Skip to content

fix(protocol): prohibit address-based access tracking - #45

Merged
zoeyrose merged 1 commit into
mainfrom
fix/access-address-privacy
Oct 4, 2026
Merged

zoeyrose merged 1 commit into
mainfrom
fix/access-address-privacy

Conversation

@zoeyrose

@zoeyrose zoeyrose commented Oct 4, 2026 •

Copy link
Copy Markdown
Member

Summary

Remove address-based requester tracking from the access-token contract. The former source-HMAC rate-limiting requirement conflicts with keeping player IP addresses out of application identity and usage records.

Implementation / behavior

  • Require shared fixed-purpose ingress circuit breakers without IP addresses, forwarded-IP headers or address-derived aliases.
  • Treat coarse limits as configurable per-edge-location capacity settings, not a globally serialized quota. Former per-source ceilings cannot become shared defaults without aggregate-load validation.
  • Preserve authenticated server/route/grant budgets, bounded concurrent attempts and replay protection derived from random protocol values.
  • Prohibit address-based identifiers in token history, audit records, rate-limit state, logs, metrics and administrative responses.
  • Retain bounded transient transport routing and explicit operator-configured server endpoints, with teardown and no history reuse.

Only spec/access-tokens.md changes. Protobuf schemas, generated Go/Rust bindings, crate sources, fixtures and publication policy are unchanged.

Validation

At 79f9511140dfd0a203ea7642c821a012d7c3d41d, full tools/validate.sh passed in the pinned Atrinik Linux build image sha256:7904a1802054662b0ede5b55de72e4c92b0112a3c211125f994ed6c62e9ec9d8. Regeneration left the tree clean, unchanged generated/consumer inputs were verified, and the full-base whitespace check passed.

Independent review approved this exact head. Required GitHub checks Protocol validation and Conventional PR title passed on this head and accepted base.

Limitations / follow-up

Metaserver and Classic implementation changes are coordinated separately under #43; this specification does not claim those runtime changes are deployed. The metaserver shared capacity defaults need their own implementation/load review.

Crate preparation remains undispatched. Its exact source-release target must be reconsidered after the privacy contract is finalized, even though generated library bytes are unchanged. No merge, registry publication, provider configuration or production change is included.

@zoeyrose
zoeyrose marked this pull request as ready for review October 4, 2026 18:17
@zoeyrose
zoeyrose merged commit a475377 into main Oct 4, 2026
9 checks passed
@zoeyrose
zoeyrose deleted the fix/access-address-privacy branch October 4, 2026 18:17
@github-actions

github-actions Bot commented Oct 4, 2026

Copy link
Copy Markdown

🎉 This PR is included in version 2.8.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant