RAES-native ready ranges project declared participant access using canonical member keys such as provision.node.synthetic-workstation#0. The participant API exposes that key, but the terminal browser URL, WebSocket route, temporary-account boundary, and ownership lookup currently accept only legacy UUID-backed instances. The terminal therefore fails before SSH begins.
Acceptance:
- URL-encode the target as one path segment in the browser.
- Admit only the closed UUID-or-canonical-RAES-member grammar at both routing and the temporary-account WebSocket boundary.
- Resolve ownership for RAES members persisted on the owning active range while retaining the legacy interpreted-instance path.
- Cover the frontend URL, route, account boundary, ownership, and rejection of non-canonical member keys.
- Keep authorization, workspace checks, and declared participant-channel checks fail-closed.
RAES-native ready ranges project declared participant access using canonical member keys such as
provision.node.synthetic-workstation#0. The participant API exposes that key, but the terminal browser URL, WebSocket route, temporary-account boundary, and ownership lookup currently accept only legacy UUID-backed instances. The terminal therefore fails before SSH begins.Acceptance: