c2c8f6e41c
## Summary UNLISTED views are personal views tied to a specific user, so API keys should not be able to create them. ## Changes - Added check in `canUserCreateView` to block API keys from creating UNLISTED views - Refactored the service to use smaller functions with early returns (no nested if/else) ## Behavior Matrix ### Creating Views | Caller | Visibility | Has VIEWS Permission | Result | |--------|------------|---------------------|--------| | User | UNLISTED | (not checked) | ✅ Allow | | User | WORKSPACE | Yes | ✅ Allow | | User | WORKSPACE | No | ❌ Denied | | **API Key** | **UNLISTED** | (not checked) | **❌ Denied** | | API Key | WORKSPACE | Yes | ✅ Allow | | API Key | WORKSPACE | No | ❌ Denied |