Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions .changeset/d1-config-derived-owner.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
---
'@objectstack/plugin-auth': patch
---

`ensureDefaultOrganization` resolves the platform admin through the L4 config-derived standing when no cross-tenant grant row exists (#13514 follow-through): the walled bootstrap mints no `sys_user_permission_set` row any more, so the ADR-0081 D1 default-org bootstrap dead-ended on `no_admin` forever on walled deployments — the enterprise organizations package invokes this same helper there. The fallback asks the same public predicates the derivation site asks (`resolvePlatformAdminEmails` + `isConfiguredPlatformAdminEmail` + the #11343 verified-email allow-list), oldest verified owner wins, and the grant row stays primary where it exists.
Original file line numberDiff line numberDiff line change
Expand Up@@ -36,6 +36,71 @@ function makeQl(seed: Partial<Record<string, Row[]>> = {}) {
};
}

describe('the L4 config-derived owner fallback (#13514 follow-through)', () => {
// Under a walled posture the bootstrap mints NO grant row, so the grant
// lookup answers nothing — the declared VERIFIED owner must be the admin,
// resolved with the same public predicates the derivation site asks.
const OWNER = 'owner@walled.example';
const withOwnerEnv = async (value: string | undefined, fn: () => Promise<void>) => {
const prev = process.env.OS_PLATFORM_OWNER_EMAIL;
if (value === undefined) delete process.env.OS_PLATFORM_OWNER_EMAIL;
else process.env.OS_PLATFORM_OWNER_EMAIL = value;
try { await fn(); } finally {
if (prev === undefined) delete process.env.OS_PLATFORM_OWNER_EMAIL;
else process.env.OS_PLATFORM_OWNER_EMAIL = prev;
}
};

it('no grant row + declared VERIFIED owner ⇒ the owner gets the default org', async () =>
withOwnerEnv(OWNER, async () => {
const ql = makeQl({
sys_user_permission_set: [],
sys_user: [
{ id: 'u_other', email: 'bystander@walled.example', email_verified: true, created_at: '2026-01-01' },
{ id: 'u_owner', email: OWNER, email_verified: true, created_at: '2026-01-02' },
],
});
const res = await ensureDefaultOrganization(ql);
expect(res.defaultOrgCreated).toBe(true);
expect(res.memberCreated).toBe(true);
expect(ql.tables.sys_member[0]).toMatchObject({ user_id: 'u_owner', role: 'owner' });
}));

it('an UNVERIFIED declared owner stays no_admin — fail closed, the #11343 allow-list holds', async () =>
withOwnerEnv(OWNER, async () => {
const ql = makeQl({
sys_user_permission_set: [],
sys_user: [{ id: 'u_owner', email: OWNER, email_verified: false, created_at: '2026-01-02' }],
});
const res = await ensureDefaultOrganization(ql);
expect(res.defaultOrgCreated).toBe(false);
expect(res.reason).toBe('no_admin');
expect(ql.tables.sys_member).toEqual([]);
}));

it('no declared owner at all stays no_admin — nobody is invented', async () =>
withOwnerEnv(undefined, async () => {
const ql = makeQl({
sys_user_permission_set: [],
sys_user: [{ id: 'u_owner', email: OWNER, email_verified: true, created_at: '2026-01-02' }],
});
const res = await ensureDefaultOrganization(ql);
expect(res.defaultOrgCreated).toBe(false);
expect(res.reason).toBe('no_admin');
}));

it('a grant row still WINS over the config fallback — the historical spelling stays primary', async () =>
withOwnerEnv(OWNER, async () => {
const ql = makeQl({
sys_user: [{ id: 'u_owner', email: OWNER, email_verified: true, created_at: '2026-01-02' }],
});
const res = await ensureDefaultOrganization(ql);
expect(res.defaultOrgCreated).toBe(true);
// makeQl's default grant row names u1 — that row, not the config owner.
expect(ql.tables.sys_member[0]).toMatchObject({ user_id: 'u1', role: 'owner' });
}));
});

describe('ensureDefaultOrganization (plugin-auth home)', () => {
it('creates the default org and binds the admin as owner', async () => {
const ql = makeQl();
Expand Down
58 changes: 38 additions & 20 deletions packages/plugins/plugin-auth/src/ensure-default-organization.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -85,6 +85,9 @@ interface BootstrapLogger {
* tests — survive it perfectly, which is why no suite would catch it. The
* property-access call form below keeps the receiver.
*/
import { resolvePlatformAdminEmails, isConfiguredPlatformAdminEmail } from '@objectstack/core';
import { isEmailVerifiedUserRow } from '@objectstack/types';

function logDurabilityFailure(
logger: BootstrapLogger | undefined,
message: string,
Expand DownExpand Up@@ -164,29 +167,44 @@ export async function ensureDefaultOrganization(
return { defaultOrgCreated: false, memberCreated: false, reason: 'no_admin' };
}

// 1. Find the platform admin permission-set id.
const adminPs = await tryFind(ql, 'sys_permission_set', { name: 'admin_full_access' }, 1);
if (adminPs.length === 0 || !adminPs[0].id) {
return { defaultOrgCreated: false, memberCreated: false, reason: 'no_admin' };
}
const adminPsId = adminPs[0].id;

// 2. Find the platform admin user (oldest cross-tenant grant).
const adminGrants = await tryFind(
ql,
'sys_user_permission_set',
{ permission_set_id: adminPsId, organization_id: null },
50,
);
if (adminGrants.length === 0) {
return { defaultOrgCreated: false, memberCreated: false, reason: 'no_admin' };
}
const sortedGrants = [...adminGrants].sort((a, b) => {
const oldestFirst = (a: any, b: any) => {
const ta = a.created_at ? new Date(a.created_at).getTime() : 0;
const tb = b.created_at ? new Date(b.created_at).getTime() : 0;
return ta - tb;
});
const adminUserId: string | undefined = sortedGrants[0]?.user_id;
};

// 1-2. Resolve the platform admin. The cross-tenant grant row is the
// historical spelling and still the primary answer where it exists
// (`single` posture first-user promotion, Choice 4A; legacy walled
// grants). Since #13514 (L4) a WALLED bootstrap mints no row at all —
// standing is config-derived at the authorization derivation site — so a
// missing row is no longer a verdict: fall back to the DECLARED VERIFIED
// OWNER, resolved with the same public predicates the derivation site
// asks (`resolvePlatformAdminEmails` + row-side membership + the #11343
// verified-email allow-list), oldest wins — the bootstrap's own tiebreak.
// Without this fallback the walled default-org bootstrap dead-ends on
// `no_admin` forever, which is how cloud's EE guided-path suite caught it.
let adminUserId: string | undefined;
const adminPs = await tryFind(ql, 'sys_permission_set', { name: 'admin_full_access' }, 1);
if (adminPs.length > 0 && adminPs[0].id) {
const adminGrants = await tryFind(
ql,
'sys_user_permission_set',
{ permission_set_id: adminPs[0].id, organization_id: null },
50,
);
adminUserId = [...adminGrants].sort(oldestFirst)[0]?.user_id;
}
if (!adminUserId) {
const config = resolvePlatformAdminEmails();
if (config.emails.length > 0) {
const users = await tryFind(ql, 'sys_user', {}, 50);
const owners = users
.filter((u: any) => isConfiguredPlatformAdminEmail(u?.email, config) && isEmailVerifiedUserRow(u))
.sort(oldestFirst);
adminUserId = owners[0]?.id;
}
}
if (!adminUserId) {
return { defaultOrgCreated: false, memberCreated: false, reason: 'no_admin' };
}
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
fix(plugin-auth): ensureDefaultOrganization resolves the L4 config-derived owner when no grant row exists (#13514 follow-through) by hotlong · Pull Request #13708 · objectstack-ai/objectstack · GitHub
Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions .changeset/d1-config-derived-owner.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
---
'@objectstack/plugin-auth': patch
---

`ensureDefaultOrganization` resolves the platform admin through the L4 config-derived standing when no cross-tenant grant row exists (#13514 follow-through): the walled bootstrap mints no `sys_user_permission_set` row any more, so the ADR-0081 D1 default-org bootstrap dead-ended on `no_admin` forever on walled deployments — the enterprise organizations package invokes this same helper there. The fallback asks the same public predicates the derivation site asks (`resolvePlatformAdminEmails` + `isConfiguredPlatformAdminEmail` + the #11343 verified-email allow-list), oldest verified owner wins, and the grant row stays primary where it exists.
Original file line numberDiff line numberDiff line change
Expand Up@@ -36,6 +36,71 @@ function makeQl(seed: Partial<Record<string, Row[]>> = {}) {
};
}

describe('the L4 config-derived owner fallback (#13514 follow-through)', () => {
// Under a walled posture the bootstrap mints NO grant row, so the grant
// lookup answers nothing — the declared VERIFIED owner must be the admin,
// resolved with the same public predicates the derivation site asks.
const OWNER = 'owner@walled.example';
const withOwnerEnv = async (value: string | undefined, fn: () => Promise<void>) => {
const prev = process.env.OS_PLATFORM_OWNER_EMAIL;
if (value === undefined) delete process.env.OS_PLATFORM_OWNER_EMAIL;
else process.env.OS_PLATFORM_OWNER_EMAIL = value;
try { await fn(); } finally {
if (prev === undefined) delete process.env.OS_PLATFORM_OWNER_EMAIL;
else process.env.OS_PLATFORM_OWNER_EMAIL = prev;
}
};

it('no grant row + declared VERIFIED owner ⇒ the owner gets the default org', async () =>
withOwnerEnv(OWNER, async () => {
const ql = makeQl({
sys_user_permission_set: [],
sys_user: [
{ id: 'u_other', email: 'bystander@walled.example', email_verified: true, created_at: '2026-01-01' },
{ id: 'u_owner', email: OWNER, email_verified: true, created_at: '2026-01-02' },
],
});
const res = await ensureDefaultOrganization(ql);
expect(res.defaultOrgCreated).toBe(true);
expect(res.memberCreated).toBe(true);
expect(ql.tables.sys_member[0]).toMatchObject({ user_id: 'u_owner', role: 'owner' });
}));

it('an UNVERIFIED declared owner stays no_admin — fail closed, the #11343 allow-list holds', async () =>
withOwnerEnv(OWNER, async () => {
const ql = makeQl({
sys_user_permission_set: [],
sys_user: [{ id: 'u_owner', email: OWNER, email_verified: false, created_at: '2026-01-02' }],
});
const res = await ensureDefaultOrganization(ql);
expect(res.defaultOrgCreated).toBe(false);
expect(res.reason).toBe('no_admin');
expect(ql.tables.sys_member).toEqual([]);
}));

it('no declared owner at all stays no_admin — nobody is invented', async () =>
withOwnerEnv(undefined, async () => {
const ql = makeQl({
sys_user_permission_set: [],
sys_user: [{ id: 'u_owner', email: OWNER, email_verified: true, created_at: '2026-01-02' }],
});
const res = await ensureDefaultOrganization(ql);
expect(res.defaultOrgCreated).toBe(false);
expect(res.reason).toBe('no_admin');
}));

it('a grant row still WINS over the config fallback — the historical spelling stays primary', async () =>
withOwnerEnv(OWNER, async () => {
const ql = makeQl({
sys_user: [{ id: 'u_owner', email: OWNER, email_verified: true, created_at: '2026-01-02' }],
});
const res = await ensureDefaultOrganization(ql);
expect(res.defaultOrgCreated).toBe(true);
// makeQl's default grant row names u1 — that row, not the config owner.
expect(ql.tables.sys_member[0]).toMatchObject({ user_id: 'u1', role: 'owner' });
}));
});

describe('ensureDefaultOrganization (plugin-auth home)', () => {
it('creates the default org and binds the admin as owner', async () => {
const ql = makeQl();
Expand Down
58 changes: 38 additions & 20 deletions packages/plugins/plugin-auth/src/ensure-default-organization.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -85,6 +85,9 @@ interface BootstrapLogger {
* tests — survive it perfectly, which is why no suite would catch it. The
* property-access call form below keeps the receiver.
*/
import { resolvePlatformAdminEmails, isConfiguredPlatformAdminEmail } from '@objectstack/core';
import { isEmailVerifiedUserRow } from '@objectstack/types';

function logDurabilityFailure(
logger: BootstrapLogger | undefined,
message: string,
Expand DownExpand Up@@ -164,29 +167,44 @@ export async function ensureDefaultOrganization(
return { defaultOrgCreated: false, memberCreated: false, reason: 'no_admin' };
}

// 1. Find the platform admin permission-set id.
const adminPs = await tryFind(ql, 'sys_permission_set', { name: 'admin_full_access' }, 1);
if (adminPs.length === 0 || !adminPs[0].id) {
return { defaultOrgCreated: false, memberCreated: false, reason: 'no_admin' };
}
const adminPsId = adminPs[0].id;

// 2. Find the platform admin user (oldest cross-tenant grant).
const adminGrants = await tryFind(
ql,
'sys_user_permission_set',
{ permission_set_id: adminPsId, organization_id: null },
50,
);
if (adminGrants.length === 0) {
return { defaultOrgCreated: false, memberCreated: false, reason: 'no_admin' };
}
const sortedGrants = [...adminGrants].sort((a, b) => {
const oldestFirst = (a: any, b: any) => {
const ta = a.created_at ? new Date(a.created_at).getTime() : 0;
const tb = b.created_at ? new Date(b.created_at).getTime() : 0;
return ta - tb;
});
const adminUserId: string | undefined = sortedGrants[0]?.user_id;
};

// 1-2. Resolve the platform admin. The cross-tenant grant row is the
// historical spelling and still the primary answer where it exists
// (`single` posture first-user promotion, Choice 4A; legacy walled
// grants). Since #13514 (L4) a WALLED bootstrap mints no row at all —
// standing is config-derived at the authorization derivation site — so a
// missing row is no longer a verdict: fall back to the DECLARED VERIFIED
// OWNER, resolved with the same public predicates the derivation site
// asks (`resolvePlatformAdminEmails` + row-side membership + the #11343
// verified-email allow-list), oldest wins — the bootstrap's own tiebreak.
// Without this fallback the walled default-org bootstrap dead-ends on
// `no_admin` forever, which is how cloud's EE guided-path suite caught it.
let adminUserId: string | undefined;
const adminPs = await tryFind(ql, 'sys_permission_set', { name: 'admin_full_access' }, 1);
if (adminPs.length > 0 && adminPs[0].id) {
const adminGrants = await tryFind(
ql,
'sys_user_permission_set',
{ permission_set_id: adminPs[0].id, organization_id: null },
50,
);
adminUserId = [...adminGrants].sort(oldestFirst)[0]?.user_id;
}
if (!adminUserId) {
const config = resolvePlatformAdminEmails();
if (config.emails.length > 0) {
const users = await tryFind(ql, 'sys_user', {}, 50);
const owners = users
.filter((u: any) => isConfiguredPlatformAdminEmail(u?.email, config) && isEmailVerifiedUserRow(u))
.sort(oldestFirst);
adminUserId = owners[0]?.id;
}
}
if (!adminUserId) {
return { defaultOrgCreated: false, memberCreated: false, reason: 'no_admin' };
}
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(plugin-auth): ensureDefaultOrganization resolves the L4 config-derived owner when no grant row exists (#13514 follow-through) by hotlong · Pull Request #13708 · objectstack-ai/objectstack · GitHub
Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions .changeset/d1-config-derived-owner.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
---
'@objectstack/plugin-auth': patch
---

