Follow-up to #75 / PR #121, which landed diagram sharing on the cluster path for password/username-mode deployments (co-located _shares grants, view/edit access grading with primary-resolved access checks, unshare, shares/shared listing, cascade over the local closure, delete-clears-grants, _shares lockdown). These remaining pieces were deferred because each needs cross-partition/async machinery that can only be validated on a live multi-node cluster.
Scope
Notes
- Access-read routing is settled (
specs/ClusterShareAccess.tla): share-gated access checks resolve on the resource primary; the bounded failover staleness window is accepted + documented. No promotion drain-gate.
- Co-location invariant: never add a secondary index on
_shares in cluster mode (index_partition hashes off the resource's partition).
Follow-up to #75 / PR #121, which landed diagram sharing on the cluster path for password/username-mode deployments (co-located
_sharesgrants, view/edit access grading with primary-resolved access checks, unshare,shares/sharedlisting, cascade over the local closure, delete-clears-grants,_shareslockdown). These remaining pieces were deferred because each needs cross-partition/async machinery that can only be validated on a live multi-node cluster.Scope
identity_cryptointoDbRequestHandler; blind-index the email intograntee_keyand store the email encrypted ingrantee_email; resolve email→canonical id. The resolve needs a synchronous cross-partition_identity_linkslookup (the async scatter model doesn't provide one), andshares-responsegrantee_emaildecryption needs forwarded-response interception.MqttDbAccess::resolve_pending_grantsno-op stub (crates/mqdb-agent/src/db_helpers.rs) with a cross-partition scatter-update that fillsgranteeon a grantee's pending grants at sign-in.shared-response resource hydration.$DB/{e}/sharedcurrently returns grant rows, not full resource records (agentlist_shared_withreturns resources). Have each primary hydrate its co-located resources during the scatter.mqdb dev test --sharing3-node E2E. AddsharingtoDevAction::Testand arun_sharing_testsrunner (modeled on the ownership runner); verify a grantee connected to a different node than the resource primary can read/edit per grant, cascade, andsharedcross-node.Notes
specs/ClusterShareAccess.tla): share-gated access checks resolve on the resource primary; the bounded failover staleness window is accepted + documented. No promotion drain-gate._sharesin cluster mode (index_partitionhashes off the resource's partition).