docs(plans): name the membership predicate the server actually calls - #1951
Merged
Merged
Conversation
Wren (74721): five lines in the connector plans state the server's rule in the
present tense and name `isPodMember` — the creator-inclusive spelling, which is
what those pages were written against and which no enforcement site calls any
more. Retargeted to `isListedPodMember`, the predicate every gate in
`routes/integrations.ts`, `installables.ts`, `podInvites.ts`, `activity.ts` and
the bridges actually calls.
- d8-phase-2-gate-surface.md:92 — a gate key must name a pod the owner is a member of
- d8-phase-2-gate-surface.md:94 — the install verb, a gate key and `PATCH { podId }` all check it
- connector-as-installable-app.md:346, :381, :385 — the write gate, the chosen pod, the target derivation
Kept as history, per the ruling: connector-as-installable-app.md:224 (Vera,
2026-09-02, describing what the old gate did) and the AX-audit entry that records
the two-functions-one-name collision.
Not a safety fix and not sold as one: a stale identifier in prose fails loudly —
a bare `require(...)()` throws, a destructured name is `undefined` and then
throws — so nothing here was silently permissive. What was wrong is narrower and
worth fixing: d8:94's "the list shows exactly what the server would accept" was
false while the creator clause counted as membership, and the page now names the
rule that makes it true.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Wren's ruling from 74721. Five lines across the two connector plans state the server's rule in the present tense and name
isPodMember— the creator-inclusive spelling those pages were written against, and one that no enforcement site calls any more.Retargeted to
isListedPodMemberdocs/plans/d8-phase-2-gate-surface.md:92docs/plans/d8-phase-2-gate-surface.md:94PATCH { podId }all check it "and nothing else"docs/plans/connector-as-installable-app.md:346isPodMember(pod, installer)— the #1297 write gate, reuseddocs/plans/connector-as-installable-app.md:381docs/plans/connector-as-installable-app.md:385The name is real on
maintoday and is the one the gates call:routes/integrations.ts,routes/installables.ts,routes/podInvites.ts,routes/activity.ts,controllers/pgMessageController.ts,server.ts,services/connectorRelayPolicy.tsand the bridges all destructureisListedPodMemberfromutils/isPodMember. The permissiveisPodMemberis still exported onmainwith zero production callers; #1949 deletes it. So this docs change is consistent before or after that merge.Left as history, per the ruling
docs/plans/connector-as-installable-app.md:224— "gated the pod byisPodMemberwhile uninstall had no matching gate" (Vera, 2026-09-02). Past tense, describing what the old gate did.docs/development/agent-experience-audit.md:3988— the entry that records the two-functions-one-name collision. It is the record of the old name, and it stays.What this is and is not
Not a safety fix, and the body should not claim one. A stale identifier in prose fails loudly:
require('./utils/isPodMember')()throws, and a destructuredisPodMemberisundefinedand then throws. Nothing here was silently permissive — which is Vera's argument (74719) for not spending a PR on the name alone, and it is why this PR does not add a guard for doc prose.What was actually wrong is narrower:
d8:94's claim that the pod list "shows exactly what the server would accept" was false while the creator clause counted as membership, because the list is built frompod.membersand the gate accepted one more principal. The page now names the rule that makes its own sentence true.Witness:
__tests__/unit/scripts/docReferences.test.js6/6 — that suite deliberately excludesdocs/prose (its own header says docs are the docs room's inventory), so I am recording that no automated arm covers these five lines rather than implying one does. The referenced symbol's existence is asserted by #1949's export-shape arm, not by this PR.One judgement disclosed: no "renamed from
isPodMember" note was added beside the new name. The old spelling stays discoverable in the two history lines above, and the plans are dated records rather than a learning surface.