mirror of
https://github.com/HeyPuter/puter.git
synced 2026-09-15 09:45:54 +00:00
An actor holding an app reads the `app-user` rows naming that app, plus its `developer` rows when the holder owns it. `account` rows reach no app, and a slice an actor may not see comes back empty rather than refused. The audience predicate becomes the enforced read path in the same change that lifts the blanket app-actor 403, layered behind an audience/app_uid SQL scope; two-segment `notif:` subjects expand server-side from the actor's own app, so an app can never name another app's uid. No feature flag: `audience` defaults to 'account', so every pre-registry row is default-denied to app actors and the backfill can only narrow.