Skip to content

docs(kanvas): sharing a design requires a signed-in account - #1275

Merged
leecalcote merged 1 commit into
masterfrom
fm/kanvas-anonymous-sign-in-to-share
Oct 6, 2026
Merged

leecalcote merged 1 commit into
masterfrom
fm/kanvas-anonymous-sign-in-to-share

Conversation

@hortison

@hortison hortison commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Description

User-facing half of the kanvas.new anonymous-user permission fix in layer5io/meshery-cloud (branch fm/kanvas-anonymous-permission-gaps, migration 20260930081500). That migration removes Share Design from the anonymous user role, so an anonymous kanvas.new visitor who chooses Share gets Kanvas's "Sign in to share design" prompt instead of the Share modal.

This page is updated to match:

  • adds an "Sharing requires an account" note under the introduction;
  • drops the figure caption that presented sharing from an anonymous session ("anonymous capture ... Owner shown as an anonymous session") as the norm. The image itself still shows the modal's controls accurately.

Merge order: merge this when the meshery-cloud release carrying migration 20260930081500 ships. Until then production still lets anonymous sessions share.

Notes for Reviewers

  • The Default Permissions page is generated from the permissions sheet, which still needs its Anonymous persona marks updated for View Workspace. It is untouched here.

Signed commits

  • Yes, I signed my commits.

Summary by CodeRabbit

  • Documentation
    • Clarified that visitors can create and edit designs on kanvas.new without signing in, but must sign in to share. Selecting Share prompts them to sign in.
    • Updated the Share modal caption.

Anonymous kanvas.new visitors no longer hold the Share Design permission;
choosing Share prompts them to sign in. Drop the caption that presented
sharing from an anonymous session as the norm.

Signed-off-by: James <160366376+hortison@users.noreply.github.com>
@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: eba14903-8c6c-4efb-82ef-76f780656942

📥 Commits

Reviewing files that changed from the base of the PR and between ccfe363 and bcbe59d.

📒 Files selected for processing (1)
  • content/en/kanvas/designer/sharing/index.md

Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review.


📝 Walkthrough

Walkthrough

The sharing guide now states that anonymous visitors can create and edit designs on kanvas.new but must sign in to share. It also updates the screenshot caption.

Changes

Designer sharing

Layer / File(s) Summary
Anonymous sharing requirements
content/en/kanvas/designer/sharing/index.md
The guide explains that anonymous visitors must sign in to share and are prompted when they choose Share. The screenshot caption no longer describes the session as anonymous.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~3 minutes

Change: Other

Suggested reviewers: banana-three-join

Merge Risk: ⚪ Minimal · up to bcbe5

This change updates sharing guidance without changing runtime permissions. No verified issue blocks merging.

Security Architecture Review

Security architecture risk: 🔵 Low · up to bcbe5

The update does not change permissions or authorization enforcement. Its sign-in guidance depends on a separate cloud release, so publication must follow that release. The available evidence does not establish whether the required change is live.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The directly affected security surface is reader-facing guidance about anonymous sharing eligibility. The changed content does not itself grant privileges or enforce denial; any mismatch would concern the accuracy of that guidance rather than a demonstrated authorization bypass introduced here.

Trust Boundaries and Controls

  • observed — The documented identity transition is from an anonymous visitor choosing Share to signing in before sharing. The PR attributes the supporting permission restriction to meshery-cloud; the documentation cannot establish server-side enforcement, asset ownership checks, or consistent denial across alternative sharing paths.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main documentation change: sharing a Kanvas design requires a signed-in account.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

🚀 Preview deployment: https://docs.layer5.io/pr-preview/pr-1275/

Note: Preview may take a moment (GitHub Pages deployment in progress). Please wait and refresh. Track deployment here

@leecalcote
leecalcote merged commit 913e6ae into master Oct 6, 2026
5 checks passed
@leecalcote
leecalcote deleted the fm/kanvas-anonymous-sign-in-to-share branch October 6, 2026 23:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants