Skip to content

feat(auth): enforce protected routing and fail-safe invalidation - #4789

Draft
cea-block wants to merge 1 commit into
cea/o4-protected-transportsfrom
cea/o4-invalidation-failsafe
Draft

feat(auth): enforce protected routing and fail-safe invalidation#4789
cea-block wants to merge 1 commit into
cea/o4-protected-transportsfrom
cea/o4-invalidation-failsafe

Conversation

@cea-block

@cea-block cea-block commented Aug 4, 2026

Copy link
Copy Markdown

Why

Every protected route needs a complete route inventory and durable invalidation state so no transport can continue authorizing after its authority becomes stale or unavailable.

What

  • Enforce protected-route classification at the shared router boundary
  • Persist monotonic invalidation floors, idempotent operation receipts, and authority epochs
  • Propagate invalidation across relay instances and enter a deny-protected mode when authority cannot be trusted
  • Apply server-owned enrollment and typed provider-installation provenance
  • Add the invalidation and authority migration sequence from 0040 through 0042
  • Reuse the same visibility fence across protected Git and related storage paths

Review guide

  • Route inventory and default-deny handling for unclassified protected requests
  • Invalidation storage, authority epochs, operation receipts, and database triggers
  • Cross-relay publication and subscription behavior, restoration, and deny-protected mode
  • Relay, workflow, and storage consumers of the shared invalidation fence

Risk assessment

Medium. This PR changes protected routing and invalidation across relay instances. Protected requests deny when routing or invalidation authority is absent, ambiguous, or stale, and the behavior remains off by default.

Testing

  • Protected-route inventory and method-classification cases
  • Invalidation ordering, replay, duplicate, restoration, and cross-relay cases
  • Fresh and incremental migration coverage through 0042
  • Trigger, visibility, workflow, formatting, linting, and hosted repository checks

References

@cea-block cea-block changed the title feat(auth): converge invalidation and fail-safe mode feat(auth): enforce protected routing and fail-safe invalidation Aug 4, 2026
@cea-block
cea-block changed the base branch from cea/o4-route-inventory to cea/o4-protected-transports August 4, 2026 21:20
Signed-off-by: Cea Stapleton Cordasco <261786559+cea-block@users.noreply.github.com>
@cea-block
cea-block force-pushed the cea/o4-protected-transports branch from cd9bf88 to e779035 Compare August 9, 2026 12:33
@cea-block
cea-block force-pushed the cea/o4-invalidation-failsafe branch from 4b030e9 to 0dfd220 Compare August 9, 2026 12:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant