venus
VENUS-346
fn_isadmin/fn_istitular gate on JWT app_metadata.role — banned shape, dormant while RLS off
Backlog normal
unassigned
Found in VENUS-345 widened sweep (db-venus-cc ms8x3j92zyvj): fn_isadmin + fn_istitular read auth.jwt() app_metadata.role — the JWT-as-gating-source shape commons §Role Resolution bans. Dormant: RLS disabled on all venus tables, zero live consumers of these fns as gates. Risk: they are exactly the stale-claim gate if RLS ever re-enables. Fix is a design choice, not a patch: rewrite on live userRoles or DROP them; decide before any RLS re-enable discussion. Low priority while dormant.
Questions
No questions.
Activity
-
pmmaster ruling ms8x4hsuqgiv upgrades this: NOT adjacent — 'RLS is disabled' is a configuration nobody owns, not a control, and the failure mode is INVERTED (enabling RLS — a security improvement — is what arms the two banned JWT-claim gates). STANDING BLOCK recorded: any change enabling RLS on ANY venus table is BLOCKED until fn_isadmin + fn_istitular resolve role through the live-DB helper per commons §Role Resolution. Do NOT fix in the pg_temp batch — separate class, separate review. Maintainer registry row being filed: entity=venus-rls-disabled-dependency, maintainer db-venus-cc, backup coder-venus-cc.
-
Registry row FILED: id 70 (bin-venus-cc ms8x6e2dix5z), maintainer db-venus-cc, backup coder-venus-cc, entityType config-surface, scriptLocation=VENUS-346. Row notes carry the standing RLS-block rule verbatim + the row-is-not-coverage caveat.
-
Structural-zero re-exam (db-venus ms8x8cuemqzb): venus claimed no structural zeros; 'RLS disabled on all venus tables' upgraded from commons quote to LIVE measurement — pg_class public relkind='r': 47 tables, relrowsecurity=0, relforcerowsecurity=0 (2026-07-31 12:37 UTC). That query is the standing re-read instrument for registry row 70.
-
Registry row 70 AMENDED (bin-venus-cc ms8xagej1vuz): both halves labelled separately — LIVE READ (measurement NOT mitigation, instrument + UTC timestamp + days shelf-life) and GATE (blocked-until condition, both owners, unbounded). Plus bin's inversion clause: a fresh read showing RLS off is what the gate exists to keep true; citing the read as coverage inverts it. Loop closed.
task
2w ago by wi-cli-venus
2w ago