Let an observer pane fleet_send to a lead #790

Open
opened 2026-10-06 06:06:42 +02:00 by ltms · 0 comments
Owner

Operator decision 2026-10-06: "allow observer to lead send".

Problem

A hand-opened pane resolves as observer. Today Authz lets an observer SEND only to another observer (auth/Authz.java, case SEND, knownObserverTarget). So a peer session can answer a lead with fleet_reply, but it cannot start a conversation with a lead. Measured live: pm (work account, mgnl space) got forbidden: observer:term_65d10655a0b8f9 may not SEND when it sent to the lead.

Wanted

  • An observer may SEND to a lead terminal (the same set CallerResolver.knownLeadOrCollaborator() uses for leads — leads only, not collaborators, unless the review decides otherwise).
  • An observer still may NOT send to a spawned member, an architect, or a collaborator.
  • The [fleet_send from observer term_…] prefix stays on every observer send.
  • An observer can find the lead's sessionId: fleet_list's leads array (or the observer's filtered panes rows) must show lead targets to an observer.
  • The lead pane's box gate (invariant 4) still applies.

Check every gate, not just Authz

A grant at one gate of two is dead (the #669 lesson). Check the MCP path, the REST path (rest/FleetApp), the injector, and any ticket/ownership check an observer-created send passes.

Docs (lead does this after merge)

CLAUDE.md block: invariant 3, the observer paragraph in "Which role am I", the intent table row for unconfigured panes. Wiki template sync and a Features entry.

Operator decision 2026-10-06: "allow observer to lead send". ## Problem A hand-opened pane resolves as `observer`. Today `Authz` lets an observer SEND only to another observer (`auth/Authz.java`, `case SEND`, `knownObserverTarget`). So a peer session can answer a lead with `fleet_reply`, but it cannot start a conversation with a lead. Measured live: `pm` (work account, mgnl space) got `forbidden: observer:term_65d10655a0b8f9 may not SEND` when it sent to the lead. ## Wanted - An observer may SEND to a **lead** terminal (the same set `CallerResolver.knownLeadOrCollaborator()` uses for leads — leads only, not collaborators, unless the review decides otherwise). - An observer still may NOT send to a spawned member, an architect, or a collaborator. - The `[fleet_send from observer term_…]` prefix stays on every observer send. - An observer can find the lead's sessionId: `fleet_list`'s `leads` array (or the observer's filtered `panes` rows) must show lead targets to an observer. - The lead pane's box gate (invariant 4) still applies. ## Check every gate, not just Authz A grant at one gate of two is dead (the #669 lesson). Check the MCP path, the REST path (`rest/FleetApp`), the injector, and any ticket/ownership check an observer-created send passes. ## Docs (lead does this after merge) CLAUDE.md block: invariant 3, the observer paragraph in "Which role am I", the intent table row for unconfigured panes. Wiki template sync and a Features entry.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: fleet/fleetd#790