Move Analytics days and epoch to per-User files #438

Open
opened 2026-09-29 12:50:48 +00:00 by kayg · 0 comments
Owner

Follow-up from #435 and docs/audits/cross-user-inventory.md. DESIGN §48 requires physical separation of each User's Derived data.

Current state: plugins/analytics/migrations/0001_analytics.sql: analytics_days and analytics_epoch. Shared User-keyed rows can expose activity totals or timing.

Acceptance: use a separate User Index file under .system/index/users/<User ID>/; open from a validated, authenticated User context; bound open handles; migrate rows once with count verification before deleting old rows; resume after a crash at each step; keep reads on the old store until the new file is verified. Test that removing an owner predicate still cannot expose another User's data. Extend tests/adversarial/xuser_matrix.py for each affected API and run the per-crate gates. Do not change shared security state.

Follow-up from #435 and docs/audits/cross-user-inventory.md. DESIGN §48 requires physical separation of each User's Derived data. Current state: plugins/analytics/migrations/0001_analytics.sql: analytics_days and analytics_epoch. Shared User-keyed rows can expose activity totals or timing. Acceptance: use a separate User Index file under `.system/index/users/<User ID>/`; open from a validated, authenticated User context; bound open handles; migrate rows once with count verification before deleting old rows; resume after a crash at each step; keep reads on the old store until the new file is verified. Test that removing an owner predicate still cannot expose another User's data. Extend tests/adversarial/xuser_matrix.py for each affected API and run the per-crate gates. Do not change shared security state.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#438
No description provided.