Enforce SSH workflow capabilities locally

This commit is contained in:
Eric Wendland 2026-05-19 15:44:13 +02:00
commit f7e85960f7
8 changed files with 328 additions and 62 deletions

View file

@ -206,8 +206,13 @@ unsupported and asks for JSONL or the spec source. Revocation lists are not yet
full CRDT-replicated resources, but the daemon can already pull cert-flow and
revocation metadata from authorized peers over the protected Iroh control ALPN.
Manual sync commands and the background live-sync loop share the same capability
checks and cursor state. The live-sync loop first asks for authorized stream
watermarks and skips module pulls whose remote high-water value has not advanced.
checks and cursor state. Local SSH certificate and revocation metadata commands
also accept an optional subject principal for authorization testing: non-owner
subjects must hold `ssh_cert.*` capabilities on `resource:ssh:certs` or
`ssh_revocation.*` capabilities on `resource:ssh:revocations` before requests,
approval/import/read operations, or revocation publish/read/import operations
are accepted. The live-sync loop first asks for authorized stream watermarks and
skips module pulls whose remote high-water value has not advanced.
## Keychain, Auth, And Secrets