The live shares of this session, and who each one is for
What this session has been published as, from the publishing end: one row per share that is still live, carrying who it is for.
IT IS THE WAY IN TO CHANGING THAT AUDIENCE. A share is retargeted by its id (PUT /v1/shares/{shareId}/recipients) and a person has a conversation rather than a 26-character id, so this is where a client learns which shares exist and what each one currently names. A client holds no share id of its own between runs and derives nothing.
REVOKED AND EXPIRED SHARES ARE NOT HERE. Their entries have been deleted and their audience can never change again, so a row for one would be an offer to retarget a conversation that no longer exists.
WHO MAY READ IT is narrower than who may read the session: whoever opened the session, or a member carrying members:manage. A colleague who may read the conversation may not read the list of the colleagues it was addressed to — that list is a statement about people rather than about the work, which is the line the disclosure audit beside it already holds and the reason a recipient’s own read of a copy never reports who else was named. A caller who may not is answered 403 NRY-0028.
A SHARE THIS CALLER MAY NOT CHANGE IS NOT HERE EITHER, so no row is ever offered that PUT /v1/shares/{shareId}/recipients would refuse. The rows are the shares this caller may settle: their own, and every one of them for a member carrying members:manage. A session somebody ELSE published — which an unmarked session allows, since it is the organisation’s already — therefore lists nothing for the person whose session it is, rather than a row naming the colleagues another member addressed their work to. An empty list is “nothing here for you to change” and not “this was never published”.
Autorizações
Enforced on every transport, with no exempt operation. A person's request — over the default local unix socket exactly as over a TCP listener — must carry a JWT issued by the configured identity provider, which the host verifies itself against that issuer's key set: signature, issuer, expiry, and the person and organisation it names. Requests without a valid one receive 401 NRY-0011. The socket's file permissions are transport and are not an authorisation.
Parâmetros de caminho
The session's id.
Resposta
The live shares of this session, newest first.
The live shares of one session, newest first. NO CURSOR AND NO LIMIT. A session is published once, occasionally twice, and every row is one a person may act on — so paging here would be a mechanism guarding a list that is already short.

