Environment
- mxcli: built from
main @ 95091765 (v0.24.0-165-g95091765), 2026-09-27. First seen on v0.23.0.
- Mendix / mxbuild: 11.12.2, blank app from
mx create-project (MPR v2)
- OS: macOS (Darwin 25.6, arm64)
Reproduction
Same setup as #1223, plus:
create association "ModA"."Tag_GuestGroup"
from "ModA"."Tag" to "ModA"."GuestGroup"
type Reference;
grant "ModA"."User" on "ModA"."Tag" (read *, write *);
After this, show access on entity "ModA"."Tag" shows ModA.Tag.Label: ReadWrite and ModA.Tag_GuestGroup: ReadWrite for ModA.User.
Each row below starts from a fresh copy:
| Statement |
mxcli output |
Member rights afterwards |
revoke "ModA"."User" on "ModA"."Tag" (write ("Label")); (attribute, control) |
Revoked partial access on ModA.Tag from ModA.User |
Label: ReadOnly ✓ |
revoke "ModA"."User" on "ModA"."Tag" (write ("Tag_GuestGroup")); |
No access rules found matching ModA.User on ModA.Tag, exit 0 |
Tag_GuestGroup: ReadWrite (unchanged) |
revoke "ModA"."User" on "ModA"."Tag" (write ("ModA"."Tag_GuestGroup")); |
Parse error: line 1:51 mismatched input '.' expecting {',', ')'} |
not applied |
check --references passes the second statement.
Expected
The association's member right drops to ReadOnly, as the attribute's does. Failing that, an error saying association members cannot be revoked individually. Not exit 0.
Actual
A message claiming the rule does not exist, although the attribute revoke on the same rule finds it. Nothing changes. Scripts that rely on the exit code carry on as if it worked.
Workaround: re-grant the whole rule with the member list you want.
Related: #947 (closed; grant replaced the member list instead of merging).
Environment
main@95091765(v0.24.0-165-g95091765), 2026-09-27. First seen on v0.23.0.mx create-project(MPR v2)Reproduction
Same setup as #1223, plus:
After this,
show access on entity "ModA"."Tag"showsModA.Tag.Label: ReadWriteandModA.Tag_GuestGroup: ReadWriteforModA.User.Each row below starts from a fresh copy:
revoke "ModA"."User" on "ModA"."Tag" (write ("Label"));(attribute, control)Revoked partial access on ModA.Tag from ModA.UserLabel: ReadOnly✓revoke "ModA"."User" on "ModA"."Tag" (write ("Tag_GuestGroup"));No access rules found matching ModA.User on ModA.Tag, exit 0Tag_GuestGroup: ReadWrite(unchanged)revoke "ModA"."User" on "ModA"."Tag" (write ("ModA"."Tag_GuestGroup"));Parse error: line 1:51 mismatched input '.' expecting {',', ')'}check --referencespasses the second statement.Expected
The association's member right drops to ReadOnly, as the attribute's does. Failing that, an error saying association members cannot be revoked individually. Not exit 0.
Actual
A message claiming the rule does not exist, although the attribute revoke on the same rule finds it. Nothing changes. Scripts that rely on the exit code carry on as if it worked.
Workaround: re-grant the whole rule with the member list you want.
Related: #947 (closed; grant replaced the member list instead of merging).