Skip to content

feat!: self-only default write access for auth collections - #17806

Open
DanRibbens wants to merge 11 commits into
mainfrom
feat/default-user-access
Open

feat!: self-only default write access for auth collections#17806
DanRibbens wants to merge 11 commits into
mainfrom
feat/default-user-access

Conversation

@DanRibbens

Copy link
Copy Markdown
Contributor

Summary

  • Adds defaultAuthAccess that constrains update/delete/unlock on auth-enabled collections to { id: { equals: req.user.id } } when req.user.collection matches the target collection slug, and denies otherwise.
  • Rewires addDefaultsToCollectionConfig to use defaultAuthAccess for update/delete/unlock when collection.auth is truthy. read, create, readVersions, and admin continue to use defaultAccess. Non-auth collections are untouched.
  • Documents the new default behavior in docs/access-control/collections.mdx under Update, Delete, and Unlock.

BREAKING CHANGE

On auth-enabled collections, the default update, delete, and unlock access is now self-only. Apps that relied on any authenticated admin-collection user being able to modify other users must add an explicit access.update (and/or delete, unlock) function to restore prior behavior. Example:

access: {
  update: ({ req }) => Boolean(req.user), // or a role-aware equivalent
}

The built-in unlock endpoint is effectively disabled by default and now requires an explicit access.unlock for admin-to-user unlock flows.

Cross-collection safety: an authenticated user in auth collection A can no longer update/delete/unlock docs in a different auth collection B, even if IDs collide (a real risk on Postgres where serial IDs are shared across collections).

Test plan

  • pnpm run test:int auth — 104 pass (includes 7 new default-access tests)
  • pnpm run test:int access-control — 41 pass
  • pnpm run test:int custom-strategy — 1 pass
  • pnpm run build:core — pass
  • Manual: pnpm run dev auth, log in as one user, attempt to update another via the admin UI — expect 403/not-found; self-update expected to succeed.

🤖 Generated with Claude Code

DanRibbens and others added 11 commits August 15, 2026 09:23
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…ctions

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
BREAKING CHANGE: defaultAuthAccess is now a factory that takes the target
collection slug. Prevents a cross-collection authorization bypass where an
authenticated user in collection A with an id colliding a doc in auth
collection B could update/delete that doc via the default access.
Removes the factory shape introduced in 0951f53 by reading `slug` from
AccessArgs directly. Keeps the security guard (`user.collection !== slug`
denies) but restores the plain `Access` signature so the export shape is
unchanged from Tasks 2/3. Also tightens the cross-collection regression
test to explicitly set the attacker user's collection instead of relying
on createLocalReq's admin.user fallback.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown
Contributor

📦 esbuild Bundle Analysis for payload

This analysis was generated by esbuild-bundle-analyzer. 🤖

Meta File Out File Size (raw) Note
packages/next/meta_index.json esbuild/index.js 213.92 KB 🆕 Added
packages/payload/meta_index.json esbuild/index.js 1.40 MB 🆕 Added
packages/payload/meta_shared.json esbuild/exports/shared.js 213.39 KB 🆕 Added
packages/richtext-lexical/meta_client.json esbuild/exports/client_optimized/index.js 286.50 KB 🆕 Added
packages/ui/meta_client.json esbuild/exports/client_optimized/index.js 36.54 KB 🆕 Added
packages/ui/meta_shared.json esbuild/exports/shared_optimized/index.js 18.95 KB 🆕 Added
Largest paths These visualization shows top 20 largest paths in the bundle.

Meta file: packages/next/meta_index.json, Out file: esbuild/index.js

Path Size
../../node_modules ${{\color{Goldenrod}{ ████████████████████████▊ }}}$ 99.0%, 209.89 KB
dist/adapters/router.js ${{\color{Goldenrod}{ }}}$ 0.3%, 718 B
dist/adapters/server.js ${{\color{Goldenrod}{ }}}$ 0.3%, 533 B
dist/adapters/layout.js ${{\color{Goldenrod}{ }}}$ 0.2%, 526 B
dist/adapters/views.js ${{\color{Goldenrod}{ }}}$ 0.2%, 409 B
dist/esbuildEntry.js ${{\color{Goldenrod}{ }}}$ 0.0%, 0 B

Meta file: packages/payload/meta_index.json, Out file: esbuild/index.js

Path Size
../../node_modules ${{\color{Goldenrod}{ ████████████████▉ }}}$ 67.6%, 944.37 KB
dist/fields/hooks ${{\color{Goldenrod}{ ▊ }}}$ 3.2%, 44.38 KB
dist/collections/operations ${{\color{Goldenrod}{ ▊ }}}$ 3.1%, 43.24 KB
dist/utilities/configToJSONSchema.js ${{\color{Goldenrod}{ ▎ }}}$ 1.1%, 15.99 KB
dist/auth/operations ${{\color{Goldenrod}{ ▎ }}}$ 1.1%, 15.63 KB
dist/queues/operations ${{\color{Goldenrod}{ ▎ }}}$ 1.0%, 14.29 KB
dist/fields/config ${{\color{Goldenrod}{ ▎ }}}$ 1.0%, 13.63 KB
dist/globals/operations ${{\color{Goldenrod}{ ▎ }}}$ 1.0%, 13.53 KB
dist/fields/validations.js ${{\color{Goldenrod}{ ▏ }}}$ 0.8%, 10.69 KB
dist/collections/config ${{\color{Goldenrod}{ ▏ }}}$ 0.7%, 9.94 KB
dist/bin/generateImportMap ${{\color{Goldenrod}{ ▏ }}}$ 0.7%, 9.84 KB
dist/config/orderable ${{\color{Goldenrod}{ ▏ }}}$ 0.6%, 8.07 KB
dist/uploads/fetchAPI-multipart ${{\color{Goldenrod}{ ▏ }}}$ 0.6%, 7.87 KB
dist/index.js ${{\color{Goldenrod}{ ▏ }}}$ 0.6%, 7.78 KB
dist/hierarchy/utils ${{\color{Goldenrod}{ ▏ }}}$ 0.5%, 7.64 KB
dist/database/migrations ${{\color{Goldenrod}{ ▏ }}}$ 0.5%, 7.55 KB
dist/config/sanitize.js ${{\color{Goldenrod}{ ▏ }}}$ 0.5%, 7.07 KB
dist/collections/endpoints ${{\color{Goldenrod}{ }}}$ 0.4%, 6.12 KB
dist/auth/strategies ${{\color{Goldenrod}{ }}}$ 0.4%, 5.61 KB
dist/uploads/endpoints ${{\color{Goldenrod}{ }}}$ 0.4%, 5.58 KB
(other) ${{\color{Goldenrod}{ ████████ }}}$ 32.4%, 451.98 KB

Meta file: packages/payload/meta_shared.json, Out file: esbuild/exports/shared.js

Path Size
../../node_modules ${{\color{Goldenrod}{ █████████████████▉ }}}$ 71.9%, 150.13 KB
dist/fields/validations.js ${{\color{Goldenrod}{ █▎ }}}$ 5.1%, 10.69 KB
dist/fields/config ${{\color{Goldenrod}{ ▋ }}}$ 2.8%, 5.83 KB
dist/utilities/traverseFields.js ${{\color{Goldenrod}{ ▌ }}}$ 2.1%, 4.45 KB
dist/collections/config ${{\color{Goldenrod}{ ▍ }}}$ 1.6%, 3.33 KB
dist/config/orderable ${{\color{Goldenrod}{ ▍ }}}$ 1.5%, 3.13 KB
dist/fields/baseFields ${{\color{Goldenrod}{ ▎ }}}$ 1.3%, 2.79 KB
dist/utilities/deepCopyObject.js ${{\color{Goldenrod}{ ▎ }}}$ 1.3%, 2.69 KB
dist/config/client.js ${{\color{Goldenrod}{ ▎ }}}$ 1.3%, 2.69 KB
dist/auth/cookies.js ${{\color{Goldenrod}{ ▏ }}}$ 0.7%, 1.55 KB
dist/utilities/flattenTopLevelFields.js ${{\color{Goldenrod}{ ▏ }}}$ 0.7%, 1.41 KB
dist/utilities/getVersionsConfig.js ${{\color{Goldenrod}{ ▏ }}}$ 0.5%, 1.04 KB
dist/globals/config ${{\color{Goldenrod}{ }}}$ 0.4%, 939 B
dist/utilities/flattenAllFields.js ${{\color{Goldenrod}{ }}}$ 0.4%, 793 B
dist/utilities/unflatten.js ${{\color{Goldenrod}{ }}}$ 0.4%, 779 B
dist/utilities/sanitizeUserDataForEmail.js ${{\color{Goldenrod}{ }}}$ 0.3%, 713 B
dist/auth/extractJWT.js ${{\color{Goldenrod}{ }}}$ 0.3%, 696 B
dist/utilities/getFieldPermissions.js ${{\color{Goldenrod}{ }}}$ 0.3%, 651 B
dist/utilities/getSafeRedirect.js ${{\color{Goldenrod}{ }}}$ 0.3%, 632 B
dist/errors/ValidationError.js ${{\color{Goldenrod}{ }}}$ 0.3%, 577 B
(other) ${{\color{Goldenrod}{ ███████ }}}$ 28.1%, 58.78 KB

Meta file: packages/richtext-lexical/meta_client.json, Out file: esbuild/exports/client_optimized/index.js

Path Size
dist/features/blocks ${{\color{Goldenrod}{ ███▎ }}}$ 13.1%, 37.20 KB
dist/lexical/ui ${{\color{Goldenrod}{ ███ }}}$ 12.1%, 34.20 KB
dist/lexical/plugins ${{\color{Goldenrod}{ ██▉ }}}$ 11.7%, 33.01 KB
dist/features/table ${{\color{Goldenrod}{ ██▍ }}}$ 9.6%, 27.22 KB
dist/features/link ${{\color{Goldenrod}{ █▋ }}}$ 6.6%, 18.82 KB
dist/features/toolbars ${{\color{Goldenrod}{ █▌ }}}$ 6.2%, 17.45 KB
dist/features/upload ${{\color{Goldenrod}{ █▎ }}}$ 5.0%, 14.28 KB
dist/features/textState ${{\color{Goldenrod}{ ▉ }}}$ 3.9%, 11.08 KB
dist/lexical/utils ${{\color{Goldenrod}{ ▉ }}}$ 3.5%, 10.02 KB
dist/features/relationship ${{\color{Goldenrod}{ ▊ }}}$ 3.4%, 9.61 KB
dist/features/converters ${{\color{Goldenrod}{ ▊ }}}$ 3.0%, 8.36 KB
dist/utilities/fieldsDrawer ${{\color{Goldenrod}{ ▋ }}}$ 2.9%, 8.12 KB
dist/features/debug ${{\color{Goldenrod}{ ▋ }}}$ 2.6%, 7.40 KB
dist/lexical/config ${{\color{Goldenrod}{ ▍ }}}$ 1.8%, 5.14 KB
dist/features/lists ${{\color{Goldenrod}{ ▎ }}}$ 1.3%, 3.64 KB
dist/features/format ${{\color{Goldenrod}{ ▎ }}}$ 1.2%, 3.28 KB
dist/lexical/LexicalEditor.js ${{\color{Goldenrod}{ ▎ }}}$ 1.1%, 3.23 KB
dist/features/horizontalRule ${{\color{Goldenrod}{ ▎ }}}$ 1.1%, 3.18 KB
dist/field/Field.js ${{\color{Goldenrod}{ ▎ }}}$ 1.0%, 2.88 KB
dist/lexical/nodes ${{\color{Goldenrod}{ ▏ }}}$ 0.9%, 2.66 KB
(other) ${{\color{Goldenrod}{ █████████████████████▋ }}}$ 86.9%, 246.09 KB

Meta file: packages/ui/meta_client.json, Out file: esbuild/exports/client_optimized/index.js

Path Size
dist/exports/client ${{\color{Goldenrod}{ █████████████████████████ }}}$ 100.0%, 26.90 KB

Meta file: packages/ui/meta_shared.json, Out file: esbuild/exports/shared_optimized/index.js

Path Size
dist/graphics/Logo ${{\color{Goldenrod}{ ███████▋ }}}$ 30.5%, 5.57 KB
../../node_modules ${{\color{Goldenrod}{ ███▌ }}}$ 14.5%, 2.65 KB
dist/graphics/Icon ${{\color{Goldenrod}{ ██ }}}$ 8.3%, 1.51 KB
dist/utilities/formatDocTitle ${{\color{Goldenrod}{ █▊ }}}$ 7.2%, 1.32 KB
dist/providers/TableColumns ${{\color{Goldenrod}{ █▏ }}}$ 4.7%, 866 B
dist/utilities/getGlobalData.js ${{\color{Goldenrod}{ █ }}}$ 4.2%, 762 B
dist/utilities/api.js ${{\color{Goldenrod}{ █ }}}$ 4.1%, 756 B
dist/utilities/groupNavItems.js ${{\color{Goldenrod}{ █ }}}$ 4.1%, 745 B
dist/elements/Translation ${{\color{Goldenrod}{ ▋ }}}$ 2.7%, 493 B
dist/utilities/handleTakeOver.js ${{\color{Goldenrod}{ ▌ }}}$ 2.4%, 440 B
dist/utilities/traverseForLocalizedFields.js ${{\color{Goldenrod}{ ▌ }}}$ 2.3%, 419 B
dist/elements/withMergedProps ${{\color{Goldenrod}{ ▍ }}}$ 1.9%, 339 B
dist/utilities/getNavGroups.js ${{\color{Goldenrod}{ ▍ }}}$ 1.9%, 338 B
dist/utilities/getVisibleEntities.js ${{\color{Goldenrod}{ ▍ }}}$ 1.8%, 329 B
dist/elements/WithServerSideProps ${{\color{Goldenrod}{ ▎ }}}$ 1.3%, 232 B
dist/layouts/Root ${{\color{Goldenrod}{ ▎ }}}$ 1.3%, 230 B
dist/utilities/handleGoBack.js ${{\color{Goldenrod}{ ▎ }}}$ 1.0%, 180 B
dist/fields/mergeFieldStyles.js ${{\color{Goldenrod}{ ▏ }}}$ 0.9%, 158 B
dist/forms/Form ${{\color{Goldenrod}{ ▏ }}}$ 0.8%, 152 B
dist/utilities/handleBackToDashboard.js ${{\color{Goldenrod}{ ▏ }}}$ 0.8%, 152 B
(other) ${{\color{Goldenrod}{ █████████████████▍ }}}$ 69.5%, 12.68 KB
Details

Next to the size is how much the size has increased or decreased compared with the base branch of this PR.

  • ‼️: Size increased by 20% or more. Special attention should be given to this.
  • ⚠️: Size increased in acceptable range (lower than 20%).
  • ✅: No change or even downsized.
  • 🗑️: The out file is deleted: not found in base branch.
  • 🆕: The out file is newly found: will be added to base branch.

@DanRibbens DanRibbens changed the title feat(payload)!: self-only default write access for auth collections feat!: self-only default write access for auth collections Aug 16, 2026
JessRynkar pushed a commit that referenced this pull request Aug 17, 2026
## What / Why

`test/trash/e2e.spec.ts` → **"Should collapse breadcrumbs into a popup
menu when they do not fit the available width"** is flaky on the `trash
[tanstack-start]` CI variant (fails all retries in some runs, passes in
others; passes reliably on `next`). Seen on [PR
#17806](https://github.com/payloadcms/payload/pull/17806/checks) and
[run
31884980215](https://github.com/payloadcms/payload/actions/runs/31884980215),
and confirmed intermittent on recent `main` runs too.

## Root cause

The test used a **400px** viewport. At 400px the expanded breadcrumbs
(`Dashboard / Posts / Trash / Trashed Post`) measure **~298px** against
**~298px** of available space — within 1px. `StepNav`'s overflow check
is `needed - available > 1`, so at that exact-fit boundary the collapse
decision is effectively a coin-flip:

| Viewport | available | needed | collapses |
| --- | --- | --- | --- |
| **400px** | **298** | **298** | **no ← flaky knife-edge** |
| 360px | 213 | 298 | yes |
| 320px | 213 | 298 | yes |
| 280px | 196 | 298 | yes |

Because the `.app-header__step-nav-wrapper` shrink-wraps to the
breadcrumb content, both the collapsed and expanded states are
self-stable, so once a run lands "expanded" at the boundary it stays
expanded and the toggle never renders. Slower environments
(tanstack-start) land on the wrong side of the boundary more often.
Reproduced deterministically locally by rendering wide (expanded) then
resizing to 400px.

## Fix

Move the test viewport to **320px** (a standard small-mobile width),
where the breadcrumbs are unambiguously past the available width (~213px
available vs ~298px needed). This makes the collapse deterministic
without touching the shared `StepNav` component.

## Verification

- 15/15 consecutive local runs of the target test pass.
- All 7 `-g "breadcrumb"` tests in the trash suite pass.

## Note

The knife-edge is a symptom of a latent measurement quirk in `StepNav`:
`available` is read from a container that shrink-wraps to the breadcrumb
content, so the measure is content-dependent rather than a stable
available-width reference. That only manifests at an exact-fit width and
is benign for users (the breadcrumbs genuinely fit), so it's
intentionally out of scope here — flagging for the UI team.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant