You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The public media API does not list or return fiscal/private media by default. If exposure is ever required, it is an explicit opt-in, not accidental. CMS public media API behaviour for normal items stays intact.
Acceptance criteria
Fiscal/private items are absent from public API list/detail by default.
Public CMS media remains available on the API as today (unless already restricted by auth).
Opt-in for fiscal API exposure, if implemented, is explicit and documented; default remains excluded.
Tests: fiscal item not in public API; public item still visible as before.
What to build
The public media API does not list or return fiscal/private media by default. If exposure is ever required, it is an explicit opt-in, not accidental. CMS public media API behaviour for normal items stays intact.
Acceptance criteria