Bind vector read handles to authenticated User capabilities #458

Open
opened 2026-09-29 14:01:22 +00:00 by kayg · 0 comments
Owner

Parent: #435, DESIGN §48 Q-index.

The #435 private vector files make an unfiltered SQL read in one file unable to return another User's rows. The read API still takes a plain owner ID: UserVectorPools::get(&str), SemanticIndexer::search(Option<&str>, ...), and PhotoClipIndexer::search(..., owner ...). The server's authenticated SearchContext currently supplies that value, but a later caller could supply another User's ID. This does not satisfy #435's requested API invariant that a store handle is obtained from authenticated User context and read methods do not accept an owner ID.

Make a read capability created only at the authenticated server boundary. Its scope must include the User and authorized Share roots. Pass that capability to text and CLIP reads; move the raw owner string methods behind private migration/write APIs. Add compile-level or unit proof that a caller without that capability cannot open another User's read handle. Keep direct owner-based cleanup for account deletion separate from reads. Verify API, MCP, CLI and WebMCP Search against two Users and Shares on a real server.

Parent: #435, DESIGN §48 Q-index. The #435 private vector files make an unfiltered SQL read in one file unable to return another User's rows. The read API still takes a plain owner ID: `UserVectorPools::get(&str)`, `SemanticIndexer::search(Option<&str>, ...)`, and `PhotoClipIndexer::search(..., owner ...)`. The server's authenticated SearchContext currently supplies that value, but a later caller could supply another User's ID. This does not satisfy #435's requested API invariant that a store handle is obtained from authenticated User context and read methods do not accept an owner ID. Make a read capability created only at the authenticated server boundary. Its scope must include the User and authorized Share roots. Pass that capability to text and CLIP reads; move the raw owner string methods behind private migration/write APIs. Add compile-level or unit proof that a caller without that capability cannot open another User's read handle. Keep direct owner-based cleanup for account deletion separate from reads. Verify API, MCP, CLI and WebMCP Search against two Users and Shares on a real server.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#458
No description provided.