Skip to content

feat(security): establish Phase 62 identity and authorization foundation - #117

Merged
hotzenplotz5 merged 530 commits into
mainfrom
phase-62-security-identity-foundation
Aug 2, 2026
Merged

feat(security): establish Phase 62 identity and authorization foundation#117
hotzenplotz5 merged 530 commits into
mainfrom
phase-62-security-identity-foundation

Conversation

@hotzenplotz5

@hotzenplotz5 hotzenplotz5 commented Jul 27, 2026

Copy link
Copy Markdown
Owner

Scope

Completes Phase 62 — Identity, RBAC and Accountability Foundation only. It does not advance Phase 63–67 runtime.

Phase 62 is technically and operationally complete. All bounded implementation slices through Slice 2X — Protected Mutation Response Outcomes have passed guarded CI and the required real-yaVDR runtime acceptance.

Completed Phase 62 capability

  • canonical actor, device, session, credential, authentication, request and correlation context;
  • persistent identity and request-time lifecycle resolution;
  • Legacy Basic compatibility plus optional Managed Basic and browser sessions;
  • strict credential precedence with no Basic fallback for a presented browser cookie;
  • browser-session issue/logout, CSRF ownership, absolute lifetime and issuer binding;
  • optional per-actor concurrency limits, idle expiry and terminal retention cleanup;
  • persisted exact actor permission and backend-scope grants;
  • fixed exact-scope role.admin and role.read-only semantics;
  • protected Remote, Timer, Channel Move, Recording, SearchTimer and Native Fuzzy mutation families;
  • explicit Safe POST classification for accepted validation and preview routes;
  • complete central POST inventory with unknown browser/enforced mutation paths failing closed;
  • append-only pre-dispatch accountability;
  • browser-session lifecycle outcomes;
  • protected mutation success/failure outcomes with non-secret context continuity;
  • guarded CI, packaging and real-yaVDR acceptance evidence.

Slice 2X — Protected Mutation Response Outcomes

For every authorized existing protected mutation reaching ApiRouter::handleClientPost:

2xx     -> event_type=operation.succeeded, outcome=succeeded
non-2xx -> event_type=operation.failed,    outcome=failed
reason_code=http_status_<status>

The outcome reuses the authenticated actor/device/session state, permission, backend, action, operation, request and correlation context. Request or response bodies, headers, credentials, cookies and secrets are not recorded.

Denials, Safe POST, GET and unsupported methods do not receive an operation outcome. Failure to append the post-dispatch outcome returns HTTP 503 accountability_unavailable; Phase 62 makes no rollback or replay-safety claim for an already executed backend mutation.

Real yaVDR runtime acceptance

Accepted source/runtime head:

4762583d5b5170866838ed9f03b928adbf39f99e

Source CI:

VDR-Suite CI #6884
Run ID: 30752351218
all five jobs successful

Runtime result:

PHASE_62_SLICE_2X_RUNTIME_ACCEPTANCE=PASS

daemon_sha256=488edade196cedfb92d5393a8725b39c5f5cdfd3265e2b15bab6aadfbe7ef5f5
loader_sha256=3758aba3c9f87c99751bb59408f69f852579581e2f8251c720b3b7845f75399a
configuration_sha256=8faffe1a18f996681d6ca5f438df9e47626f8992e8cd8d1b67e0c25b1895ed6b
runtime_report_sha256=bf165416b5ad041f44b2514182dac582a7f1060bf1ae8cc584964f3fc5a98bdf

Durable evidence:

/var/backups/vdr-suite-phase62-slice2x-20260802T145043Z-4762583d5b51

The guarded acceptance proved successful and failed protected-mutation outcomes, context continuity, unchanged production database during the isolated scenario, removal of the temporary systemd override and an active normal daemon service after completion.

Final Phase 62 closeout

Final closeout head:

75787cf61cc123f111b421a261ecd535068a6789

Final CI:

VDR-Suite CI #6920
Run ID: 30755925693
status: completed
conclusion: success

All five final gates passed:

  • docs-check
  • make-test-audit
  • frontend-regression-test
  • fast-regression-test, including the daemon build
  • packaging-regression-test

Canonical closeout documents:

  • docs/development/phase-62-closeout.md
  • docs/development/phase-62-slice-2x-runtime-closeout.md
  • docs/development/current-status.md
  • docs/CURRENT.md
  • docs/NEW-CHAT-HANDOFF.md

Compatibility-retirement decision

Legacy Basic remains an explicitly transitional deployment mode. It is not removed in this pull request because it remains the compatibility default and packaged deployments do not yet have a mandatory migration to enforced.

