Skip to content

AREA_REQUIRED_PERMISSIONS_RETIRED 的处方在 #4722 之后过时:仍写着「the server does not walk areas」 #4749

Description

@os-zhuang

从 #4722 的实现中记录的越界发现(未认领)。

现象

#4722 让服务端权威闸门 filterAppForUser 走 areas[].navigation,area 内导航项的
requiredPermissions / requiresService 现在由服务端剥离。但 packages/spec 里两处
仍然陈述改前的事实:

  1. packages/spec/src/ui/app.zod.ts:662(AREA_REQUIRED_PERMISSIONS_RETIRED 处方正文):

    requiredPermissions / requiresService on a navigation ITEM are stripped server-side
    from the app's top-level navigation tree and re-checked in the shell. Items nested
    under areas[] are gated in the shell only — the server does not walk areas — so
    anything that must never reach the browser belongs in the top-level tree, or in its own app.

    这段话是作者写错 area 级键时唯一能读到的处方(strict schema 的 unknown-key 报错正文),
    现在它把一个已经关闭的缺口描述成仍然存在。方向上是「过度保守」而非不安全(它劝作者把
    敏感项挪到顶层树,这仍然可行),但它是错的,而且是说给作者听的那一份。

  2. packages/spec/src/ui/app.test.ts:1374 有一条断言把这个措辞钉死:

    // The honest caveat: the server does not walk areas, so an item gate
    // INSIDE an area is shell-side only.
    expect(msg).toMatch(/shell only|does not walk/is);
    

    所以改处方正文必须同时改这条 pin —— 两者是一个耦合改动。

为什么没在 #4722 里顺手改

#4722 的派发约束是 packages/spec/** 零改动(单文件例外只开给
packages/spec/liveness/app.json 的账本 note,已按预案改写)。处方正文是 .describe 级别的
用户可见字符串,改它要连带 pin 与 spec 生成物(gen:schema / gen:docs)一起动,正是
发布窗口里该避开的涟漪。故按 Prime Directive #10 独立记录。

建议的修法(一次改完)

  • 改 AREA_REQUIRED_PERMISSIONS_RETIRED 正文:项级 requiredPermissions / requiresService
    在两棵树(顶层 navigation 与 areas[].navigation)都由服务端剥离(filterAppForUser 只走 app 顶层 navigation —— areas[] 里的 nav 项权限过滤仅客户端生效(#4651 移除假闸门后剩下的真缺口) #4722);仍然只在
    客户端求值的是 visible(CEL)与 requiresObject —— 必须永不到达浏览器的东西写
    requiredPermissions,不要写 visible。
  • 同步改 app.test.ts 那条断言(改成钉新的正确措辞,别只是删掉)。
  • 跑 pnpm --filter @objectstack/spec check:generated,按它报的 stale 项重新生成。
  • 顺带核对 AREA_VISIBLE_RETIRED 正文:它指向项级 visible,那一层依然只在客户端求值,
    所以那段大概率不用改 —— 确认一下即可。

区分清楚:退役的 area 级键(areas[].visible / areas[].requiredPermissions)不复活,
本单只是把处方里关于 area 内部项级闸门的那句事实改对。

参考:#4722(实现)、#4651(退役裁决)、packages/spec/liveness/app.json 的
areas.navigation note(已在 #4722 里改写,可作为正确措辞的蓝本)。

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions