~bigbes/sr-ht-dolt · parade

main · last commit 6 hours ago · ti41arbu

← Back to the parade

sr-ht-dolt-0qf.2 authn: the tokens.sr.ht bearer plane and core.GrantRead Past Stand

status: closed P1 task
bd reopen sr-ht-dolt-0qf.2
Created byEugene Blikh
Ownerbigbes@gmail.com
Created2026-08-12T20:11:44Z
Started2026-08-12T20:17:10Z
Updated2026-08-12T20:27:26Z
Closed2026-08-12T20:27:26Z
Description
/mcp is bearer-only, and this service has no bearer plane today: cookie, meta PAT over HTTP Basic, and the dolt keypair JWT on gRPC. Add ParseBearer plus a plane over sr-ht-ecore/bearer (working tokens issued by tokens.sr.ht, ClientID tokens.sr.ht, gated on the new core.GrantRead = "dolt:read") and a meta-PAT arm over the existing decode path, gated by authn.TokenGrantsAllow at core.AccessRO. A token that fails verification is a refusal, never a downgrade to anonymous.
Design
docs/DESIGN.mcp.md §4. sr-ht-ecore/bearer + /grants are already reachable (sr-ht-ecore is a direct dependency); cov.sr.ht authn/instance.go is the donor, including the consumer-side InstanceValidator seam. [tokens.sr.ht]origin absent means no such daemon: working tokens refused, meta PATs and anonymity still work.
Acceptance criteria
Table-driven classification tests with no network: working token with/without dolt:read, meta PAT, garbage, absent header (anonymous), expired.

Depends on

  • sr-ht-dolt-0qf — MCP surface: a read-only agent door to hosted databases parent-child closed

Depended on by

  • sr-ht-dolt-0qf.3 — mcpsrv: skeleton, Host allowlist, grant gate, list_databases blocks

Unblocks — everything waiting on this, transitively

  • sr-ht-dolt-0qf.3 — mcpsrv: skeleton, Host allowlist, grant gate, list_databases blocks closed
  • sr-ht-dolt-0qf.5 — mcpsrv: beads tools over the shared projection blocks closed
  • sr-ht-dolt-0qf.6 — Wire /mcp into the daemon, config and README blocks closed
  • sr-ht-dolt-0qf.4 — mcpsrv: generic tools over the browse seam blocks closed

No comments.

