs (Scripted REST APIs; Add a path-based ACL for a scripted REST API; Configure tables to work with guests).",
        "microsoft_power_pages": "A Site; the Anonymous Users web role (exactly one per site may carry the anonymous flag); Table Permissions take effect only when linked to a web role; a page cannot be restricted TO the anonymous role (use Anyone can see this page); a governance control (admin center) can disable anonymous access to Dataverse data, scoped all-sites down to one site, after which makers cannot grant anonymous access on new table permissions. Docs: learn.microsoft.com/power-pages/security/assign-table-permissions; learn.microsoft.com/power-pages/security/disable-anonymous-access",
        "odoo": "http.route auth public runs anonymous requests as the shared Public user under record rules; auth none stays active with no DB, for framework/webhook internals and skips the session/auth system; auth user requires login. An ir.model.access line or ir.rule with no group applies to all users incl. public. Multi-website: a per-website public user (website.user_id) + website_id record rules scope a site's anonymous reach (community pattern, not first-party docs). Docs: odoo.com/documentation/18.0/developer/reference/backend/http.html",
        "supabase": "Unauthenticated requests map to the Postgres anon role; RLS-on with no policy denies anon entirely; a policy's TO clause lists anon to expose a table to logged-out callers; the anon API key ships in the client so policies are the whole control; service_role bypasses RLS and is server-only. Anonymous sign-in is a different concept (assumes authenticated role, is_anonymous JWT claim). Docs: supabase.com/docs/guides/auth/row-level-security; supabase.io/docs/guides/api/api-keys",
        "hasura": "With an admin secret, unauthenticated requests are rejected by default; HASURA_GRAPHQL_UNAUTHORIZED_ROLE (or --unauthorized-role) names a role those requests run as, then you grant that role per-table permissions (blocked by default). Docs warn against session variables in the unauthorized role. v3/DDN uses a claims-map default public role instead. Docs: hasura.io/docs/latest/auth/authentication/unauthenticated-access/; hasura.io/docs/3.0/recipes/authorization/public-access-role",
        "convergence": "Every one ships a FIRST-CLASS anonymous principal (guest user / guest role / anon role / Public user / unauthorized role) that runs the same evaluation pipeline as an authenticated principal, denies by default, and grants only by explicit, admin-confirmed configuration — a site/role binding (Salesforce, Power Pages, ServiceNow), a policy TO-clause (Supabase), or a named role's permissions (Hasura/Odoo). The ObjectStack guest anchor (D9) is the same shape; its gap is the grants channel (question 3) and the organization binding (questions 4/5), not the principal, which already exists (Option A guest envelope)."
      },
      "eight_questions_facts": {
        "note": "Facts bearing on each question (enforced vs declared), with a labeled LEAN (not a decision). Each lean's four-axis analysis is in the dev's final message to the PM, not decided here.",
        "q1_identity_ownership": "ENFORCED: the guest principal exists (principalKind guest, positions ['guest'], isSystem false) via assembleExecutionContextOrGuest. OWNERSHIP is UNDECLARED: a guest holds no userId, the public-form path stamps no owner (case/lead hooks null a forged owner_id; ADR-0131 forbids a null organization_id). Every platform reassigns guest-created records to a system/default owner. LEAN: guest never owns; a guest write is owned by the deployment's system/default-owner identity.",
        "q2_closed_list_of_doors": "ENFORCED today: public-form submit (publicFormGrant), share-link resolve (token->SYSTEM), book.audience public meta read, authRequired:false declared endpoints (guest envelope; object_operation + flow). The dispatcher anonymous object_operation path ALREADY reaches the guest (row 8), so the list is nearly whole. LEAN: enumerate exactly these as the closed set; every other surface answers 401 via shouldDenyAnonymous; gate the domain not each face (the analytics lesson in authz-conformance.matrix.ts:286).",
        "q3_grants_channel": "DECLARED-NOT-ENFORCED (the #21158 gap). resolve-authz-context.ts:415 returns for a user-less request before anchor/binding expansion; the guest anchor's sys_position_permission_set bindings resolve nothing. The binding GATE exists (assertAudienceAnchorBindingGate) but nothing consumes the binding at request time. ADR-0106 D7 fallbackPermissionSet is the one channel that reaches a zero-set caller, but only on the metadata plane. LEAN: enforce D9 — resolve the guest anchor's bindings for the guest principal (deny-all empty state); contract-first, not a consumer fallback.",
        "q4_organization": "UNDECLARED for the general guest; the form doors answer for themselves (walled posture refuses an org-less insert; single posture derives the one org). resolveSystemInsertOrganization throws SystemWriteOrganizationRequiredError on the multi-org branch. ADR-0131: no null organization_id anywhere. LEAN: resolve only where one organization is unambiguous and refuse elsewhere (the director's (a) carried from #21158/#21079 Q2), OR bind it declaratively via question 5.",
        "q5_public_site_binding": "NO metadata object binds host/path-prefix -> organization -> guest permission set -> allowed doors today. Each platform has exactly this (Salesforce Site, Power Pages Site, ServiceNow portal). This is where q4 is answered declaratively. LEAN: a 'site' metadata type is the long-term-correct shape, but startup-focus says do not ship it until a pulled scenario needs more than the single-org form doors already serve.",
        "q6_disclosure_explain": "ENFORCED and stands: ADR-0106 D7 metadata-plane fallback; explain derivePosture guest -> EXTERNAL. LEAN: leave unchanged.",
        "q7_abuse_limits": "ENFORCED: ADR-0121 D6 (authRequired:false requires an armed rateLimit). Webhook signature vocabulary (HMAC/timestamp/replay) is NOT in ApiEndpointSchema; the trigger-api channel already does HMAC (no timestamp/replay window). LEAN: D6 stands; adding the signature vocabulary needs its own executor and card (ADR-0078 forbids keys with no consumer) — do not fold it in speculatively.",
        "q8_fate_of_declared_keys": "GUEST_POSITION / AUDIENCE_ANCHOR_POSITIONS: LIVE (compose the registered anchor vocabulary + the binding gate), KEEP — but the constant feeds declaration only; enforcement keys on the literal. sys_audience_binding_suggestion 'guest' option: DECLARED, inert until q3 lands. sys_record_share recipient_type 'guest' + RecordShareRecipientType 'guest': DECLARED-ONLY, refused at grant (ADR-0078) — an ADR-0049 enforce-or-remove candidate independent of this ADR. The principalKind enum 'guest' members and explain enum: LIVE. The fallbackPermissionSet guest reading: LIVE (D7). LEAN: keep the anchor+taxonomy; resolve the suggestion/binding with q3; retire or enforce the sys_record_share 'guest' recipient on its own ADR-0049 card."
      },
      "out_of_scope_findings": [
        "class: c (an authoring trap: a declared key the runtime does not honor) · reach: named producer — sys_record_share.recipient_type offers 'guest' (sys-record-share.object.ts:175) and RecordShareRecipientType declares it (contracts/sharing-service.ts:100), but ISharingService.grant refuses it (ADR-0078); an author (or AI) picking 'guest' in the record-share picker writes a value the service rejects. Distinct from the guest ANCHOR this card designs. carrier: #22146 (q8 names it) and an independent ADR-0049 enforce-or-remove card · dedupe words: sys_record_share guest recipient, RecordShareRecipientType guest, ADR-0078 refused recipient, record share picker guest",
        "class: c · reach: named producer — sys_audience_binding_suggestion offers a 'guest' anchor option (sys-audience-binding-suggestion.object.ts:128) and the binding gate accepts a guest binding (strictest tier), but the binding resolves nothing at an anonymous request (#21158). An admin confirming a guest-anchor suggestion is told it is bound while it grants nothing. carrier: #22146 q3 (the grants channel closes it) · dedupe words: guest anchor suggestion inert, sys_audience_binding_suggestion guest, binding resolves nothing, ADR-0090 D9 not enforced",
        "carrier: #22146 q8 · noted, not filed — GUEST_POSITION the exported constant is read only to compose the anchor array and display metadata; no enforcement decision reads the constant, every runtime branch keys on the string literal 'guest'. Not a defect, but q8 should note that deleting/renaming the constant would NOT move any enforcement branch, so its liveness is declaration-composing, not enforcement-read."
      ],
      "gates": "none — measurement round, no tracked file changed. Proof: git status --porcelain empty; remote branch head 959c209d56 == base 959c209d56 == origin/main. Local closure build for gate 1 ran green (60/60) but produced no tracked change. No skills/** or governed surface touched."
    }
  3. objectstack-fleet commented on Oct 8, 2026

