Skip to content

chore: make overrideAccess explicit in tests - #17859

Merged
nathanlentz merged 7 commits into
mainfrom
override-access/tests
Sep 23, 2026
Merged

nathanlentz merged 7 commits into
mainfrom
override-access/tests

Conversation

@nathanlentz

@nathanlentz nathanlentz commented Aug 19, 2026 •

Copy link
Copy Markdown
Collaborator

Adds an explicit overrideAccess: true to every Local API call in test/ that previously relied on the default.

This is preparation for flipping the Local API default to false, which lands later in this stack. It is split out so that the breaking change itself stays small enough to read (still big, sorry)

This changes no behaviour

The Local API currently defaults overrideAccess to true. All 21 local operations
destructure overrideAccess = true. Writing the value explicitly produces exactly what
the default already produced, so every one of these tests asserts the same thing it did
before.

A note on verification

tsconfig.base.json excludes **/*.spec.ts, so a typecheck cannot see most of this directory and test/ carries thousands of pre-existing type errors regardless. Relying on all tests to pass to confirm correct changes.

@github-actions

github-actions Bot commented Aug 19, 2026 •

Copy link
Copy Markdown
Contributor

📦 esbuild Bundle Analysis for payload

This analysis was generated by esbuild-bundle-analyzer. 🤖
This PR introduced no changes to the esbuild bundle! 🙌

@nathanlentz
nathanlentz force-pushed the override-access/tests branch 2 times, most recently from 3903c69 to 3f55ee9 Compare August 20, 2026 02:41
@nathanlentz
nathanlentz marked this pull request as ready for review August 20, 2026 13:10
@nathanlentz
nathanlentz force-pushed the override-access/tests branch 3 times, most recently from 2d2fd3f to e384d86 Compare August 20, 2026 16:42
@nathanlentz
nathanlentz force-pushed the override-access/tests branch from e384d86 to 128f4bb Compare August 21, 2026 17:33
Adds an explicit `overrideAccess: true` to every Local API call in test/
that previously relied on the default.

The Local API currently defaults `overrideAccess` to `true`, so writing
the value explicitly produces exactly what the default already produced.
No behaviour changes.

Four kinds of call site are invisible to both the codemod and a typecheck,
and were found by running the suites instead:

- `(payload as any).create({ ... })` — the receiver is cast, so there is no
  typed parameter to be missing (plugin-mcp, pg-replica)
- `payload2.create({ ... } as any)` — the cast is on the argument, so the
  object literal is `any` (config)
- `payload.create(createDirector)` — the arguments are hoisted into a
  variable, so there is no object literal at the call (relationships)
- Calls added to `main` after this sweep first ran, which arrive whenever
  the branch is rebased (queues, versions)

`test/__helpers/shared/sdk/types.ts` makes `overrideAccess` required on the
PayloadTestSDK argument types, so writing an e2e test asks the same question
as writing product code. Every existing call site already passes a value.

Preparation for making `overrideAccess` a required property.
@nathanlentz
nathanlentz force-pushed the override-access/tests branch from 128f4bb to 1aaa858 Compare September 8, 2026 14:07
@nathanlentz
nathanlentz merged commit a8c8bb0 into main Sep 23, 2026
283 checks passed
@nathanlentz
nathanlentz deleted the override-access/tests branch September 23, 2026 19:36
nathanlentz added a commit that referenced this pull request Sep 23, 2026
## Summary

Make `overrideAccess: true` explicit in Local API calls across
first-party packages, plugins, templates, and examples. These calls
currently rely on a default of `true`, so their behavior stays the same.
This prepares them for the default change in #17869.

## Scope

Calls that intentionally exercise the default remain unchanged. Template
calls keep their current access behavior; changes to template access
decisions need separate review. The test call sites were addressed in
#17859, which is already merged.

This PR combines #17862, #17864, and #17865 into #17861.

## Validation

The branches merged without conflicts. `git diff --check` passes for the
combined change. CI will validate the consolidated branch.
nathanlentz added a commit that referenced this pull request Sep 24, 2026
This changes the Local API default for `overrideAccess` from `true` to
`false`, including `payload.jobs.*` operations. An omitted option now
enforces access control.

## Before and after

```ts
// Payload 3: omission bypasses access control.
await payload.find({ collection: 'posts' })

// Payload 4: omission enforces access control.
await payload.find({ collection: 'posts' })

// Explicitly preserve the previous behavior where it is intended.
await payload.find({ collection: 'posts', overrideAccess: true })
```

## Changes

- Local API auth, collection, global, and jobs operations now default to
`overrideAccess: false`.
- First-party calls that need the previous behavior pass
`overrideAccess: true` explicitly.
- The trusted CLI keeps its existing behavior through explicit
`overrideAccess: true` calls.
- REST and GraphQL behavior is unchanged; both already enforce access
control.
- The migration guide, Payload skill, jobs documentation, and examples
describe the new default.

## Migration

For a Payload 3 to 4 upgrade, run this from the project root:

```bash
npx @payloadcms/codemod upgrade
```

`upgrade run` is the mechanical step in the upgrade flow. It installs
Payload 4 and applies all registered transforms, including
`add-override-access-true`. A separate codemod run is unnecessary when
you complete this step.

If you manage the upgrade yourself, run this transform after upgrading:

```bash
npx @payloadcms/codemod --transform add-override-access-true
```

Review each inserted `true`. For calls on behalf of a user, use
`overrideAccess: false` and pass the request or authenticated user. The
transform skips argument objects with spreads and calls it cannot
identify as Payload Local API calls. Review aliases, casts, and
nonliteral arguments manually.

## Review notes

The first-party call-site updates are already on `main` through #17859
and #17861. This PR includes the documentation work from #17873.
Access-control integration tests and codemod tests cover the changed
default and migration behavior.

---------

Co-authored-by: Jake Fletcher <jacobsfletch@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants