paperclipai/paperclip · error
Timeline is outside this actor's authorization boundary
Error message
Timeline is outside this actor's authorization boundary
What it means
Authorization gate on GET /companies/:companyId/timeline: the 'company_scope:read' access decision for this company was denied, so the actor may not read the company-wide timeline and the route withholds it with 403.
Source
Thrown at server/src/routes/companies.ts:436
});
router.get("/:companyId/artifacts", async (req, res) => {
const companyId = req.params.companyId as string;
assertCompanyAccess(req, companyId);
const query = companyArtifactsQuerySchema.parse(req.query);
res.json(await artifacts.list(companyId, query, {
userId: query.starred && req.actor.type === "board" ? req.actor.userId : undefined,
}));
});
router.get("/:companyId/timeline", async (req, res) => {
const companyId = req.params.companyId as string;
assertCompanyAccess(req, companyId);
const companyScopeDecision = await access.decide({
actor: req.actor,
action: "company_scope:read",
resource: { type: "company", companyId },
});
if (!companyScopeDecision.allowed) {
res.status(403).json({ error: "Timeline is outside this actor's authorization boundary" });
return;
}
const query = timelineQuerySchema.parse(req.query);
const timeline = workTimelineService(db);
const result = await timeline.getTimeline({
companyId,
from: parseDateQuery(query.from, "from"),
to: parseDateQuery(query.to, "to"),
userId: query.userId,
goalId: query.goalId,
projectId: query.projectId,
issueId: query.issueId,
limit: parseIntegerQuery(query.limit, "limit"),
offset: parseIntegerQuery(query.offset, "offset"),View on GitHub (pinned to 01ad858492)
Solutions
- This is an authorization rule, not a bug: perform the action with an actor that satisfies the stated constraint (board user, the owning agent, or an in-scope resource).
- If access should be allowed, verify the actor's credentials/company scope and the resource's ownership before retrying.
Defensive patterns
Strategy: validation
When it happens
Trigger: Thrown at server/src/routes/companies.ts:404 when the library encounters an invalid state.
Common situations: See trigger scenarios.
AI-assisted analysis of paperclipai/paperclip@01ad858492 (2026-08-18).
Data as JSON: /api/errors/8a01fd556a5108f2.
Report an issue: GitHub.