Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Server administrators currently cannot discover private channels they have not joined. Adds
GET /api/community/servers/{id}/channels/adminso Server Settings can show every top-level text/forum with its group, name, creator handle/name, and creation time.The human-only route checks current server admin/owner membership on a primary D1 session. The query independently scopes by server and admin membership, excludes threads/DMs, and selects only display metadata. Responses use
Cache-Control: private, no-store; existing sidebar visibility and private-message access remain unchanged. No migration or dependencies.Validation: 29 focused directory/access tests, repository typecheck/lint/tests and bind-contract/typegrep/knip checks passed. Local browser/API QA passed on exact commit
f0e639c2f307b369bb4d0297f36b23b3d5229adb: both owner/admin responses matched 7 local D1 metadata rows; member/outsider/cross-server/bot were denied, anonymous was 401, same-session role downgrade was immediately denied, existing private sidebar/messages remained inaccessible, and complete membership/read-state snapshots were unchanged. Null/deleted creators, thread/DM exclusion, and no-store headers were verified.Frontend integration and the combined lazy-loading/settings-page QA remain in Alook task #152; this PR is the backend portion and should merge only after that combined verification.
Added lines: 238 total; 59 application code, 171 tests and 8 bind-strategy manifest entries. One existing import line replaced.