mirror of
https://github.com/HeyPuter/puter.git
synced 2026-10-02 09:58:16 +00:00
CI caught three HTTP-level tests the earlier merge left behind, and they were right to fail: dropping this branch's `manage` gate in favour of main's row filter lost a case main's filter does not cover. Main bounds an app to the rows it issued. A *scoped* access token is not an app, so it was falling through unbounded — `/fs/stat` with `return_shares` handed a `fs:<uid>:list` token the owner's whole share list. Addresses stayed withheld, but who else can reach a file is no more a narrow token's business than the addresses are. So the filter is generalised rather than the gate restored: a scoped token is bounded to nothing, since it issues nothing under its own name. Filtering it by a null app would have been worse than not filtering — that matches the owner's own rows. Apps and sessions behave exactly as they do on main, and a full-access token still holds the account's reach. The three tests now assert the answer instead of a refusal, including the one whose name had always promised a refusal its body never checked.