Remove pre-1.0 audit and protected request scaffolding
This commit is contained in:
@@ -10,7 +10,7 @@
|
||||
|
||||
## Authorization roles
|
||||
|
||||
- `platform-admin`: user/provider/plugin installation and state, Run endpoint administration, platform metrics, audit, and global internal resource creation.
|
||||
- `platform-admin`: user/provider/plugin installation and state, Run endpoint administration, platform metrics, and global internal resource creation.
|
||||
- server owner: server membership, runtime binding changes, destructive/archive operations, and all visible server actions.
|
||||
- server administrator: non-owner operational access to assigned server resources, but no owner-only membership or secret/key rotation.
|
||||
- Run service: control/job/log/artifact channels for its current endpoint session; it cannot use browser bearer authority.
|
||||
@@ -25,6 +25,6 @@ The canonical payload is `METHOD + "\n" + PATH + "\n" + TIMESTAMP + "\n" + NONCE
|
||||
|
||||
## Secret boundary
|
||||
|
||||
Platform snapshots may contain password verifiers, bearer/Run token hashes, encrypted component-key ciphertext, fingerprints, generations, and controlled `secret://`/`vault://` references. They never contain raw bearer tokens, raw component keys, provider key values, host paths, or direct sockets. Browser DTOs expose secret presence/configured flags only.
|
||||
Platform snapshots may contain password verifiers, bearer/Run token hashes, encrypted component-key ciphertext, fingerprints, generations, and scoped `secret://`/`vault://` references. They never contain raw bearer tokens, raw component keys, provider key values, host paths, or direct sockets. Browser DTOs expose secret presence/configured flags only.
|
||||
|
||||
Component-key ciphertext uses an injectable AES-GCM envelope derived from `PLATFORM_SECRET_ENVELOPE_KEY`; the built-in key is a disposable-development fallback only. This boundary is not a production KMS/vault. External key wrapping, KMS/HSM integration, multi-node replay coordination, envelope-key migration, and secret-value rotation remain deferred risks.
|
||||
|
||||
Reference in New Issue
Block a user