- Shipped
- October 5, 2026 at 7:47 AM UTC
- Author
- Kamo
- Commit
- befb5c3
POST **************** now requires source MEMBER or SYSTEM (else 400 SOURCE_REQUIRED). A MEMBER line is checked by chat policy as a member's own send (open-then-send when no DM exists; the existing DM's guid for the ONE_WAY reply window), refused 403 CHAT_POLICY, and an AI sender's line is counted by the turn guard (429 AI_TURN_LIMIT). The AI's line to its own human supervisor is never counted, and passes the rules while protectManagerLine is on. A SYSTEM line (calendar notices) skips both. The handler opens no transaction: the turn limit is read first, then InternalDirectMessageWriter (@Transactional @RetryOnDbConflict) opens the DM, admits the turn, writes the line and prepares the fan-out; the announcement follows the commit. media_objs.source is written: MEMBER by member sends and Exec2Exec posts, SYSTEM by internal SYSTEM lines and the Exec2Exec welcome, SERVICE by alerts. A SYSTEM or SERVICE line is not a human turn, so it no longer resets the AI counter. The fan-out frames, the send response, its NATS frame and history rows carry source (MEMBER for a NULL row).
