Skip to content

Nk/edit perm editbound cleanup - #29

Merged
nadeem-fileverse merged 4 commits into
mainfrom
nk/edit-perm-editbound-cleanup
Jul 24, 2026
Merged

nadeem-fileverse merged 4 commits into
mainfrom
nk/edit-perm-editbound-cleanup

Conversation

@nadeem-fileverse

Copy link
Copy Markdown
Contributor

No description provided.

nadeem-fileverse and others added 4 commits July 24, 2026 14:53
Edit admission for token-based editors no longer makes a network call to the
gate. It now runs entirely offline: verify the gate-signed edit token and
compare its epoch against a per-document edit-epoch floor. The floor is
advanced on key rotation (which also terminates the superseded session), and
the eviction route stamps the floor and drops the matching sockets directly.

Removes the now-unused gate URL configuration and the cache layer it fed.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
…delta

The /flush beacon now carries the caller's edit token and re-runs the same
offline admission check used at socket join (token validity + document
edit-epoch) before writing. Callers without an edit token — public and
workspace editors, and owners — are unchanged.

Narrows resolveEditAdmission's dependencies to a small EditAdmissionDeps type
so the flush route can reuse it without pulling in the full socket-handler
surface.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
…lures

getOwnerDid re-hit the RPC on every unregistered/garbage lookup because a
cached empty result was treated as a miss. Cache a confirmed-absent result on
a short TTL so repeat lookups skip the RPC, but never cache a null: a caught
read is indistinguishable from a rate-limited blip, and caching it would lock
the real owner out for the TTL. Both getOwnerDid and refreshOwnerDid route
through one helper so the two writers cannot diverge.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@nadeem-fileverse
nadeem-fileverse merged commit 684e47e into main Jul 24, 2026
1 check passed
nadeem-fileverse added a commit that referenced this pull request Jul 27, 2026
#30)

The editbound cleanup (#29) swapped the live gp-actor edit re-check from a
per-actor-handle check to a doc-wide minEditEpoch floor. On removal the client
evicts the removed actor with the bumped gateEpoch, stamping the floor doc-wide
before the make-before-break rotation re-issues survivors a fresh-epoch editUcan
at cutover. In the gap every surviving co-editor (admitted at the old epoch)
fails isStillAdmitted and is disconnected, so it misses the one-shot
/session/cutover and is stranded with "Session not found" until a full refresh.

isStillAdmitted now tolerates a below-floor gp-actor while a make-before-break
rotation for the doc is in flight (rotationCoordinator.isActive). JOIN admission
(resolveEditAdmission) stays strict, so the removed actor still cannot rejoin.

Unit-verified (socket-handlers.isStillAdmitted.rotationGrace.test.ts); not yet
E2E-verified. Known residual windows (evict->begin gap, post-cutover drain, and
the doc-wide grace briefly re-admitting an evict-failed actor) are tracked for a
follow-up hardening (per-doc evicted-handle denylist).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant