Skip to content

Node: let operators decide who may read what #4

Description

@oesteban

Public-read-only is not enough for the communities this is for. Operators get identity keys they can rotate, per-collection allowlists of peer identities, and revocable share tokens they can hand to a collaborator and take back. What the transport does and does not protect is written down publicly rather than left implicit.

Outcomes

  • Node identity and key management: generation, protected storage at rest, and rotation without losing collection identity
  • Per-collection access control: peer-identity allowlists plus revocable capability tokens, default-deny for non-public collections, with tests for both the allowed and refused cases
  • Published threat model and SECURITY.md, stating what the transport protects against and what it does not
  • Operator-inspectable request log recording who fetched what and when

Metadata

Metadata

Assignees

No one assigned

    Labels

    effort: mediumEstimated medium effort taskenhancementNew feature or requestimpact: highEstimated high impact task

    Type

    No type

    Projects

    Status
    Todo

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions