Scope thumbnail cache identity and reads to each User #449

Open
opened 2026-09-29 13:03:27 +00:00 by kayg · 0 comments
Owner

Follow-up from #435 and docs/audits/cross-user-inventory.md. DESIGN §48 requires physical separation of User Derived data; DESIGN §5 permits the Instance Blob store only without a cross-User oracle.

Current state: calternal-fs/src/thumbnails.rs stores hash-keyed files in .system/cache/thumbs; plugins/files/src/thumbnails.rs schedules generation. Audit read authorization, migrate or regenerate cache files per User or Share recipient, and test cross-User existence/timing.

Acceptance: document the exact current boundary, migrate affected durable User state restartably where required, verify cross-User isolation with a negative control and extend tests/adversarial/xuser_matrix.py. Keep the server as the only writer and use calternal-fs for all filesystem access.

Follow-up from #435 and docs/audits/cross-user-inventory.md. DESIGN §48 requires physical separation of User Derived data; DESIGN §5 permits the Instance Blob store only without a cross-User oracle. Current state: calternal-fs/src/thumbnails.rs stores hash-keyed files in .system/cache/thumbs; plugins/files/src/thumbnails.rs schedules generation. Audit read authorization, migrate or regenerate cache files per User or Share recipient, and test cross-User existence/timing. Acceptance: document the exact current boundary, migrate affected durable User state restartably where required, verify cross-User isolation with a negative control and extend tests/adversarial/xuser_matrix.py. Keep the server as the only writer and use calternal-fs for all filesystem access.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#449
No description provided.