- Shipped
- September 28, 2026 at 4:51 PM UTC
- Author
- Kamo
- Commit
- eff32c0
Every note on a lead now sends the lead stream's guid on /topic/media/feed/<orgId> (SP99-T3), which any member of the organization may subscribe to. The guid-addressed post endpoints checked only the organization (SP98-T3), so a member who may not open a lead could read its first note (GET /posts/{guid}) and write notes onto it (POST /posts/{guid}/comments) - around SP98-C-6's per-lead rule. Read, comment, like, edit and delete by guid now go through one gate: a POST session of the caller's organization that is either a lead's stream the caller may open (LeadViewGate, the lead GET's rule; the lead found through media_session_post.lead_id) or the organization's own feed. Anything else - a stream detached from a deleted lead, an orphan - answers 404. createPost and LeadCallbackService now bind a new lead stream to its lead, as getFeed and LeadReassignmentNoteService already did. Production: the one lead stream made without its lead (session 724b6446-..., lead 1189894336349536262) was bound by **************** before this deploy (UPDATE 1; reversal in the file). SP99 final review I-1.
