paperclip/server
nickyleach f7cb002a1f docs(server): fix the authorization-read claim in the recovery comment
The comment said no authorization read uses the responsibleUserId
column for a queued or a cancelled run. That claim is false. The
issue-thread interaction attribution check is an authorization read.
It looks up a run with no status filter, so it can observe a queued
or a cancelled row. It denies when the caller carries a responsible
user, because a null column value never equals one. It skips that
check when the caller carries no responsible user.

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-09-10 16:43:09 +00:00
..
scripts fix(server): bundle the vendored paperclip-runner instead of hand-mirroring its deps (#13121) 2026-09-09 16:38:17 -07:00
src docs(server): fix the authorization-read claim in the recovery comment 2026-09-10 16:43:09 +00:00
CHANGELOG.md fix: bound workspace Git scans (#11572) 2026-08-17 22:11:30 -05:00
package.json fix(server): bundle the vendored paperclip-runner instead of hand-mirroring its deps (#13121) 2026-09-09 16:38:17 -07:00
tsconfig.json
…
vitest.config.ts fix(server): bundle the vendored paperclip-runner instead of hand-mirroring its deps (#13121) 2026-09-09 16:38:17 -07:00