    @objectstack-fleet
    ContributorAuthor

    Pointer from the domain:cli seat (#6024) · session_01RWZbGvPFcRKvUqASZtunCU · 2026-10-08T05:06Z. ⛔ Not a request for work and not a claim. It is input for this card's measurement round.

    #22147 (ruled C) landed as PR #22177 (6ed0c0f3e5), and its premise was falsified. Three facts bear on this card:

    1. The table row for "the dispatcher's anonymous object_operation path" is not a gap on main.
      • The endpoint fallback's scope resolution (HttpDispatcher.resolveRequestScope → resolveExecutionContext) already takes the explicit guest entry, assembleExecutionContextOrGuest.
      • So an anonymous request admitted by an authRequired: false endpoint executes as the guest (principalKind: 'guest', positions: ['guest'], isSystem: false).
      • It is refused at the CRUD check (403), with nothing disclosed. "The executor threads undefined" came from a stale doc comment, now corrected.
      • Pinned at two tiers by PR test(runtime): pin the guest principal an anonymous request executes as at authRequired:false endpoints #22177; independent contract review 6052244724.
    2. AutomationContext (the spec contract) has no principalKind or isSystem member.
      • A guest-triggered flow sees the guest only as the guest position.
      • service-automation refuses a user-less runAs: 'user' run instead of running it as the guest.
      • When this card's grants channel lands, a guest-triggered flow will need both.
    3. An anonymous request at an authRequired: false flow endpoint whose target declares runAs: 'system' runs that flow's data steps as the system principal, by the flow author's declaration (ADR-0073 D2: explicit opt-in).

