vulns.co
/
GKData.io MCP

Conceptual model · 1 min read

Combined views preserve every source's access boundary

Original conceptual model for a view that requires multiple independently protected sources. Permission to use one source cannot authorize another source. The convergence is an AND requirement: both source decisions must permit the requesting actor before composition. GitHub’s comparison disclosure supports the cross-repository boundary; Frappe’s linked-document disclosure supports independent document permissions and field selection. OWASP provides the general per-request and deny-by-default guidance. The graph assumes an all-or-nothing response contract. Applications supporting partial results need a separately specified non-disclosing omission policy. Field selection remains a distinct requirement even when every source check permits access. This is not either vendor’s architecture or patch implementation. Snapshot consistency, permission-change races and inference from combined values are outside this model.

The conceptual model

A caller requests a combined view using required source A and required source B. Each source has its own authorization decision for that caller. Either No denies the combined view without protected source data. Both Yes decisions are required at an explicit AND gate before composition. Field selection preserves each source’s field permissions, and only permitted data is returned.
A caller requests a combined view using required source A and required source B. Each source has its own authorization decision for that caller. Either No denies the combined view without protected source data. Both Yes decisions are required at an explicit AND gate before composition. Field selection preserves each source’s field permissions, and only permitted data is returned.

Cases and references behind the model

Sources and provenance

  1. docs.github.com Primary source
  2. securitylab.github.com Primary source
  3. cheatsheetseries.owasp.org Primary source

Record reviewed 2026-10-04. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software