You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Say in the forum list what a caller may do in each forum (#17)
A client could not tell a feed-only forum from an ordinary one until it tried to
post into it. `news` on bbs.hqtui.com is `memberPosting: 'replies'`, so a new
topic there answers 403, and `GET /api/v1/forums` described it exactly as it
described `announcements`. A posting client therefore discovered the difference
in public, which is what happened to myna's release announcement.
The board already knew: `resolvePermissions` resolves `canPost` per viewer and
`forum.isLocked` sits beside it, and the write route checks both. So the tree
now carries `canPost` and `canReply` for the viewer it was built for, resolved
by that same function, and both `/api/v1/forums` and `/api/v1/board` return them
along with the forum's own `locked` flag. A category is never postable: it holds
forums, not topics.
The test asserts the claim against the write route in the same run, posting to a
reply-only forum for the 403 and to an ordinary one for the 201. A permission
hint that can drift from the thing it describes is worse than no hint.
Claude-Session: https://claude.ai/code/session_011XqFUXQkK6npCGxBtgizQg
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
summary: 'The same forums, flattened, with a depth on each.',
93
-
responses: {'200': json('A flat list of forums.')},
93
+
description:
94
+
'Each forum carries canPost and canReply for the caller: whether this token may start a topic here and whether it may reply, resolved exactly as the write routes resolve it, so a feed-only forum, a locked one, or one above the caller\'s rank can be told apart before a post is attempted rather than by being refused. `locked` is the forum\'s own flag. A category is never postable.',
95
+
responses: {'200': json('A flat list of forums, each with what the caller may do in it.')},
0 commit comments