For CIRISServer#148, limb (b). At v31.0.0 one CohortProvider drives the subject set for Key, IdentityOccurrence and TransportDestination together (src/replication/bridge.rs ~1182, ~1299). CIRISEdge#311 collapsed the selectors into one.
cohort_scope is per-flow, and the server needs to decide per plane which subjects' records it may relay. For a third party's key record, onward flow needs a share or publish transmission principle on THEIR grant (persist consent grammar, #509/#625). retain authorises holding, not forwarding. One selector for three planes cannot honour that. It either relays every plane or none.
Ask: a per-EnvelopeKind selector hook (or one hook that receives the kind), so a host can publish its own and anchored keys on the Key plane while withholding third-party occurrences and transport routes whose subject never granted onward flow. The default behaviour stays as it is today.
For CIRISServer#148, limb (b). At v31.0.0 one
CohortProviderdrives the subject set for Key, IdentityOccurrence and TransportDestination together (src/replication/bridge.rs~1182, ~1299). CIRISEdge#311 collapsed the selectors into one.cohort_scopeis per-flow, and the server needs to decide per plane which subjects' records it may relay. For a third party's key record, onward flow needs ashareorpublishtransmission principle on THEIR grant (persist consent grammar, #509/#625).retainauthorises holding, not forwarding. One selector for three planes cannot honour that. It either relays every plane or none.Ask: a per-
EnvelopeKindselector hook (or one hook that receives the kind), so a host can publish its own and anchored keys on the Key plane while withholding third-party occurrences and transport routes whose subject never granted onward flow. The default behaviour stays as it is today.