M12: principals and roles #12
Labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Blocks
Depends on
#13 M13: live sharing and presence
jhgaylor/illogical
#14 M14: safe write access
jhgaylor/illogical
#31 M19: teams (sharing, roles, team daemons, invites)
jhgaylor/illogical
Reference
jhgaylor/illogical#12
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Depends on: #11
Blocks: #31, #13, #14
From PLAN.md, section "Multiplayer track → M12".
Every request has an author, and every session has an access list.
Principals:
at most that user's role;
Roles per session:
agents;
capture,tail.The daemon's owner is owner of every session.
Enforced on every path in one place (a
coreauthorization functionover intents and API calls): the WebSocket, HTTP API, Unix socket (uid maps
to the daemon owner), CLI, M5's tmux front end, and federation between
daemons. M4's per-daemon allowlist becomes this.
Grants are data.
acl.jsonper session is written atomically likelayout.json, and an audit log records grant changes (who, what, when).Push and approvals are per user. Web Push subscriptions belong to a
principal.
needs-inputgoes to editors who opted in. An agent permissionrequest records who approved it.
Done when:
vieweron one session sees it live andnothing else;
sendandapprovefrom them are refused, with a403 on the API and a toast in the UI;
editortakes effect without reconnecting, and revokingdisconnects them within a second;
Track overview
Superlogical builds sharing in "from the start". illogical adds it as its own
track, for a small group: a few people you'd hand a shell to, plus their
agents. Enterprise access control stays a non-goal (BRIEF.md).
What changes from single-user:
config.ownerbecomes a list of principals with roles.Order:
to M11, but agent blocks (M6b) gain per-person approvals when both exist.
Decisions this track makes: