Owner-granted data shares: let named users at one user's per-user data - #33
Merged
Merged
Conversation
Grants say who may open an app; a share says who may act on someone else's
data in it. ShareStore (auth/shares.py) keeps (app, owner, grantee) records
with an rw/ro access level and a grantee-facing label, beside grants under the
platform store. A share names existing accounts only and is removed with
either account (admin delete_user cascades).
- /auth/shares/{app}: the signed-in owner lists, grants and revokes; a
grantee can leave. /_admin/api/shares and `enlace-auth share|list-shares|
revoke-share` let an admin manage shares for an owner who cannot (a child).
- The per-user store honours ?owner= with an active share (404 otherwise,
writes need rw), gains a list route (GET /api/{app}/store?prefix=, walking
only the owner's directory, capped), ETags and If-Match / If-None-Match
conditional writes (412 with the current value), and CSRF on writes
(CSRFMiddleware.enforce_prefixes) although /api/ is otherwise exempt.
- An app gets a per-user store when it is protected:user or sets
`user_store = true` (needs enlace>=0.1.42), so a public app can keep data
for its signed-in visitors.
Design and its adversarial review: misc/docs/decisions/0001-owner-granted-data-shares.md.
…rom no_key, cap labels; correct the ADR (adversarial code review)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Owner-granted data shares. Grants say who may open an app; a share says who may act on someone else's data in it: in app A, the owner's per-user store is readable (and by default writable) by a named grantee, signed in as themselves. First consumer: a public maths-practice app where a child's sessions are shared with her parents.
ShareStore(auth/shares.py):(app, owner, grantee)records withaccess(rw/ro) and a grantee-facinglabel, beside grants under the platform store. A share names existing accounts only and is removed with either account (admindelete_usercascades)./auth/shares/{app}(list, grant, revoke; a grantee can leave), admin/_admin/api/shares, CLIshare/list-shares/revoke-share.?owner=honoured through an active share (404no_accessotherwise; writes needrw), a list routeGET /api/{app}/store?prefix=(walks only the owner's directory, sorted, capped), ETags andIf-Match/If-None-Match: *conditional writes (412 with the current value), refusal of values that cannot round-trip (NaN, lone surrogates), and CSRF on writes viaCSRFMiddleware(enforce_prefixes=...)although/api/is otherwise exempt.user_store = truein anapp.toml(enlace >= 0.1.43) gives a public app a per-user store for its signed-in visitors.Upgrading: store writes now need
X-CSRF-Token;/api/{app}/storeis reserved. No known deployment used either.Design, its adversarial review, and a second adversarial review of this code (findings fixed in the second and third commits):
misc/docs/decisions/0001-owner-granted-data-shares.md.Tests:
tests/test_shares.py(store, routes, router, an end-to-end publicuser_storeapp, CSRF, admin cascade, review fixes); full suite 437 passed.