GET /master takes VIEW_NOTES, like every other read here

FixKBService
Name
lúc 00:49 28 tháng 8, 2026 UTC
Tác giả
Kamo
Cam kết
8dd52ec

It was the one read in this controller that took no right, deliberately: the two master notes were called fixtures of the home launchpad rather than the Notes app, so "every member always has one" was read as every member SEES one. What that produced was a member whose role withholds the Notes app — no icon, no /notes page, every other endpoint here refusing them — opening their home page onto their own master note and the organisation's, with no way to reach either anywhere else in the product. That is the same shape as the bug the 2026-08-14 pass fixed for the other ten endpoints, where VIEW_NOTES was enforced only by navRegistry.ts hiding the app in the browser. Provisioning is unchanged and still unconditional: the notes exist for every member from first ask and appear the day the right is granted. A member who may write the organisation's note but not read notes at all is a role misconfiguration, not a case to serve — VIEW_NOTES is the read, MANAGE_ORG_MASTER_NOTE is the write on top of it.

Mọi thay đổi

Như những gì anh thấy vận chuyển?

Mỗi một bản cập nhật này đều được tự động cập nhật trong không gian làm việc của bạn. Bắt đầu tự do và xem nó lớn lên tuần này qua tuần khác.

Bắt đầu tự do mãi mãiXem truy cập