style.css gains the classes the views spelled out in full: .section-label
(17 sites), .hint (20), .form-error (13), .alert-error (5), .row-card (5),
.list-empty (5), .field (5), .page-shell (3), and the small row action
.btn-sm (4) / .btn-sm-danger (3). Only exact runs moved, so nothing renders
differently; spacing a site adds beyond a run stays a utility beside it.
Kept: the Reminders and Timeline small buttons. They carry no text colour
and inherit it, so putting them on .btn-sm would recolour them.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The Share dialog lists people and groups in one picker and shows a group share
as its name and member count. Settings gains a Groups section for the admin:
create, rename, delete, and add or remove people.
The core client reads the directory's groups and group shares (ShareTarget:
a member or a group); the desktop command takes user_id or group_id.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The ACL has gated every read since M0, but nothing could write a share.
Server:
- shares_api: GET /api/users/directory (everyone but you, signed-in only),
GET/POST /api/notes/<id>/shares and DELETE …/shares/<share_id>, owner
only. Sharing again with the same person changes the permission
(ON CONFLICT on the new unique index).
- acl.visible_to_user takes permission=; granted_to and shared_ids feed
the serializer.
- Edit covers body and checklist (_get_editable). Everything else stays
_get_owned. A view share's write is a 404 like a stranger's (#1984). An
editor's PATCH naming anything but body is a 403.
- Serialized notes carry permission, shared and shared_by. A recipient
never gets the owner's labels, and a #tag an editor types files under
the owner's (it always went to note.owner_id).
- ?shared=with_me, also allowed in saved views. Trash and reminders are the
owner's. purge_note drops the note's shares.
- Migration 0034: one share per note and person (and per group), permission
limited to view and edit, an index for "shared with me".
Web:
- ShareDialog (one, mounted by the shell): pick a member, Can view or Can
edit, change or remove existing shares, with loading, error and empty
states.
- Card: "Shared by X" or "Shared" chip; owner-only actions and reminder
buttons hidden for recipients; checkboxes inert at view.
- Editor: read-only at view; text and checklist only at edit; Share button
for the owner.
- FilterBar: Shared with me. Repo seam gains `shares`; the offline desktop
shows none of it (#5175 brings sharing there).
Tests: owner, recipient and stranger across reads, every write at view and
edit, tag filing, unshare, trash, delete and validation; web unit tests for
the facet and permission helpers. #5174.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>