privacy(ui-mac): main-authoritative upload manifest + conditional consent dialog (#225) - #511
Merged
Merged
Conversation
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
#225) Implements aw#10 client-side upload consent in the alpha-code desktop app: main process is the sole authority for the upload manifest (tenant binding, canonical paths, per-file SHA-256, totals, retention, egress, consent_required) and issuance of the upload_consent token via alpha-web; renderer can only send an opaque request id + kind. Conditional consent (dialog only when genuine privacy content is present). Free-text PII classification lives here (server #33 handles high-confidence markers only). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #225
Client-side upload consent for the alpha-code desktop app (aw#10 Privacy). The main process is the sole authority for the upload manifest and consent-token issuance; the renderer can only send an opaque request id + kind.
ACs (all verified by Fable review — 0 blockers/majors)
UploadManifestV1binds tenant, canonical paths, per-file SHA-256, per-file+total bytes, retention, egress,consent_required;purpose=artifact.uploadin the consent claims, composite-bound bymanifest_sha256+manifest_id.{kind}+ opaque main-minted requestId; paths/content/manifest/consent/token all main-side; sender isolation byevent.sender.id+ UUID; content frozen at prepare (hashed == classified == uploaded, no TOCTOU).Scope (owner-decided)
Gates
tsgo -btypecheck — PASSbun test src— 2502 pass / 0 fail@alpha-code/contracts-consumer— 19 passKnown minor (owner follow-up, non-blocking): phone-PII regex matches contiguous digits only, so separator-formatted mainland numbers evade the sensitivity decision — recall gap vs the '裸中国手机号' claim, not an architectural bypass. Dead i18n key
alpha.ext.cloudErrConsentDeclinedleft as harmless leftover.🤖 Generated with Claude Code