How to use this reference
Editorial lesson: include cleanup, cache invalidation and relationship changes in the authorization boundary, and assess state preservation on rejected operations. The maintainer says 12.1.0 moves access checks before side effects or defers effects until an authorized mutation succeeds. PR 27800 independently corroborates the ordering correction.
Before reading
- Basic server-side authorization and persistent-state concepts
Context and limits
- The maintainer lists versions before 12.1.0 as affected. The automation impact requires knowledge of the affected flow identifier; the advisory describes anonymous as well as unauthorized callers.
- The advisory reports state changes, not a production incident. It explicitly excludes content disclosure and privilege elevation; impact is confined to availability, cached state and specified attribution fields.
- Published August 5, 2026 by br41nslug; tr4ce-ju is credited as reporter. PR 27800 merged July 1, 2026. The release page displays July 1 and includes that fix; its rendered timestamp omits the year, so the review does not independently assert a full software release date.
- The advisory identifies 12.1.0 as patched but does not establish restoration of previously lost state. No in-application workaround is supplied. The resource edition date remains unknown; software chronology is recorded separately.
Sources and provenance
- Directus pre-authorization side effects advisory Directus · reviewed 2026-10-03
- Fix side effects in service overrides Directus · reviewed 2026-10-03
- Directus v12.1.0 release Directus · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.