M15: beyond the tailnet #15

Closed
opened 2026-10-02 00:16:06 +00:00 by jhgaylor · 1 comment
Owner

Depends on: #14, #11

From PLAN.md, section "Multiplayer track → M15".


Share with someone who isn't on your tailnet and won't install anything.

  • Invites.
    • An owner creates an invite link (role, session, expiry, single-use)
      served over Tailscale Funnel on its own hostname (S12). It is never the
      app's origin on 443.
    • The invitee signs in with GitHub (OAuth) or a passkey. Their principal is
      that GitHub login.
    • Funnel traffic reaches only the invite and session endpoints, never the
      host list or other sessions.
  • Read-only share links (this replaces M4c's share tokens).
    • A link that shows one session live, read-only, with no sign-in, until it
      expires.
    • It's "from now" by default.
  • Hardening (needed once the app faces the internet):
    • rate limits and lockouts per invite;
    • a CSP, and the M6a origin rules for proxied pages;
    • audit entries carry the invitee's IP;
    • a kill switch, illogical sharing off, that closes Funnel and revokes
      every outside principal.
  • Sessions shared with you. Your client lists sessions other people's
    daemons share with you, using M4a federation with your identity, under a
    "shared with me" section of the host list.
  • Done when:
    • someone with only a browser and a GitHub account opens an invite, signs
      in, watches a session, takes control of a pane in their own VM, and loses
      access when the invite is revoked;
    • a read-only link stops working at expiry;
    • illogical sharing off cuts everyone outside the tailnet within a
      second.

Not planned in this track:

  • organisations, SSO/SCIM and policy engines (Superlogical's step 3);
  • text chat and comments (for now, use a notes block from S8 if it exists);
  • voice;
  • shared undo of layout changes.
**Depends on:** #14, #11 _From PLAN.md, section "Multiplayer track → M15"._ --- Share with someone who isn't on your tailnet and won't install anything. - **Invites.** - An owner creates an invite link (role, session, expiry, single-use) served over Tailscale Funnel on its own hostname (S12). It is never the app's origin on 443. - The invitee signs in with GitHub (OAuth) or a passkey. Their principal is that GitHub login. - Funnel traffic reaches only the invite and session endpoints, never the host list or other sessions. - **Read-only share links** (this replaces M4c's share tokens). - A link that shows one session live, read-only, with no sign-in, until it expires. - It's "from now" by default. - **Hardening** (needed once the app faces the internet): - rate limits and lockouts per invite; - a CSP, and the M6a origin rules for proxied pages; - audit entries carry the invitee's IP; - a kill switch, `illogical sharing off`, that closes Funnel and revokes every outside principal. - **Sessions shared with you.** Your client lists sessions other people's daemons share with you, using M4a federation with your identity, under a "shared with me" section of the host list. - **Done when:** - someone with only a browser and a GitHub account opens an invite, signs in, watches a session, takes control of a pane in their own VM, and loses access when the invite is revoked; - a read-only link stops working at expiry; - `illogical sharing off` cuts everyone outside the tailnet within a second. **Not planned in this track:** - organisations, SSO/SCIM and policy engines (Superlogical's step 3); - text chat and comments (for now, use a notes block from S8 if it exists); - voice; - shared undo of layout changes.
Author
Owner

Superseded by #31 (control track, decided 2026-10-01): invites, sign-in and read-only links move to illogical control instead of per-daemon Funnel and GitHub OAuth. M12–M14 carry over. See PLAN.md, "Control track".

Superseded by #31 (control track, decided 2026-10-01): invites, sign-in and read-only links move to illogical control instead of per-daemon Funnel and GitHub OAuth. M12–M14 carry over. See PLAN.md, "Control track".
Sign in to join this conversation.
No description provided.