forked from mosaicstack/stack
f10-coder holds gitea-mosaicstack-f10-coder.token with write:repository scope and was verified at mint by 'repo access returns 200'. It cannot push: collaborator lookup 404s and its own token reports push:false, pull:true. Capability has three independent layers — token file (raw-API auth), tea login (tea path), repository permission (actual write authority) — and satisfying two proves nothing about the third. Scope bounds what a token may ATTEMPT; repository permission decides what the user may DO. The charter principle failing on the check meant to confirm capability: a 200 on a READ was accepted as evidence of WRITE. written-unverified treated as verified, by both provisioner and orchestrator, one layer above D-12. RM-50's pre-dispatch check must assert effective permission for the intended operation (permissions.push == true as that seat), not token existence or a read returning 200. A capability check that cannot fail on a seat lacking write permission is itself an inert gate. Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>