mirror of
https://github.com/HeyPuter/puter.git
synced 2026-10-05 03:18:30 +00:00
getShares (and stat's return_shares, which runs the same listing) gated on #assertCanManage's default 'see' mode, so any credential that could see the node got every unclaimed invite's raw email — including an app handed one file by the picker, a list-scoped token on the stat surface, and a manage delegate reading the owner's invitees. Two bounds, matching the invariant clientShare.ts already claimed: - An invite's address goes only to the item's owner and to whoever sent it, and never to an app or token. A delegate can revoke only what they issued, so withholding costs them nothing they could act on. - An app or token must hold manage reach of its own to read the listing at all; it answers for the ancestors too, which is not what being handed one file grants. tryListSharesOf turns that into an empty shares array, so stat itself keeps working. The share dialog names an unattributable invite rather than rendering a blank row with a dead revoke button. Closes PUT-1806.