Close reason

Landed in 6288fc1: ParseBearer, the InstanceValidator seam over sr-ht-ecore/bearer, BearerCaller with Authorize, ResolveBearer branching on ClientID, core.GrantRead. Plus 0f6d50a (gofmt drift in authn tests, pre-existing at 587483e).
  • Eugene Blikh added under epic sr-ht-dolt-0qf · 2026-08-12T23:11:43Z
  • Eugene Blikh created the issue · 2026-08-12T23:11:43Z
  • Eugene Blikh sr-ht-dolt-0qf.3 now depends on this · 2026-08-12T23:12:54Z
  • Eugene Blikh changed status to in_progress · 2026-08-12T23:17:10Z
  • Eugene Blikh closed the issue · 2026-08-12T23:27:26Z
    Landed in 6288fc1: ParseBearer, the InstanceValidator seam over sr-ht-ecore/bearer, BearerCaller with Authorize, ResolveBearer branching on ClientID, core.GrantRead. Plus 0f6d50a (gofmt drift in authn tests, pre-existing at 587483e).
Stored rows — what this pane was built from, as read
issues 1 row
id sr-ht-dolt-0qf.2
content_hash 8e6146eadd1e58f2b423fb9dd6cd47903d1e79ea7e967d24566aea9812fb090c
title authn: the tokens.sr.ht bearer plane and core.GrantRead
description /mcp is bearer-only, and this service has no bearer plane today: cookie, meta PAT over HTTP Basic, and the dolt keypair JWT on gRPC. Add ParseBearer plus a plane over sr-ht-ecore/bearer (working tokens issued by tokens.sr.ht, ClientID tokens.sr.ht, gated on the new core.GrantRead = "dolt:read") and a meta-PAT arm over the existing decode path, gated by authn.TokenGrantsAllow at core.AccessRO. A token that fails verification is a refusal, never a downgrade to anonymous.
design docs/DESIGN.mcp.md §4. sr-ht-ecore/bearer + /grants are already reachable (sr-ht-ecore is a direct dependency); cov.sr.ht authn/instance.go is the donor, including the consumer-side InstanceValidator seam. [tokens.sr.ht]origin absent means no such daemon: working tokens refused, meta PATs and anonymity still work.
acceptance_criteria Table-driven classification tests with no network: working token with/without dolt:read, meta PAT, garbage, absent header (anonymous), expired.
notes
status closed
priority 1
issue_type task
assignee NULL
estimated_minutes NULL
created_at 2026-08-12T20:11:44Z
created_by Eugene Blikh
owner bigbes@gmail.com
updated_at 2026-08-12T20:27:26Z
closed_at 2026-08-12T20:27:26Z
closed_by_session
external_ref NULL
spec_id
compaction_level 0
compacted_at NULL
compacted_at_commit NULL
original_size NULL
sender
ephemeral 0
wisp_type
pinned 0
is_template 0
mol_type
work_type
source_system
metadata �{}
source_repo
close_reason Landed in 6288fc1: ParseBearer, the InstanceValidator seam over sr-ht-ecore/bearer, BearerCaller with Authorize, ResolveBearer branching on ClientID, core.GrantRead. Plus 0f6d50a (gofmt drift in authn tests, pre-existing at 587483e).
event_kind
actor
target
payload
await_type
await_id
timeout_ns 0
waiters
hook_bead
role_bead
agent_state
last_activity NULL
role_type
rig
due_at NULL
defer_until NULL
no_history 0
started_at 2026-08-12T20:17:10Z
is_blocked 0
dependencies 2 rows
id 077a135e-06c7-595a-9dda-2a09f4c1225d
issue_id sr-ht-dolt-0qf.2
type parent-child
created_at 2026-08-12T23:11:43Z
created_by Eugene Blikh
metadata �{}
thread_id
depends_on_issue_id sr-ht-dolt-0qf
depends_on_wisp_id NULL
depends_on_external NULL
id cd1b0742-7b5a-53bf-b62a-806b6efbd306
issue_id sr-ht-dolt-0qf.3
type blocks
created_at 2026-08-12T23:12:54Z
created_by Eugene Blikh
metadata �{}
thread_id
depends_on_issue_id sr-ht-dolt-0qf.2
depends_on_wisp_id NULL
depends_on_external NULL
events 3 rows
id 019ff79a-2a11-7d27-a52c-70861396e9b9
issue_id sr-ht-dolt-0qf.2
event_type created
actor Eugene Blikh
old_value
new_value
comment NULL
created_at 2026-08-12T23:11:43Z
id 019ff79f-25ae-7036-9bcd-66793937ac23
issue_id sr-ht-dolt-0qf.2
event_type status_changed
actor Eugene Blikh
old_value {"id":"sr-ht-dolt-0qf.2","title":"authn: the tokens.sr.ht bearer plane and core.GrantRead","description":"/mcp is bearer-only, and this service has no bearer plane today: cookie, meta PAT over HTTP Basic, and the dolt keypair JWT on gRPC. Add ParseBearer plus a plane over sr-ht-ecore/bearer (working tokens issued by tokens.sr.ht, ClientID tokens.sr.ht, gated on the new core.GrantRead = \"dolt:read\") and a meta-PAT arm over the existing decode path, gated by authn.TokenGrantsAllow at core.AccessRO. A token that fails verification is a refusal, never a downgrade to anonymous.","design":"docs/DESIGN.mcp.md §4. sr-ht-ecore/bearer + /grants are already reachable (sr-ht-ecore is a direct dependency); cov.sr.ht authn/instance.go is the donor, including the consumer-side InstanceValidator seam. [tokens.sr.ht]origin absent means no such daemon: working tokens refused, meta PATs and anonymity still work.","acceptance_criteria":"Table-driven classification tests with no network: working token with/without dolt:read, meta PAT, garbage, absent header (anonymous), expired.","status":"open","priority":1,"issue_type":"task","owner":"bigbes@gmail.com","created_at":"2026-08-12T20:11:44Z","created_by":"Eugene Blikh","updated_at":"2026-08-12T20:11:44Z"}
new_value {"status":"in_progress"}
comment NULL
created_at 2026-08-12T23:17:10Z
id 019ff7a8-8bb7-77df-a512-511d22133429
issue_id sr-ht-dolt-0qf.2
event_type closed
actor Eugene Blikh
old_value
new_value Landed in 6288fc1: ParseBearer, the InstanceValidator seam over sr-ht-ecore/bearer, BearerCaller with Authorize, ResolveBearer branching on ClientID, core.GrantRead. Plus 0f6d50a (gofmt drift in authn tests, pre-existing at 587483e).
comment NULL
created_at 2026-08-12T23:27:26Z