id is a routing address only. The real authorization subject is the block's owning finding,req.block_idtemper-services/src/authz/audit_gate.rs:65-77). citation_audit_service::record_citation_auditid, so a caller cannot addressCitationAuditRequest carries no act/authorship fields (unlike AssertRelationshipRequest'sActInput) — that shape was fixed in Task 7/3 and is not this task's to change — soact is always the empty default here.curl --location '/api/resources//citation-audits' \
--header 'X-Temper-Surface;' \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{
"block_id": "bd8cc6cb-1750-49ca-a3b6-034ebc9ab225",
"reason": "string",
"source": {
"kind": "event",
"value": "a860a344-d7b2-406e-828e-8d442f23f344"
},
"value": 0
}'{
"error": {
"code": "string",
"details": null,
"message": "string"
}
}