---
{
  "n": 50,
  "title": "Public read-only view route for a shared document",
  "abstract": "Unauthenticated route that serves a document's content for a valid, unrevoked share token",
  "refs": [
    "message:11528"
  ],
  "seen": [
    "agent",
    "user"
  ],
  "data": {
    "source": "user",
    "stage": "To do",
    "board": 13,
    "draft": true,
    "covers": [
      2
    ],
    "agent": "board-filler",
    "dispatcher": "c35e7375-7ce3-4bc3-b1ae-7cdf73bd1488",
    "environment": "main",
    "dependencies": {
      "ticket:48": "proposed"
    }
  },
  "created": 1790373710.959032,
  "updated": 1790373952.646493,
  "deleted": 1790373952.646453,
  "completed": 0.0,
  "outcome": "",
  "type": "ticket"
}
---
What: a route/endpoint that takes a share token, looks up the share-link, and returns the document read-only with no journal login required.
Why: this is the actual sharing — the outside person opens the link and sees the document.
Touches: routing layer, doc feature's read path, share-link model from card 1.
Done when: opening the link shows the document; the response is read-only with no edit affordance.
Risk: medium; must not leak any other journal data through this route.
