Skip to content

fix(studio): scope Access matrix by { packageId } + slice-merge on save (ADR-0086 P0) - #2222

Merged
os-zhuang merged 2 commits into
mainfrom
claude/access-matrix-packageid-scope-pbndje
Jul 4, 2026
Merged

fix(studio): scope Access matrix by { packageId } + slice-merge on save (ADR-0086 P0)#2222
os-zhuang merged 2 commits into
mainfrom
claude/access-matrix-packageid-scope-pbndje

Conversation

@os-zhuang

@os-zhuangos-zhuang commented Jul 4, 2026

Copy link
Copy Markdown
Contributor

Closes#2221.

Problem

The Access pillar (#2196) embedded the permission matrix at environment scope, producing two real security/safety issues:

  1. "84-object leak" — opening the Access panel in a package listed the permission matrix for every object in the environment, not just the ones the package declares. An admin editing package A could see (and mis-edit) authorization for objects belonging to other packages.
  2. Cross-package data loss — Save overwrote the whole permission set, silently clobbering authorization rows other packages had contributed.

Per ADR-0086 (framework #2559) — this PR executes, it does not re-decide.

What changed

Opened inside a package, PermissionMatrixEditPage now:

  • Scopes the object list by { packageId }list('object', { packageId }), so the panel lists only the objects that package declares (the package's manifest-declared object set, discovered via the existing server-side ?package= filter).
  • Slice-merges on Save — it re-reads the record and writes back only this package's slice via mergePermissionSlice, leaving every row contributed by other packages byte-for-byte intact. The post-save refresh re-narrows to the slice too.

The Access rail also scopes to permission sets this package owns (scopePermissionSetList): environment-owned platform defaults (admin_full_access, member_default, …) are hidden once the backend tags sets with a record-level package_id (framework ADR-0086 P1, framework#2566). A mid-migration guard keeps the rail populated on backends that predate the P1 provenance seeding — if no set carries a package_id yet, all are shown, so the rail never collapses to empty. (Follows the coordination update on #2221.)

When PermissionMatrixEditPage is rendered without a packageId (e.g. the generic metadata-resource editor), behavior is unchanged: full object list, whole-record save.

The scope/merge logic is a pure, dependency-free helper — packages/app-shell/src/views/metadata-admin/permission-slice.ts (scopePermissionSet, mergePermissionSlice, scopePermissionSetList).

Acceptance criteria

  • Opening package A's Access panel shows only package A's declared objects (no 84-object environment list).
  • After editing + saving package A's matrix, package B's prior authorization rows are preserved byte-for-byte (write-back regression test).
  • Closed loop open → edit → save → reopen, with a cross-package slice-retention check.
  • Platform-default permission sets (no package_id) are hidden from a package's rail once provenance is tagged.
  • type-check 0 errors; existing tests do not regress (516 app-shell tests green).

Testing

  • permission-slice.test.ts — unit tests for object scoping, slice-merge (other-package rows survive as the same reference, both directions), and rail scoping incl. the mid-migration guard.
  • PermissionMatrixEditor.scope.test.tsx — component integration test that drives the real editor through load → edit (clear a package-A object) → save → reopen against a fake client that behaves like the server, asserting: only package A's objects render (b_order never appears), and the saved payload preserves package B's objects/fields rows verbatim.

Note on the browser closed-loop: the live backend that provides ?package= scoping and permission persistence lives in the framework repo, which is not present in this environment. The component integration test exercises the same load→edit→save→reopen path against a server-faithful fake client as the closest achievable substitute.

🤖 Generated with Claude Code

https://claude.ai/code/session_01QWcZRYnJXN3YXFTbm3PLg5

The Access pillar embedded the permission matrix at environment scope: it
listed every object in the environment (the "84-object leak"), and Save
overwrote the whole permission set — silently dropping authorization rows
other packages had contributed (ADR-0086 P0, upstream-blocking).
Opened inside a package, the matrix now:
- lists only the objects that package declares
(`list('object', { packageId })`), so a package's Access panel no longer
exposes unrelated objects; and
- saves via slice-merge — it re-reads the record and writes back only this
package's slice, leaving every row contributed by other packages
byte-for-byte intact.
Permission sets remain platform-level (the left rail still lists them all);
only the object matrix and its Save are package-scoped. Behavior is unchanged
when `PermissionMatrixEditPage` is rendered without a `packageId` (full object
list, whole-record save).
The scope/merge logic lives in a pure, unit-tested helper
(`metadata-admin/permission-slice.ts`). A component integration test drives the
real editor through load -> edit -> save -> reopen, asserting both the scoped
object list and byte-for-byte preservation of another package's slice.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QWcZRYnJXN3YXFTbm3PLg5
@vercel

vercelBot commented Jul 4, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
ProjectDeploymentActionsUpdated (UTC)
objectuiIgnoredIgnoredJul 4, 2026 7:44am

Request Review

@github-actionsgithub-actionsBot added documentation Improvements or additions to documentation tests labels Jul 4, 2026
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Main entry (gzip)59.5 KB350 KB
Entry fileindex-dp-qijhx.js
StatusPASS

📦 Bundle Size Report

PackageSizeGzipped
app-shell (index.js)7.51KB2.72KB
app-shell (runtime-config.js)4.72KB1.69KB
app-shell (types.js)0.01KB0.04KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)17.90KB3.67KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)4.79KB1.88KB
auth (LoginForm.js)9.55KB3.36KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.63KB2.15KB
auth (SocialSignInButtons.js)8.89KB3.61KB
auth (UserMenu.js)3.40KB1.22KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)26.07KB6.30KB
auth (createAuthenticatedFetch.js)3.93KB1.55KB
auth (index.js)1.75KB0.76KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)4.29KB0.82KB
auth (useIsWorkspaceAdmin.js)1.61KB0.85KB
collaboration (CommentThread.js)18.38KB4.49KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)3.65KB1.42KB
collaboration (PresenceProvider.js)2.42KB0.96KB
collaboration (index.js)1.25KB0.53KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)435.83KB93.60KB
core (index.js)1.65KB0.59KB
create-plugin (index.js)9.28KB2.98KB
data-objectstack (index.js)109.24KB26.96KB
fields (index.js)184.84KB45.12KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.32KB1.77KB
i18n (index.js)2.46KB0.96KB
i18n (pickLocalized.js)1.31KB0.67KB
i18n (provider.js)5.37KB1.72KB
i18n (useObjectLabel.js)21.15KB4.68KB
i18n (useSafeTranslation.js)2.68KB0.98KB
layout (index.js)36.30KB10.04KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.74KB
mobile (index.js)1.50KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)4.42KB1.27KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.71KB0.42KB
mobile (useResponsiveConfig.js)1.36KB0.63KB
mobile (useSpecGesture.js)1.77KB0.77KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)5.09KB1.84KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)3.46KB1.03KB
permissions (evaluator.js)4.00KB1.23KB
permissions (index.js)0.91KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.52KB
permissions (usePermissions.js)1.50KB0.70KB
plugin-ai (index.js)15.71KB3.79KB
plugin-calendar (index.js)45.10KB12.33KB
plugin-charts (index.js)46.11KB12.99KB
plugin-chatbot (index.js)172.75KB41.13KB
plugin-dashboard (index.js)108.28KB26.86KB
plugin-designer (index.js)213.48KB42.95KB
plugin-detail (index.js)201.40KB48.47KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)99.18KB24.14KB
plugin-gantt (index.js)136.67KB33.88KB
plugin-grid (index.js)165.48KB43.77KB
plugin-kanban (index.js)48.15KB12.94KB
plugin-list (index.js)97.89KB23.09KB
plugin-map (index.js)16.02KB4.98KB
plugin-markdown (index.js)13.65KB4.67KB
plugin-report (index.js)37.83KB9.97KB
plugin-timeline (index.js)25.37KB7.20KB
plugin-tree (index.js)8.21KB2.76KB
plugin-view (index.js)84.50KB20.37KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.55KB0.67KB
providers (UploadProvider.js)11.71KB3.53KB
providers (index.js)0.44KB0.22KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)3.19KB1.38KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)18.23KB5.97KB
react (index.js)0.76KB0.42KB
sdui-parser (codegen.js)4.09KB1.74KB
sdui-parser (index.js)2.16KB0.94KB
sdui-parser (parse.js)10.04KB2.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)4.69KB1.48KB
tenant (TenantContext.js)0.31KB0.25KB
tenant (TenantGuard.js)1.04KB0.43KB
tenant (TenantProvider.js)2.76KB0.98KB
tenant (TenantScopedQuery.js)0.77KB0.44KB
tenant (index.js)0.75KB0.38KB
tenant (resolver.js)2.64KB0.76KB
tenant (useTenant.js)0.50KB0.32KB
tenant (useTenantBranding.js)0.62KB0.39KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)0.77KB0.41KB
types (disclosure.js)0.20KB0.18KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (index.js)1.54KB0.68KB
types (layout.js)0.20KB0.18KB
types (mobile.js)0.20KB0.18KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.26KB1.96KB
types (tenant.js)0.20KB0.18KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)0.75KB0.46KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

Follow-up to the coordination update on #2221: framework ADR-0086 P1
(framework#2566) adds a record-level `package_id` / `managed_by` provenance
axis to permission sets, and platform defaults (admin_full_access,
member_default, …) are environment-owned with no package_id. Those must not
appear in a package's Access panel.
The Access pillar's left rail now filters permission sets to the ones this
package owns (`scopePermissionSetList`). A mid-migration guard keeps the rail
populated on backends that predate the P1 provenance seeding: if no set carries
a package_id yet, all are shown, so the rail never collapses to empty. Tighten
(drop the guard) once the provenance axis is guaranteed live.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QWcZRYnJXN3YXFTbm3PLg5
@github-actions

Copy link
Copy Markdown
Contributor

✅ Console Performance Budget

MetricValueBudget
Main entry (gzip)59.5 KB350 KB
Entry fileindex-QSxsQKlV.js
StatusPASS

📦 Bundle Size Report

PackageSizeGzipped
app-shell (index.js)7.51KB2.72KB
app-shell (runtime-config.js)4.72KB1.69KB
app-shell (types.js)0.01KB0.04KB
auth (AuthContext.js)0.31KB0.24KB
auth (AuthGuard.js)1.17KB0.53KB
auth (AuthProvider.js)17.90KB3.67KB
auth (AuthShell.js)3.49KB1.40KB
auth (ForgotPasswordForm.js)4.79KB1.88KB
auth (LoginForm.js)9.55KB3.36KB
auth (PreviewBanner.js)0.90KB0.50KB
auth (RegisterForm.js)6.63KB2.15KB
auth (SocialSignInButtons.js)8.89KB3.61KB
auth (UserMenu.js)3.40KB1.22KB
auth (auth-gate-events.js)1.29KB0.66KB
auth (authStyles.js)5.04KB1.72KB
auth (createAuthClient.js)26.07KB6.30KB
auth (createAuthenticatedFetch.js)3.93KB1.55KB
auth (index.js)1.75KB0.76KB
auth (types.js)0.59KB0.35KB
auth (useAuth.js)4.29KB0.82KB
auth (useIsWorkspaceAdmin.js)1.61KB0.85KB
collaboration (CommentThread.js)18.38KB4.49KB
collaboration (LiveCursors.js)3.17KB1.27KB
collaboration (PresenceAvatars.js)3.65KB1.42KB
collaboration (PresenceProvider.js)2.42KB0.96KB
collaboration (index.js)1.25KB0.53KB
collaboration (useCommentSearch.js)1.98KB0.88KB
collaboration (useConflictResolution.js)7.75KB1.86KB
collaboration (useMentionNotifications.js)1.81KB0.68KB
collaboration (usePresence.js)6.33KB1.84KB
collaboration (useRealtimeSubscription.js)7.91KB2.01KB
components (index.js)435.83KB93.60KB
core (index.js)1.65KB0.59KB
create-plugin (index.js)9.28KB2.98KB
data-objectstack (index.js)109.24KB26.96KB
fields (index.js)184.84KB45.12KB
i18n (LocalizationContext.js)1.76KB0.96KB
i18n (currency.js)1.22KB0.64KB
i18n (i18n.js)4.32KB1.77KB
i18n (index.js)2.46KB0.96KB
i18n (pickLocalized.js)1.31KB0.67KB
i18n (provider.js)5.37KB1.72KB
i18n (useObjectLabel.js)21.15KB4.68KB
i18n (useSafeTranslation.js)2.68KB0.98KB
layout (index.js)36.30KB10.04KB
mobile (MobileProvider.js)0.92KB0.49KB
mobile (ResponsiveContainer.js)0.94KB0.38KB
mobile (breakpoints.js)1.51KB0.70KB
mobile (createOfflineDataSource.js)5.61KB1.74KB
mobile (index.js)1.50KB0.62KB
mobile (offlineQueue.js)3.91KB1.35KB
mobile (pwa.js)0.97KB0.49KB
mobile (serviceWorker.js)1.48KB0.62KB
mobile (serviceWorkerSource.js)3.41KB1.48KB
mobile (useBreakpoint.js)1.54KB0.65KB
mobile (useGesture.js)4.42KB1.27KB
mobile (useOfflineSync.js)1.99KB0.72KB
mobile (usePullToRefresh.js)2.53KB0.85KB
mobile (useResponsive.js)0.71KB0.42KB
mobile (useResponsiveConfig.js)1.36KB0.63KB
mobile (useSpecGesture.js)1.77KB0.77KB
mobile (useTouchTarget.js)1.01KB0.54KB
permissions (MePermissionsProvider.js)5.09KB1.84KB
permissions (PermissionContext.js)0.31KB0.25KB
permissions (PermissionGuard.js)0.89KB0.45KB
permissions (PermissionProvider.js)3.46KB1.03KB
permissions (evaluator.js)4.00KB1.23KB
permissions (index.js)0.91KB0.41KB
permissions (store.js)0.91KB0.42KB
permissions (useFieldPermissions.js)1.28KB0.52KB
permissions (usePermissions.js)1.50KB0.70KB
plugin-ai (index.js)15.71KB3.79KB
plugin-calendar (index.js)45.10KB12.33KB
plugin-charts (index.js)46.11KB12.99KB
plugin-chatbot (index.js)172.75KB41.13KB
plugin-dashboard (index.js)108.28KB26.86KB
plugin-designer (index.js)213.48KB42.95KB
plugin-detail (index.js)201.40KB48.47KB
plugin-editor (index.js)2.46KB1.10KB
plugin-form (index.js)99.18KB24.14KB
plugin-gantt (index.js)136.67KB33.88KB
plugin-grid (index.js)165.48KB43.77KB
plugin-kanban (index.js)48.15KB12.94KB
plugin-list (index.js)97.89KB23.09KB
plugin-map (index.js)16.02KB4.98KB
plugin-markdown (index.js)13.65KB4.67KB
plugin-report (index.js)37.83KB9.97KB
plugin-timeline (index.js)25.37KB7.20KB
plugin-tree (index.js)8.21KB2.76KB
plugin-view (index.js)84.50KB20.37KB
providers (DataSourceProvider.js)0.75KB0.39KB
providers (MetadataProvider.js)1.37KB0.59KB
providers (ThemeProvider.js)1.55KB0.67KB
providers (UploadProvider.js)11.71KB3.53KB
providers (index.js)0.44KB0.22KB
providers (types.js)0.01KB0.04KB
react-runtime (index.js)3.19KB1.38KB
react (LazyPluginLoader.js)3.77KB1.33KB
react (SchemaRenderer.js)18.23KB5.97KB
react (index.js)0.76KB0.42KB
sdui-parser (codegen.js)4.09KB1.74KB
sdui-parser (index.js)2.16KB0.94KB
sdui-parser (parse.js)10.04KB2.82KB
sdui-parser (types.js)0.29KB0.24KB
sdui-parser (validate.js)4.69KB1.48KB
tenant (TenantContext.js)0.31KB0.25KB
tenant (TenantGuard.js)1.04KB0.43KB
tenant (TenantProvider.js)2.76KB0.98KB
tenant (TenantScopedQuery.js)0.77KB0.44KB
tenant (index.js)0.75KB0.38KB
tenant (resolver.js)2.64KB0.76KB
tenant (useTenant.js)0.50KB0.32KB
tenant (useTenantBranding.js)0.62KB0.39KB
types (ai.js)0.20KB0.17KB
types (api-types.js)0.20KB0.18KB
types (app.js)2.87KB0.99KB
types (base.js)0.20KB0.18KB
types (blocks.js)0.20KB0.18KB
types (complex.js)0.20KB0.18KB
types (crud.js)0.20KB0.18KB
types (data-display.js)0.20KB0.18KB
types (data-protocol.js)0.20KB0.19KB
types (data.js)0.20KB0.18KB
types (designer.js)0.77KB0.41KB
types (disclosure.js)0.20KB0.18KB
types (feedback.js)0.20KB0.18KB
types (field-types.js)0.20KB0.18KB
types (form.js)0.20KB0.18KB
types (index.js)1.54KB0.68KB
types (layout.js)0.20KB0.18KB
types (mobile.js)0.20KB0.18KB
types (navigation.js)0.20KB0.18KB
types (objectql.js)0.20KB0.18KB
types (overlay.js)0.20KB0.18KB
types (permissions.js)0.20KB0.18KB
types (plugin-scope.js)0.20KB0.18KB
types (record-components.js)0.20KB0.19KB
types (registry.js)0.20KB0.18KB
types (reports.js)0.20KB0.18KB
types (spec-report.js)5.26KB1.96KB
types (tenant.js)0.20KB0.18KB
types (theme.js)0.20KB0.18KB
types (ui-action.js)0.75KB0.46KB
types (views.js)0.20KB0.18KB
types (widget.js)0.20KB0.18KB

Size Limits

  • ✅ Core packages should be < 50KB gzipped
  • ✅ Component packages should be < 100KB gzipped
  • ⚠️ Plugin packages should be < 150KB gzipped

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentationImprovements or additions to documentationtests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[P0][security] Access 矩阵按 { packageId } 限定作用域 + 保存切片合并(ADR-0086 P0,生产上线阻断)

2 participants

@os-zhuang@claude