main · last commit
6 hours ago ·
ti41arbu
sr-ht-dolt-0qf.2 authn: the tokens.sr.ht bearer plane and core.GrantRead
Past Stand
bd reopen sr-ht-dolt-0qf.2
| Created by | Eugene Blikh |
| Owner | bigbes@gmail.com |
| Created | 2026-08-12T20:11:44Z |
| Started | 2026-08-12T20:17:10Z |
| Updated | 2026-08-12T20:27:26Z |
| Closed | 2026-08-12T20:27:26Z |
/mcp is bearer-only, and this service has no bearer plane today: cookie, meta PAT over HTTP Basic, and the dolt keypair JWT on gRPC. Add ParseBearer plus a plane over sr-ht-ecore/bearer (working tokens issued by tokens.sr.ht, ClientID tokens.sr.ht, gated on the new core.GrantRead = "dolt:read") and a meta-PAT arm over the existing decode path, gated by authn.TokenGrantsAllow at core.AccessRO. A token that fails verification is a refusal, never a downgrade to anonymous.
docs/DESIGN.mcp.md §4. sr-ht-ecore/bearer + /grants are already reachable (sr-ht-ecore is a direct dependency); cov.sr.ht authn/instance.go is the donor, including the consumer-side InstanceValidator seam. [tokens.sr.ht]origin absent means no such daemon: working tokens refused, meta PATs and anonymity still work.
Table-driven classification tests with no network: working token with/without dolt:read, meta PAT, garbage, absent header (anonymous), expired.
sr-ht-dolt-0qf
— MCP surface: a read-only agent door to hosted databases
parent-child
closed
sr-ht-dolt-0qf.3
— mcpsrv: skeleton, Host allowlist, grant gate, list_databases
blocks
sr-ht-dolt-0qf.3
— mcpsrv: skeleton, Host allowlist, grant gate, list_databases
blocks
closed
sr-ht-dolt-0qf.5
— mcpsrv: beads tools over the shared projection
blocks
closed
sr-ht-dolt-0qf.6
— Wire /mcp into the daemon, config and README
blocks
closed
sr-ht-dolt-0qf.4
— mcpsrv: generic tools over the browse seam
blocks
closed
| id | sr-ht-dolt-0qf.2 |
| content_hash | 8e6146eadd1e58f2b423fb9dd6cd47903d1e79ea7e967d24566aea9812fb090c |
| title | authn: the tokens.sr.ht bearer plane and core.GrantRead |
| description | /mcp is bearer-only, and this service has no bearer plane today: cookie, meta PAT over HTTP Basic, and the dolt keypair JWT on gRPC. Add ParseBearer plus a plane over sr-ht-ecore/bearer (working tokens issued by tokens.sr.ht, ClientID tokens.sr.ht, gated on the new core.GrantRead = "dolt:read") and a meta-PAT arm over the existing decode path, gated by authn.TokenGrantsAllow at core.AccessRO. A token that fails verification is a refusal, never a downgrade to anonymous. |
| design | docs/DESIGN.mcp.md §4. sr-ht-ecore/bearer + /grants are already reachable (sr-ht-ecore is a direct dependency); cov.sr.ht authn/instance.go is the donor, including the consumer-side InstanceValidator seam. [tokens.sr.ht]origin absent means no such daemon: working tokens refused, meta PATs and anonymity still work. |
| acceptance_criteria | Table-driven classification tests with no network: working token with/without dolt:read, meta PAT, garbage, absent header (anonymous), expired. |
| notes | |
| status | closed |
| priority | 1 |
| issue_type | task |
| assignee | NULL |
| estimated_minutes | NULL |
| created_at | 2026-08-12T20:11:44Z |
| created_by | Eugene Blikh |
| owner | bigbes@gmail.com |
| updated_at | 2026-08-12T20:27:26Z |
| closed_at | 2026-08-12T20:27:26Z |
| closed_by_session | |
| external_ref | NULL |
| spec_id | |
| compaction_level | 0 |
| compacted_at | NULL |
| compacted_at_commit | NULL |
| original_size | NULL |
| sender | |
| ephemeral | 0 |
| wisp_type | |
| pinned | 0 |
| is_template | 0 |
| mol_type | |
| work_type | |
| source_system | |
| metadata | �{} |
| source_repo | |
| close_reason | Landed in 6288fc1: ParseBearer, the InstanceValidator seam over sr-ht-ecore/bearer, BearerCaller with Authorize, ResolveBearer branching on ClientID, core.GrantRead. Plus 0f6d50a (gofmt drift in authn tests, pre-existing at 587483e). |
| event_kind | |
| actor | |
| target | |
| payload | |
| await_type | |
| await_id | |
| timeout_ns | 0 |
| waiters | |
| hook_bead | |
| role_bead | |
| agent_state | |
| last_activity | NULL |
| role_type | |
| rig | |
| due_at | NULL |
| defer_until | NULL |
| no_history | 0 |
| started_at | 2026-08-12T20:17:10Z |
| is_blocked | 0 |
| id | 077a135e-06c7-595a-9dda-2a09f4c1225d |
| issue_id | sr-ht-dolt-0qf.2 |
| type | parent-child |
| created_at | 2026-08-12T23:11:43Z |
| created_by | Eugene Blikh |
| metadata | �{} |
| thread_id | |
| depends_on_issue_id | sr-ht-dolt-0qf |
| depends_on_wisp_id | NULL |
| depends_on_external | NULL |
| id | cd1b0742-7b5a-53bf-b62a-806b6efbd306 |
| issue_id | sr-ht-dolt-0qf.3 |
| type | blocks |
| created_at | 2026-08-12T23:12:54Z |
| created_by | Eugene Blikh |
| metadata | �{} |
| thread_id | |
| depends_on_issue_id | sr-ht-dolt-0qf.2 |
| depends_on_wisp_id | NULL |
| depends_on_external | NULL |
| id | 019ff79a-2a11-7d27-a52c-70861396e9b9 |
| issue_id | sr-ht-dolt-0qf.2 |
| event_type | created |
| actor | Eugene Blikh |
| old_value | |
| new_value | |
| comment | NULL |
| created_at | 2026-08-12T23:11:43Z |
| id | 019ff79f-25ae-7036-9bcd-66793937ac23 |
| issue_id | sr-ht-dolt-0qf.2 |
| event_type | status_changed |
| actor | Eugene Blikh |
| old_value | {"id":"sr-ht-dolt-0qf.2","title":"authn: the tokens.sr.ht bearer plane and core.GrantRead","description":"/mcp is bearer-only, and this service has no bearer plane today: cookie, meta PAT over HTTP Basic, and the dolt keypair JWT on gRPC. Add ParseBearer plus a plane over sr-ht-ecore/bearer (working tokens issued by tokens.sr.ht, ClientID tokens.sr.ht, gated on the new core.GrantRead = \"dolt:read\") and a meta-PAT arm over the existing decode path, gated by authn.TokenGrantsAllow at core.AccessRO. A token that fails verification is a refusal, never a downgrade to anonymous.","design":"docs/DESIGN.mcp.md §4. sr-ht-ecore/bearer + /grants are already reachable (sr-ht-ecore is a direct dependency); cov.sr.ht authn/instance.go is the donor, including the consumer-side InstanceValidator seam. [tokens.sr.ht]origin absent means no such daemon: working tokens refused, meta PATs and anonymity still work.","acceptance_criteria":"Table-driven classification tests with no network: working token with/without dolt:read, meta PAT, garbage, absent header (anonymous), expired.","status":"open","priority":1,"issue_type":"task","owner":"bigbes@gmail.com","created_at":"2026-08-12T20:11:44Z","created_by":"Eugene Blikh","updated_at":"2026-08-12T20:11:44Z"} |
| new_value | {"status":"in_progress"} |
| comment | NULL |
| created_at | 2026-08-12T23:17:10Z |
| id | 019ff7a8-8bb7-77df-a512-511d22133429 |
| issue_id | sr-ht-dolt-0qf.2 |
| event_type | closed |
| actor | Eugene Blikh |
| old_value | |
| new_value | Landed in 6288fc1: ParseBearer, the InstanceValidator seam over sr-ht-ecore/bearer, BearerCaller with Authorize, ResolveBearer branching on ClientID, core.GrantRead. Plus 0f6d50a (gofmt drift in authn tests, pre-existing at 587483e). |
| comment | NULL |
| created_at | 2026-08-12T23:27:26Z |
No comments.
Close reason