- Shipped
- September 28, 2026 at 10:11 AM UTC
- Author
- Kamo
- Commit
- 1048ea9
PUT /api/security/leads/{id} and POST /api/security/media/posts checked only the lead's organization, so a member without VIEW_UNASSIGNED_LEADS could change the status of, or post a note on, an unassigned lead the lead page refuses to open. Both now apply the lead GET's per-lead read rule (assigned to anyone, VIEW_UNASSIGNED_LEADS, a free-for-all product, or god), and so does the lead's GET /feed?leadId=, which also stops making a stream for it. The Tool Plane's status and note tools come through these doors as their member and are held to the same rule (SP98-C-6). A guid-addressed comment, like or read now serves only a POST session made in the caller's own organization. Before, any signed-in member who knew a guid could write into any session: another organization's feed, a chat, a system bug. Anything else answers 404. A note on a lead now reaches its author's accept gate. The publish sat after the lead branch's early return, so it never ran.
