- Shipped
- October 5, 2026 at 7:15 AM UTC
- Author
- Kamo
- Commit
- 7360ed2
GET /api/notes/members/{memberId}, .../{noteId} and .../{noteId}/versions now record the read after it succeeds, through the shared PhiAccessRecorder: one LIST row per note listed (one recordAll batch), one VIEW row for a note or its history; resourceType NOTE, the caller's org and member, purposeOfUse OPERATIONS, justification **************** A refused read (403, 404) or an empty list writes nothing; VIEW and LIST fail open, so a write failure never reaches the supervisor's answer. kbservice gains its PHI writer: PhiAuditPersistenceConfig declares **************** with destroyMethod shutdown, and KBServiceApplication scans com.kamo.z.shared.phi.audit in the same commit (the 2026-08-03 lesson; KbPhiAuditWiringTest holds the two together). The audit stamps occurredAt itself: PhiAccessRecorder rebuilds an unstamped event without its purposeOfUse.