Actual retirement requires a future deployment migration contract. It is not an unfinished Phase-62 slice.

Explicitly deferred

No Phase-62 requirement proves a need for an audit HTTP product, generic security administration, native/service credential lifecycle, universal revision/idempotency infrastructure or transactional Outbox.

Phase 63 begins only under a separate approved bounded contract.

Repository state

Base remains:

main @ cb77ff66e11dca7db2eafa36525762dcde35102d

PR #118 remains separate paused TVScraper work and is not part of this pull request.

Copy link
Copy Markdown
Owner Author

Slice 2F CI checkpoint

Commit 1801024f23b9d4a457e05c41723657dc9758789d (feat(security): add minimal backend-scoped roles) passed VDR-Suite CI #6533.

Successful jobs:

  • docs-check
  • frontend-regression-test
  • make-test-audit
  • fast-regression-test, including daemon build
  • packaging-regression-test

Repository validation for the fixed backend-scoped role.admin / role.read-only contract is therefore complete. Installed yaVDR runtime acceptance remains pending. PR #117 remains Draft.

Copy link
Copy Markdown
Owner Author

Slice 2F installed-runtime acceptance — PASS

Accepted repository head:

ad13b6c3622dc1635ff3ad5a92809e0f9c14af09

Installed daemon SHA-256:

da1b245622b656416eae69a97f5ef8db2a1a42de00b413905b4664f080c9b688

Installed frontend runtime-loader SHA-256:

8a18cf06f3384695ff30a1edf263cd689c9e3544a8a399bad4e699098c03df4b

Runtime evidence:

  • exact role.admin@default authorized Remote actions while the direct remote.control@default grant was disabled;
  • accountability persisted allowed, role_permission_granted and dispatch_authorized;
  • exact role.read-only@default overrode Admin and the direct Remote grant for the same backend;
  • accountability persisted denied, role_read_only and dispatch_denied;
  • the installed Webfrontend rendered the dedicated German read-only message;
  • transient SQLite writer contention was reproduced as SQLITE_BUSY, corrected with a connection busy timeout and reaccepted under repeated Remote actions;
  • PRAGMA quick_check returned ok;
  • the normal runtime grant state was restored: remote.control@default active, test role rows inactive;
  • vdr-suite-daemon.service remained active.

GitHub Actions VDR-Suite CI #6541 completed successfully for the accepted head.

PHASE 62 SLICE 2F RUNTIME ACCEPTANCE: PASS

PR #117 remains Draft.

Copy link
Copy Markdown
Owner Author

Slice 2G installed-runtime acceptance — PASS

Accepted repository head:

73a9d6cb47ad5fdf80987e769cedc6b8fdc43640

Installed daemon SHA-256:

53ea4e45cd60c74d84fa45d29f3761111afc659655f52978262eac363c75f920

Installed deferred runtime loader SHA-256:

74ecc75bd091bbf74cf4251eaefad7242454795468eb98f98fc28eabee21d43b

Controlled public-origin runtime acceptance through https://127.0.0.1/vdr-suite proved:

  • the direct daemon listener and the Nginx-prefixed public browser-session route became HTTP-ready after restart;
  • Managed Basic issued a real browser session through the installed daemon;
  • missing and wrong browser CSRF were denied before Timer authorization;
  • browser sessions and Managed Basic identities without Timer policy received permission_denied;
  • Legacy Basic compatibility remained available on the migrated Timer route;
  • exact backend-scoped direct grants authorized timers.create, timers.modify and timers.delete;
  • a direct grant for another backend scope received backend_scope_denied;
  • exact role.admin granted all three Timer permissions;
  • exact role.read-only overrode Admin and direct Timer grants for the same backend;
  • Read-only on one backend did not block an exact direct grant on another backend;
  • authorized probes were stopped safely by the independent backend policy using deliberately unknown backend IDs, before Timer adapter dispatch;
  • accountability persisted the expected permission, backend scope, decision, reason and pre-dispatch outcome for every tested path;
  • browser logout revoked the temporary browser session;
  • the original runtime configuration and legacy-local-web grant rows were restored exactly;
  • remote.control@default remains active, test roles are inactive, no temporary actors remain, PRAGMA quick_check returns ok, and the daemon remains active.

Runtime backup:

/var/backups/vdr-suite-phase62-slice2g-runtime-20260731-060304
PHASE 62 SLICE 2G BROWSER-SESSION RUNTIME ACCEPTANCE: PASS

PR #117 remains open and Draft.

@hotzenplotz5
hotzenplotz5 marked this pull request as ready for review August 2, 2026 17:11
@hotzenplotz5
hotzenplotz5 merged commit f9e5f88 into main Aug 2, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant