Skip to content

Per-plane cohort selectors: one CohortProvider drives Key, IdentityOccurrence and TransportDestination, so a host can't honour per-flow consent on relays #678

Description

@emooreatx

For CIRISServer#148, limb (b). At v31.0.0 one CohortProvider drives the subject set for Key, IdentityOccurrence and TransportDestination together (src/replication/bridge.rs ~1182, ~1299). CIRISEdge#311 collapsed the selectors into one.

cohort_scope is per-flow, and the server needs to decide per plane which subjects' records it may relay. For a third party's key record, onward flow needs a share or publish transmission principle on THEIR grant (persist consent grammar, #509/#625). retain authorises holding, not forwarding. One selector for three planes cannot honour that. It either relays every plane or none.

Ask: a per-EnvelopeKind selector hook (or one hook that receives the kind), so a host can publish its own and anchored keys on the Key plane while withholding third-party occurrences and transport routes whose subject never granted onward flow. The default behaviour stays as it is today.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions