Commit c03108c
fix(auth): degraded tenancy must not hand out a default organization (#4423)
`TenancyService.defaultOrgId()` documented "returns null under any walled
posture" but keyed on the posture actually IN FORCE, not the one requested.
Those disagree in exactly one state — DEGRADED — and there the resolver
answered with "the slug='default' org, or the only org that exists".
Everything downstream binds new users to that answer. The membership
reconciler (ADR-0093 D2) sits on `user.create.after`, the seam every creation
path flows through, so a degraded deployment auto-bound every fresh signup,
admin-created user and SSO JIT user as a `member` of whichever organization
was resolvable — and `backfillMemberships` (D6) would sweep the pre-existing
member-less ones in on the next `kernel:ready`.
This reached production: ObjectStack Cloud's control plane requests
`isolated` while deliberately not mounting `@objectstack/organizations` (it
enforces its own control-plane wall), so the `org-scoping` probe missed, the
posture resolved degraded, and self-serve signups landed inside a stranger's
organization with read access to its environments (cloud#957).
`defaultOrgId()` now keys on `requestedPosture` — any walled request,
enforced or degraded, returns null and the framework never guesses. Same
judgement D6 already applies to the backfill ("a wrong org in a
tenant-isolated deployment is a data-exposure bug, not a convenience"),
applied to the resolver those consumers share, and now consistent with the
default-org bootstrap in `AuthPlugin.start()`, which was already gated on the
requested posture.
Single-org is unchanged. A degraded deployment loses the auto-bind, which is
the point — ADR-0093 D5 already refuses to boot it without
`OS_ALLOW_DEGRADED_TENANCY=1`.
Co-authored-by: Jack Zhuang <277994282+os-zhuang@users.noreply.github.com>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>1 parent eb4204b commit c03108c
3 files changed
Lines changed: 91 additions & 6 deletions
File tree
- .changeset
- packages/plugins/plugin-auth/src
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
129 | 129 | | |
130 | 130 | | |
131 | 131 | | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
| 138 | + | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
| 149 | + | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
| 153 | + | |
| 154 | + | |
| 155 | + | |
| 156 | + | |
| 157 | + | |
| 158 | + | |
| 159 | + | |
| 160 | + | |
| 161 | + | |
132 | 162 | | |
133 | 163 | | |
134 | 164 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
77 | 77 | | |
78 | 78 | | |
79 | 79 | | |
80 | | - | |
81 | | - | |
82 | | - | |
83 | | - | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
84 | 96 | | |
85 | 97 | | |
86 | 98 | | |
| |||
213 | 225 | | |
214 | 226 | | |
215 | 227 | | |
216 | | - | |
217 | | - | |
| 228 | + | |
| 229 | + | |
| 230 | + | |
| 231 | + | |
218 | 232 | | |
219 | 233 | | |
220 | 234 | | |
| |||
0 commit comments