* fix: require an unscoped token to read the workspace encryption key
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix: hold the encryption key's write path to the same token bar
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix: audit a workspace export only once nothing can still reject it
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* chore: carry the new audit operation into the served openapi spec
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>