Research 024: the composed grants, checked against a server once built

This commit is contained in:
jochen
2026-10-04 02:50:02 +02:00
parent e1b0bbde91
commit 6b4da63261
@@ -69,6 +69,11 @@ an unrestricted user and used by two users holding only the subjects below (`B`
| stop a watch cleanly | `$JS.API.CONSUMER.DELETE.KV_B.>` | yes | yes |
| answers | its own inbox, which every principal already subscribes | — | — |
*Checked again once built, 2026-10-04:* the grants the controller composes for two machines' runtimes —
one carrying the owner, one only a reader — were loaded into a server as composed, and each operation
was run as each runtime's user. The owner's did all of them; the reader's read, listed and watched,
and its put and delete were refused by the server.
Three things the measurement showed that reading the documentation would not have:
1. **A refused put is not an error to the caller; it is a timeout.** The server reports the