Brad Groux
|
58f39ea2b5
|
Implement secure device pairing sessions
Add signed pairing-code exchange, hashed device session secrets, identity device session management, desktop pairing onboarding, docs, and regression coverage.
|
2026-06-03 02:02:22 -07:00 |
|
Brad Groux
|
5cf82db881
|
docs: define v5 identity RBAC model
## Summary
- adds the v5 identity, workspace, and RBAC design document
- defines users, workspaces, memberships, invitations, sessions, agent identities, scoped API tokens, roles, route permissions, entity-level rules, and actor attribution
- documents local mode, server mode, localhost bypass behavior, backward-compatible migration, recovery, invitation, device pairing, and agent token UX flows
- links the design from the README docs map, security guide, and SQLite schema strategy
Closes #334.
## Verification
- CI: Build
- CI: Lint & Type Check
- CI: Security Audit
- CI: Workspace Unit Tests
- `./node_modules/.bin/prettier --check docs/IDENTITY-RBAC.md README.md docs/security.md docs/SQLITE-SCHEMA.md`
- `git diff --check`
## Notes
- This is the design slice for #334. It intentionally does not implement the RBAC tables or middleware.
|
2026-05-31 02:04:08 -05:00 |
|