Skip to content

platform-admin re-anchor L1 (spec seat): export the kernel platform-admin capability declaration — one list, imported by plugin-security (Choice 6A) #11965

Description

@os-support-ai

Leg L1 of the accepted #11663 platform-admin re-anchor design. Provenance: design document = #11663 comment 5394453215 (§4 Choice 6, §6 row L1); maintainer acceptance = #11663 comment 5404675670 (2026-08-25, verbatim 「接受你的建议,继续」, bundle 1A/2B/3A/4A/5A/6A/7A). Filed by PM session session_01KWRU3s15AJz7PGW7a7wdCh.

Surface: packages/spec — ⛔ spec seat only (sole owner of this package).

Content: @objectstack/spec exports the platform-admin capability declaration (the capability set today carried by the org-less admin_full_access row); plugin-security's admin_full_access declaration imports that same list, so exactly one copy exists. Behaviour-neutral; lands alone (migration sequence step 2). Measured precedent in the design: core already imports ADMIN_FULL_ACCESS from @objectstack/spec.

Acceptance criterion: git grep -n ADMIN_FULL_ACCESS packages/spec/src packages/plugins/plugin-security/src shows the capability list declared once (spec) and imported — not duplicated — by plugin-security, and no behaviour change lands with it.

Notes: the design expects no authorable-surface movement (no new authorable key) — the spec seat must confirm that on the tree rather than take the design's word. Premise-first: re-verify the cited files/lines on current origin/main before implementing; the design was measured at cad8b42f00.

Downstream: the core derivation leg (L2) declares Blocked-by: on this card.

Metadata

Metadata

Assignees

No one assigned

    Type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions