summaryrefslogtreecommitdiffstats
path: root/tmp-decisions.md
Commit message (Collapse)AuthorAgeFilesLines
* docs: rework Phase 12 — hub minimization deferred by operator decisionChristophe Besson2026-08-131-15/+33
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Operator decisions (tmp-decisions.md D1/D2/D4): - the hub keeps serving the web UI (zero-install path stays) - a native desktop client is offered ALONGSIDE it, not as a replacement - hub minimization is off the critical path and may be dropped Phase 12 was "Hub minimization: registrar and nothing more". Most of it is dropped: route-inventory blindness test, opaque private-group metadata, chat_notify metadata minimization, residual schema cleanup. The swarm item already shipped in 11.5.18. Two items are kept, because the decision makes them more relevant rather than less — the hub stays in the trusted path by choice, so what it can substitute and what code it serves both still matter: 12.1 key transparency + safety numbers [H3]. This is the last open High finding and nothing else fixes it: the hub is the public key directory, so substituting a key during an invite hands it the group key silently, with no JWT forgery and no code injection. Dropping Phase 12 wholesale would have left it open indefinitely. 12.2 served-SPA integrity: CSP, SRI, and a hub-published signed digest of the bundle so a native client can verify what the browser was given. 12.3 honest labelling of /app/ as the hub-served path. 12.4 written threat model — the thing that stops the overclaiming pattern. Recorded consequence: T3 is now accepted permanently for browser users. A hub that serves the code can exfiltrate keys from the page whatever the protocol does. The claim that still holds, and that the docs should make, is "the hub cannot read your content unless it actively attacks you" — not "unreadable by other parties, even the hub". Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* docs: second security review + roadmap rewrite0.1Christophe Besson2026-08-131-0/+145
Second architecture and security review (second-review.md): 6 critical and 7 high findings against the Phase 12 implementation, plus an assessment of whether the system meets its end-to-end confidentiality claim. Roadmap rewritten against those findings (devel-phases-next.md): new blocking Phase 11.5 (security remediation), Phase 12 (hub minimization), Phase 13 (native desktop client). Old phases 12-17 renumbered to 14-19. tmp-decisions.md records two open decisions: whether the hub keeps serving the web UI, and browser extension vs native desktop client vs both. CLAUDE.md and devel-phases-next.md also carry pre-existing Phase 12 edits from the working tree that could not be cleanly separated from the review changes. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>