feat: publish fail-closed RBAC authority (TIN-2822) - #42
Conversation
|
Live 2026-07-13 reconciliation against tinyland-invitation 0.2.5 confirms this PR's source boundary and the next interoperability work:
Recommended sequence remains: land the auth-owned versioned RBAC source contract after #41; replace invitation's embedded hierarchy with injected structural authority and trusted actor resolution; add distributed accept CAS/receipt; then add a canonical assignRole transaction with actor/target reload, last-super-admin protection, grant validation, and session revocation/auth epoch. No release or adoption claim is made here. |
0e73d22 to
7f19df6
Compare
|
Restack evidence (2026-07-14)
Boundary: this remains a source-only draft at package version 0.7.1. It does not release auth 0.8, implement PostgreSQL/Redis adapters, prove invitation parity, adopt the graph in tinyland.dev, migrate sessions, run a canary, or unfreeze production. |
Summary
Boundary
DRAFT / SOURCE-ONLY / DO NOT MERGE, TAG, RELEASE, OR ADOPT YET.
This is stacked on #41 and implements only the tinyland-auth source half of TIN-2822. The invitation package still needs its embedded default authority removed in favor of injected structural authority, with custom hooks restricted to narrowing policy. Cross-package packed-artifact parity, consumer translation maps, TIN-2831, and the coordinated 0.8 release remain outstanding. tinyland.dev #731 remains held.
Tracks TIN-2822; does not close it.
Validation
Signed commit: 0e73d22