Snapshot access is decided on the snapshot, and absence answered first
The rule
Normative: this is the rule
- Reading or deleting a snapshot loads it by execution id and asks it for view or delete authority: a snapshot that does not exist is
404, one the caller may not reach is403, and absence is answered before denial. - A read that finds the record but no readable payload answers
404as well, never a partial document. - The list door does not ask per record: it narrows the query by ownership, so a snapshot belonging to another principal is absent from the list rather than a denial on it.
Rule identifiers are permanent and are never renumbered. Each implementation publishes its own standing against these rules; this specification does not.spec 1.0-draft · SNAP-2 · changed in spec 1.0