0.5.0
Curated-partner sharing
A new per-partner sharing scope on the Partners screen: standard (unchanged — receives every listing shared with everyone, plus anything selected for it) or curated — a partner that receives only listings explicitly selected for it, directly or via a group. Built for yacht-show organisers, trials, and press feeds.
- Explicit selections are now additive: they share a listing with the selected partner under any audience except "no one", so an everyone-audience listing can also reach a curated partner without changing what any other partner sees. Standard partners behave exactly as before.
- Flipping a partner's scope replays through the visibility event log: narrowing tombstones the listings the partner saw only via "everyone", widening resurfaces them — on the partner's next poll, with no listing content churn.
- Curated partners get a per-type shared-listings picker on their sharing screen (sale and charter separately — the twins carry different price information), with select-all, group-derived shares shown with their provenance, and a hint when a shared vessel's sale/charter twin exists unshared.
- Selecting listings on the listing editor's audience picker is unchanged; audience changes now preserve the partner selection when moving to "everyone" and when temporarily hiding a listing.
- Schema v8:
sharing_scopecolumn on partners, defaulting every existing partner to standard (no behaviour change on upgrade). No wire or protocol change; hidden listings still dereference as NOT_FOUND.
Federation security hardening
This release also carries the fixes from the federation security review: TOFU key pinning is armed at first contact (and established on approve for pre-existing partners), plus the further verifier and partner-lifecycle hardenings from that review.