mirror of
https://github.com/HeyPuter/puter.git
synced 2026-10-06 03:42:15 +00:00
- PUT-1800: gate `createWorkerSessionToken` on actor type, so an app or an access token can no longer mint an app-less, root-shaped worker session; `WorkerDriver` binds on `effectiveApp` instead of `app`. - PUT-1799: add `isAccountContext` and read it where "no app" was being read as "the account" — handler publish, events-worker listing, kv handle mint/revoke/list. A scoped API token is no longer an account session. - PUT-1802: re-authorize a durable row before its backlog drains, settling it permanently when the grant is gone. Covers an ancestor-level unshare, which the revoke settle deliberately leaves to the delivery re-check. - PUT-1803: mask the owner's absolute path out of deliveries and subscription anchors on a foreign node, the way every FS surface already does. - PUT-1804: let a revoke reach rows already suspended for a resumable reason, re-stamping them so a resume cannot hand over the held backlog. - PUT-1805: apply the subscribe path's audience gate to `/events/fetch` before the query, so a cursor can no longer count and name invisible notifications. - PUT-1807: refuse `mode: 'manage'` from any actor holding an app — inside its own AppData the ACL short-circuit would otherwise supply the reach. - PUT-1808: take the sending peer from the verified signature header rather than the request body. - PUT-1810: re-base a kv share-handle row's stored match filter on the handle, so the owner's absolute key prefix stays hidden. - PUT-1814: escape LIKE wildcards and anchor the issuer-prefix queries on a segment; anchor `manage:` stripping; reject a backslash in a share prefix; assert a resolved actor in `subscribeDurable`. - PUT-1815: bound the char/varchar columns behind `event_subscriptions` and `kv_share_handles` at the store layer.