`ensureDefaultOrganization` resolves the platform admin through the L4 config-derived standing when no cross-tenant grant row exists (#13514 follow-through): the walled bootstrap mints no `sys_user_permission_set` row any more, so the ADR-0081 D1 default-org bootstrap dead-ended on `no_admin` forever on walled deployments — the enterprise organizations package invokes this same helper there. The fallback asks the same public predicates the derivation site asks (`resolvePlatformAdminEmails` + `isConfiguredPlatformAdminEmail` + the #11343 verified-email allow-list), oldest verified owner wins, and the grant row stays primary where it exists.
Original file line numberDiff line numberDiff line change
Expand Up@@ -36,6 +36,71 @@ function makeQl(seed: Partial<Record<string, Row[]>> = {}) {
};
}

describe('the L4 config-derived owner fallback (#13514 follow-through)', () => {
// Under a walled posture the bootstrap mints NO grant row, so the grant
// lookup answers nothing — the declared VERIFIED owner must be the admin,
// resolved with the same public predicates the derivation site asks.
const OWNER = 'owner@walled.example';
const withOwnerEnv = async (value: string | undefined, fn: () => Promise<void>) => {
const prev = process.env.OS_PLATFORM_OWNER_EMAIL;
if (value === undefined) delete process.env.OS_PLATFORM_OWNER_EMAIL;
else process.env.OS_PLATFORM_OWNER_EMAIL = value;
try { await fn(); } finally {
if (prev === undefined) delete process.env.OS_PLATFORM_OWNER_EMAIL;
else process.env.OS_PLATFORM_OWNER_EMAIL = prev;
}
};

it('no grant row + declared VERIFIED owner ⇒ the owner gets the default org', async () =>
withOwnerEnv(OWNER, async () => {
const ql = makeQl({
sys_user_permission_set: [],
sys_user: [
{ id: 'u_other', email: 'bystander@walled.example', email_verified: true, created_at: '2026-01-01' },
{ id: 'u_owner', email: OWNER, email_verified: true, created_at: '2026-01-02' },
],
});
const res = await ensureDefaultOrganization(ql);
expect(res.defaultOrgCreated).toBe(true);
expect(res.memberCreated).toBe(true);
expect(ql.tables.sys_member[0]).toMatchObject({ user_id: 'u_owner', role: 'owner' });
}));

it('an UNVERIFIED declared owner stays no_admin — fail closed, the #11343 allow-list holds', async () =>
withOwnerEnv(OWNER, async () => {
const ql = makeQl({
sys_user_permission_set: [],
sys_user: [{ id: 'u_owner', email: OWNER, email_verified: false, created_at: '2026-01-02' }],
});
const res = await ensureDefaultOrganization(ql);
expect(res.defaultOrgCreated).toBe(false);
expect(res.reason).toBe('no_admin');
expect(ql.tables.sys_member).toEqual([]);
}));

it('no declared owner at all stays no_admin — nobody is invented', async () =>
withOwnerEnv(undefined, async () => {
const ql = makeQl({
sys_user_permission_set: [],
sys_user: [{ id: 'u_owner', email: OWNER, email_verified: true, created_at: '2026-01-02' }],
});
const res = await ensureDefaultOrganization(ql);
expect(res.defaultOrgCreated).toBe(false);
expect(res.reason).toBe('no_admin');
}));

it('a grant row still WINS over the config fallback — the historical spelling stays primary', async () =>
withOwnerEnv(OWNER, async () => {
const ql = makeQl({
sys_user: [{ id: 'u_owner', email: OWNER, email_verified: true, created_at: '2026-01-02' }],
});
const res = await ensureDefaultOrganization(ql);
expect(res.defaultOrgCreated).toBe(true);
// makeQl's default grant row names u1 — that row, not the config owner.
expect(ql.tables.sys_member[0]).toMatchObject({ user_id: 'u1', role: 'owner' });
}));
});

describe('ensureDefaultOrganization (plugin-auth home)', () => {
it('creates the default org and binds the admin as owner', async () => {
const ql = makeQl();
Expand Down
58 changes: 38 additions & 20 deletions packages/plugins/plugin-auth/src/ensure-default-organization.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -85,6 +85,9 @@ interface BootstrapLogger {
* tests — survive it perfectly, which is why no suite would catch it. The
* property-access call form below keeps the receiver.
*/
import { resolvePlatformAdminEmails, isConfiguredPlatformAdminEmail } from '@objectstack/core';
import { isEmailVerifiedUserRow } from '@objectstack/types';

function logDurabilityFailure(
logger: BootstrapLogger | undefined,
message: string,
Expand DownExpand Up@@ -164,29 +167,44 @@ export async function ensureDefaultOrganization(
return { defaultOrgCreated: false, memberCreated: false, reason: 'no_admin' };
}

// 1. Find the platform admin permission-set id.
const adminPs = await tryFind(ql, 'sys_permission_set', { name: 'admin_full_access' }, 1);
if (adminPs.length === 0 || !adminPs[0].id) {
return { defaultOrgCreated: false, memberCreated: false, reason: 'no_admin' };
}
const adminPsId = adminPs[0].id;

// 2. Find the platform admin user (oldest cross-tenant grant).
const adminGrants = await tryFind(
ql,
'sys_user_permission_set',
{ permission_set_id: adminPsId, organization_id: null },
50,
);
if (adminGrants.length === 0) {
return { defaultOrgCreated: false, memberCreated: false, reason: 'no_admin' };
}
const sortedGrants = [...adminGrants].sort((a, b) => {
const oldestFirst = (a: any, b: any) => {
const ta = a.created_at ? new Date(a.created_at).getTime() : 0;
const tb = b.created_at ? new Date(b.created_at).getTime() : 0;
return ta - tb;
});
const adminUserId: string | undefined = sortedGrants[0]?.user_id;
};

// 1-2. Resolve the platform admin. The cross-tenant grant row is the
// historical spelling and still the primary answer where it exists
// (`single` posture first-user promotion, Choice 4A; legacy walled
// grants). Since #13514 (L4) a WALLED bootstrap mints no row at all —
// standing is config-derived at the authorization derivation site — so a
// missing row is no longer a verdict: fall back to the DECLARED VERIFIED
// OWNER, resolved with the same public predicates the derivation site
// asks (`resolvePlatformAdminEmails` + row-side membership + the #11343
// verified-email allow-list), oldest wins — the bootstrap's own tiebreak.
// Without this fallback the walled default-org bootstrap dead-ends on
// `no_admin` forever, which is how cloud's EE guided-path suite caught it.
let adminUserId: string | undefined;
const adminPs = await tryFind(ql, 'sys_permission_set', { name: 'admin_full_access' }, 1);
if (adminPs.length > 0 && adminPs[0].id) {
const adminGrants = await tryFind(
ql,
'sys_user_permission_set',
{ permission_set_id: adminPs[0].id, organization_id: null },
50,
);
adminUserId = [...adminGrants].sort(oldestFirst)[0]?.user_id;
}
if (!adminUserId) {
const config = resolvePlatformAdminEmails();
if (config.emails.length > 0) {
const users = await tryFind(ql, 'sys_user', {}, 50);
const owners = users
.filter((u: any) => isConfiguredPlatformAdminEmail(u?.email, config) && isEmailVerifiedUserRow(u))
.sort(oldestFirst);
adminUserId = owners[0]?.id;
}
}
if (!adminUserId) {
return { defaultOrgCreated: false, memberCreated: false, reason: 'no_admin' };
}
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(plugin-auth): ensureDefaultOrganization resolves the L4 config-derived owner when no grant row exists (#13514 follow-through) by hotlong · Pull Request #13708 · objectstack-ai/objectstack · GitHub
Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions .changeset/d1-config-derived-owner.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
---
'@objectstack/plugin-auth': patch
---

`ensureDefaultOrganization` resolves the platform admin through the L4 config-derived standing when no cross-tenant grant row exists (#13514 follow-through): the walled bootstrap mints no `sys_user_permission_set` row any more, so the ADR-0081 D1 default-org bootstrap dead-ended on `no_admin` forever on walled deployments — the enterprise organizations package invokes this same helper there. The fallback asks the same public predicates the derivation site asks (`resolvePlatformAdminEmails` + `isConfiguredPlatformAdminEmail` + the #11343 verified-email allow-list), oldest verified owner wins, and the grant row stays primary where it exists.
Original file line numberDiff line numberDiff line change
Expand Up@@ -36,6 +36,71 @@ function makeQl(seed: Partial<Record<string, Row[]>> = {}) {
};
}

describe('the L4 config-derived owner fallback (#13514 follow-through)', () => {
// Under a walled posture the bootstrap mints NO grant row, so the grant
// lookup answers nothing — the declared VERIFIED owner must be the admin,
// resolved with the same public predicates the derivation site asks.
const OWNER = 'owner@walled.example';
const withOwnerEnv = async (value: string | undefined, fn: () => Promise<void>) => {
const prev = process.env.OS_PLATFORM_OWNER_EMAIL;
if (value === undefined) delete process.env.OS_PLATFORM_OWNER_EMAIL;
else process.env.OS_PLATFORM_OWNER_EMAIL = value;
try { await fn(); } finally {
if (prev === undefined) delete process.env.OS_PLATFORM_OWNER_EMAIL;
else process.env.OS_PLATFORM_OWNER_EMAIL = prev;
}
};

it('no grant row + declared VERIFIED owner ⇒ the owner gets the default org', async () =>
withOwnerEnv(OWNER, async () => {
const ql = makeQl({
sys_user_permission_set: [],
sys_user: [
{ id: 'u_other', email: 'bystander@walled.example', email_verified: true, created_at: '2026-01-01' },
{ id: 'u_owner', email: OWNER, email_verified: true, created_at: '2026-01-02' },
],
});
const res = await ensureDefaultOrganization(ql);
expect(res.defaultOrgCreated).toBe(true);
expect(res.memberCreated).toBe(true);
expect(ql.tables.sys_member[0]).toMatchObject({ user_id: 'u_owner', role: 'owner' });
}));

it('an UNVERIFIED declared owner stays no_admin — fail closed, the #11343 allow-list holds', async () =>
withOwnerEnv(OWNER, async () => {
const ql = makeQl({
sys_user_permission_set: [],
sys_user: [{ id: 'u_owner', email: OWNER, email_verified: false, created_at: '2026-01-02' }],
});
const res = await ensureDefaultOrganization(ql);
expect(res.defaultOrgCreated).toBe(false);
expect(res.reason).toBe('no_admin');
expect(ql.tables.sys_member).toEqual([]);
}));

it('no declared owner at all stays no_admin — nobody is invented', async () =>
withOwnerEnv(undefined, async () => {
const ql = makeQl({
sys_user_permission_set: [],
sys_user: [{ id: 'u_owner', email: OWNER, email_verified: true, created_at: '2026-01-02' }],
});
const res = await ensureDefaultOrganization(ql);
expect(res.defaultOrgCreated).toBe(false);
expect(res.reason).toBe('no_admin');
}));

it('a grant row still WINS over the config fallback — the historical spelling stays primary', async () =>
withOwnerEnv(OWNER, async () => {
const ql = makeQl({
sys_user: [{ id: 'u_owner', email: OWNER, email_verified: true, created_at: '2026-01-02' }],
});
const res = await ensureDefaultOrganization(ql);
expect(res.defaultOrgCreated).toBe(true);
// makeQl's default grant row names u1 — that row, not the config owner.
expect(ql.tables.sys_member[0]).toMatchObject({ user_id: 'u1', role: 'owner' });
}));
});

describe('ensureDefaultOrganization (plugin-auth home)', () => {
it('creates the default org and binds the admin as owner', async () => {
const ql = makeQl();
Expand Down
58 changes: 38 additions & 20 deletions packages/plugins/plugin-auth/src/ensure-default-organization.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -85,6 +85,9 @@ interface BootstrapLogger {
* tests — survive it perfectly, which is why no suite would catch it. The
* property-access call form below keeps the receiver.
*/
import { resolvePlatformAdminEmails, isConfiguredPlatformAdminEmail } from '@objectstack/core';
import { isEmailVerifiedUserRow } from '@objectstack/types';

function logDurabilityFailure(
logger: BootstrapLogger | undefined,
message: string,
Expand DownExpand Up@@ -164,29 +167,44 @@ export async function ensureDefaultOrganization(
return { defaultOrgCreated: false, memberCreated: false, reason: 'no_admin' };
}

// 1. Find the platform admin permission-set id.
const adminPs = await tryFind(ql, 'sys_permission_set', { name: 'admin_full_access' }, 1);
if (adminPs.length === 0 || !adminPs[0].id) {
return { defaultOrgCreated: false, memberCreated: false, reason: 'no_admin' };
}
const adminPsId = adminPs[0].id;

// 2. Find the platform admin user (oldest cross-tenant grant).
const adminGrants = await tryFind(
ql,
'sys_user_permission_set',
{ permission_set_id: adminPsId, organization_id: null },
50,
);
if (adminGrants.length === 0) {
return { defaultOrgCreated: false, memberCreated: false, reason: 'no_admin' };
}
const sortedGrants = [...adminGrants].sort((a, b) => {
const oldestFirst = (a: any, b: any) => {
const ta = a.created_at ? new Date(a.created_at).getTime() : 0;
const tb = b.created_at ? new Date(b.created_at).getTime() : 0;
return ta - tb;
});
const adminUserId: string | undefined = sortedGrants[0]?.user_id;
};

// 1-2. Resolve the platform admin. The cross-tenant grant row is the
// historical spelling and still the primary answer where it exists
// (`single` posture first-user promotion, Choice 4A; legacy walled
// grants). Since #13514 (L4) a WALLED bootstrap mints no row at all —
// standing is config-derived at the authorization derivation site — so a
// missing row is no longer a verdict: fall back to the DECLARED VERIFIED
// OWNER, resolved with the same public predicates the derivation site
// asks (`resolvePlatformAdminEmails` + row-side membership + the #11343
// verified-email allow-list), oldest wins — the bootstrap's own tiebreak.
// Without this fallback the walled default-org bootstrap dead-ends on
// `no_admin` forever, which is how cloud's EE guided-path suite caught it.
let adminUserId: string | undefined;
const adminPs = await tryFind(ql, 'sys_permission_set', { name: 'admin_full_access' }, 1);
if (adminPs.length > 0 && adminPs[0].id) {
const adminGrants = await tryFind(
ql,
'sys_user_permission_set',
{ permission_set_id: adminPs[0].id, organization_id: null },
50,
);
adminUserId = [...adminGrants].sort(oldestFirst)[0]?.user_id;
}
if (!adminUserId) {
const config = resolvePlatformAdminEmails();
if (config.emails.length > 0) {
const users = await tryFind(ql, 'sys_user', {}, 50);
const owners = users
.filter((u: any) => isConfiguredPlatformAdminEmail(u?.email, config) && isEmailVerifiedUserRow(u))
.sort(oldestFirst);
adminUserId = owners[0]?.id;
}
}
if (!adminUserId) {
return { defaultOrgCreated: false, memberCreated: false, reason: 'no_admin' };
}
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' fix(plugin-auth): ensureDefaultOrganization resolves the L4 config-derived owner when no grant row exists (#13514 follow-through) by hotlong · Pull Request #13708 · objectstack-ai/objectstack · GitHub
Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions .changeset/d1-config-derived-owner.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
---
'@objectstack/plugin-auth': patch
---

