P2: Photos shared semantic search lacks owner vector authority #895

Open
opened 2026-10-02 17:37:37 +00:00 by kayg · 1 comment
Owner

P2: Shared semantic search has no Share vector capability

crates/plugins/photos/src/search.rs:622 adds an incoming Share to metadata authority for a full-Home request. crates/plugins/photos/src/routes.rs:518 still creates vector authority from the original request context. A normal session has only the recipient Home. crates/calternal-embed/src/lib.rs:77 creates Share capabilities only from foreign roots in that context. CLIP therefore searches no owner vectors on this route. Metadata can find a shared photo, but a semantic query with no metadata match cannot. Global Search adds incoming Share roots before it creates vector authority (crates/calternal-server/src/main.rs:730). The new tests use empty queries or direct row lookups, so they do not check this behaviour.

Fix: derive vector authority from the live, request-authorized Photos roots through a safe server-owned capability API. Keep narrow request roots narrow. Add a semantic-only shared-photo route test, with revoke and narrow-root cases. DESIGN §§28 and 54 require Photos semantic search and recipient reads.

## P2: Shared semantic search has no Share vector capability `crates/plugins/photos/src/search.rs:622` adds an incoming Share to metadata authority for a full-Home request. `crates/plugins/photos/src/routes.rs:518` still creates vector authority from the original request context. A normal session has only the recipient Home. `crates/calternal-embed/src/lib.rs:77` creates Share capabilities only from foreign roots in that context. CLIP therefore searches no owner vectors on this route. Metadata can find a shared photo, but a semantic query with no metadata match cannot. Global Search adds incoming Share roots before it creates vector authority (`crates/calternal-server/src/main.rs:730`). The new tests use empty queries or direct row lookups, so they do not check this behaviour. Fix: derive vector authority from the live, request-authorized Photos roots through a safe server-owned capability API. Keep narrow request roots narrow. Add a semantic-only shared-photo route test, with revoke and narrow-root cases. DESIGN §§28 and 54 require Photos semantic search and recipient reads.
Author
Owner

Source review target: job/isolation-707 at 0bb018a98f, reviewed for #707. This is a pre-existing gap exposed by the new shared metadata-read support. No runtime checks ran in the LIGHT review job.

Source review target: job/isolation-707 at 0bb018a98fa5be97b3fcf9e2a5d62bc1a51b9abf, reviewed for #707. This is a pre-existing gap exposed by the new shared metadata-read support. No runtime checks ran in the LIGHT review job.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#895
No description provided.