fix(nextly): a trusted batch update has a trusted path - #1801
Conversation
updateEntries takes overrideAccess as createEntries does: the collection gate judges no user, the transition pre-resolve is told, and the per-entry write already honoured it once forwarded.
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Warning Review limit reachedNext included review available in 39 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (3)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b34b1f44eb
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…rs-override-access
…ss are load-bearing A refused publish rule and a field-level update rule, each behind a gate that allows everyone, so dropping either forwarding step fails a case. The docblock names real callers rather than a plugin method that does not exist; that gap is a ledger task.
@nextlyhq/adapter-drizzle
@nextlyhq/adapter-mysql
@nextlyhq/adapter-postgres
@nextlyhq/adapter-sqlite
@nextlyhq/admin
@nextlyhq/admin-css
@nextlyhq/blocks-engine
@nextlyhq/blocks-react
@nextlyhq/builder
create-nextly-app
@nextlyhq/eslint-plugin
nextly
@nextlyhq/plugin-form-builder
@nextlyhq/plugin-page-builder
@nextlyhq/plugin-sdk
@nextlyhq/plugin-seo
@nextlyhq/storage-s3
@nextlyhq/storage-uploadthing
@nextlyhq/storage-vercel-blob
@nextlyhq/ui
commit: |
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2d3b82603d
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
|
Codex Review: Didn't find any major issues. Bravo. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
What
updateEntriesonCollectionEntryServiceandCollectionBulkServicenow takesoverrideAccess, ascreateEntrieshas since D35. When set, the collection-level gate judges no user, the publish-transition pre-resolve is told, and each per-entry write skips access (the write's own params already carried the flag; it was never forwarded).Why
A trusted batch update had no trusted path: a plugin's system-elevated batch update or a seed was judged as an anonymous caller at the gate and refused every row on a collection whose update rule wants a user. The create path took the flag; the update path was the same method shape without it. Tracker 110, ledger
task:schema-bulk-update-override-access(claimed with--forceas mechanical: the sibling method is the design).Scope
The pooled
updateEntriesonly, to matchcreateEntries. NeithercreateEntriesInTransactionnorupdateEntriesInTransactiontakes the flag, and they stay alike.Tests
bulk-update-override-access.integration.test.ts: a collection whoseupdaterule wants a user; an elevated batch with no user updates the row, and the same batch without elevation is refused and leaves the row untouched (the control that keeps the flag from being a no-op). Againstmain's bulk service the elevated case fails. The three batch suites beside it pass.Also: the pre-push hook refused my first push of this branch because the test file failed
check-typesunder the tests tsconfig, which I had not run. The hook from #1781 doing what it was merged for.Patch changeset, every package.