Who has opened this shared copy, and when
The disclosure audit at the home where the shared copy lives, addressed by the share id its reads are addressed by. IT IS THE SAME AUDIT the session-addressed operation serves, asked from the receiving end. A copy here has no session row to ask about, so a read of it is recorded against the share and read back by it. THE PAGE IS THIS COPY’S ALONE and carries no access to any other, which is where it differs from the session-addressed road: who may read a copy here is decided against the share the caller named, so the page is keyed by that same share. A home holding two copies of one conversation keeps two audits, and reading one says nothing about the other. WHO MAY READ IT IS NARROWER THAN WHO MAY READ THE CONVERSATION. Whoever published the share reads the list, and so does a member administering the organisation; everybody else is refused, the holder of sessions:read-private included, because a list of everyone who has read a conversation is a statement about people rather than about the work. A REVOKED SHARE STILL ANSWERS, which is what the tombstone is for: revoking deletes the conversation and leaves standing the history of who had read it. No retention window reaches these rows. Reading the audit is not itself recorded.
Autorizaciones
Enforced on every transport, with no exempt operation. A person's request — over the default local unix socket exactly as over a TCP listener — must carry a JWT issued by the configured identity provider, which the host verifies itself against that issuer's key set: signature, issuer, expiry, and the person and organisation it names. Requests without a valid one receive 401 NRY-0011. The socket's file permissions are transport and are not an authorisation.
Parámetros de ruta
The share's id, as SessionShare.shareId reports it: 26 characters of RFC 4648 base32 drawn from a cryptographic source, carrying no encoding of anything. It is NOT a uuid and is deliberately unrelated to the session id it was published from — a share id travels, so an id derived from a session would make every leaked link a statement about the machine it came from.
26^[A-Z2-7]{26}$Parámetros de consulta
Opaque pagination cursor from a previous page's nextCursor or prevCursor.
1024Maximum items per page.
1 <= x <= 100Respuesta
One page of the audit, newest first.
One page of a shared session's audit, newest first. An EMPTY page never means the audit is unavailable: a home that cannot read its own audit answers 500 rather than an empty list.
x >= 1The position the next page starts from, present only when this home holds an older entry. There is no prevCursor: the audit is append-only and read backwards from the newest, so the page a client came from is the one it already has.

