Skip to main content
← Back to list
01Issue
FeatureClosedSwamp ClubPublic
AssigneesNone

Relationships

#3091 Docs: serve authorization of expression references, env and direct-type runs (swamp-club#2786)

Opened by stack72 · 10/6/2026

swamp-club#2786 (with #2755 and #2672) changes how swamp serve authorizes expressions and direct-type runs. The manual page content/manual/reference/swamp-serve/authorization.md needs updating:

  1. "Not yet covered" lists direct type execution (swamp-club#2672). Remove it. A direct run (a type plus a definition name) is now authorized, locked and audited on the definition the definition name refers to, as well as the requested model and the type.

  2. Add a section on expression references over serve:

    • Expression text is authorized against the principal who supplies it, when they supply it. That covers model create (global arguments), model edit and workflow edit (only expressions the stored content does not already hold), and model method run inputs. Runs, evaluate and validate of stored content are never re-checked, so users running automation an admin wrote are unaffected.
    • A reference to another model's data (data.latest/version/listVersions/findBySpec, model.NAME.resource, file.contents) needs read on that data. Computed model names, data.query, data.findByTag, the whole model map, and ns:/star prefixes need read on all data, so any data deny refuses them.
    • env: writers (who hold write on the model) may use env. In run inputs, env needs write on the model run; a run-only caller is refused and told to reference env in the model definition. evaluate and validate never resolve env.
    • Editing a plain value that a computed reference reads through self or inputs re-checks that reference.
    • Workflow edits that add a step need run on the step's model (or nested workflow); stored steps are not re-checked.
    • Admins and auth mode none are not checked.
  3. The CEL expressions reference page could link to this from its env section, noting that over serve env is the server's environment.

Design source: design/enablers/access-control.md, section "Expression references", in the swamp repo.

  1. Document the limits, matching the design doc's "What this does not cover" list:
    • A target computed from inputs (or from another model's data, steps.* or run.*) is the runner's or data writer's choice.
    • Global arguments a run can override are the runner's choice. A workflow step's globalArgs, and a direct-type run's inputs, replace a model's global arguments with only run access. So a stored reference computed from self.globalArguments reads whatever model the runner names. Advise against computing a data target from a global argument when runners shouldn't choose the model.
    • The check runs when text is saved; expressions stored before it are not re-checked.
02Bog Flow
✓OPEN○TRIAGED○IN PROGRESS◉CLOSED

Closed

10/6/2026, 11:44:32 PM

No activity in this phase yet.

03Sludge Pulse
Editable. Press Enter to edit.

stack72 commented 10/6/2026, 11:44:32 PM

Documented in swamp-club PR 1299: https://github.com/swamp-club/swamp-club/pull/1299 . Samples are real output from swamp 20261006.221608.0-sha.5c0c6532. Closing.

Sign in to post a ripple.