Skip to content

Files Changed: enforce provenance privacy and serializer policy #1078

Description

@jeonghun-jj-lee

Files Changed: enforce provenance privacy and serializer policy

Important

Problem - Session sharing, exports, telemetry, logs, errors, and browser projections have independent serialization paths. A ledger can expose sensitive paths, hashes, baselines, capabilities, redaction decisions, or evidence unless every field has explicit egress policy.
Approach - Define a schema-owned field exposure matrix and separate host-only mutation management from display-safe receipt projections. Enforce the matrix across all serialization boundaries.
Scope - in: receipt/evidence projection, sharing, export, telemetry, logs, errors, browser data, and no-store detail responses. out: mutation storage implementation and individual mutator adoption.
Assumptions - The receipt, assessment, evidence, context, and resource-identity contracts from earlier slices exist.

Acceptance Criteria

  • Every receipt and evidence field is classified as allow, redact, or deny for the UI, sharing, export, telemetry, logs, and error responses.
  • Context capabilities, canonical paths, raw hashes, baselines, and redaction decisions are denied from every client and egress serializer.
  • Display-safe projections expose only the evidence necessary for the authorized Files Changed view.
  • External detail responses are authenticated, no-store, and omit evidence when policy or expiry denies it.
  • Generated-artifact sentinels cannot reach transcripts, ordinary session metadata, shares, exports, telemetry, or logs.
  • Serializer coverage fails when a new receipt or evidence field lacks an exposure classification.

Testing Decisions

  • Extend sharing, export, telemetry, HTTP, browser-relay, and error-serialization tests with field and sentinel matrices.
  • Add schema tests that require an explicit exposure decision for new fields.

Key Decisions

  • Privacy is a schema contract, not a convention in individual callers.
  • Host-only evidence and display-safe projections are distinct representations.

Constraints & Invariants

  • No serializer can infer permission from a UI request alone.
  • Legacy session sharing behavior remains unchanged until the capability-gated rollout.

Prior Art

Deliberation Resolution

  • The exposure matrix has explicit columns for Files Changed projection, browser relay, transcript, ordinary session metadata, export, share, telemetry, log, error, and external-detail response.
  • allow permits the original typed value, redact replaces it with a stable policy-safe marker, and deny omits it entirely. The schema enumerates receipt, assessment, evidence, context, and derived-field inventories; nested and derived values inherit the strictest source classification.
  • An external detail request requires an authenticated session viewer, an authorized display-safe receipt reference, and a current evidence policy decision. Success includes no-store headers; denial, expiry, and redirect responses include no evidence bytes or sensitive metadata.
  • Legacy serialization is selected only when capability discovery returns legacy. Fixtures assert unchanged legacy payloads and separately assert full-mode projections.

Source

Part of #972. Blocked by #1076 and #1077.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

hitlNeeds human review before merge

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions