Skip to content

platform-admin re-anchor L4 (plugin-security): bootstrap stops granting under walled postures; explain reports config-derived standing; deprecation log for legacy grants #11974

Description

@os-support-ai

Leg L4 of the accepted #11663 platform-admin re-anchor design. Provenance: design document = #11663 comment 5394453215 (§6 row L4, migration step 4); maintainer acceptance = #11663 comment 5404675670 (2026-08-25, verbatim 「接受你的建议,继续」). Filed by PM session session_01KWRU3s15AJz7PGW7a7wdCh.

Blocked-by: #11970

Surface: packages/plugins/plugin-security.

Content:

  • bootstrapPlatformAdmin stops writing grant rows under walled postures (Choice 4A: single keeps first-user promotion and its grant row — that branch stays inside the one derivation site, never a second site).
  • Local isEmailVerified deleted in favour of core's promoted one (L2); replay narrowed accordingly.
  • The platformAdmin service registered; explain reports config-derived standing (pin Implement ObjectStack protocol specification with Zod schemas and TypeScript interfaces #3 auditability: the resolved admin list surfaced read-only — Setup / discovery / health — since no grant row is left to query).
  • This is the step where the deprecation log starts firing: a detected legacy row-id grant logs a pointer at the config path (pin [WIP] Fix error in step four of the action run #5 loud migration; ⛔ never a silent dual-track). File the legacy-path removal card (L5's removal half) at this leg's landing, not later.

Discipline: Clause-② expected yes; needs:contract-review at review. Also touches packages/verify/src/harness.ts fixtures (verified-email shape).

Acceptance criterion: on a walled rig with the variable set, bootstrap mints no org-less grant; explain/standing surface reports the config-derived admin list read-only; a seeded legacy grant produces exactly one deprecation log line naming OS_PLATFORM_OWNER_EMAIL.

Metadata

Metadata

Assignees

No one assigned

    Type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions