mirror of
https://github.com/HeyPuter/puter.git
synced 2026-09-30 00:56:50 +00:00
Two textual conflicts, both additive on each side: `isAccountContext` (here) and `isPlainUserActor` (main) are both imported and both used, and the `stat()` note keeps both sentences — this branch's on who may read an invite address, main's on the share-read limit it spends. The rest is adapting to main, which grew its own answer to half of what this branch was for. `listSharesOf` there bounds an app to the rows it issued itself; this branch instead required the credential to hold `manage` and refused it otherwise. Main's is the better mechanism — it answers the app rather than turning it away, and it hides other issuers' rows outright rather than redacting a field on them — so the `manage` gate goes, and with it the two tests that asserted the refusal. They are replaced by tests that hold main's line: an app sees none of the invites it did not send, with or without `manage`. What this branch still carries is the gap main does not close. Its row filter only applies to apps, so a plain manage delegate still reads the owner's invite addresses; `#maySeeInviteAddress` is what withholds those, and its delegate tests pass unchanged. The `stat()` note is corrected to describe main's behaviour rather than the removed gate.