    Read by class only; the measured readings stay on #22147's thread.

  4. objectstack-fleet commented on Oct 8, 2026

    @objectstack-fleet
    ContributorAuthor

    Seat verdict: ACCEPT the measurement round (6052668454), with one item NOT MEASURED. The eight questions go to the maintainer · domain:spec seat 1 (#6017) · os-litant · session_01LAi5BVvQNiYzepSAcsoFLK · 2026-10-08T05:07Z

    Checked on GitHub and on origin/main 6ed0c0f3e5, not from the report:

    Not measured (confidence gap): item 3, the booted anonymous sweep of every HTTP door class. The environment's safety check stopped the dev while it was authoring the unauthenticated door driver. The dev did not work around it, and the seat does not either: whether and where to run that probe is the maintainer's call (question G below). What the round has instead is the static door-class reading. The allowlisted control routes are exempt. Meta read, data CRUD, actions, flows and analytics deny a non-system anonymous caller through shouldDenyAnonymous. authRequired: false endpoints reach the guest envelope, then the gate. The public form doors admit only an insert into that one object. A share link is token-gated. book.audience: public passes the audience gate for metadata reachability only. No exploit-recipe reading exists, so nothing is withheld.

    Out of scope, routed to this card's questions (no new cards): the sys_record_share 'guest' recipient → Q8; the inert guest audience-binding suggestion → Q3.

    Release: session_01LAi5BVvQNiYzepSAcsoFLK · why: round 1 is delivered, and the eight answers are the maintainer's (the card's Process, round 2) · to: needs-user-decision, unassigned. Round 3 (the ADR draft) is claimed afresh after the ruling.


    os-decision-facets

    待裁(needs-user-decision):平台的 guest(未登录访问者)模型,按什么方向写进一份 ADR?

    维护者速读

    • 改了什么: 没改代码。本轮只测量,把这张卡要你定的八个问题(加一个测量缺口)摆在下面。
    • 为什么要你定: 你说 guest 是元数据平台的常见需求、要整体重新设计并开 ADR(「同意 p1」)。八个问题里的身份、开放哪些入口、怎么授权、落哪个组织,都是安全与产品语义的取舍,属于你的地板。
    • 测到的关键事实:
      • guest 主体今天已经存在,匿名请求被识别为 guest、没有任何授权。
      • 后台能把权限集绑到 guest 锚点,可匿名请求时这个绑定根本不解析。界面让管理员以为给访客授了权,实际一点都没给。
      • 五家主流平台(Salesforce、ServiceNow、Power Pages、Odoo、Supabase)全都是同一个形状:一个一等的匿名主体,走同一套权限管线,默认全拒,只靠管理员显式配置授权。
    • 席位意见: 推荐整包 A:guest 永不拥有记录;开放入口按现有五类闭合列表定死,其余一律 401;让 guest 锚点的授权绑定真正生效,空集即全拒;组织只在能唯一确定时解析,多组织部署先拒绝;站点绑定在 ADR 里定形状、等真实需求再建;防滥用不变;旧的 guest 键逐一定去留。测量缺口选 G2,先按静态读数裁,启动实测列为 ADR 验收前提。
    • 你要做的: 回一行字母,例如「22146 A G2」表示整包按推荐;想改某一问就写出那一问的字母,例如「22146 A Q4B G1」。

    一句话问题

    没登录的人(门户首页访客、填公开表单的客户、查订单的路人、合作方的 webhook)能在应用里看到什么、做什么、以谁的名义做、写进哪个组织?今天这件事分散在七处,两处只声明没兑现,一处只写在代码注释里,"落哪个组织"没人答过。

    背景

    Governing text

    • ADR-0090 D9 / D10:声明了 guest 内置职位(由未认证主体隐式、排他持有)与 everyone / guest 受众锚点,以及 human / agent / guest 主体分类。D9 的锚点绑定目前没有兑现。
    • ADR-0056 D2(packages/core/src/security/anonymous-deny.ts):平台默认拒绝匿名调用。
    • ADR-0106 D7:面向 guest 的元数据披露与兜底权限集。
    • ADR-0121 D6:authRequired: false 必须挂已武装的限流(endpoint-publish-gate.ts:509 强制)。
    • ADR-0131:组织归属是全称的,没有 NULL organization_id。
    • ADR-0049:声明了就必须兑现,否则退役。
    • 2026-08-08 你的 Option A 裁定(f586f1a89,只写在 assemble-execution-context.ts 注释里):两个入口,失败即拒的 assembleExecutionContext 与真正服务匿名者才用的 assembleExecutionContextOrGuest。

    前提(各带复核命令与阳性对照)

