# ADR-0006: Conceal File Ownership Boundaries Status: Accepted Date: 2026-07-15 ## Context Authenticated callers must not infer the existence of files owned by another user from status codes or response messages. ## Decision - Map missing, deleted, and cross-user file targets to the same not-found result. - Apply the same rule to parent-directory lookups. - Return success for one deletion of an active owned file. - Return not found for repeated deletion and cross-user deletion. - Guard soft deletion with ownership and active-state predicates. ## Consequences - File responses conceal resource ownership from other authenticated users. - The first successful deletion returns `204 No Content`; later attempts return `404 Not Found`. - Non-empty directory deletion continues to return a conflict.