From 6b4da6326186c57c53909a52290743686f91ea1e Mon Sep 17 00:00:00 2001 From: jochen Date: Sun, 4 Oct 2026 02:50:02 +0200 Subject: [PATCH] Research 024: the composed grants, checked against a server once built --- .../024-state-a-module-keeps-on-the-bus/00-overview.md | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/01-RESEARCH/024-state-a-module-keeps-on-the-bus/00-overview.md b/01-RESEARCH/024-state-a-module-keeps-on-the-bus/00-overview.md index 036d1cd..91bc89e 100644 --- a/01-RESEARCH/024-state-a-module-keeps-on-the-bus/00-overview.md +++ b/01-RESEARCH/024-state-a-module-keeps-on-the-bus/00-overview.md @@ -69,6 +69,11 @@ an unrestricted user and used by two users holding only the subjects below (`B` | stop a watch cleanly | `$JS.API.CONSUMER.DELETE.KV_B.>` | yes | yes | | answers | its own inbox, which every principal already subscribes | — | — | +*Checked again once built, 2026-10-04:* the grants the controller composes for two machines' runtimes — +one carrying the owner, one only a reader — were loaded into a server as composed, and each operation +was run as each runtime's user. The owner's did all of them; the reader's read, listed and watched, +and its put and delete were refused by the server. + Three things the measurement showed that reading the documentation would not have: 1. **A refused put is not an error to the caller; it is a timeout.** The server reports the