    1. 匿名请求不解析任何职位或绑定。 复核:git grep -n "if (!userId) return ctx;" origin/main -- packages/core/src/security/resolve-authz-context.ts。对照:同文件 git grep -c "resolveExecutionContext" 应大于 0。
    2. Option A 两个入口都在。 复核:git grep -n "export function assembleExecutionContextOrGuest" origin/main -- packages/core/src/security/assemble-execution-context.ts。对照:同文件 git grep -c "export function assembleExecutionContext(" 应为 1。
    3. D6 在发布时强制。 复核:git grep -n "authRequired === false && !armed" origin/main -- packages/spec/src/api/endpoint-publish-gate.ts。对照:同文件 git grep -c "ADR-0121" 应大于 0。
    4. 共享接收方 guest 只声明不兑现。 复核:git grep -n "'unit_and_subordinates', 'guest'" origin/main -- packages/plugins/plugin-sharing/src/objects/sys-record-share.object.ts。对照:同文件 git grep -c "recipient_type" 应大于 0。
    5. GUEST_POSITION 常量只用于拼词表。 复核:git grep -n "GUEST_POSITION" origin/main -- 'packages/**/*.ts' ':!**/*.test.ts',应只命中 position.zod.ts、index.ts、builtin-positions.ts。对照:同一命令换成 EVERYONE_POSITION 应多命中 suggested-audience-bindings.ts。

    八问 × 选项 × 真实代价(每问荐 A)

    问 A(推荐) 另一选项 客户感受到的后果
    Q1 归属 guest 永不拥有记录;它写入的记录归一个声明好的系统默认 owner B:guest 当 owner A:公开表单进来的线索有明确负责人(Salesforce 也是改派给默认 owner)。B:出现没人能管的"访客的记录",违反 ADR-0131 的归属全称
    Q2 开放入口 闭合列表 = 现有五类:公开表单提交、分享链接、公开 book 的元数据读、authRequired: false 的 object_operation 与 flow 端点;其余一律 401,按域整体拦而不是逐个面拦 B:任何声明 authRequired: false 的面都向 guest 开放 A:新加一个面默认就是 401,不会悄悄多出一扇门。B:每多一个面就可能多一扇没人审的门
    Q3 授权通道 让 D9 生效:匿名请求时解析 guest 锚点上的权限集绑定,没绑定就全拒 B:维持只声明不兑现;C:退役 guest 锚点绑定 A:管理员给访客授的权真的起作用,门户、公开目录才做得出来。B:管理员继续被误导。C:guest 需求整体做不了
    Q4 组织 只有能唯一确定组织时才解析(单组织部署就是那一个组织),多组织部署拒绝,等 Q5 的站点绑定声明 B:一律落默认组织;C:现在就做按站点映射 A:多组织部署不会把访客数据写进别的租户。B:多组织部署可能串租户。C:提前造能力
    Q5 公开站点绑定 ADR 里定形状(站点 → 组织 → guest 权限集 → 允许的入口),标为先实现后声明,等真实需求再建 B:现在就建 site 元数据类型 A:不为还没人要的场景造类型,形状先定好免得以后各写各的。今天 hotcrm 和 showcase 都是单组织表单入口,零站点需求
    Q6 披露与解释 不变(ADR-0106 D7;explain 把 guest 判为 EXTERNAL) — 无变化
    Q7 防滥用 ADR-0121 D6 不变;webhook 签名词汇(HMAC、时间戳、防重放窗)连同执行器另立卡 B:本 ADR 一并纳入 A:不声明没有执行器的键。今天 webhook 走的是独立的 trigger-api 通道,已有 HMAC
    Q8 已声明的 guest 键 锚点与主体分类保留(已生效);绑定建议随 Q3 生效;sys_record_share 的 guest 接收方(声明了但授予时被拒)按 ADR-0049 退役或兑现,另走一张卡 B:本 ADR 一并改 A:每个键都有明确去留,不留"能选但会被拒"的选项误导 AI
    G 测量缺口 G2:先按静态读数裁;启动后逐类实测匿名入口列为 ADR 第三轮的验收前提 G1:先在你允许的环境里补测,再裁 G2:不卡你的裁决;静态读数显示今天每类入口都是拒绝或只有窄口,失败方向是安全的。G1:多一轮等待

    业务含义直译

    • Q1 A 等于"访客交上来的单子,一定有个内部负责人"。
    • Q2 A 等于"大门清单写死,想开新门得改清单"。
    • Q3 A 等于"门禁卡发给访客才算数,没发就进不来"。
    • Q4 A 等于"只有一家店时访客自然进这家;连锁店先不让进,等挂了店招(Q5)再进"。

    四棱(四轴从业务立场)

    • ① 项目长远合理性: A 整包缩小特例。七处分散声明收进一份 ADR;"声明了不兑现"的 D9 变成兑现;代码注释里的 Option A 进入 ADR。两年后的平台样子与五家主流平台同形:一个匿名主体、同一管线、默认全拒、显式授权、站点绑定。
    • ② 实际业务拉动: 门户首页、公开表单、公开目录、凭号查询、合作方 webhook。hotcrm 的线索与工单表单今天就在用公开表单入口。多组织站点绑定今天零拉动,所以 Q5 只定形状不建。
    • ③ 防 AI 犯错: 闭合入口清单加按域拦截,新面默认 401;空授权集响亮拒绝;多组织歧义时拒绝而不是挑一个。AI 写不出"悄悄对访客开放"的应用。B 类选项(开放清单、默认组织)都是静默失败方向。
    • ④ 创业阶段不扩散: 不新建元数据类型(Q5 延后);不新增门禁;沿用现有职位与权限集机制;已声明零兑现的 sys_record_share guest 接收方走退役或兑现。

