PLAN_REDESIGNS section 1.
- Every sync reads the store (perm.inventory), reconciles it against the
site's record and its ledger, and pushes. A change made in the game is
settled by the server's policy (D161): auto-adopt (default), adopt, or
revoke. The first read of a server imports everything (D198).
- Groups belong to one server unless an admin shares them (D189), in new
id-keyed tables; the old ones are copied once at boot and left unread.
Holders may be a Steam account nobody linked (D188).
- An in-game change affects that server only (D190): a grant that reaches
further gains an exception, a shared group is split.
- Never judged: a permission the server does not register right now (an
unloaded plugin is not a revocation), and a pair an event lease holds.
- A new admin API (server view, grant/revoke with everywhere-or-here,
groups by id, share/split, members, drift answers) and a screen on
PermissionsManager's flow with a state on every toggle (D162, D163, U-1).
- The announcement voice names a group by id; old name settings still read.
Walked on both rigs against the walk core: import on an existing install,
auto-adopt of a grant and a revoke, a fleet grant's exception, Kits
unloaded without loss, a shared group split, adopt and revoke policies.
Server 420/420, client 58/58, swagger, imports and route manifest current.
Refs #21
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01E14m6SuuY6i1vASFeGDBeY