Clarify session visibility docs after view-all-off tightening.
Some checks failed
ci / test (push) Has been cancelled
ci / test-postgresql (push) Has been cancelled

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
oliver 2026-09-16 23:52:33 +08:00
parent ef57e05942
commit 92a6827aef

View file

@ -386,10 +386,9 @@ function throwForbidden(code) {
/** /**
* Shared session visibility helpers (sidebar + @ mention + query reads). * Shared session visibility helpers (sidebar + @ mention + query reads).
* Visibility: * Visibility:
* - canViewAllSessions (super/fallback toggle): see all * - canViewAllSessions (admin-class preference, default on): see all
* - else: own owner stamp OR own user-workspace path * - else: own owner stamp OR own user-workspace path only
* - canViewSystemSessions (admin+): also see system/channel sessions whose cwd * (shared project / channel roots are not exposed when view-all is off)
* is outside the per-user workspace root (IM bots, harness cwd, unstamped)
*/ */
export function createSessionAccess({ export function createSessionAccess({
sessionAcl, sessionAcl,