Materialize Shared vectors in the recipient User Index #455

Open
opened 2026-09-29 13:34:18 +00:00 by kayg · 0 comments
Owner

Follow-up from #435 and DESIGN §48. The vector files are separated by source User. A recipient Search request with a Share root still opens the source User's vector file to select the Shared path. The current path authorization prevents content reads, but first-open migration time and candidate bucket work can reveal the source User's unrelated Index size. A missing path predicate could expose unshared paths in that source file.

Acceptance: materialize authorized Shared text and CLIP vectors into the recipient User's private Derived Index, as the Tantivy recipient generation already does. A Search request opens only the authenticated recipient's vector files. Share grant, revoke, move, source update and User deletion invalidate or rebuild that recipient projection durably. Keep old reads until the recipient file is verified. Test a Share of one item while the source has many private items: remove the SQL owner/path filters in a test build and prove the recipient cannot see or time the private items. Extend tests/adversarial/xuser_matrix.py and run per-crate gates.

Follow-up from #435 and DESIGN §48. The vector files are separated by source User. A recipient Search request with a Share root still opens the source User's vector file to select the Shared path. The current path authorization prevents content reads, but first-open migration time and candidate bucket work can reveal the source User's unrelated Index size. A missing path predicate could expose unshared paths in that source file. Acceptance: materialize authorized Shared text and CLIP vectors into the recipient User's private Derived Index, as the Tantivy recipient generation already does. A Search request opens only the authenticated recipient's vector files. Share grant, revoke, move, source update and User deletion invalidate or rebuild that recipient projection durably. Keep old reads until the recipient file is verified. Test a Share of one item while the source has many private items: remove the SQL owner/path filters in a test build and prove the recipient cannot see or time the private items. Extend tests/adversarial/xuser_matrix.py and run per-crate gates.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#455
No description provided.