refactor: rename cli-v2 → cli, archive legacy cli, plus broker-side grants + auto-migrate
- apps/cli/ is now the canonical CLI (was apps/cli-v2/). - apps/cli/ legacy v0 archived as branch 'legacy-cli-archive' and tag 'cli-v0-legacy-final' before deletion; git history preserves it too. - .github/workflows/release-cli.yml paths updated. - pnpm-lock.yaml regenerated. Broker-side peer-grant enforcement (spec: 2026-04-15-per-peer-capabilities): - 0020_peer-grants.sql adds peer_grants jsonb + GIN index on mesh.member. - handleSend in broker fetches recipient grant maps once per send, drops messages silently when sender lacks the required capability. - POST /cli/mesh/:slug/grants to update from CLI; broker_messages_dropped_by_grant_total metric. - CLI grant/revoke/block now mirror to broker via syncToBroker. Auto-migrate on broker startup: - apps/broker/src/migrate.ts runs drizzle migrate with pg_advisory_lock before the HTTP server binds. Exits non-zero on failure so Coolify healthcheck fails closed. - Dockerfile copies packages/db/migrations into /app/migrations. - postgres 3.4.5 added as direct broker dep. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
27
packages/db/migrations/0020_peer-grants.sql
Normal file
27
packages/db/migrations/0020_peer-grants.sql
Normal file
@@ -0,0 +1,27 @@
|
||||
-- Per-peer capability grants on mesh membership.
|
||||
--
|
||||
-- Spec: .artifacts/specs/2026-04-15-per-peer-capabilities.md
|
||||
--
|
||||
-- Adds a jsonb column to mesh_member tracking which peers may send what
|
||||
-- kind of messages to this member. Shape:
|
||||
-- { "<peer_pubkey_hex>": ["dm", "broadcast", "state-read", ...] }
|
||||
--
|
||||
-- Default = empty object, meaning "use the global default set"
|
||||
-- (read + dm + broadcast + state-read). Explicit empty array for a
|
||||
-- specific peer = blocked.
|
||||
--
|
||||
-- Enforcement lives in the broker's message router — before queueing an
|
||||
-- encrypted blob for a recipient, check peer_grants to see if the sender
|
||||
-- has the relevant capability. Silent drop on denial (Signal block
|
||||
-- semantics — sender's delivery receipt succeeds, recipient sees nothing).
|
||||
--
|
||||
-- Additive + nullable → safe to deploy before CLI knows about it.
|
||||
|
||||
ALTER TABLE "mesh"."member"
|
||||
ADD COLUMN IF NOT EXISTS "peer_grants" jsonb NOT NULL DEFAULT '{}'::jsonb;
|
||||
|
||||
-- GIN index for fast existence checks: does this member have any grant
|
||||
-- entry for this sender pubkey? Used on every message-send hot path.
|
||||
CREATE INDEX IF NOT EXISTS "member_peer_grants_gin_idx"
|
||||
ON "mesh"."member"
|
||||
USING gin ("peer_grants");
|
||||
@@ -164,8 +164,19 @@ export const meshMember = meshSchema.table("member", {
|
||||
joinedAt: timestamp().defaultNow().notNull(),
|
||||
lastSeenAt: timestamp(),
|
||||
revokedAt: timestamp(),
|
||||
/**
|
||||
* Per-peer capability grants — which peer pubkeys can send this member
|
||||
* which kinds of messages. Empty object = use defaults (read + dm +
|
||||
* broadcast + state-read). Empty array for a specific pubkey = blocked.
|
||||
* See .artifacts/specs/2026-04-15-per-peer-capabilities.md.
|
||||
*/
|
||||
peerGrants: jsonb()
|
||||
.$type<Record<string, string[]>>()
|
||||
.notNull()
|
||||
.default({}),
|
||||
}, (table) => [
|
||||
index("member_dashboard_user_idx").on(table.dashboardUserId),
|
||||
index("member_peer_grants_gin_idx").using("gin", table.peerGrants),
|
||||
]);
|
||||
|
||||
/**
|
||||
|
||||
Reference in New Issue
Block a user