You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
test(security): ADR-0099 P2′ — pin the per-object super-bit as the Layer 1 scope axis (#3211 M3′)
The two-axis Amendment's documentation cells (zero behavior change). The
original P2 (collapse Layer 1 tier onto posture) was rejected; these cells
pin the corrected model in CI:
- seeded-face agreement: every seeded super-bit holder is already
>= TENANT_ADMIN, so the two axes coincide on the seeded surface (why the
collapse looked safe until the delegation case);
- the delegation cell (LOAD-BEARING): a MEMBER holding a delegated
per-object viewAllRecords/modifyAllRecords on a private object
short-circuits Layer 1 (sees all rows in-org) AND stays walled by Layer 0
(org-1 only) — the auditor pattern; a future posture-convergence cleanup
must keep this green or it silently deletes the capability;
- I7: the holder cannot read/write/insert cross-tenant (the scope axis never
crosses a boundary posture has not opened);
- contrast: a plain member without the bit is denied on the private object,
so the bit is a real grantable capability, not conditionally inert
(the ADR-0049 class the collapse would have introduced).
New fixture invoice_auditor (delegated per-object super-bit). G2 audit:
single authority per axis holds — boundary fact derived once (core resolver)
+ consumed at the Layer 0 gate (fallback probe narrows only); scope fact
evaluated only via hasSuperuser*Bypass.
plugin-security 510 passed; tsc + check:role-word + check:doc-authoring clean;
plugin-security build green.
Refs #3211 - ADR-0099 two-axis Amendment (#3245)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DAHp4K7FvyMPBY1DPNkmRu
0 commit comments