Relationships
#2787 Docs: authorization reference should say access-control records need admin, not a data grant (swamp-club#2756)
Opened by stack72 · 9/30/2026
swamp-club#2756 changes who can read swamp's access-control records over serve. Page: content/manual/reference/swamp-serve/authorization.md.
What changes:
- Records of the internal types swamp/grant, swamp/group, swamp/server-token, swamp/enrollment-token, swamp/worker, swamp/step-lease, swamp/pending-dispatch and swamp/fleet-probe are owned by the access kind, not data or model. Every request that reaches them (data get, list, versions, search, query, delete, rename, model output get, data and logs, method history) is authorized as admin on access:, e.g. access:swamp/grant, whatever action the request asks for. admin on access:* covers them, and so does a narrower grant such as admin on access:swamp/*.
- A read or write on data:* or model:* no longer returns or touches these records. Collections leave them out.
- Expressions (data.latest, data.query and the rest, and model.) never return these records, in serve or locally.
- read on access:grant and access:group (used by access grant list and access group list) is unchanged.
Suggested edits:
- The selector table (~line 207): note that data:* does not cover access-control records, and add access:swamp/* with its meaning.
- The model output section (~lines 248-264): note the admin requirement for control-plane models.
- The action table (~line 88): admin also covers reading access-control records through data and output commands.
Closed
No activity in this phase yet.
stack72 commented 10/1/2026, 6:02:08 AM
Documented in swamp-club PR #1274 (https://github.com/swamp-club/swamp-club/pull/1274, merged 8cb2788). reference/swamp-serve/authorization.md has a new Access-control records section: the eight internal types are authorized as admin on access:swamp/, data:* and model:* no longer reach them, and the selector and action tables are updated. One correction to the issue text: admin on access:swamp/* covers reading and writing a record, but creating a model of these types or running a method on one still needs admin on access:*. Verified against a live serve. cel-expressions.md notes that expressions never return these records.
Sign in to post a ripple.