`ensureDefaultOrganization` resolves the platform admin through the L4 config-derived standing when no cross-tenant grant row exists (#13514 follow-through): the walled bootstrap mints no `sys_user_permission_set` row any more, so the ADR-0081 D1 default-org bootstrap dead-ended on `no_admin` forever on walled deployments — the enterprise organizations package invokes this same helper there. The fallback asks the same public predicates the derivation site asks (`resolvePlatformAdminEmails` + `isConfiguredPlatformAdminEmail` + the #11343 verified-email allow-list), oldest verified owner wins, and the grant row stays primary where it exists.
Original file line numberDiff line numberDiff line change
Expand Up@@ -36,6 +36,71 @@ function makeQl(seed: Partial<Record<string, Row[]>> = {}) {
};
}

describe('the L4 config-derived owner fallback (#13514 follow-through)', () => {
// Under a walled posture the bootstrap mints NO grant row, so the grant
// lookup answers nothing — the declared VERIFIED owner must be the admin,
// resolved with the same public predicates the derivation site asks.
const OWNER = 'owner@walled.example';
const withOwnerEnv = async (value: string | undefined, fn: () => Promise<void>) => {
const prev = process.env.OS_PLATFORM_OWNER_EMAIL;
if (value === undefined) delete process.env.OS_PLATFORM_OWNER_EMAIL;
else process.env.OS_PLATFORM_OWNER_EMAIL = value;
try { await fn(); } finally {
if (prev === undefined) delete process.env.OS_PLATFORM_OWNER_EMAIL;
else process.env.OS_PLATFORM_OWNER_EMAIL = prev;
}
};

it('no grant row + declared VERIFIED owner ⇒ the owner gets the default org', async () =>
withOwnerEnv(OWNER, async () => {
const ql = makeQl({
sys_user_permission_set: [],
sys_user: [
{ id: 'u_other', email: 'bystander@walled.example', email_verified: true, created_at: '2026-01-01' },
{ id: 'u_owner', email: OWNER, email_verified: true, created_at: '2026-01-02' },
],
});
const res = await ensureDefaultOrganization(ql);
expect(res.defaultOrgCreated).toBe(true);
expect(res.memberCreated).toBe(true);
expect(ql.tables.sys_member[0]).toMatchObject({ user_id: 'u_owner', role: 'owner' });
}));

it('an UNVERIFIED declared owner stays no_admin — fail closed, the #11343 allow-list holds', async () =>
withOwnerEnv(OWNER, async () => {
const ql = makeQl({
sys_user_permission_set: [],
sys_user: [{ id: 'u_owner', email: OWNER, email_verified: false, created_at: '2026-01-02' }],
});
const res = await ensureDefaultOrganization(ql);
expect(res.defaultOrgCreated).toBe(false);
expect(res.reason).toBe('no_admin');
expect(ql.tables.sys_member).toEqual([]);
}));

it('no declared owner at all stays no_admin — nobody is invented', async () =>
withOwnerEnv(undefined, async () => {
const ql = makeQl({
sys_user_permission_set: [],
sys_user: [{ id: 'u_owner', email: OWNER, email_verified: true, created_at: '2026-01-02' }],
});
const res = await ensureDefaultOrganization(ql);
expect(res.defaultOrgCreated).toBe(false);
expect(res.reason).toBe('no_admin');
}));

it('a grant row still WINS over the config fallback — the historical spelling stays primary', async () =>
withOwnerEnv(OWNER, async () => {
const ql = makeQl({
sys_user: [{ id: 'u_owner', email: OWNER, email_verified: true, created_at: '2026-01-02' }],
});
const res = await ensureDefaultOrganization(ql);
expect(res.defaultOrgCreated).toBe(true);
// makeQl's default grant row names u1 — that row, not the config owner.
expect(ql.tables.sys_member[0]).toMatchObject({ user_id: 'u1', role: 'owner' });
}));
});

describe('ensureDefaultOrganization (plugin-auth home)', () => {
it('creates the default org and binds the admin as owner', async () => {
const ql = makeQl();
Expand Down
58 changes: 38 additions & 20 deletions packages/plugins/plugin-auth/src/ensure-default-organization.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -85,6 +85,9 @@ interface BootstrapLogger {
* tests — survive it perfectly, which is why no suite would catch it. The
* property-access call form below keeps the receiver.
*/
import { resolvePlatformAdminEmails, isConfiguredPlatformAdminEmail } from '@objectstack/core';
import { isEmailVerifiedUserRow } from '@objectstack/types';

function logDurabilityFailure(
logger: BootstrapLogger | undefined,
message: string,
Expand DownExpand Up@@ -164,29 +167,44 @@ export async function ensureDefaultOrganization(
return { defaultOrgCreated: false, memberCreated: false, reason: 'no_admin' };
}

// 1. Find the platform admin permission-set id.
const adminPs = await tryFind(ql, 'sys_permission_set', { name: 'admin_full_access' }, 1);
if (adminPs.length === 0 || !adminPs[0].id) {
return { defaultOrgCreated: false, memberCreated: false, reason: 'no_admin' };
}
const adminPsId = adminPs[0].id;

// 2. Find the platform admin user (oldest cross-tenant grant).
const adminGrants = await tryFind(
ql,
'sys_user_permission_set',
{ permission_set_id: adminPsId, organization_id: null },
50,
);
if (adminGrants.length === 0) {
return { defaultOrgCreated: false, memberCreated: false, reason: 'no_admin' };
}
const sortedGrants = [...adminGrants].sort((a, b) => {
const oldestFirst = (a: any, b: any) => {
const ta = a.created_at ? new Date(a.created_at).getTime() : 0;
const tb = b.created_at ? new Date(b.created_at).getTime() : 0;
return ta - tb;
});
const adminUserId: string | undefined = sortedGrants[0]?.user_id;
};

// 1-2. Resolve the platform admin. The cross-tenant grant row is the
// historical spelling and still the primary answer where it exists
// (`single` posture first-user promotion, Choice 4A; legacy walled
// grants). Since #13514 (L4) a WALLED bootstrap mints no row at all —
// standing is config-derived at the authorization derivation site — so a
// missing row is no longer a verdict: fall back to the DECLARED VERIFIED
// OWNER, resolved with the same public predicates the derivation site
// asks (`resolvePlatformAdminEmails` + row-side membership + the #11343
// verified-email allow-list), oldest wins — the bootstrap's own tiebreak.
// Without this fallback the walled default-org bootstrap dead-ends on
// `no_admin` forever, which is how cloud's EE guided-path suite caught it.
let adminUserId: string | undefined;
const adminPs = await tryFind(ql, 'sys_permission_set', { name: 'admin_full_access' }, 1);
if (adminPs.length > 0 && adminPs[0].id) {
const adminGrants = await tryFind(
ql,
'sys_user_permission_set',
{ permission_set_id: adminPs[0].id, organization_id: null },
50,
);
adminUserId = [...adminGrants].sort(oldestFirst)[0]?.user_id;
}
if (!adminUserId) {
const config = resolvePlatformAdminEmails();
if (config.emails.length > 0) {
const users = await tryFind(ql, 'sys_user', {}, 50);
const owners = users
.filter((u: any) => isConfiguredPlatformAdminEmail(u?.email, config) && isEmailVerifiedUserRow(u))
.sort(oldestFirst);
adminUserId = owners[0]?.id;
}
}
if (!adminUserId) {
return { defaultOrgCreated: false, memberCreated: false, reason: 'no_admin' };
}
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(plugin-auth): ensureDefaultOrganization resolves the L4 config-derived owner when no grant row exists (#13514 follow-through) by hotlong · Pull Request #13708 · objectstack-ai/objectstack · GitHub
Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions .changeset/d1-config-derived-owner.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
---
'@objectstack/plugin-auth': patch
---

`ensureDefaultOrganization` resolves the platform admin through the L4 config-derived standing when no cross-tenant grant row exists (#13514 follow-through): the walled bootstrap mints no `sys_user_permission_set` row any more, so the ADR-0081 D1 default-org bootstrap dead-ended on `no_admin` forever on walled deployments — the enterprise organizations package invokes this same helper there. The fallback asks the same public predicates the derivation site asks (`resolvePlatformAdminEmails` + `isConfiguredPlatformAdminEmail` + the #11343 verified-email allow-list), oldest verified owner wins, and the grant row stays primary where it exists.
Original file line numberDiff line numberDiff line change
Expand Up@@ -36,6 +36,71 @@ function makeQl(seed: Partial<Record<string, Row[]>> = {}) {
};
}

describe('the L4 config-derived owner fallback (#13514 follow-through)', () => {
// Under a walled posture the bootstrap mints NO grant row, so the grant
// lookup answers nothing — the declared VERIFIED owner must be the admin,
// resolved with the same public predicates the derivation site asks.
const OWNER = 'owner@walled.example';
const withOwnerEnv = async (value: string | undefined, fn: () => Promise<void>) => {
const prev = process.env.OS_PLATFORM_OWNER_EMAIL;
if (value === undefined) delete process.env.OS_PLATFORM_OWNER_EMAIL;
else process.env.OS_PLATFORM_OWNER_EMAIL = value;
try { await fn(); } finally {
if (prev === undefined) delete process.env.OS_PLATFORM_OWNER_EMAIL;
else process.env.OS_PLATFORM_OWNER_EMAIL = prev;
}
};

it('no grant row + declared VERIFIED owner ⇒ the owner gets the default org', async () =>
withOwnerEnv(OWNER, async () => {
const ql = makeQl({
sys_user_permission_set: [],
sys_user: [
{ id: 'u_other', email: 'bystander@walled.example', email_verified: true, created_at: '2026-01-01' },
{ id: 'u_owner', email: OWNER, email_verified: true, created_at: '2026-01-02' },
],
});
const res = await ensureDefaultOrganization(ql);
expect(res.defaultOrgCreated).toBe(true);
expect(res.memberCreated).toBe(true);
expect(ql.tables.sys_member[0]).toMatchObject({ user_id: 'u_owner', role: 'owner' });
}));

it('an UNVERIFIED declared owner stays no_admin — fail closed, the #11343 allow-list holds', async () =>
withOwnerEnv(OWNER, async () => {
const ql = makeQl({
sys_user_permission_set: [],
sys_user: [{ id: 'u_owner', email: OWNER, email_verified: false, created_at: '2026-01-02' }],
});
const res = await ensureDefaultOrganization(ql);
expect(res.defaultOrgCreated).toBe(false);
expect(res.reason).toBe('no_admin');
expect(ql.tables.sys_member).toEqual([]);
}));

it('no declared owner at all stays no_admin — nobody is invented', async () =>
withOwnerEnv(undefined, async () => {
const ql = makeQl({
sys_user_permission_set: [],
sys_user: [{ id: 'u_owner', email: OWNER, email_verified: true, created_at: '2026-01-02' }],
});
const res = await ensureDefaultOrganization(ql);
expect(res.defaultOrgCreated).toBe(false);
expect(res.reason).toBe('no_admin');
}));

it('a grant row still WINS over the config fallback — the historical spelling stays primary', async () =>
withOwnerEnv(OWNER, async () => {
const ql = makeQl({
sys_user: [{ id: 'u_owner', email: OWNER, email_verified: true, created_at: '2026-01-02' }],
});
const res = await ensureDefaultOrganization(ql);
expect(res.defaultOrgCreated).toBe(true);
// makeQl's default grant row names u1 — that row, not the config owner.
expect(ql.tables.sys_member[0]).toMatchObject({ user_id: 'u1', role: 'owner' });
}));
});

describe('ensureDefaultOrganization (plugin-auth home)', () => {
it('creates the default org and binds the admin as owner', async () => {
const ql = makeQl();
Expand Down
58 changes: 38 additions & 20 deletions packages/plugins/plugin-auth/src/ensure-default-organization.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -85,6 +85,9 @@ interface BootstrapLogger {
* tests — survive it perfectly, which is why no suite would catch it. The
* property-access call form below keeps the receiver.
*/
import { resolvePlatformAdminEmails, isConfiguredPlatformAdminEmail } from '@objectstack/core';
import { isEmailVerifiedUserRow } from '@objectstack/types';

function logDurabilityFailure(
logger: BootstrapLogger | undefined,
message: string,
Expand DownExpand Up@@ -164,29 +167,44 @@ export async function ensureDefaultOrganization(
return { defaultOrgCreated: false, memberCreated: false, reason: 'no_admin' };
}

// 1. Find the platform admin permission-set id.
const adminPs = await tryFind(ql, 'sys_permission_set', { name: 'admin_full_access' }, 1);
if (adminPs.length === 0 || !adminPs[0].id) {
return { defaultOrgCreated: false, memberCreated: false, reason: 'no_admin' };
}
const adminPsId = adminPs[0].id;

// 2. Find the platform admin user (oldest cross-tenant grant).
const adminGrants = await tryFind(
ql,
'sys_user_permission_set',
{ permission_set_id: adminPsId, organization_id: null },
50,
);
if (adminGrants.length === 0) {
return { defaultOrgCreated: false, memberCreated: false, reason: 'no_admin' };
}
const sortedGrants = [...adminGrants].sort((a, b) => {
const oldestFirst = (a: any, b: any) => {
const ta = a.created_at ? new Date(a.created_at).getTime() : 0;
const tb = b.created_at ? new Date(b.created_at).getTime() : 0;
return ta - tb;
});
const adminUserId: string | undefined = sortedGrants[0]?.user_id;
};

// 1-2. Resolve the platform admin. The cross-tenant grant row is the
// historical spelling and still the primary answer where it exists
// (`single` posture first-user promotion, Choice 4A; legacy walled
// grants). Since #13514 (L4) a WALLED bootstrap mints no row at all —
// standing is config-derived at the authorization derivation site — so a
// missing row is no longer a verdict: fall back to the DECLARED VERIFIED
// OWNER, resolved with the same public predicates the derivation site
// asks (`resolvePlatformAdminEmails` + row-side membership + the #11343
// verified-email allow-list), oldest wins — the bootstrap's own tiebreak.
// Without this fallback the walled default-org bootstrap dead-ends on
// `no_admin` forever, which is how cloud's EE guided-path suite caught it.
let adminUserId: string | undefined;
const adminPs = await tryFind(ql, 'sys_permission_set', { name: 'admin_full_access' }, 1);
if (adminPs.length > 0 && adminPs[0].id) {
const adminGrants = await tryFind(
ql,
'sys_user_permission_set',
{ permission_set_id: adminPs[0].id, organization_id: null },
50,
);
adminUserId = [...adminGrants].sort(oldestFirst)[0]?.user_id;
}
if (!adminUserId) {
const config = resolvePlatformAdminEmails();
if (config.emails.length > 0) {
const users = await tryFind(ql, 'sys_user', {}, 50);
const owners = users
.filter((u: any) => isConfiguredPlatformAdminEmail(u?.email, config) && isEmailVerifiedUserRow(u))
.sort(oldestFirst);
adminUserId = owners[0]?.id;
}
}
if (!adminUserId) {
return { defaultOrgCreated: false, memberCreated: false, reason: 'no_admin' };
}
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(plugin-auth): ensureDefaultOrganization resolves the L4 config-derived owner when no grant row exists (#13514 follow-through) by hotlong · Pull Request #13708 · objectstack-ai/objectstack · GitHub
Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions .changeset/d1-config-derived-owner.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
---
'@objectstack/plugin-auth': patch
---

