Isolate Notes collaboration state and DAV sync feeds per User #451

Open
opened 2026-09-29 13:03:30 +00:00 by kayg · 0 comments
Owner

Follow-up from #435 and docs/audits/cross-user-inventory.md. DESIGN §48 requires physical separation of User Derived data; DESIGN §5 permits the Instance Blob store only without a cross-User oracle.

Current state: plugins/notes note_collab_state, note_dav_moves, journal_* and reminder_* rows plus live Yjs rooms hold Note content, sync tokens and move hints. Move durable state per User and key live rooms by User or authorized Share; test stale tokens, revocation and concurrent edits.

Acceptance: document the exact current boundary, migrate affected durable User state restartably where required, verify cross-User isolation with a negative control and extend tests/adversarial/xuser_matrix.py. Keep the server as the only writer and use calternal-fs for all filesystem access.

Follow-up from #435 and docs/audits/cross-user-inventory.md. DESIGN §48 requires physical separation of User Derived data; DESIGN §5 permits the Instance Blob store only without a cross-User oracle. Current state: plugins/notes note_collab_state, note_dav_moves, journal_* and reminder_* rows plus live Yjs rooms hold Note content, sync tokens and move hints. Move durable state per User and key live rooms by User or authorized Share; test stale tokens, revocation and concurrent edits. Acceptance: document the exact current boundary, migrate affected durable User state restartably where required, verify cross-User isolation with a negative control and extend tests/adversarial/xuser_matrix.py. Keep the server as the only writer and use calternal-fs for all filesystem access.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#451
No description provided.