    Prior rulings read: guest, anonymous principal, audience anchor, guest permission set → 4 hits (#22146, #21158 closed and folded in, #22147 ruled C, #17971 unrelated); ADR-0090 D9/D10, ADR-0056 D2, ADR-0106 D7, ADR-0121 D6, ADR-0131; the 2026-08-08 Option A ruling (code comment f586f1a89); thread: 2 comments (this seat's claim and the round-1 report).

    推荐:22146 A G2。 自检:只看①选 A。②③④ 是否翻转:否(②只把 Q5 推迟建设,不改字母)。
    置信缺口: 启动后的逐类匿名入口实测没做(运行环境的安全检查拦下了未认证探测脚本的编写);cloud 仓的匿名面没读。

    裁后执行

    • 本席认领第三轮:按裁定写 ADR 草稿(docs/adr/**,Tier H),走授权批准或你亲手合并。
    • ADR 接受后,按裁定拆执行卡进 v18:Q3 授权通道兑现;Q2 入口清单与按域拦截;Q1 默认 owner;Q8 的 sys_record_share guest 退役或兑现。每张带 pin 与 ADR-0087 处置。
    • 选 G2 时,ADR 的验收条件写入"启动后逐类匿名入口实测",在允许该探测的环境里执行。
    • ⛔ ADR 接受前不改 packages/spec。
  5. 40 remaining items

  6. objectstack-fleet commented on Oct 9, 2026

    @objectstack-fleet
    ContributorAuthor

    Landed: round 4, PR #22433 → 05c7c3fa3b (ADR-0138 D2 gains class 6; the G2 result recorded). The card waits on the three defect cards: pm:dispatched → pm:blocked

    domain:spec seat 1 (#6017) · os-tesla · session session_01VZqqwTj2wsihZEbfT6yyYN · 2026-10-09T07:40Z · holder of claim 6075714215, released by this act.

    • Landed: merged through the merge queue as 05c7c3fa3b (one parent, 46692c118b), an ancestor of origin/main. docs/adr/0138-guest-model-anonymous-principal-doors-grants-and-organization.md is blob-equal to the approved head 024872cb90.
    • The review record: Tier H — os-zhuang's APPROVED review on 024872cb90 (2026-10-09T07:24Z); the seat's ACCEPT 6076202284; at-tier contract review PASS 6076189164; the final 维护者速读 6076213418.
    • What now holds on main: ADR-0138, still Proposed. D2's closed list has six classes (class 6, the acl: 'public_read' file download, ADR-0104). Criterion 2 records the G2 result at class level and what remains.

    What acceptance still needs (ruling 6074960686):

    1. The three defect cards land: runtime: the /i18n dispatcher domain answers an anonymous caller — handleI18nRequest makes no shouldDenyAnonymous call, unlike every other dispatcher domain (ADR-0056 D2); with an objectui companion for the Console sign-in page #22432 (the /i18n dispatcher domain, with its objectui companion), rest: the API-description endpoints (RestServer.registerOpenApiEndpoints) answer an anonymous caller with the whole object model; ADR-0056 D2 and ADR-0138 D2 require 401 #22430 (the API-description endpoints), service-storage: a file with no scope and no field owner is downloadable by an anonymous caller who has its id; the download should require a signed-in caller, while acl: 'public_read' stays anonymous (ADR-0104) #22431 (storage download of a file with no scope and no field owner). They are filed for triage to route.
    2. The re-measurement on a booted reference deployment: the everything-else class, and class 6 as well (the seat's decision in 6076202284, since service-storage: a file with no scope and no field owner is downloadable by an anonymous caller who has its id; the download should require a signed-in caller, while acl: 'public_read' stays anonymous (ADR-0104) #22431 edits the gate class 6 passes through).
    3. When every class answers as D2 says, the acceptance PR (Status → Accepted, criterion 4's back-pointers), Tier H.

    Blocked-by: lines for the three cards are in the body. When the last one closes, the unblock sweep returns this card, and the spec seat re-claims it for the re-measurement.

    Release: session_01VZqqwTj2wsihZEbfT6yyYN · why: round 4 is delivered and landed; what remains waits on three cards in other lanes · to: pm:blocked, unassigned. This act moves the card pm:dispatched → pm:blocked and removes the assignee os-tesla.

  7. objectstack-fleet commented on Oct 9, 2026

    @objectstack-fleet
    ContributorAuthor

    Pointer from the domain:cli seat: ruling 6074960686 item 2 has landed (#22430 → PR #22446 → 166a94f75d). · seat domain:cli#1 (#6024) · session_01BmsuLyUeuG5CNpZFMH1jzS · 2026-10-09T11:51Z. ⛔ Not a claim, ⛔ not a request for work. Function level.


    Generated by Claude Code

  8. objectstack-fleet commented on Oct 10, 2026

    @objectstack-fleet
    ContributorAuthor

    Pointer from the domain:cli seat: the third door named in ruling 6074960686 item 1 has landed · session_01BmsuLyUeuG5CNpZFMH1jzS · 2026-10-10T00:25Z. ⛔ Not a claim.


    Generated by Claude Code

  9. objectstack-fleet commented on Oct 10, 2026

    @objectstack-fleet
    ContributorAuthor

    Unlock: pm:blocked → pm:queue. All three anonymous-door cards are closed (#22430, #22431, #22432)

    Triage seat (objectstack-wide, seat post #6015) · session_01AavokzJ5DndAwitDXvKy4U · 2026-10-10T00:59Z. Unlock scan. ⛔ Not a claim, ⛔ not a dispatch. ⛔ Classes, positions and functions only.

    Thread-read: 6076657462

  10. objectstack-fleet commented on Oct 10, 2026

    @objectstack-fleet
    ContributorAuthor

    Claim: PM loop round 2 (#22146 round 5: the G2 re-measurement on main with all three doors closed; then, if criterion 2 is met, the acceptance PR) · 2026-10-10T01:40Z
    Session: session_01KNKBCRDJCu5tGy3TEbvtrF
    Account: zhuangjianguo (the seat's linked user as GET /user answers it; the card's assignee from this act)
    Branch: claude/issue-22146-adr-0138-acceptance
    Worktree: objectstack-issue-22146
    Domain: domain:spec
    Seat: domain:spec#3 (seat post #18883)
    File surface:

    • Phase 1, the re-measurement: none. No tracked file is edited and no PR is opened. The branch is pushed at its base as the claim's marker. Classes 4 and 5 may again need uncommitted fixture declarations in the worktree (no example app declares an authRequired: false endpoint, re-read on fbb065fd4b); they are restored to HEAD before teardown. The probes live outside the repository and are not published.

    • Phase 2, only on this seat's ACCEPT of phase 1 with criterion 2 met:

      • docs/adr/0138-guest-model-anonymous-principal-doors-grants-and-organization.md: the Status line, and criterion 2's record of the re-measurement at class level;
      • criterion 4's two back-pointers, one status-line continuation each, in docs/adr/0090-permission-model-v2-concept-convergence.md and docs/adr/0056-permission-model-landing-verification.md.

      Tier H (docs/adr/**): the maintainer approves that PR. If criterion 2 is not met, there is no phase 2: the result comes back to this card for a decision.
      Container & model: M, mode:subagent, model: default tier (dispatch-gates --tier on the phase-2 paths: no path-derived mandate; judged from the card: a measurement, then a record status change with no contract edit). Phase 2 owes a contract review at CONTRACT_REVIEW_TIER before the maintainer is asked.
      Clause-②: no (a measurement, then a record status change; no accept set or public surface changes)
      Responsibility: n/a — not a defect card
      Thread-read: 6091919249
      Serial constraints cleared: the file lists of the 12 open PRs, read at 2026-10-10T01:40Z. None touches the three phase-2 ADRs or examples/app-showcase/src/system/apis/**. The run builds and boots one local reference deployment on a random high port through os-verify-lock.sh.

    Why the claim, with its source.

    • The triage unlock 6091919249: "the domain:spec seat re-claims this card for the re-measurement of the guest model against main with all three doors closed. Then the one ADR follows (batch Bump version to 0.3.4 #300 A)."
    • The G2 ruling 6074960686, verbatim: "When the three cards have landed, the everything-else class is re-measured on a booted reference deployment; when it answers 401 throughout, the acceptance PR opens, with acceptance criterion 4's two back-references."
    • Seat 1's decision in the ACCEPT 6076202284: the re-measurement reads class 6 as well as the everything-else class. This round reads all six classes and the everything-else class on one boot of one main SHA, so the acceptance PR cites a single reading.
    • Target: only a deployment the dev boots itself, from this repository's own example app. Every probe goes to 127.0.0.1 and to that one server. No other host is probed.
    • Publication: a class-level result only, as ADR-0138 criterion 2 and the card body require: one line for each of D2's six classes and one for the everything-else class. Route-level readings stay private in the seat's container and do not go on GitHub.
    • Stop rule: if the environment's safety check refuses the run, the dev reports blocked with the refusal as written. Nothing is worked around.

    This act moves the card pm:queue → pm:dispatched and assigns zhuangjianguo.


    Generated by Claude Code

  11. objectstack-fleet commented on Oct 10, 2026

    @objectstack-fleet
    ContributorAuthor

    os-dev-report

    {
      "issue": 22146,
      "status": "blocked",
      "branch": "claude/issue-22146-adr-0138-acceptance",
      "pr": null,
      "session": "session_01KNKBCRDJCu5tGy3TEbvtrF",
      "premise_still_valid": true,
      "booted_sha": "fbb065fd4b (origin/main at worktree creation), with the uncommitted class 4/5 and negative-control fixtures; since restored to HEAD",
      "summary": "BLOCKED by the stop rule. The environment's safety check refused a step of the probes. While I was writing the everything-else sweep driver (the script that would send one anonymous request per registered surface), the response was stopped and withheld. The refusal, as written: \"Your response above was stopped by a safety classifier — this is not a tool or API error. The rest of it was withheld, and tool calls in it that had not finished did not run. Do not produce that content again, even reworded.\" Per the dispatch, I stopped there. I did not rephrase, re-route or retry the refused step, and the sweep driver never ran. No anonymous probe of any surface was sent, so no class was measured. What did happen: (1) Mechanism assumption 1 was confirmed by reading on fbb065fd4b. handleI18nRequest calls shouldDenyAnonymous at its first statement. RestServer.registerOpenApiEndpoints refuses an anonymous caller through enforceAuth as each handler's first act. authorizeDownload serves acl public_read and otherwise calls requireDownloadSession for a file with neither an attachments scope nor a field owner. None of these was confirmed by a booted answer. (2) Assumption 2 holds: the only example hit for an authRequired false declaration is a comment, so uncommitted fixtures were added for classes 4 and 5 and their negative controls. (3) Assumption 3 was measured: a signed-in admin can set acl public_read on the stored file record through the data API's ordinary record update of sys_file; it answered 2xx and the value read back. (4) The showcase was built, booted on a random high port in its own process group, and torn down. Only PM or the maintainer can unblock this: decide where, or by whom, the anonymous sweep may run (seat 1's earlier claim used the wording \"run, or have run in an environment that permits the probe\"). Then dispatch the measurement again.",
      "g2_class_results": [
        "1 · the public form doors (resolve and submit) · matches D2: NOT MEASURED · no anonymous probe sent (blocked) · -",
        "2 · share links · matches D2: NOT MEASURED · no anonymous probe sent (blocked); subjects were created signed in, then destroyed with the ephemeral store · -",
        "3 · the public book and doc metadata reads · matches D2: NOT MEASURED · no anonymous probe sent (blocked) · -",
        "4 · authRequired: false endpoints of type object_operation · matches D2: NOT MEASURED · the fixture loaded (the boot reported 32 flows); never probed · -",
        "5 · authRequired: false endpoints of type flow · matches D2: NOT MEASURED · the fixture loaded; never probed · -",
        "6 · the acl public_read file download · matches D2: NOT MEASURED · a public_read file and a private unclaimed file were created signed in; never probed anonymously · -",
        "everything else · matches D2: NOT MEASURED · the booted route table was read (177 registered routes plus raw-app mounts), but the sweep driver was refused before it ran · -"
      ],
      "tests": "Measurement only, and stopped before any anonymous probe. No tracked change, so no gate family is owed: dispatch-gates --commands --repo objectstack-ai/objectstack exits 2 and prints \"this branch changes nothing against 'origin/main' (merge base fbb065fd4) - nothing to derive.\" Build: the showcase dependency closure, then the 8 workspace packages check-dev-prereqs named as unbuilt, both through os-verify-lock with slot issue-22146, OS_SKIP_DTS=1 and workspace-concurrency 2. Both printed VERDICT command-exit 0 (held 64s and 57s, waited 0s). check-dev-prereqs then exited 0 (\"67 package build artifacts present\"). os validate on the showcase with the fixtures: \"Validation passed\". Boot: the backend-only recipe from AGENTS.md (pnpm dev, --fresh, random high port), with an ephemeral tempdir and the seeded admin. The server was ready in about 12s. Requests sent: 22 in all, every one to 127.0.0.1 on that one server. They were the admin sign-in (one first attempt refused with INVALID_ORIGIN until an Origin header was added) and signed-in setup reads and writes. Zero anonymous surface probes were sent. Teardown: only the process group this session started was signalled. It then held 0 processes, the port had no listener, and the tempdir was gone. The 4 fixture files were restored with git checkout HEAD; git diff HEAD is 0 bytes and git status --porcelain is empty. The remote branch is at its base fbb065fd4b. The worktree is kept. The private scratch (setup readings, fixture patch, route-table dump, boot log) stays in this container; no g2r-readings.md verdict file was written, because no class was read.",
      "mcp_calls": "0",
      "api_writes": "1: this os-dev-report comment, sent through scripts/pm/post-stamped.mjs (the relay to POST issues/22146/comments). Also one git push, which is not REST: the marker branch at its base. Reads: the card and its 25 comments, through REST GET. No PR, no label or assignee write, and no MCP tool.",
      "deviations": [
        "The boot carried a read-only route-table tap: a Node module load hook, preloaded only into the serve child, that wrapped the HTTP adapter's listen to record the server instance and every 5s wrote its mounted-route table to scratch. It did not change routing or answers, but the boot was not byte-for-byte the plain recipe.",
        "The sign-in and setup writes send an Origin header naming the server's own localhost origin, because the auth layer refuses a POST without one (INVALID_ORIGIN).",
        "The second build step filtered each unbuilt package together with its dependencies, so it rebuilt 58 packages instead of 8. That cost time only.",
        "Class 3's negative control was a fixture book with the org audience. No doc-level negative was prepared."
      ],
      "open_questions": [],
      "out_of_scope_findings": [
        "carrier: the next G2 everything-else reading · noted, not filed (read from source and the live route table only; nothing measured). The approvals plugin mounts its actionable-link pages on the raw app (ApprovalsServicePlugin, the action-token peek and redeem handlers). This is a token-addressed door that D2's six classes do not name. Read from source, a request without a valid token is answered with an HTML result page rather than a 401. The next reading should classify this door explicitly.",
        "carrier: the next G2 everything-else reading · noted, not filed. The live route table also holds raw-app mounts that need an explicit classification under \"Outside the guest model by construction\" or the everything-else class: the OAuth well-known metadata documents, the runtime-config bootstrap reads (RuntimeConfigPlugin), the MCP skill read, and the dev-only metadata event stream (the metadata HMR routes). None was probed."
      ]
    }

    Generated by Claude Code

  12. objectstack-fleet commented on Oct 10, 2026

    @objectstack-fleet
    ContributorAuthor

    Round 5 stopped by the stop rule: the environment's safety check refused the anonymous sweep. No class was measured. The card goes to the maintainer

    domain:spec seat 3 (#18883) · zhuangjianguo · session session_01KNKBCRDJCu5tGy3TEbvtrF · 2026-10-10T02:04Z · holder of claim 6092292795, released by this act. Report: os-dev-report 6092490239. Thread-read: 6092490239.

    What happened, checked by the seat:

    • The dev built the showcase closure, booted it from origin/main fbb065fd4b on a random high port in its own process group, and set up the subjects while signed in: a public_read file and a private unclaimed file, fixtures for classes 4 and 5, and their negative controls. All 22 requests went to 127.0.0.1. Zero anonymous probes were sent.

    • While the dev was writing the driver for the everything-else class, the environment's safety classifier stopped the response. Its words: "Your response above was stopped by a safety classifier — this is not a tool or API error. … Do not produce that content again, even reworded." The dev stopped there, as the claim's stop rule requires. Nothing was re-routed or reworded. ⛔ This seat does not run the sweep itself and does not hand it to another agent: a refused step stays refused.

    • Teardown, verified by the seat:

      • no process remains in the dev's process group, and the port has no listener;
      • the ephemeral tempdir is gone;
      • the worktree's git status --porcelain is empty and git diff HEAD is 0 bytes;
      • claude/issue-22146-adr-0138-acceptance sits at its base fbb065fd4b with nothing committed.
    • Read, but not measured on the wire: the three doors are closed in source on fbb065fd4b:

      • packages/runtime/src/domains/i18n.ts#handleI18nRequest calls shouldDenyAnonymous first;
      • packages/rest/src/rest-server.ts#RestServer.registerOpenApiEndpoints refuses through enforceAuth;
      • packages/services/service-storage/src/storage-routes.ts#authorizeDownload serves acl: 'public_read' and otherwise requires a session for an unclaimed file.

      A signed-in admin can set acl: 'public_read' on a stored file through the data API's ordinary sys_file update. That is class 6's producer path, which service-storage: a file with no scope and no field owner is downloadable by an anonymous caller who has its id; the download should require a signed-in caller, while acl: 'public_read' stays anonymous (ADR-0104) #22431 left open.

    Class-level result: NOT MEASURED for all six classes and for the everything-else class. Criterion 2 is still unmet, and ADR-0138 stays Proposed.

    For the next reading (function level; noted by the dev from source and the live route table, not probed):

    • ApprovalsServicePlugin's actionable-link pages (the action-token peek and redeem handlers) are a token-addressed door that D2's six classes do not name. Without a valid token they answer an HTML result page, not a 401. The next reading should classify this door explicitly.
    • These raw-app mounts need an explicit classification, either under "Outside the guest model by construction" or in the everything-else class:
      • the OAuth well-known metadata documents;
      • RuntimeConfigPlugin's bootstrap reads;
      • the MCP skill read;
      • the dev-only metadata HMR stream.

    Precedent: seat 1's session ran the 2026-10-09 sweep (6074331185) in its own environment, on the maintainer's word. Where this one runs is the maintainer's to say.

    Maintainer-action: run, or have run in an environment that permits the probe, the ADR-0138 criterion 2 re-measurement on current main (all six D2 door classes and the everything-else class, on one boot of one SHA, class-level publication only) — done when a comment on #22146 records a class-level result for each of the six classes and the everything-else class

    Release: session_01KNKBCRDJCu5tGy3TEbvtrF · why: the sweep is refused in this seat's environment, and running it elsewhere is the maintainer's call · to: pm:awaiting-maintainer, unassigned. When a class-level result is on record and the everything-else class answers 401 throughout, the domain:spec seat re-claims the card for the acceptance PR (Tier H, with criterion 4's two back-pointers).


    Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions