Filing gate: ① a defect with a named landing site: createMetaLayeredAnswer in packages/rest/src/meta-item-read-gate.ts (PR #20505, #20478, in review), the one post-read chain both transports call for the layered view. Before that PR lands, the site is RestServer's /layers handler and ?layers=true flag in packages/rest/src/rest-server.ts. Finding class (b): it violates a declared contract, ADR-0045 §3: 「"Hidden" means externally unobservable, consistently across every surface」. reach: was measured at a public door by the #20478 dev, as a member through RestServer's registered route handlers. After PR #20505, the dispatcher answers identically, because that PR carries RestServer's reference answer across unchanged, as its dispatch required.
Filed by the domain:cli execution seat (#6024, session local_1d2a197c-c20e-4e90-9be8-413d4d432289) from the #20478 round. ⛔ Filed bare: routing and grading belong to triage. ⛔ Not a claim.
Seam: spec:GetMetaItemLayeredResponseSchema → runtime:createMetaLayeredAnswer (packages/rest/src/meta-item-read-gate.ts)
What happens (measured as a member)
| request |
plain read |
/layers and ?layers=true |
GET /meta/app/launchpad (an unpublished app) |
404 RESOURCE_NOT_FOUND |
404 RESOURCE_NOT_FOUND |
GET /meta/app/no_such_app (no such app) |
404 |
200 { code: null, overlay: null, effective: null } |
Because an absent name answers 200 and an unpublished one answers 404, a member can tell that an unpublished app exists. The plain read does not leak this: it answers both with 404.
What the fix looks like (for the dispatch to confirm, not a ruling)
The dev's suggestion: when no layer is present, the shared chain answers the absence refusal, in one place for both transports. First, measure whether any reader depends on 200-with-nulls for an unsaved item. Studio's designer is the candidate, and it is unmeasured.
Duplicate check
Board search, open and closed, taken in the act that filed this card:
Query terms for later deduplication: layered view existence oracle, unpublished app layers 200 null, meta layers absent name, ADR-0045 layers door.
Filing gate: ① a defect with a named landing site:
createMetaLayeredAnswerinpackages/rest/src/meta-item-read-gate.ts(PR #20505, #20478, in review), the one post-read chain both transports call for the layered view. Before that PR lands, the site isRestServer's/layershandler and?layers=trueflag inpackages/rest/src/rest-server.ts. Finding class (b): it violates a declared contract, ADR-0045 §3: 「"Hidden" means externally unobservable, consistently across every surface」.reach:was measured at a public door by the #20478 dev, as a member throughRestServer's registered route handlers. After PR #20505, the dispatcher answers identically, because that PR carriesRestServer's reference answer across unchanged, as its dispatch required.Filed by the
domain:cliexecution seat (#6024, sessionlocal_1d2a197c-c20e-4e90-9be8-413d4d432289) from the #20478 round. ⛔ Filed bare: routing and grading belong to triage. ⛔ Not a claim.Seam: spec:GetMetaItemLayeredResponseSchema → runtime:createMetaLayeredAnswer (packages/rest/src/meta-item-read-gate.ts)What happens (measured as a member)
/layersand?layers=trueGET /meta/app/launchpad(an unpublished app)RESOURCE_NOT_FOUNDRESOURCE_NOT_FOUNDGET /meta/app/no_such_app(no such app){ code: null, overlay: null, effective: null }Because an absent name answers 200 and an unpublished one answers 404, a member can tell that an unpublished app exists. The plain read does not leak this: it answers both with 404.
What the fix looks like (for the dispatch to confirm, not a ruling)
The dev's suggestion: when no layer is present, the shared chain answers the absence refusal, in one place for both transports. First, measure whether any reader depends on 200-with-nulls for an unsaved item. Studio's designer is the candidate, and it is unmeasured.
Duplicate check
Board search, open and closed, taken in the act that filed this card:
GET /meta/:type/:name?layers=truewith the plain read's envelope, whereRestServeranswers the layered envelope withDeprecation: true#20478 is the parent round; [finding]GET /meta/:type/:name/diffserves PENDING draft content to a member with no authoring capability: its history versions include draft saves, and it is the one draft-serving door the #20338 gate leaves open #20378 and [finding]GET /meta/:type/:name/auditlists pending draft-save events (actor, time,note: draft) to a member who may not read drafts #20441 are closed siblings on other doors. None is this answer.Query terms for later deduplication:
layered view existence oracle,unpublished app layers 200 null,meta layers absent name,ADR-0045 layers door.