|
22 | 22 | * > SUBJECT record's organization; actor context is the fallback, never the |
23 | 23 | * > primary. |
24 | 24 | * |
25 | | - * ⛔ The stamp-only divergence this resolver reads stays scope-pinned (#8778, |
26 | | - * widened by name on cloud#1395): exactly THREE consumers are sanctioned — |
27 | | - * audit stamping, the approval-row writer, and the automation-run recorder — |
28 | | - * and no others. A fourth consumer needs its own maintainer ruling, exactly as |
29 | | - * #8778 required. Sharing the implementation here does not open it: it closes |
30 | | - * the excuse for a fourth copy. |
| 25 | + * ⛔ The stamp-only divergence this resolver reads stays scope-pinned by the |
| 26 | + * ruling quoted above, widened by name on cloud#1395: exactly THREE consumers |
| 27 | + * are sanctioned — audit stamping, the approval-row writer, and the |
| 28 | + * automation-run recorder — and no others. A fourth consumer needs its own |
| 29 | + * maintainer ruling, exactly as the original scope-pin required. Sharing the |
| 30 | + * implementation here does not open it: it closes the excuse for a fourth copy. |
31 | 31 | * |
32 | 32 | * ⭐ [#19054] The divergence is no longer AUTHORABLE. It used to be declared by |
33 | 33 | * the `tenancy.organizationField` spec key, which every application could write |
@@ -77,7 +77,7 @@ import { SystemFieldName } from '@objectstack/spec/system'; |
77 | 77 | * |
78 | 78 | * ⛔ Adding a row is a PROTOCOL decision, not a convenience. Each row is an |
79 | 79 | * object whose platform rows are stamped from somewhere other than its wall, |
80 | | - * which is exactly the divergence the #8778 / cloud#1395 rulings scope-pinned; |
| 80 | + * which is exactly the divergence the cloud#1395 ruling scope-pinned; |
81 | 81 | * a new one needs its own ruling, the same bar a fourth consumer of the old key |
82 | 82 | * needed. ⛔ And it is never a substitute for `tenancy.tenantField`: an object |
83 | 83 | * whose tenant column genuinely is not `organization_id` declares that key, |
@@ -191,7 +191,7 @@ export function createFieldPresenceProbe( |
191 | 191 | * |
192 | 192 | * 0. **A {@link PLATFORM_STAMP_ORGANIZATION_COLUMNS} row for this object, |
193 | 193 | * when the object really has that column.** The stamp-only divergence |
194 | | - * #8778's ruling introduced (option A; #8707's remaining half), carried |
| 194 | + * the stamp-only ruling introduced (option A), carried |
195 | 195 | * since protocol 18 by the platform-internal table above instead of the |
196 | 196 | * retired authorable `tenancy.organizationField` key. It answers "which |
197 | 197 | * column says who this row is ABOUT" — a different question from "what is |
@@ -237,9 +237,10 @@ export function createFieldPresenceProbe( |
237 | 237 | * the same conclusion through a heuristic is the same mistake with no gate on |
238 | 238 | * it. |
239 | 239 | * |
240 | | - * `sys_api_key.active_organization_id` is reachable through limb 0 since |
241 | | - * #8778 (it was the object that motivated the divergence). Its column is still |
242 | | - * not — and must never become — the object's tenant-scope column: |
| 240 | + * `sys_api_key.active_organization_id` is reachable through limb 0 since the |
| 241 | + * stamp-only ruling (it was the object that motivated the divergence). Its |
| 242 | + * column is still not — and must never become — the object's tenant-scope |
| 243 | + * column: |
243 | 244 | * `tenancy.tenantField` feeds `applyTenantScope` / `injectTenantOnInsert`, so |
244 | 245 | * declaring it there would wall the credential table on an equality that |
245 | 246 | * excludes NULL — every pre-#8287 key would vanish from its own owner's |
@@ -341,8 +342,8 @@ function resolveOrganizationField( |
341 | 342 | { objectName, readStampColumn }: { objectName: string | undefined; readStampColumn: boolean }, |
342 | 343 | ): string | null { |
343 | 344 | if (!objectDef || typeof objectDef !== 'object') return null; |
344 | | - // Limb 0 — the platform's own stamp-only divergence (#8778, carried by |
345 | | - // `PLATFORM_STAMP_ORGANIZATION_COLUMNS` since #19054) wins over everything, |
| 345 | + // Limb 0 — the platform's own stamp-only divergence, carried by |
| 346 | + // `PLATFORM_STAMP_ORGANIZATION_COLUMNS` since #19054, wins over everything, |
346 | 347 | // the ADR-0066 opt-out below included: see the precedence doc above. Reached |
347 | 348 | // by the three sanctioned platform-row writers and by nobody else. |
348 | 349 | if (readStampColumn && objectName !== undefined) { |
|
0 commit comments