You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
bootstrapPlatformAdmin stops writing grant rows under walled postures (Choice 4A: single keeps first-user promotion and its grant row — that branch stays inside the one derivation site, never a second site).
Local isEmailVerified deleted in favour of core's promoted one (L2); replay narrowed accordingly.
This is the step where the deprecation log starts firing: a detected legacy row-id grant logs a pointer at the config path (pin [WIP] Fix error in step four of the action run #5 loud migration; ⛔ never a silent dual-track). File the legacy-path removal card (L5's removal half) at this leg's landing, not later.
Discipline: Clause-② expected yes; needs:contract-review at review. Also touches packages/verify/src/harness.ts fixtures (verified-email shape).
Acceptance criterion: on a walled rig with the variable set, bootstrap mints no org-less grant; explain/standing surface reports the config-derived admin list read-only; a seeded legacy grant produces exactly one deprecation log line naming OS_PLATFORM_OWNER_EMAIL.
Leg L4 of the accepted #11663 platform-admin re-anchor design. Provenance: design document = #11663 comment 5394453215 (§6 row L4, migration step 4); maintainer acceptance = #11663 comment 5404675670 (2026-08-25, verbatim 「接受你的建议,继续」). Filed by PM session
session_01KWRU3s15AJz7PGW7a7wdCh.Blocked-by: #11970
Surface:
packages/plugins/plugin-security.Content:
bootstrapPlatformAdminstops writing grant rows under walled postures (Choice 4A:singlekeeps first-user promotion and its grant row — that branch stays inside the one derivation site, never a second site).isEmailVerifieddeleted in favour of core's promoted one (L2); replay narrowed accordingly.platformAdminservice registered;explainreports config-derived standing (pin Implement ObjectStack protocol specification with Zod schemas and TypeScript interfaces #3 auditability: the resolved admin list surfaced read-only — Setup / discovery / health — since no grant row is left to query).Discipline: Clause-② expected yes;
needs:contract-reviewat review. Also touchespackages/verify/src/harness.tsfixtures (verified-email shape).Acceptance criterion: on a walled rig with the variable set, bootstrap mints no org-less grant;
explain/standing surface reports the config-derived admin list read-only; a seeded legacy grant produces exactly one deprecation log line namingOS_PLATFORM_OWNER_EMAIL.