SP00 T16 ruling — the AIService chain also turns logout off, and a wiring test proves the chain
SP00 T12 ruling — the administrator test also proves the service was asked
SP00 T51A rulings — dispatch tests, and the Step 7 audit carves the pre-existing internal subtrees
KamoAI internal endpoints never leave the gateway
Carves the seven KamoAI internal subtrees (master spec §7 item 13) out of the wildcard forwards, and with them the server-to-server endpoints that predate the p...
SP00 T39 ruling — the rights mirror guard also requires every AI Workforce right
The AI Workforce app and its four rights; the app-mirror guard reads Java again
Capabilities come from the shared seat rule the servers enforce
EntitlementService reads the seat facts and asks SeatCapabilityRules for the decision, then maps it onto the unchanged MemberCapabilities wire shape, so the con...
SP00 T15 ruling — AiCaller reads the platform flags through SessionPlatformFacts and never throws
SP00 Task 32 ship ruling — the sign-in check is proven from real signed-in traffic through the new gateway pods
A private inbox prefix for new services, and the LOS webhook worker is opt-in
SP00 T9 ruling — SharedRedisConfig wiring tests and an accurate helper Javadoc
Services log in to Redis with a username and password when given one
SP00 T37 ship ruling — X-Spam-Status is checked on real inbound mail
rspamd's milter_headers skips local senders by default, so an in-cluster probe is delivered DKIM-signed but never carries X-Spam-Status.
SP00 Task 36 ship ruling — the signed-in session check is proven in-pod against a live session
SP00 Task 34 ship ruling — the signing-link check runs first and sends no email
SP00 Task 8 ruling — the seat resolver fetches the organization and opens no transaction
One seat rule for the console and every service that enforces it
The resolver reads the member with its organization fetched and opens no transaction of its own, so a seat is decided correctly on a thread with no persistence ...
SP00 Task 37 rulings — rspamd pod fsGroup, bwrap image check, Redis-side ship gate
Log in to Redis as mail_rspamd
rspamd reads its password from Secret mail/rspamd-redis-auth, included into local.d/redis.conf. The pod gains fsGroup 11333: the image runs as 11333:11333 and a...
SP00 Task 36 ruling — the session check's Redis login is pinned to the Secret's key names
SP00 Task 34 ruling — the signer's turbo env declares the Redis username
Redis login
The signer's session store logs in to Redis as the platform ACL user (Secret redis-auth: REDIS_USERNAME, REDIS_PASSWORD), so it keeps working when the open defa...
Like what you see shipping?
All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.
