Problem
A guessed stream ID or alternate endpoint can expose or mutate a stream outside the caller's sender or recipient scope.
Objective
Deliver a production-quality improvement to stream access control and route/service boundaries that creates measurable value for correctness, security, reliability, performance, or maintainability.
Implementation scope
- Centralize ownership and participant policy at the service layer; cover list, detail, update, cancel, and withdraw paths; prevent enumeration.
Acceptance criteria
- Only permitted participants can access each action; unauthorized responses do not reveal existence; privileged access is explicit and audited.
Required validation
- Authorization matrix and API integration tests across sender, recipient, unrelated actor, and operator roles.
- Existing tests and CI remain passing.
- Add regression coverage for the original failure mode.
- Do not weaken, delete, or skip unrelated tests to obtain a green build.
PR quality bar
- Keep the PR focused and explain design tradeoffs, compatibility impact, and test evidence.
- Avoid typo-only, documentation-only, cosmetic-only, or unrelated refactor submissions.
Out of scope
- Broad rewrites not required by the acceptance criteria.
- Changes to unrelated services, contracts, or user flows.
Problem
A guessed stream ID or alternate endpoint can expose or mutate a stream outside the caller's sender or recipient scope.
Objective
Deliver a production-quality improvement to stream access control and route/service boundaries that creates measurable value for correctness, security, reliability, performance, or maintainability.
Implementation scope
Acceptance criteria
Required validation
PR quality bar
Out of scope