You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Files Changed: enforce provenance privacy and serializer policy
Important
Problem - Session sharing, exports, telemetry, logs, errors, and browser projections have independent serialization paths. A ledger can expose sensitive paths, hashes, baselines, capabilities, redaction decisions, or evidence unless every field has explicit egress policy. Approach - Define a schema-owned field exposure matrix and separate host-only mutation management from display-safe receipt projections. Enforce the matrix across all serialization boundaries. Scope - in: receipt/evidence projection, sharing, export, telemetry, logs, errors, browser data, and no-store detail responses. out: mutation storage implementation and individual mutator adoption. Assumptions - The receipt, assessment, evidence, context, and resource-identity contracts from earlier slices exist.
Acceptance Criteria
Every receipt and evidence field is classified as allow, redact, or deny for the UI, sharing, export, telemetry, logs, and error responses.
Context capabilities, canonical paths, raw hashes, baselines, and redaction decisions are denied from every client and egress serializer.
Display-safe projections expose only the evidence necessary for the authorized Files Changed view.
External detail responses are authenticated, no-store, and omit evidence when policy or expiry denies it.
Existing external-diff no-store and sharing safeguards
Deliberation Resolution
The exposure matrix has explicit columns for Files Changed projection, browser relay, transcript, ordinary session metadata, export, share, telemetry, log, error, and external-detail response.
allow permits the original typed value, redact replaces it with a stable policy-safe marker, and deny omits it entirely. The schema enumerates receipt, assessment, evidence, context, and derived-field inventories; nested and derived values inherit the strictest source classification.
An external detail request requires an authenticated session viewer, an authorized display-safe receipt reference, and a current evidence policy decision. Success includes no-store headers; denial, expiry, and redirect responses include no evidence bytes or sensitive metadata.
Legacy serialization is selected only when capability discovery returns legacy. Fixtures assert unchanged legacy payloads and separately assert full-mode projections.
Files Changed: enforce provenance privacy and serializer policy
Important
Problem - Session sharing, exports, telemetry, logs, errors, and browser projections have independent serialization paths. A ledger can expose sensitive paths, hashes, baselines, capabilities, redaction decisions, or evidence unless every field has explicit egress policy.
Approach - Define a schema-owned field exposure matrix and separate host-only mutation management from display-safe receipt projections. Enforce the matrix across all serialization boundaries.
Scope - in: receipt/evidence projection, sharing, export, telemetry, logs, errors, browser data, and no-store detail responses. out: mutation storage implementation and individual mutator adoption.
Assumptions - The receipt, assessment, evidence, context, and resource-identity contracts from earlier slices exist.
Acceptance Criteria
Testing Decisions
Key Decisions
Constraints & Invariants
Prior Art
Deliberation Resolution
allowpermits the original typed value,redactreplaces it with a stable policy-safe marker, anddenyomits it entirely. The schema enumerates receipt, assessment, evidence, context, and derived-field inventories; nested and derived values inherit the strictest source classification.Source
Part of #972. Blocked by #1076 and #1077.