Repository navigation
Add artifact owners and an opt-in restricted access setting - #88
Draft
josipmrsic wants to merge 2 commits into
Draft
josipmrsic wants to merge 2 commits into
josipmrsic wants to merge 2 commits into
Conversation
Decision 0030 records every artifact's owner and adds a third access setting, restricted, that limits one artifact to its owner and installation administrators. account_required stays the default and public_link is unchanged. AUTH-030 and AUTH-031 specify the behavior; AUTH-002, AUTH-008, SCP-008-F, and the product specification now describe three settings.
Artifacts record their creator as owner, backfilled from the version 1
publisher on SQLite (schema 13), Postgres (0012_artifact_owner), and D1
(revision 10). The restricted setting is stored as a flag beside
access_setting, so the existing CHECK constraint stays and no table is
rebuilt; the repositories map the pair onto one API value.
Listings filter restricted artifacts inside SQL. Reads, versions,
comparisons, comments, content sessions, publishing, dispatch threads, and
git history credentials answer exactly like a missing artifact to everyone
but the owner and administrators, and only they can switch an artifact to or
from restricted. Switching ends other principals' content sessions in the
same transaction. Only a person can publish a new restricted artifact.
HTTP, MCP, the web share dialog ("Only me", "Signed-in members", "Public
link"), and the publishing client accept the third setting. The Postgres
migration creates its index before the backfill, because the backfill queues
events for the deferred current-version foreign key and Postgres refuses
CREATE INDEX on a table with pending trigger events.
AUTH-030 and AUTH-031 conformance tests drive the local server with an
administrator, member-bound keys, and a service key; Postgres and D1 runtime
tests cover owners, the listing filter, replay, and the upgrade backfill.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Hi! This is the follow-up we mentioned in #86. We run Artifact Server for our company (about 300 people), and one thing would help a lot: letting an author keep an artifact to themselves. Today every member can find, read, overwrite, and delete every artifact, and many pages people publish from their agents are drafts that aren't ready to share.
We know
f1586f7removed per-artifact ownership on purpose, so this is a draft. We built and tested it end to end, but the direction is yours to decide. Would you take an opt-in, per-artifact setting like this at all? If not, we'd rather hear it early.The idea
restricted, joinsaccount_requiredandpublic_link. Only the owner and installation administrators can see or manage the artifact.account_requiredstays the default.The removed ownership only gated changes and never reading, so this is a new, narrow rule, not the old
manage:owned/publish:ownedpair coming back. Decision record 0030 has the reasoning and the rejected alternatives.restrictedartifactartifact:manage:any404 ARTIFACT_NOT_FOUND, the same as for a missing artifactOnly the owner or an administrator can switch an artifact to or from
restricted. The switch ends other people's open content sessions immediately.Questions for you
access_settingrather than a third CHECK value, which would need a rebuild ofartifactson SQLite and D1. Do you have a preference?If it's easier to review, we're happy to split this into (a) recording owners and (b) the restricted setting.
Behavior details
restricteddeletes other principals' content sessions and unconsumed bootstraps in the same transaction. Administrators simply open the artifact again.--only-meflag yet; happy to add one.Storage and migrations
artifactsgains a nullableowner_principal_idand arestrictedflag.idempotency_recordsgainsrestrictedfor replays.access_settingand its CHECK stay untouched, and the repositories map the pair to one API field with three values.0012_artifact_ownerThe Postgres migration creates its index before the backfill. The backfill queues events for the deferred
artifacts_current_version_fk, and Postgres refusesCREATE INDEXon a table with pending trigger events. The populated-v1 upgrade test caught this.Spec and tests
implementingwith proof gaps; amended AUTH-002, AUTH-008, SCP-008-F, and product-spec wording.tests/conformance/auth-030-031-artifact-owner-restricted.test.tsdrives the local server with an administrator, member-bound keys, and a service key. It covers owners and the backfill, owners surviving other members' changes, full use by the owner and administrator, and outsiders refused like a missing artifact, including revocation and dispatch.Verification
pnpm check, the Postgres suite (19/19), and the browser suite (27/27) pass locally.