- Shipped
- October 11, 2026 at 4:52 PM UTC
- Author
- Kamo
- Commit
- 7da7202
DisclosureLedgerController at /api/security/disclosures: GET (list), /stats (event counts per decision plus reads.WOULD_WITHHOLD, R1-19), /source/{kind}/{id} (canonicalized path) and /member/{memberId}. The session comes from OTKPreAuthFilter; no session is 401, the org comes only from the session, and every request records a REPORT/SEARCH row with resource id disclosure-ledger, allowed or refused. Filters answer 400 BAD_FILTER naming the field, BAD_SOURCE or WINDOW_TOO_LARGE. DisclosureLedgerAccess (pure) decides AUDITOR (VIEW_ACCESS_LOGS or an open god window), SUPERVISOR (a person supervising the SI, with SUPERVISE_AI_MEMBERS) or NONE; /member resolves the target in the caller's org first (404 MEMBER_NOT_FOUND) and redacts source refs on the supervisor path. PhiAuditController's boundary parsing moves, unchanged, to audit/AuditTimeBoundaries, which both controllers use.
