BREAKING: All nodes must upgrade together. Legacy p2ns.core-request string messages are rejected; invite/consensus control plane uses protomux-rpc (invite.request, invite.ack, invite.relay*, consensus.*). Shared Corestore namespaces are the default for plugin DBs and drives; USE_SHARED_CORESTORE_NAMESPACES=false is debug-only. Admin plugin actions with params are validated before run. EXPERIMENTAL: End-to-end RPC invite path reuses existing handlers via adapters; invite wire still ships on the invite channel. Multi-peer invite/relay integration tests are not in CI yet (core-rpc-smoke only). SDK & channels: - channel-rpc.js, sdk.channels.rpc (register/request/event) - core-rpc.js for p2ns.core; action-params + plugin route validation - sdk.db.getCore/reopen, sdk.state.getPeerChannelSnapshot, sdk.metrics.getHolepunchStats (schema v1) Runtime: - p2ns.js: RPC-first core invite/consensus; Hyperswarm firewall/reconnect - channel-manager: required protomux-rpc per peer - db-shared-namespace-migration; drive-manager shared namespaces - proxy-server: invite.request RPC for joiners Plugins: file.drop, global.profile, peer.directory, domain.consensus, peer.visualize, example.plugin (RPC demo); peer.directory UI polish Also: CI/smoke scripts, diagnostics hardening, plugin config schema validation, admin action param modal, docs/RFCS, package-lock + engines.node >= 18
1.1 KiB
1.1 KiB
RFC 0004: Admin Authentication and RBAC
Status
Draft
Problem
p2ns.admin provides powerful operational endpoints and currently assumes a trusted local context. Multi-user environments and remote access scenarios need stronger controls.
Proposal
Introduce optional authentication and role-based authorization for admin APIs and UI operations.
Scope
- Define auth modes (disabled, local token, signed session).
- Define role model (viewer, operator, admin).
- Add endpoint-level authorization policy mapping.
- Add audit log for privileged actions.
Non-Goals
- External identity provider integrations in first phase.
- Breaking existing local-default behavior for current users.
Migration Plan
- Add feature flags and middleware scaffolding.
- Enforce auth on high-risk endpoints first.
- Add RBAC checks and permission-aware UI controls.
- Make authenticated mode recommended default after stabilization.
Risks
- Operational lockout risks during misconfiguration.
- Backward compatibility with existing automation scripts.
Rollback
Disable auth/RBAC flags and revert to current trusted-local behavior.