From 92a6827aef2196c066b05738fa9c5b6b9782bae7 Mon Sep 17 00:00:00 2001 From: oliver Date: Wed, 16 Sep 2026 23:52:33 +0800 Subject: [PATCH] Clarify session visibility docs after view-all-off tightening. Co-authored-by: Cursor --- uds-auth/lib/dsh-acl.js | 7 +++---- 1 file changed, 3 insertions(+), 4 deletions(-) diff --git a/uds-auth/lib/dsh-acl.js b/uds-auth/lib/dsh-acl.js index bfb8596b..25dd2e2e 100644 --- a/uds-auth/lib/dsh-acl.js +++ b/uds-auth/lib/dsh-acl.js @@ -386,10 +386,9 @@ function throwForbidden(code) { /** * Shared session visibility helpers (sidebar + @ mention + query reads). * Visibility: - * - canViewAllSessions (super/fallback toggle): see all - * - else: own owner stamp OR own user-workspace path - * - canViewSystemSessions (admin+): also see system/channel sessions whose cwd - * is outside the per-user workspace root (IM bots, harness cwd, unstamped) + * - canViewAllSessions (admin-class preference, default on): see all + * - else: own owner stamp OR own user-workspace path only + * (shared project / channel roots are not exposed when view-all is off) */ export function createSessionAccess({ sessionAcl,