## Summary
- Infer genlocke visibility from the first leg's run visibility (public/private)
- Add ownership checks on genlocke mutation endpoints via the first leg's run owner
- Filter private genlockes from list/detail views for non-owners
**Note:** This PR targets `feature/enforce-run-ownership-on-all-mutation-endpoints` (#74) as it depends on the ownership enforcement changes.
## Test plan
- [ ] Verify private genlockes are hidden from non-owners in list view
- [ ] Verify private genlocke detail returns 403 for non-owners
- [ ] Verify genlocke mutations are restricted to the first leg's run owner
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Genlockes now inherit visibility from their first leg's run:
- Private runs make genlockes hidden from public listings
- All genlocke read endpoints now accept optional auth
- Returns 404 for private genlockes to non-owners
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
TheFurya
merged commit 596393d5b8 into feature/enforce-run-ownership-on-all-mutation-endpoints2026-03-22 09:15:20 +01:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Summary
Note: This PR targets
feature/enforce-run-ownership-on-all-mutation-endpoints(#74) as it depends on the ownership enforcement changes.Test plan
🤖 Generated with Claude Code