Files
p2ns/docs/rfcs/0004-admin-auth-rbac.md
T
Raven Scott ea9124c429 BREAKING EXPERIMENTAL: Holepunch-native hard migration (RPC core, shared storage, SDK v2)
BREAKING: All nodes must upgrade together. Legacy p2ns.core-request string
messages are rejected; invite/consensus control plane uses protomux-rpc
(invite.request, invite.ack, invite.relay*, consensus.*). Shared Corestore
namespaces are the default for plugin DBs and drives; USE_SHARED_CORESTORE_NAMESPACES=false
is debug-only. Admin plugin actions with params are validated before run.

EXPERIMENTAL: End-to-end RPC invite path reuses existing handlers via adapters;
invite wire still ships on the invite channel. Multi-peer invite/relay
integration tests are not in CI yet (core-rpc-smoke only).

SDK & channels:
- channel-rpc.js, sdk.channels.rpc (register/request/event)
- core-rpc.js for p2ns.core; action-params + plugin route validation
- sdk.db.getCore/reopen, sdk.state.getPeerChannelSnapshot,
  sdk.metrics.getHolepunchStats (schema v1)

Runtime:
- p2ns.js: RPC-first core invite/consensus; Hyperswarm firewall/reconnect
- channel-manager: required protomux-rpc per peer
- db-shared-namespace-migration; drive-manager shared namespaces
- proxy-server: invite.request RPC for joiners

Plugins: file.drop, global.profile, peer.directory, domain.consensus,
peer.visualize, example.plugin (RPC demo); peer.directory UI polish

Also: CI/smoke scripts, diagnostics hardening, plugin config schema validation,
admin action param modal, docs/RFCS, package-lock + engines.node >= 18
2026-05-28 10:51:19 -04:00

1.1 KiB

RFC 0004: Admin Authentication and RBAC

Status

Draft

Problem

p2ns.admin provides powerful operational endpoints and currently assumes a trusted local context. Multi-user environments and remote access scenarios need stronger controls.

Proposal

Introduce optional authentication and role-based authorization for admin APIs and UI operations.

Scope

  • Define auth modes (disabled, local token, signed session).
  • Define role model (viewer, operator, admin).
  • Add endpoint-level authorization policy mapping.
  • Add audit log for privileged actions.

Non-Goals

  • External identity provider integrations in first phase.
  • Breaking existing local-default behavior for current users.

Migration Plan

  1. Add feature flags and middleware scaffolding.
  2. Enforce auth on high-risk endpoints first.
  3. Add RBAC checks and permission-aware UI controls.
  4. Make authenticated mode recommended default after stabilization.

Risks

  • Operational lockout risks during misconfiguration.
  • Backward compatibility with existing automation scripts.

Rollback

Disable auth/RBAC flags and revert to current trusted-local behavior.