You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
fix(selectors): rebind Copilot principals for nested domain use cases
Selectors backed by another domain (knowledge documents, table columns,
workflows, sandboxes, MCP tools) forwarded the Copilot principal admitted
under the selector audience into use cases that accept only their own
audience. The refusal is a DelegatedWorkspaceAuthorizationError, which the
v2 surface conceals as 404, so Chat saw "Workspace not found" on workspaces
the user administers. Fork sync previews hit it whenever a saved dependent
value (a table conflict column, a knowledge document) needed validation.
Selectors now rebind through bindCopilotWorkspaceOperation, which can also
project the single resource a nested call reaches, as the executor and Chat
MCP paths do when they mint. A grant already narrowed to one resource is
never moved to another. Managed MCP connections now reach their
credential-group rule and return its 403 instead of the concealed 404.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
// permission-group-exempt: no static capability names selector browsing — credential access is authorized per credential, and per-integration denial is the parameterized allowedIntegrations key, which the funnel cannot apply because it never sees which integration a selector reaches. That decision is enforced from the use case by assertSelectorIntegrationAllowed, against the selector's own resource, ahead of the provider call.
0 commit comments