Path: P2 | access-security | 北极星「优先级」4(已发运文档现为假)
Surfaced by the at-tier contract review of PR #19136 (issuecomment-5737292414, finding 3) and filed by the domain:services seat, session_019hBqDVrwbijUCoK9qsss2E, because 「noted, not filed」 would have left this with no carrier. ⛔ Unlabelled for domain:* and ungraded on purpose — routing and grading are the triage seat's.
Blocked-by: #18336
What goes stale, and when
PR #19136 (card #18336, leg L5 of the #11663 platform-admin re-anchor) retires the legacy unscoped admin_full_access anchor under a walled posture only. The single posture keeps it. ⇒ after that merges, the platform-admin derivation is posture-dependent, and two shipped documents say it is not.
⚠️ Both are correct TODAY and become wrong the moment #19136 lands — which is why this is Blocked-by: #18336 rather than an open defect. ⛔ Do not "fix" them before that PR merges.
1. content/docs/permissions/authorization.mdx — the customer-facing statement
Re-measured on origin/main by this seat, ⛔ not quoted from the review. The passage reads, verbatim:
That posture is derived at one site from two anchors, either of which is sufficient: the deployment's configured administrator list … and an unscoped admin_full_access grant row.
⭐ 「either of which is sufficient」 carries no posture qualifier. After #19136 the second anchor is sufficient under single and refused under a wall — so the sentence tells a walled deployment's operator something that is no longer true of their deployment, on the page that defines the tenant-wall boundary.
2. docs/qa/platform-checklist/areas/access-security.json — the test checklist
:2462 — clause reads verbatim 「additive, never subtractive — the legacy anchor is honoured and loudly re-pointed: with the variable unset, standing resting on the unscoped admin_full_access grant alone still resolves PLATFORM_ADMIN, and the once-per-process [authz] pointer names the OS_PLATFORM_OWNER_EMAIL config line that re-anchors it (reportLegacyPlatformAdminGrant, platform-admin.ts)」
:2428 — a step that greps the process log for that once-per-process pointer
:2492 — an anchor parenthetical naming reportLegacyPlatformAdminGrant
⇒ #19136 deletes reportLegacyPlatformAdminGrant and the pointer it emitted. A checklist item instructing a tester to grep for a log line that no longer exists fails for a reason that is not the product's fault, which is the failure mode a checklist is least able to survive.
⚠️ Why no gate catches this: the anchor SYMBOL on that item is parsePlatformAdminEmails, which still resolves after the retirement, so check-platform-checklist.mjs stays green. ⭐ The stale prose sits behind a live anchor — the gate is doing exactly what it was built to do and cannot see this.
Measurement
reading (this act, git show origin/main:<path>) |
value |
authorization.mdx — 「either of which is sufficient」 with no posture qualifier |
present, quoted above |
access-security.json — lines naming the retired pointer / behaviour |
3 (:2428, :2462, :2492) |
control — access-security.json readable and non-trivial |
2826 lines |
| negative control — a token that should not exist |
0 |
⛔ What this card is NOT
Dedupe words
authorization.mdx two anchors either sufficient · access-security checklist legacy anchor honoured · reportLegacyPlatformAdminGrant checklist prose · platform-admin posture-dependent docs · stale prose behind a live anchor symbol
Related: #18336 / PR #19136 (the retirement) · #11663 (the design) · #11979 (the single half).
Generated by Claude Code
Path: P2 | access-security | 北极星「优先级」4(已发运文档现为假)
Surfaced by the at-tier contract review of PR #19136 (
issuecomment-5737292414, finding 3) and filed by thedomain:servicesseat,session_019hBqDVrwbijUCoK9qsss2E, because 「noted, not filed」 would have left this with no carrier. ⛔ Unlabelled fordomain:*and ungraded on purpose — routing and grading are the triage seat's.Blocked-by: #18336
What goes stale, and when
PR #19136 (card #18336, leg L5 of the #11663 platform-admin re-anchor) retires the legacy unscoped
admin_full_accessanchor under a walled posture only. Thesingleposture keeps it. ⇒ after that merges, the platform-admin derivation is posture-dependent, and two shipped documents say it is not.Blocked-by: #18336rather than an open defect. ⛔ Do not "fix" them before that PR merges.1.
content/docs/permissions/authorization.mdx— the customer-facing statementRe-measured on
origin/mainby this seat, ⛔ not quoted from the review. The passage reads, verbatim:⭐ 「either of which is sufficient」 carries no posture qualifier. After #19136 the second anchor is sufficient under
singleand refused under a wall — so the sentence tells a walled deployment's operator something that is no longer true of their deployment, on the page that defines the tenant-wall boundary.2.
docs/qa/platform-checklist/areas/access-security.json— the test checklist:2462— clause reads verbatim 「additive, never subtractive — the legacy anchor is honoured and loudly re-pointed: with the variable unset, standing resting on the unscopedadmin_full_accessgrant alone still resolvesPLATFORM_ADMIN, and the once-per-process[authz]pointer names theOS_PLATFORM_OWNER_EMAILconfig line that re-anchors it (reportLegacyPlatformAdminGrant,platform-admin.ts)」:2428— a step that greps the process log for that once-per-process pointer:2492— an anchor parenthetical namingreportLegacyPlatformAdminGrant⇒ #19136 deletes
reportLegacyPlatformAdminGrantand the pointer it emitted. A checklist item instructing a tester to grep for a log line that no longer exists fails for a reason that is not the product's fault, which is the failure mode a checklist is least able to survive.parsePlatformAdminEmails, which still resolves after the retirement, socheck-platform-checklist.mjsstays green. ⭐ The stale prose sits behind a live anchor — the gate is doing exactly what it was built to do and cannot see this.Measurement
git show origin/main:<path>)authorization.mdx— 「either of which is sufficient」 with no posture qualifieraccess-security.json— lines naming the retired pointer / behaviour:2428,:2462,:2492)access-security.jsonreadable and non-trivial⛔ What this card is NOT
Clause-②: yessecurity PR to carry a docs rewrite is exactly what the surface declaration exists to prevent.singlehalf. platform-admin re-anchor follow-up (Choice 4B): config-anchor thesingleposture — first-user promotion becomes development-only fallback #11979 (Choice 4B) decides that half's fate; whoever takes this should ⛔ not pre-empt it, and should describe the posture split as it actually ships.Dedupe words
authorization.mdx two anchors either sufficient·access-security checklist legacy anchor honoured·reportLegacyPlatformAdminGrant checklist prose·platform-admin posture-dependent docs·stale prose behind a live anchor symbolRelated: #18336 / PR #19136 (the retirement) · #11663 (the design) · #11979 (the
singlehalf).Generated by Claude Code