Commit da28be0
docs(security): document scope-depth (ADR-0057 D1) + open/paid boundary (ADR-0016) (#2118)
scope-depth (readScope/writeScope = own/own_and_reports/unit/unit_and_below/org)
is the core declarative ERP authz axis, but it was undocumented in both the
objectstack-data skill and the security guide — so an AI author wouldn't know it
exists (and would fall back to hand-written RLS, exactly what ADR-0057 removes),
and wouldn't know the open/paid boundary (using `unit` in open-source silently
fails closed to `own`).
- skills/objectstack-data: new "Access depth (scope-depth)" section before RLS —
the 5-value table + a usage example + the ADR-0016 open-core boundary
(hierarchy-relative scopes need @objectstack/security-enterprise; fail closed to
`own` without it; defineStack requires ['hierarchy-security']).
- guides/security.mdx: matching scope-depth section under Object Permission Levels.
Doc/skill-only. check:skill-docs in sync; docs build green (1113 pages).
showcase deliberately NOT touched — it's open-source, so a `unit` scope there
would fail-closed to `own` and mislead; the showcase-scope-depth dogfood already
proves the capability with a reference resolver.
Co-authored-by: Jack Zhuang <277994282+os-zhuang@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>1 parent 52853f3 commit da28be0
2 files changed
Lines changed: 68 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
118 | 118 | | |
119 | 119 | | |
120 | 120 | | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
| 138 | + | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
| 149 | + | |
| 150 | + | |
121 | 151 | | |
122 | 152 | | |
123 | 153 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
424 | 424 | | |
425 | 425 | | |
426 | 426 | | |
| 427 | + | |
| 428 | + | |
| 429 | + | |
| 430 | + | |
| 431 | + | |
| 432 | + | |
| 433 | + | |
| 434 | + | |
| 435 | + | |
| 436 | + | |
| 437 | + | |
| 438 | + | |
| 439 | + | |
| 440 | + | |
| 441 | + | |
| 442 | + | |
| 443 | + | |
| 444 | + | |
| 445 | + | |
| 446 | + | |
| 447 | + | |
| 448 | + | |
| 449 | + | |
| 450 | + | |
| 451 | + | |
| 452 | + | |
| 453 | + | |
| 454 | + | |
| 455 | + | |
| 456 | + | |
| 457 | + | |
| 458 | + | |
| 459 | + | |
| 460 | + | |
| 461 | + | |
| 462 | + | |
| 463 | + | |
| 464 | + | |
427 | 465 | | |
428 | 466 | | |
429 | 467 | | |
| |||
0 commit comments