Commit e0695b5
* feat(cloud-connection): gate the four mutating install-local routes on manage_metadata (#8976)
`requireAuthenticatedUser` asked one question — "is there a session?" — and it
was the only check on `POST /api/v1/marketplace/install-local`, `DELETE
…/install-local/:id`, `…/reseed-sample-data` and `…/purge-sample-data`. It also
ended in a bare `x-user-id` header fallback.
Measured through the composed plugin, to the point the state actually changes
(`manifest.register()`, `objectql.syncSchemas()`, the on-disk ledger,
`SeedLoaderService.load()`, `driver.delete()`), all three principal shapes were
indistinguishable — 200 on every route, every effect fired:
principal install reseed purge uninstall
bare `x-user-id` header, NO session 200 200 200 200
authenticated, no capability 200 200 200 200
authenticated, `manage_metadata` 200 200 200 200
Nothing downstream refused any of it, and the first row completed a full
schema-mutating install with `installedBy` recorded as a caller-chosen string.
The four doors now resolve identity AND capability through `resolveAuthzContext`
— the platform's single authorization resolver — and demand ADR-0066 D1's
`manage_metadata`, the same key the `/meta` write doors carry (#6603, #8919).
The `x-user-id` fallback is removed rather than mode-gated, matching the two
sibling raw-route surfaces that made the same move (plugin-sharing,
service-settings); it was the last `x-user-id` trust left in packages/ source.
The mount stays unconditional (cloud#1287) — this is authorization on the
routes, not un-mounting the plugin.
Adds `marketplace-install-local-capability-enumeration.test.ts`, which derives
the mutating routes from the plugin's own route table so a new ungated door
fails the build, and annotates the two sibling suites whose names read as
authorization coverage and are not — with an executable pointer, so the
correction cannot rot.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NaS1PAHJcPfAA2acnV53Tn
* chore(changeset): document the install-local capability gate (#8976)
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NaS1PAHJcPfAA2acnV53Tn
* fix(cloud-connection): annotate the enumeration pin's headers literal for the tsc ledger (#8976)
TS2345 under the package's own `tsc --noEmit`: the ternary widened to
`{ 'x-user-id': string } | { 'x-user-id'?: undefined }`, which the
`Record<string, string>` parameter refuses. check:type-check-debt measured it
as +1 raw error against @objectstack/cloud-connection's frozen DEBT entry of 13.
Fixing the error is the author's remedy; raising the entry is maintainer-only.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NaS1PAHJcPfAA2acnV53Tn
* fix(cloud-connection): type the new objectql lookup with the slot's contract (#8976)
The install-local capability gate's `resolveInstallPrincipal` introduced one
NEW service-lookup erasure in a file that is grandfathered for its existing
sites only, so `check:slot-lookup` went red: erasure count grew 16 -> 17.
The site is the split-declaration shape (#4251) in the resolveAuthzContext
wiring:
let ql: any;
try { ql = ctx.getService('objectql'); } catch { /* no data engine */ }
Typed with the slot's declared contract (`IObjectQLEngine`, the same spelling
the two sibling surfaces named in the docblock use for this slot), which is
what the ratchet's own message instructs. The grandfather count is NOT raised
and `SLOT_LOOKUP_UNSWEPT` is untouched - raising a ratchet cap is a gate
weakening and maintainer-only. The file's other 16 sites are left alone: they
are #4251's batch work.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NaS1PAHJcPfAA2acnV53Tn
---------
Co-authored-by: Claude <noreply@anthropic.com>
1 parent 6468df1 commit e0695b5
17 files changed
Lines changed: 892 additions & 75 deletions
File tree
- .changeset
- packages/cloud-connection/src
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
Lines changed: 97 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
Lines changed: 5 additions & 4 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
13 | 13 | | |
14 | 14 | | |
15 | 15 | | |
| 16 | + | |
16 | 17 | | |
17 | 18 | | |
18 | 19 | | |
| |||
58 | 59 | | |
59 | 60 | | |
60 | 61 | | |
61 | | - | |
62 | | - | |
| 62 | + | |
| 63 | + | |
63 | 64 | | |
64 | 65 | | |
65 | 66 | | |
| |||
90 | 91 | | |
91 | 92 | | |
92 | 93 | | |
93 | | - | |
94 | | - | |
| 94 | + | |
| 95 | + | |
95 | 96 | | |
96 | 97 | | |
97 | 98 | | |
| |||
0 commit comments