Round out the "read-only users can't write anything" boundary: a READ_ALL principal is forbidden from posting a block comment, replying, and editing a comment (the prior tests only used a no-authority principal for create). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>