For Florida law firms
Pinned shares: a share's link gives exactly the version that was shared
firm lane · Deterministic — no model call
Current availability
ShippedConfigured and enabled: every share of a firm's matter — pinned when it is made.
- Where it lives
- The matter's Disclosure (/admin/matter/[id]/disclosure) → each share's "What this link gives" · a share's link (/shared/[token]) · /api/shared/download
- What unlocks it
- every share is pinned the moment it is made; its recipient downloads only the pinned version, checked against its fingerprint first
Status is evaluated against this deployment's configuration by the capability-status service at build time; the catalogue's facts were last reviewed on the date shown.
Capabilities
- ShippedEvery document on a share is pinned when the share is made: the exact version (the SHA-256 fingerprint recorded when the file passed the upload check), where it is stored and the name it had — set once, never changed.
- ShippedThe link lists and gives the pinned version: a later revision of the document never reaches a link already sent, and the recipient sees, for each file, the date it was shared and a short version check. In five languages.
- ShippedBefore a download, the platform reads the stored file and checks its fingerprint against the pin; a file that no longer matches — or is no longer held — is refused, the recipient is told the file changed after it was shared, and the refusal goes on the share's own record.
- ShippedA signed-in user can never rewrite a stored document, nor delete one a share has pinned — the database refuses both; the check at download is the second guard.
- ShippedThe firm sees, on each share, what its link gives: every pinned version with its date and version check, a document that has since moved on (a newer version is on the matter — the link still gives the one shared), and any refused download.
Limits
- A share made before versions were pinned, whose document had no recorded fingerprint, lists that document and does not give it; the firm makes a new share to send it.
- A newer version never joins an existing share: the firm makes a new share to send it.
- The recipient is told that a file changed or cannot be checked; the firm reads which file, and when, on the share.
What EstateDraftFL refuses
| Reason code | HTTP | What it means |
|---|---|---|
| not-shareable | 409 | A chosen document carries no recorded fingerprint to pin (or is unreviewed, not for the recipient's audience, or not past the upload check) — nothing was shared. |
| closed | 404 | The link has closed — expired, withdrawn or unknown; the same answer for each. |
| unavailable | 503 | The file could not be checked just now — nothing was sent. |
Evidence
- supabase/migrations/20260930000000_phase11_pinned_shares.sql
- src/app/api/shared/download/route.ts
- src/lib/disclosure/server.ts
- src/lib/disclosure/policy.ts
- src/app/shared/[token]/page.tsx
- src/components/disclosure/SharedDocumentsView.tsx
- src/components/disclosure/DisclosureView.tsx
- docs/security/MASTER-PLAN-PHASE11-PART3-2026-09-30.md
Last reviewed 2026-09-29