mirror of
https://gitee.com/mateos/mateclaw.git
synced 2026-09-13 19:23:42 +08:00
- requireSessionOwnership now also checks session.kbId() == path kbId (404 on mismatch), so a research session started under one KB cannot be addressed via another KB path even when the caller's key is bound to both — defense-in-depth on top of the keyId ownership check. - Drop internal "R7" / "review #446" markers from the controller Javadoc in favour of functional wording. - Import Set/Map/concurrent types and static any() instead of inline FQNs in the new kb-open research/auth tests, per code style. |
||
|---|---|---|
| .. | ||
| auth | ||
| controller | ||
| research | ||