`ensureDefaultOrganization` resolves the platform admin through the L4 config-derived standing when no cross-tenant grant row exists (#13514 follow-through): the walled bootstrap mints no `sys_user_permission_set` row any more, so the ADR-0081 D1 default-org bootstrap dead-ended on `no_admin` forever on walled deployments — the enterprise organizations package invokes this same helper there. The fallback asks the same public predicates the derivation site asks (`resolvePlatformAdminEmails` + `isConfiguredPlatformAdminEmail` + the #11343 verified-email allow-list), oldest verified owner wins, and the grant row stays primary where it exists.
Original file line numberDiff line numberDiff line change
Expand Up@@ -36,6 +36,71 @@ function makeQl(seed: Partial<Record<string, Row[]>> = {}) {
};
}

describe('the L4 config-derived owner fallback (#13514 follow-through)', () => {
// Under a walled posture the bootstrap mints NO grant row, so the grant
// lookup answers nothing — the declared VERIFIED owner must be the admin,
// resolved with the same public predicates the derivation site asks.
const OWNER = 'owner@walled.example';
const withOwnerEnv = async (value: string | undefined, fn: () => Promise<void>) => {
const prev = process.env.OS_PLATFORM_OWNER_EMAIL;
if (value === undefined) delete process.env.OS_PLATFORM_OWNER_EMAIL;
else process.env.OS_PLATFORM_OWNER_EMAIL = value;
try { await fn(); } finally {
if (prev === undefined) delete process.env.OS_PLATFORM_OWNER_EMAIL;
else process.env.OS_PLATFORM_OWNER_EMAIL = prev;
}
};

it('no grant row + declared VERIFIED owner ⇒ the owner gets the default org', async () =>
withOwnerEnv(OWNER, async () => {
const ql = makeQl({
sys_user_permission_set: [],
sys_user: [
{ id: 'u_other', email: 'bystander@walled.example', email_verified: true, created_at: '2026-01-01' },
{ id: 'u_owner', email: OWNER, email_verified: true, created_at: '2026-01-02' },
],
});
const res = await ensureDefaultOrganization(ql);
expect(res.defaultOrgCreated).toBe(true);
expect(res.memberCreated).toBe(true);
expect(ql.tables.sys_member[0]).toMatchObject({ user_id: 'u_owner', role: 'owner' });
}));

it('an UNVERIFIED declared owner stays no_admin — fail closed, the #11343 allow-list holds', async () =>
withOwnerEnv(OWNER, async () => {
const ql = makeQl({
sys_user_permission_set: [],
sys_user: [{ id: 'u_owner', email: OWNER, email_verified: false, created_at: '2026-01-02' }],
});
const res = await ensureDefaultOrganization(ql);
expect(res.defaultOrgCreated).toBe(false);
expect(res.reason).toBe('no_admin');
expect(ql.tables.sys_member).toEqual([]);
}));

it('no declared owner at all stays no_admin — nobody is invented', async () =>
withOwnerEnv(undefined, async () => {
const ql = makeQl({
sys_user_permission_set: [],
sys_user: [{ id: 'u_owner', email: OWNER, email_verified: true, created_at: '2026-01-02' }],
});
const res = await ensureDefaultOrganization(ql);
expect(res.defaultOrgCreated).toBe(false);
expect(res.reason).toBe('no_admin');
}));

it('a grant row still WINS over the config fallback — the historical spelling stays primary', async () =>
withOwnerEnv(OWNER, async () => {
const ql = makeQl({
sys_user: [{ id: 'u_owner', email: OWNER, email_verified: true, created_at: '2026-01-02' }],
});
const res = await ensureDefaultOrganization(ql);
expect(res.defaultOrgCreated).toBe(true);
// makeQl's default grant row names u1 — that row, not the config owner.
expect(ql.tables.sys_member[0]).toMatchObject({ user_id: 'u1', role: 'owner' });
}));
});

describe('ensureDefaultOrganization (plugin-auth home)', () => {
it('creates the default org and binds the admin as owner', async () => {
const ql = makeQl();
Expand Down
58 changes: 38 additions & 20 deletions packages/plugins/plugin-auth/src/ensure-default-organization.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -85,6 +85,9 @@ interface BootstrapLogger {
* tests — survive it perfectly, which is why no suite would catch it. The
* property-access call form below keeps the receiver.
*/
import { resolvePlatformAdminEmails, isConfiguredPlatformAdminEmail } from '@objectstack/core';
import { isEmailVerifiedUserRow } from '@objectstack/types';

function logDurabilityFailure(
logger: BootstrapLogger | undefined,
message: string,
Expand DownExpand Up@@ -164,29 +167,44 @@ export async function ensureDefaultOrganization(
return { defaultOrgCreated: false, memberCreated: false, reason: 'no_admin' };
}

// 1. Find the platform admin permission-set id.
const adminPs = await tryFind(ql, 'sys_permission_set', { name: 'admin_full_access' }, 1);
if (adminPs.length === 0 || !adminPs[0].id) {
return { defaultOrgCreated: false, memberCreated: false, reason: 'no_admin' };
}
const adminPsId = adminPs[0].id;

// 2. Find the platform admin user (oldest cross-tenant grant).
const adminGrants = await tryFind(
ql,
'sys_user_permission_set',
{ permission_set_id: adminPsId, organization_id: null },
50,
);
if (adminGrants.length === 0) {
return { defaultOrgCreated: false, memberCreated: false, reason: 'no_admin' };
}
const sortedGrants = [...adminGrants].sort((a, b) => {
const oldestFirst = (a: any, b: any) => {
const ta = a.created_at ? new Date(a.created_at).getTime() : 0;
const tb = b.created_at ? new Date(b.created_at).getTime() : 0;
return ta - tb;
});
const adminUserId: string | undefined = sortedGrants[0]?.user_id;
};

// 1-2. Resolve the platform admin. The cross-tenant grant row is the
// historical spelling and still the primary answer where it exists
// (`single` posture first-user promotion, Choice 4A; legacy walled
// grants). Since #13514 (L4) a WALLED bootstrap mints no row at all —
// standing is config-derived at the authorization derivation site — so a
// missing row is no longer a verdict: fall back to the DECLARED VERIFIED
// OWNER, resolved with the same public predicates the derivation site
// asks (`resolvePlatformAdminEmails` + row-side membership + the #11343
// verified-email allow-list), oldest wins — the bootstrap's own tiebreak.
// Without this fallback the walled default-org bootstrap dead-ends on
// `no_admin` forever, which is how cloud's EE guided-path suite caught it.
let adminUserId: string | undefined;
const adminPs = await tryFind(ql, 'sys_permission_set', { name: 'admin_full_access' }, 1);
if (adminPs.length > 0 && adminPs[0].id) {
const adminGrants = await tryFind(
ql,
'sys_user_permission_set',
{ permission_set_id: adminPs[0].id, organization_id: null },
50,
);
adminUserId = [...adminGrants].sort(oldestFirst)[0]?.user_id;
}
if (!adminUserId) {
const config = resolvePlatformAdminEmails();
if (config.emails.length > 0) {
const users = await tryFind(ql, 'sys_user', {}, 50);
const owners = users
.filter((u: any) => isConfiguredPlatformAdminEmail(u?.email, config) && isEmailVerifiedUserRow(u))
.sort(oldestFirst);
adminUserId = owners[0]?.id;
}
}
if (!adminUserId) {
return { defaultOrgCreated: false, memberCreated: false, reason: 'no_admin' };
}
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); fix(plugin-auth): ensureDefaultOrganization resolves the L4 config-derived owner when no grant row exists (#13514 follow-through) by hotlong · Pull Request #13708 · objectstack-ai/objectstack · GitHub
Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions .changeset/d1-config-derived-owner.md
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
---
'@objectstack/plugin-auth': patch
---

`ensureDefaultOrganization` resolves the platform admin through the L4 config-derived standing when no cross-tenant grant row exists (#13514 follow-through): the walled bootstrap mints no `sys_user_permission_set` row any more, so the ADR-0081 D1 default-org bootstrap dead-ended on `no_admin` forever on walled deployments — the enterprise organizations package invokes this same helper there. The fallback asks the same public predicates the derivation site asks (`resolvePlatformAdminEmails` + `isConfiguredPlatformAdminEmail` + the #11343 verified-email allow-list), oldest verified owner wins, and the grant row stays primary where it exists.
Original file line numberDiff line numberDiff line change
Expand Up@@ -36,6 +36,71 @@ function makeQl(seed: Partial<Record<string, Row[]>> = {}) {
};
}

describe('the L4 config-derived owner fallback (#13514 follow-through)', () => {
// Under a walled posture the bootstrap mints NO grant row, so the grant
// lookup answers nothing — the declared VERIFIED owner must be the admin,
// resolved with the same public predicates the derivation site asks.
const OWNER = 'owner@walled.example';
const withOwnerEnv = async (value: string | undefined, fn: () => Promise<void>) => {
const prev = process.env.OS_PLATFORM_OWNER_EMAIL;
if (value === undefined) delete process.env.OS_PLATFORM_OWNER_EMAIL;
else process.env.OS_PLATFORM_OWNER_EMAIL = value;
try { await fn(); } finally {
if (prev === undefined) delete process.env.OS_PLATFORM_OWNER_EMAIL;
else process.env.OS_PLATFORM_OWNER_EMAIL = prev;
}
};

it('no grant row + declared VERIFIED owner ⇒ the owner gets the default org', async () =>
withOwnerEnv(OWNER, async () => {
const ql = makeQl({
sys_user_permission_set: [],
sys_user: [
{ id: 'u_other', email: 'bystander@walled.example', email_verified: true, created_at: '2026-01-01' },
{ id: 'u_owner', email: OWNER, email_verified: true, created_at: '2026-01-02' },
],
});
const res = await ensureDefaultOrganization(ql);
expect(res.defaultOrgCreated).toBe(true);
expect(res.memberCreated).toBe(true);
expect(ql.tables.sys_member[0]).toMatchObject({ user_id: 'u_owner', role: 'owner' });
}));

it('an UNVERIFIED declared owner stays no_admin — fail closed, the #11343 allow-list holds', async () =>
withOwnerEnv(OWNER, async () => {
const ql = makeQl({
sys_user_permission_set: [],
sys_user: [{ id: 'u_owner', email: OWNER, email_verified: false, created_at: '2026-01-02' }],
});
const res = await ensureDefaultOrganization(ql);
expect(res.defaultOrgCreated).toBe(false);
expect(res.reason).toBe('no_admin');
expect(ql.tables.sys_member).toEqual([]);
}));

it('no declared owner at all stays no_admin — nobody is invented', async () =>
withOwnerEnv(undefined, async () => {
const ql = makeQl({
sys_user_permission_set: [],
sys_user: [{ id: 'u_owner', email: OWNER, email_verified: true, created_at: '2026-01-02' }],
});
const res = await ensureDefaultOrganization(ql);
expect(res.defaultOrgCreated).toBe(false);
expect(res.reason).toBe('no_admin');
}));

it('a grant row still WINS over the config fallback — the historical spelling stays primary', async () =>
withOwnerEnv(OWNER, async () => {
const ql = makeQl({
sys_user: [{ id: 'u_owner', email: OWNER, email_verified: true, created_at: '2026-01-02' }],
});
const res = await ensureDefaultOrganization(ql);
expect(res.defaultOrgCreated).toBe(true);
// makeQl's default grant row names u1 — that row, not the config owner.
expect(ql.tables.sys_member[0]).toMatchObject({ user_id: 'u1', role: 'owner' });
}));
});

describe('ensureDefaultOrganization (plugin-auth home)', () => {
it('creates the default org and binds the admin as owner', async () => {
const ql = makeQl();
Expand Down
58 changes: 38 additions & 20 deletions packages/plugins/plugin-auth/src/ensure-default-organization.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -85,6 +85,9 @@ interface BootstrapLogger {
* tests — survive it perfectly, which is why no suite would catch it. The
* property-access call form below keeps the receiver.
*/
import { resolvePlatformAdminEmails, isConfiguredPlatformAdminEmail } from '@objectstack/core';
import { isEmailVerifiedUserRow } from '@objectstack/types';

function logDurabilityFailure(
logger: BootstrapLogger | undefined,
message: string,
Expand DownExpand Up@@ -164,29 +167,44 @@ export async function ensureDefaultOrganization(
return { defaultOrgCreated: false, memberCreated: false, reason: 'no_admin' };
}

// 1. Find the platform admin permission-set id.
const adminPs = await tryFind(ql, 'sys_permission_set', { name: 'admin_full_access' }, 1);
if (adminPs.length === 0 || !adminPs[0].id) {
return { defaultOrgCreated: false, memberCreated: false, reason: 'no_admin' };
}
const adminPsId = adminPs[0].id;

// 2. Find the platform admin user (oldest cross-tenant grant).
const adminGrants = await tryFind(
ql,
'sys_user_permission_set',
{ permission_set_id: adminPsId, organization_id: null },
50,
);
if (adminGrants.length === 0) {
return { defaultOrgCreated: false, memberCreated: false, reason: 'no_admin' };
}
const sortedGrants = [...adminGrants].sort((a, b) => {
const oldestFirst = (a: any, b: any) => {
const ta = a.created_at ? new Date(a.created_at).getTime() : 0;
const tb = b.created_at ? new Date(b.created_at).getTime() : 0;
return ta - tb;
});
const adminUserId: string | undefined = sortedGrants[0]?.user_id;
};

// 1-2. Resolve the platform admin. The cross-tenant grant row is the
// historical spelling and still the primary answer where it exists
// (`single` posture first-user promotion, Choice 4A; legacy walled
// grants). Since #13514 (L4) a WALLED bootstrap mints no row at all —
// standing is config-derived at the authorization derivation site — so a
// missing row is no longer a verdict: fall back to the DECLARED VERIFIED
// OWNER, resolved with the same public predicates the derivation site
// asks (`resolvePlatformAdminEmails` + row-side membership + the #11343
// verified-email allow-list), oldest wins — the bootstrap's own tiebreak.
// Without this fallback the walled default-org bootstrap dead-ends on
// `no_admin` forever, which is how cloud's EE guided-path suite caught it.
let adminUserId: string | undefined;
const adminPs = await tryFind(ql, 'sys_permission_set', { name: 'admin_full_access' }, 1);
if (adminPs.length > 0 && adminPs[0].id) {
const adminGrants = await tryFind(
ql,
'sys_user_permission_set',
{ permission_set_id: adminPs[0].id, organization_id: null },
50,
);
adminUserId = [...adminGrants].sort(oldestFirst)[0]?.user_id;
}
if (!adminUserId) {
const config = resolvePlatformAdminEmails();
if (config.emails.length > 0) {
const users = await tryFind(ql, 'sys_user', {}, 50);
const owners = users
.filter((u: any) => isConfiguredPlatformAdminEmail(u?.email, config) && isEmailVerifiedUserRow(u))
.sort(oldestFirst);
adminUserId = owners[0]?.id;
}
}
if (!adminUserId) {
return { defaultOrgCreated: false, memberCreated: false, reason: 'no_admin' };
}
Expand Down
Loading