HarperFast / HarperFast/harper
[Epic] Access-control enforcement gaps
- Dominant language
- JavaScript
- Stars
- 89
- Forks
- 10
- Avg merge
- 2d 6h
- Merged PRs (30d)
- 200
Description
Tracking epic for permission/authorization checks that are declared or intended but not actually enforced at some code path: REST attribute-level permissions, JWT role claims, GraphQL @allow, read-only mode, Studio access gating, and custom-operation permission declarations.
---
_Filed by Claude (Opus 4.8), issue-backlog triage & grouping pass._
Contributor guide
Research direction
No files, tests, or entry points are identified. Start by separating the REST attribute-level permissions, JWT role claims, GraphQL @allow, read-only mode, Studio access gating, and custom-operation declarations into concrete code paths; done means each intended permission is enforced consistently where it applies.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- graphql, javascript, nodejs
- Domain
- api, authorization, backend, security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100