Skip to content

privacy(ui-mac): main-authoritative upload manifest + conditional consent dialog (#225) - #511

Merged
jinjunnn merged 2 commits into
alphafrom
feat/alpha-code-225
Jul 22, 2026
Merged

jinjunnn merged 2 commits into
alphafrom
feat/alpha-code-225

Conversation

@jinjunnn

Copy link
Copy Markdown
Owner

Fixes #225

Client-side upload consent for the alpha-code desktop app (aw#10 Privacy). The main process is the sole authority for the upload manifest and consent-token issuance; the renderer can only send an opaque request id + kind.

ACs (all verified by Fable review — 0 blockers/majors)

  • AC1 manifest is main-authoritative: UploadManifestV1 binds tenant, canonical paths, per-file SHA-256, per-file+total bytes, retention, egress, consent_required; purpose=artifact.upload in the consent claims, composite-bound by manifest_sha256+manifest_id.
  • AC2 renderer cannot inject: sends only {kind} + opaque main-minted requestId; paths/content/manifest/consent/token all main-side; sender isolation by event.sender.id + UUID; content frozen at prepare (hashed == classified == uploaded, no TOCTOU).
  • AC3 boundary rejection is fail-closed: missing dir, path traversal, symlink escape (realpath compare after resolution + O_NOFOLLOW + lstat), duplicates, non-regular, unreadable, non-UTF-8 all throw; never falls back to whole-project upload.
  • AC4 cancel/picker-cancel → zero issuance/dispatch; all four approval UX states covered by a real built-component harness.

Scope (owner-decided)

Gates

  • tsgo -b typecheck — PASS
  • ui-mac bun test src — 2502 pass / 0 fail
  • @alpha-code/contracts-consumer — 19 pass
  • renderer harness (real render in happy-dom) — 7 pass

Known minor (owner follow-up, non-blocking): phone-PII regex matches contiguous digits only, so separator-formatted mainland numbers evade the sensitivity decision — recall gap vs the '裸中国手机号' claim, not an architectural bypass. Dead i18n key alpha.ext.cloudErrConsentDeclined left as harmless leftover.

🤖 Generated with Claude Code

jinjunnn and others added 2 commits July 22, 2026 10:07
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
#225)

Implements aw#10 client-side upload consent in the alpha-code desktop app:
main process is the sole authority for the upload manifest (tenant binding,
canonical paths, per-file SHA-256, totals, retention, egress, consent_required)
and issuance of the upload_consent token via alpha-web; renderer can only send
an opaque request id + kind. Conditional consent (dialog only when genuine
privacy content is present). Free-text PII classification lives here (server
#33 handles high-confidence markers only).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@jinjunnn
jinjunnn merged commit 4ae92de into alpha Jul 22, 2026
5 of 6 checks passed
@jinjunnn
jinjunnn deleted the feat/alpha-code-225 branch July 22, 2026 14:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Privacy] Create main-owned cloud upload manifest and consent token

1 participant