Move Notes, Tasks, and link projections to per-User files #443

Open
opened 2026-09-29 12:50:55 +00:00 by kayg · 0 comments
Owner

Follow-up from #435 and docs/audits/cross-user-inventory.md. DESIGN §48 requires physical separation of each User's Derived data.

Current state: plugins/notes/migrations/*: note_items, note_links, note_tags, note_blocks, note_capture_fts, note_link_refs/anchors/target_keys, note_calendar_logs, task_items, note_log_order, task attachments/identity, block reminders and repair intents. Shared User-keyed rows can expose Note and Task content.

Acceptance: use a separate User Index file under .system/index/users/<User ID>/; open from a validated, authenticated User context; bound open handles; migrate rows once with count verification before deleting old rows; resume after a crash at each step; keep reads on the old store until the new file is verified. Test that removing an owner predicate still cannot expose another User's data. Extend tests/adversarial/xuser_matrix.py for each affected API and run the per-crate gates. Do not change shared security state.

Follow-up from #435 and docs/audits/cross-user-inventory.md. DESIGN §48 requires physical separation of each User's Derived data. Current state: plugins/notes/migrations/*: note_items, note_links, note_tags, note_blocks, note_capture_fts, note_link_refs/anchors/target_keys, note_calendar_logs, task_items, note_log_order, task attachments/identity, block reminders and repair intents. Shared User-keyed rows can expose Note and Task content. Acceptance: use a separate User Index file under `.system/index/users/<User ID>/`; open from a validated, authenticated User context; bound open handles; migrate rows once with count verification before deleting old rows; resume after a crash at each step; keep reads on the old store until the new file is verified. Test that removing an owner predicate still cannot expose another User's data. Extend tests/adversarial/xuser_matrix.py for each affected API and run the per-crate gates. Do not change shared security state.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#443
No description provided.