Skip to content

feat(access): replace password discovery with access tokens - #64

Draft
zoeyrose wants to merge 3 commits into
mainfrom
feat/access-tokens
Draft

zoeyrose wants to merge 3 commits into
mainfrom
feat/access-tokens

Conversation

@zoeyrose

@zoeyrose zoeyrose commented Oct 4, 2026 •

Copy link
Copy Markdown
Member

Summary

Replace replacement-client invite/password discovery with the access-token consumer contract. The client now consumes directory v2 access_required metadata, resolves 16-character access codes through the fixed rendezvous service, binds the resolved certificate to both the directory leaf identity and GP1 SPKI identity, and gates protected sessions before account or world state is admitted.

Implementation / behavior

  • Consume the generated metaserver v2 directory schema and preserve only the public directory snapshot in the cache.
  • Normalize a 16-character Crockford access code, derive its route capability, and send one bounded strict POST to https://rendezvous.meta.atrinik.org/v1/access/resolve with redirects and cache/cookie channels disabled.
  • Validate canonical resolve responses, nonce and expiry bounds, the DER leaf serverId, and the P-256 SPKI pin derived from the same certificate.
  • Negotiate exactly GP1 1.1 with ACCESS_TOKENS_V1 and a mandatory open/protected policy before credentials are exposed.
  • Construct the fixed GP1 1.1 client access offer through the shared access_client_hello validator before exposing it to the adapter's immediate serialization/send callback.
  • Track protected authentication as AccessRequired then AccessPending; only an accepted result after the encrypted session-bound authentication write opens account flow.
  • Reject unsolicited, early, duplicate, stale, and unavailable results atomically, and fence account/world state throughout protected admission.
  • Keep access codes, route capabilities, nonces, grants, and private response bodies out of URLs, persistent caches, and printable/loggable types, with best-effort buffer clearing.
  • Preserve the existing account-authentication and saved-player boundary after access admission.

Validation

  • Independent architecture re-review approved exact head 4cd8709db5e0a676e74942b8e1afc67964fc16ee, including the protected-state corrections and the concrete shared-validator ClientHello adapter.
  • tools/validate.sh passed in the pinned Linux build image, including strict workspace clippy, all workspace and documentation tests, dependency policy, foundation and architecture checks, headless/window smoke checks, and two byte-identical package builds.
  • The refreshed full aggregate log has SHA-256 f7a4561085f1444d76db286f919044baa8d9b245fc18cf832fe5fc8994a92d5b against reviewed protocol candidate e48902dc3cb7051e589c48fdb448af3433c12ac6.
  • Focused access validation passed 35 directory tests, 13 protocol-adapter tests, and 12 session tests. The reviewer independently reran the 13 adapter tests and documentation tests in the pinned build image.

Limitations / follow-up

atrinik-protocol 0.2.0 is not yet published to the immutable registry. Local qualification used a task-only path override to the reviewed protocol candidate; no path or Git override is committed. Before this PR is ready for review or merge, regenerate Cargo.lock from the published atrinik-protocol = 0.2.0 package so it contains the registry source and checksum, then rerun the complete validation and normal CI without an override. This draft does not authorize publication, merge, release, deployment, or runtime changes.

The ClientHello integration ends at the adapter's construction and immediate serialization/send callback. This milestone does not claim a live GP1 transport, encrypted-session runtime, or Windows runtime execution.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant