Skip to content

platform-admin re-anchor L1 (spec seat): export the kernel platform-admin capability declaration — one list, imported by plugin-security (Choice 6A) #11965

Description

@os-support-ai

Leg L1 of the accepted #11663 platform-admin re-anchor design. Provenance: design document = #11663 comment 5394453215 (§4 Choice 6, §6 row L1); maintainer acceptance = #11663 comment 5404675670 (2026-08-25, verbatim 「接受你的建议,继续」, bundle 1A/2B/3A/4A/5A/6A/7A). Filed by PM session session_01KWRU3s15AJz7PGW7a7wdCh.

Surface: packages/spec — ⛔ spec seat only (sole owner of this package).

Content: @objectstack/spec exports the platform-admin capability declaration (the capability set today carried by the org-less admin_full_access row); plugin-security's admin_full_access declaration imports that same list, so exactly one copy exists. Behaviour-neutral; lands alone (migration sequence step 2). Measured precedent in the design: core already imports ADMIN_FULL_ACCESS from @objectstack/spec.

Acceptance criterion: git grep -n ADMIN_FULL_ACCESS packages/spec/src packages/plugins/plugin-security/src shows the capability list declared once (spec) and imported — not duplicated — by plugin-security, and no behaviour change lands with it.

Notes: the design expects no authorable-surface movement (no new authorable key) — the spec seat must confirm that on the tree rather than take the design's word. Premise-first: re-verify the cited files/lines on current origin/main before implementing; the design was measured at cad8b42f00.

Downstream: the core derivation leg (L2) declares Blocked-by: on this card.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions