Skip to content

Cross-module association with owner Both: the other module's access rules get no member entry, the build fails CE0066, and update security says all is up to date #1223

Description

@MendixMau

Environment

  • mxcli: built from main @ 95091765 (v0.24.0-165-g95091765), 2026-09-27. First seen on v0.23.0.
  • Mendix / mxbuild: 11.12.2, blank app from mx create-project (MPR v2)
  • OS: macOS (Darwin 25.6, arm64)

Summary

A Reference association between entities in two modules, created with owner Both, reconciles the access rules on the FROM side only. The TO entity's rules get no member access for the association, and mx check fails with CE0066 on the TO module. update security reports that everything is up to date and changes nothing. The same association with owner Default builds cleanly.

Reproduction

Setup (the blank app still builds with 0 errors after this):

alter project security level production;
create module "ModA";
create module "ModB";
create module role "ModA"."User";
create module role "ModB"."User";
alter user role "User" add module roles ("ModA"."User", "ModB"."User");
create persistent entity "ModA"."GuestGroup" ("Name": String(100));
create persistent entity "ModB"."App" ("Title": String(100));
create persistent entity "ModA"."Guest" ("Email": String(200), "CreatedDate": AutoCreatedDate);
create persistent entity "ModA"."Tag" ("Label": String(100));
grant "ModA"."User" on "ModA"."GuestGroup" (create, delete, read *, write *);
grant "ModA"."User" on "ModA"."Guest" (create, delete, read *, write *);
grant "ModA"."User" on "ModA"."Tag" (read *, write *);
grant "ModB"."User" on "ModB"."App" (read *, write *);

Then:

create association "ModA"."GuestGroup_App"
from "ModA"."GuestGroup" to "ModB"."App"
type Reference
owner Both;
$ mxcli check 01-owner-both.mdl -p Repro.mpr --references
Check passed!
$ mxcli exec 01-owner-both.mdl -p Repro.mpr
Reconciled 1 access rule(s) for new association
Created association: ModA.GuestGroup_App
$ mx check Repro.mpr
[error] [CE0066] "Entity access is out of date. Please update security by clicking the 'Update security' button in the domain model editor." at Domain model of module 'ModB'
The app contains: 1 errors.
$ mxcli -p Repro.mpr -c "UPDATE SECURITY"
All entity access rules are up to date
$ mx check Repro.mpr
[error] [CE0066] "Entity access is out of date. ..." at Domain model of module 'ModB'
The app contains: 1 errors.
Variant (fresh copy of the setup each time) exec mx check
owner Default, ModA → ModB Reconciled 1 access rule(s) 0 errors
owner Both, ModA → ModB Reconciled 1 access rule(s) CE0066 at ModB

Expected

With owner Both, the access rules on ModB.App also need a member entry for ModA.GuestGroup_App. exec should add it (as it does on the owner side), or update security should find and fix the gap.

Actual

Only the owner side's rule is reconciled. The far side is left without an entry, and update security does not detect it. There is no MDL workaround; we patched the unit's BSON by hand.

Severity

Build-breaking (CE0066) on Mendix 11.12.2, with no MDL route out.

Related, but not this case: #758, #1067 (closed).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions