Space Security's Instance Read setting doesn't appear to work right
Summary: This is potentially a serious security issue, so investigate soon.
- In a Space, create a Member with no particular rights.
- From the Space root, go to Security.
- Go to the Instances Tab.
- Set Read permission to "Owner".
- The Member shouldn't be able to see any Things.
In fact, it looks like the Member can still see Things by default. This is quite broken!