Problem
When an unauthenticated visitor opens the Sharing tab on any pod resource, the pane renders a red 401 Unauthorized banner. This is the legitimate response from the server (reading ACL needs a WebID), but as UX it reads like an error rather than a missing-auth state.
Repro
- Open
melvin.solid.social/public/ in a private window (no session)
- Click Sharing tab
- See: red
401 Unauthorized banner
Proposed shape
When canHandle runs and there's no auth context (window.xlogin?.account / localStorage token / however the pane currently checks), short-circuit the ACL fetch and render:
Log in to manage sharing
[Login button or link to existing xlogin flow]
Optionally still show the public-access toggle in a read-only state (with a tooltip "Log in to change") so the page isn't empty.
If canHandle can't tell whether auth is available without firing the request, then catch the 401 in render and swap the empty-state UI in.
Out of scope
Acceptance
Problem
When an unauthenticated visitor opens the Sharing tab on any pod resource, the pane renders a red
401 Unauthorizedbanner. This is the legitimate response from the server (reading ACL needs a WebID), but as UX it reads like an error rather than a missing-auth state.Repro
melvin.solid.social/public/in a private window (no session)401 UnauthorizedbannerProposed shape
When
canHandleruns and there's no auth context (window.xlogin?.account/localStoragetoken / however the pane currently checks), short-circuit the ACL fetch and render:Optionally still show the public-access toggle in a read-only state (with a tooltip "Log in to change") so the page isn't empty.
If
canHandlecan't tell whether auth is available without firing the request, then catch the 401 inrenderand swap the empty-state UI in.Out of scope
Acceptance