Commit 8251d2c
authored
feat(model-apps): verify what persona security roles grant, + public-repo doc hygiene (#425)
* feat(model-apps): verify what persona security roles actually grant
Two metadata-only verification gaps, both found while auditing what `verify`
can and cannot prove. Neither needs a live browser or new infrastructure.
1. verify now proves what a persona role GRANTS, not just that it exists.
The `role` check asserted only that a role ROW exists carrying the SDK
ownership marker. It never looked at privileges - so a role created with the
wrong access, or one whose privilege write failed after the row landed,
verified clean.
The new `role-privileges` check resolves each declared (entity, access) to
its Dataverse PrivilegeId from the SAME metadata source the SDK writes
against - EntityDefinitions(...)?$select=Privileges - and asserts the role
holds it at AT LEAST the declared depth.
SUBSET, not equality, and lib/role-privileges.js records why: appAccess
injects appmodule read, unioned jobs escalate a shared entity+access to the
max declared scope, and distinct entities can share ONE Dataverse privilege
(a role holds one depth per privilege). Equality would fail on all three
while telling us nothing true. Fails CLOSED on an unreadable role or table.
The read deliberately does NOT go through sdk.fetchEntityMetadata: that
returns a projected shape which drops Privileges entirely, so routing through
it would have silently reported every privilege as unreadable.
2. personas[].jobs[].surfaces[] is checked instead of documentary.
app-spec.js validated each entry as a non-empty string and stopped;
spec-lint warned only when the array was EMPTY. So a job could name "My Open
Work Orders" when no such view existed anywhere in the spec and every gate
passed.
lib/surface-resolver.js resolves each entry against the spec's own views,
forms, pages (key OR name), dashboards, tables and sitemap titles. spec-lint
WARNS on no match - a warning, never an error, because app-spec.js is loose
on purpose: a surface may legitimately name an out-of-the-box artifact this
spec does not author.
verify adds a `job-surface` rollup - a PURE rollup over checks already
computed, so it costs no extra reads - reporting a deployed failure as the
job it broke ("persona P can no longer do job J") rather than only "view X
is missing".
Both wire into verifySpec's existing READER-GATED seam (the pattern
entityRelationships / commandBar already use), so an existence-only reader
behaves exactly as it did before.1 parent 051c279 commit 8251d2c
62 files changed
Lines changed: 1768 additions & 361 deletions
File tree
- .github/workflows
- evals/model-apps
- app-builder
- genpage/fixtures
- 1-account-card-gallery
- 11-recruitment-multi-page
- 11-recruitment-pages-real
- 13-contact-localization
- 15-support-tickets-real
- 2-mock-dashboard-real
- 2-mock-dashboard
- 4-case-wizard
- 5-kanban-task-board
- 7-job-candidates-new-entities
- plugins/model-apps
- agents
- docs
- references
- scripts
- lib
- tests
- scripts
- tests
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
10 | 10 | | |
11 | 11 | | |
12 | 12 | | |
| 13 | + | |
13 | 14 | | |
14 | 15 | | |
15 | 16 | | |
| |||
36 | 37 | | |
37 | 38 | | |
38 | 39 | | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
6 | 6 | | |
7 | 7 | | |
8 | 8 | | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
9 | 55 | | |
10 | 56 | | |
11 | 57 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | 3 | | |
4 | | - | |
| 4 | + | |
5 | 5 | | |
6 | 6 | | |
7 | 7 | | |
| |||
117 | 117 | | |
118 | 118 | | |
119 | 119 | | |
120 | | - | |
| 120 | + | |
121 | 121 | | |
Lines changed: 2 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
16 | 16 | | |
17 | 17 | | |
18 | 18 | | |
19 | | - | |
20 | | - | |
| 19 | + | |
| 20 | + | |
21 | 21 | | |
22 | 22 | | |
23 | 23 | | |
| |||
Lines changed: 2 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
12 | 12 | | |
13 | 13 | | |
14 | 14 | | |
15 | | - | |
16 | | - | |
| 15 | + | |
| 16 | + | |
17 | 17 | | |
18 | 18 | | |
19 | 19 | | |
| |||
Lines changed: 2 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
16 | 16 | | |
17 | 17 | | |
18 | 18 | | |
19 | | - | |
20 | | - | |
| 19 | + | |
| 20 | + | |
21 | 21 | | |
22 | 22 | | |
23 | 23 | | |
| |||
Lines changed: 2 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
11 | 11 | | |
12 | 12 | | |
13 | 13 | | |
14 | | - | |
15 | | - | |
| 14 | + | |
| 15 | + | |
16 | 16 | | |
17 | 17 | | |
18 | 18 | | |
| |||
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
6 | 6 | | |
7 | 7 | | |
8 | 8 | | |
9 | | - | |
| 9 | + | |
10 | 10 | | |
11 | 11 | | |
12 | 12 | | |
| |||
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
10 | 10 | | |
11 | 11 | | |
12 | 12 | | |
13 | | - | |
| 13 | + | |
14 | 14 | | |
15 | 15 | | |
16 | 16 | | |
| |||
Lines changed: 6 additions & 6 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
12 | 12 | | |
13 | 13 | | |
14 | 14 | | |
15 | | - | |
16 | | - | |
17 | | - | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
18 | 18 | | |
19 | | - | |
| 19 | + | |
20 | 20 | | |
21 | 21 | | |
22 | | - | |
| 22 | + | |
23 | 23 | | |
24 | 24 | | |
25 | 25 | | |
| |||
75 | 75 | | |
76 | 76 | | |
77 | 77 | | |
78 | | - | |
| 78 | + | |
79 | 79 | | |
80 | 80 | | |
81 | 81 | | |
| |||
0 commit comments