Skip to content

Enforce the accepted runtime API trust boundary #1359

Description

@Brad-Edwards

Implement the accepted control-plane exposure model across every runtime route that can reveal state or cause effects.

Acceptance criteria

  • Apply the route/authority matrix to current APIs. Make the resulting authorization boundary available to new operation and inject routes; bind identity, audience, participant, and episode only where the selected exposure model requires them.
  • Prevent credentials limited to participant views from retrieving full snapshots or another participant's state. Enforce the selected administrative-only boundary where direct participant access is excluded.
  • Cover alternate retrieval paths, errors, events, cached results, and idempotent readback. Keep backend-owned organizational authentication and policy at their defined boundary.
  • Publish deployment guidance and verify permitted access plus cross-scope and route-bypass rejection using the actual HTTP/API boundary.

Prerequisites: #1356.

References: Diagnosis.

Requirements

  • API-404 — Secure, Durable, And Idempotent Control-Plane Semantics

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:runtimeRuntime and control-plane codeenhancementNew feature or requestsecuritySecurity vulnerabilities and hardening issues

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions