Skip to content

cluster diagram sharing: identity-mode resolution, pending sweep, cross-partition cascade, and 3-node E2E #122

Description

@fabracht

Follow-up to #75 / PR #121, which landed diagram sharing on the cluster path for password/username-mode deployments (co-located _shares grants, view/edit access grading with primary-resolved access checks, unshare, shares/shared listing, cascade over the local closure, delete-clears-grants, _shares lockdown). These remaining pieces were deferred because each needs cross-partition/async machinery that can only be validated on a live multi-node cluster.

Scope

  • Identity/OAuth-mode grantee resolution + crypto. Plumb identity_crypto into DbRequestHandler; blind-index the email into grantee_key and store the email encrypted in grantee_email; resolve email→canonical id. The resolve needs a synchronous cross-partition _identity_links lookup (the async scatter model doesn't provide one), and shares-response grantee_email decryption needs forwarded-response interception.
  • Pending-grant sign-in sweep. Replace the MqttDbAccess::resolve_pending_grants no-op stub (crates/mqdb-agent/src/db_helpers.rs) with a cross-partition scatter-update that fills grantee on a grantee's pending grants at sign-in.
  • Cross-partition cascade. The current cascade walks only the locally-held closure. Extend to closure members on other partitions via cycle-safe cross-node fan-out (distributed visited set or depth bound) plus a cross-owner auth-bypass for internal cascade grants.
  • shared-response resource hydration. $DB/{e}/shared currently returns grant rows, not full resource records (agent list_shared_with returns resources). Have each primary hydrate its co-located resources during the scatter.
  • mqdb dev test --sharing 3-node E2E. Add sharing to DevAction::Test and a run_sharing_tests runner (modeled on the ownership runner); verify a grantee connected to a different node than the resource primary can read/edit per grant, cascade, and shared cross-node.

Notes

  • Access-read routing is settled (specs/ClusterShareAccess.tla): share-gated access checks resolve on the resource primary; the bounded failover staleness window is accepted + documented. No promotion drain-gate.
  • Co-location invariant: never add a secondary index on _shares in cluster mode (index_partition hashes off the resource's partition).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions