--- id: META-9 family: RT-META level: extended profiles: [runtime, editor-client] posture: normative-target added: "1.0" changed: "1.0" source: https://flowdrop.io/spec/rules/rt-meta/meta-9 specification: FlowDrop Workflow Specification 1.0-draft licence: CC BY 4.0 --- # META-9 — The editor metadata doors are read-only and gated before the handler *RT-META (Part II) · level: extended · profiles: runtime, editor-client · added in 1.0* Neither door has a handler-side check to fall back on, so what the surface declares is the whole access contract. ## The rule > **Normative.** This is the rule. > > 1. The category door and the workflow schema door accept `GET` and no other method, and each requires a named authorization decided before the handler runs: neither carries a handler-side check as a backstop. > > 2. The set of methods and the named authorization are part of the contract (widening either is a visible change), and a named authorization the implementation does not define is a defect, not a locked door. ## Related rules - Names: META-1, META-4 --- Rule identifiers are permanent and are never renumbered. This specification carries no implementation status: each implementation publishes its own standing against these rules. Licensed CC BY 4.0.