Skip to content

tests(access-security): pin the read side of FLS mask/strip and the persona×CRUD cell matrix — coverage gaps from QA run #9401 #9481

Description

@os-zhuang

QA-source: #9401 · access-security.fls-mask-and-strip · read-side clauses
QA-source: #9401 · access-security.crud-permission-matrix · persona-grained cells

The Tier-1 pinned sweep (#9401) found these two access-security items green on their pins but with the pins covering only a subset of the items' acceptance clauses. Security-priority per the maintainer's 2026-08-18 approval of the QA landing plan; the remaining (non-security) coverage gaps from that run are parked on the wave anchor #9296, not filed.

Unpinned clauses to cover with real tests

  1. fls-mask-and-strip — the existing pin (showcase-permission-zoo) covers the write half only (its ref says so explicitly). Unpinned: the read side — a masked field returns its masked value in the GET payload, and a stripped field is absent from the response shape, for an unentitled persona, asserted server-side.
  2. crud-permission-matrixobjectstack verify proves object-level CRUD + cross-owner RLS; the persona × CRUD-cell matrix (each persona's per-cell allow/deny, both sides) remains manual. Pin the cells, or the subset that is automatable, and update the item's automated.ref scope note for whatever remains manual.

Acceptance: new tests land in the package that owns the surface (likely packages/qa/dogfood — triage to confirm the landing package and domain); the checklist items' automated.ref entries are extended/re-scoped so the next Tier-1 run scores these items honestly.

Triage note: suggested lane by test-landing package; both items' evidence and clause text live in #9401's per-item table and coverage-gaps section.

Metadata

Metadata

Assignees

No one assigned

    Type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions