Skip to content

🔒️ Only accept presence for the doc on its channel - #752

Draft
alecgibson wants to merge 1 commit into
mainfrom
check-doc-presence-channel
Draft

alecgibson wants to merge 1 commit into
mainfrom
check-doc-presence-channel

Conversation

@alecgibson

Copy link
Copy Markdown
Collaborator

Fixes #738

At the moment, the server checks read access against a presence's c and d, but broadcasts it on its ch:

  1. Deny docs/secret in readSnapshots
  2. Send presence on docs.secret with the c/d of a readable doc
  3. docs/secret subscribers apply it

This change rejects doc presence whose c and d don't match its channel, and DocPresence ignores presence for any other doc, which also covers untyped presence and dotted-name channel collisions. Subscribing, write access and presence ID ownership are left to middleware, which the new "Access control" docs cover.

The server check only holds once every instance is upgraded, and the client filter only protects upgraded clients.

🤖 Generated with Claude Code

Co-Authored-By: Claude [email protected]

Fixes #738

At the moment, the server checks read access against a presence's `c`
and `d`, but broadcasts it on its `ch`:

 1. Deny `docs/secret` in `readSnapshots`
 2. Send presence on `docs.secret` with the `c`/`d` of a readable doc
 3. `docs/secret` subscribers apply it

This change rejects doc presence whose `c` and `d` don't match its
channel, and `DocPresence` ignores presence for any other doc, which
also covers untyped presence and dotted-name channel collisions.
Subscribing, write access and presence ID ownership are left to
middleware, which the new "Access control" docs cover.

The server check only holds once every instance is upgraded, and the
client filter only protects upgraded clients.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <[email protected]>
@coveralls

Copy link
Copy Markdown

Coverage Status

coverage: 97.883% (+0.03%) from 97.851% — check-doc-presence-channel into main

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Document that presence has no built-in access control (eavesdrop/inject/hijack via channels)

2 participants