You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Filed by the PM dispatch loop on behalf of the #15352 round (PR #16017), which measured it but deliberately did not file it — it is family-wide rather than that card's, and the REST search endpoint is refused in that container, so it could not dedupe. ⛔ Filing blind is the one failure mode the dedupe rule exists to stop. ⛔ Unassigned and ungraded — domain:*, type and priority are triage's.
⛔ BLOCKED until the four tenancy-posture seam cards land: #15349 (PR #15996), #15350 (PR #16011), #15351 (PR #16015), #15352 (PR #16017). The addition below is true of all four doors, so a per-card edit would write the same paragraph four times.
The page and the row
content/docs/permissions/attachments-access.mdx, the "Download — authenticated and parent-scoped" section. Its AUTH_REQUIRED (401) row reads:
Anonymous download of an attachments-scope file
⚠️ It is INCOMPLETE, not wrong — and the distinction decides the remedy
Under a wall-enforcing posture, that same 401 is now also the answer for:
an ex-member's org-stamped API key — under both isolated and group;
an organization-less key — under isolated only.
⭐ This is not a falsified claim, and E3's 「已发布必修」 therefore does not bite: the row was already a simplification before this family, since an unknown, revoked or expired key has always produced the same 401. So the work is an addition, not a correction. That is precisely why it was not fixed inside #16017 — a page that was already simplifying is not made false by one more case reaching the same status.
Why one card rather than four
The four repaired doors (plugin-sharing share-link admission, service-datasource admin routes, service-settings manifest gate, service-storage file read) now share this behaviour. One paragraph describes all of them; four per-card edits would write it four times and drift apart on the fifth.
⚠️ Measure before writing — the four doors do NOT agree on everything
Two readings from the family that a docs edit must not flatten:
The page was read in full (141 lines) by the #15352 round precisely because it is the drift check's declared blind spot — it documents this door by its inputs, and an emitter-only diff can never list it. Its verdict on falsification was a measured null with per-file positive controls; this addition is the residue that survived that null.
Filed by the PM dispatch loop on behalf of the #15352 round (PR #16017), which measured it but deliberately did not file it — it is family-wide rather than that card's, and the REST search endpoint is refused in that container, so it could not dedupe. ⛔ Filing blind is the one failure mode the dedupe rule exists to stop. ⛔ Unassigned and ungraded —
domain:*, type and priority are triage's.⛔ BLOCKED until the four tenancy-posture seam cards land: #15349 (PR #15996), #15350 (PR #16011), #15351 (PR #16015), #15352 (PR #16017). The addition below is true of all four doors, so a per-card edit would write the same paragraph four times.
The page and the row
content/docs/permissions/attachments-access.mdx, the "Download — authenticated and parent-scoped" section. ItsAUTH_REQUIRED(401) row reads:Under a wall-enforcing posture, that same 401 is now also the answer for:
isolatedandgroup;isolatedonly.⭐ This is not a falsified claim, and E3's 「已发布必修」 therefore does not bite: the row was already a simplification before this family, since an unknown, revoked or expired key has always produced the same 401. So the work is an addition, not a correction. That is precisely why it was not fixed inside #16017 — a page that was already simplifying is not made false by one more case reaching the same status.
Why one card rather than four
The four repaired doors (
plugin-sharingshare-link admission,service-datasourceadmin routes,service-settingsmanifest gate,service-storagefile read) now share this behaviour. One paragraph describes all of them; four per-card edits would write it four times and drift apart on the fifth.Two readings from the family that a docs edit must not flatten:
groupis not uniform. Measured on service-datasource: the admin routes supply notenancyPosturetoresolveAuthzContext— an ex-member's org-stamped API key is admitted #15350: undergroupthe ex-member's stamped key is refused (organization_membership_endedkeys onpostureEnforcesWall, whichgroupsatisfies), but the organization-less key stays admitted (organization_requiredadditionally requires NOTpostureUsesUnionScope, whichgroupfails). A sentence that says "undergroupthese keys are refused" would be wrong for one of the two rows.service-datasourcerenders 500,service-storagerenders 403 FILE_DOWNLOAD_DENIED. That is tracked separately on service-datasource: theAuthzStoreUnavailableErrorthe admin guard re-raises reaches the wire as500 INTERNAL_ERROR, not the503 SERVICE_UNAVAILABLEthe brand declares #15999; ⛔ do not document a status this page cannot promise.Provenance
The page was read in full (141 lines) by the #15352 round precisely because it is the drift check's declared blind spot — it documents this door by its inputs, and an emitter-only diff can never list it. Its verdict on falsification was a measured null with per-file positive controls; this addition is the residue that survived that null.
Refs
#15349 · #15350 · #15351 · #15352 (the four doors) · PRs #15996 / #16011 / #16015 / #16017 · #15999 (the outage-status divergence) · #16013 (the helper extraction, also blocked on the same four)
Generated by Claude Code