Administrative credentials can read both participant projections and full snapshots. This is unsafe if those credentials are also used as participant-view credentials; the deployment boundary is currently unclear.
Acceptance criteria
- Inventory public runtime entry points and credentials, including snapshot, projection, operation, history, error, and event access. Specify who may use each surface and where authorization is enforced.
- Decide whether participant clients access RAE directly or through a backend boundary. Specify the required principal, audience, participant, and episode bindings for the selected exposure model.
- Cover alternate retrieval and mutation paths, cached/readback results, and cross-participant access. Authentication principals do not require new SDL participant declarations or roles.
- Publish the accepted trust-boundary decision, route/authority matrix, deployment requirements, and affected API-404/ADR-104 clauses. Keep organizational identity and policy responsibilities with the backend.
References: Diagnosis, Control-plane authorization, Ecosystem responsibilities.
Requirements
- API-404 — Secure, Durable, And Idempotent Control-Plane Semantics
Administrative credentials can read both participant projections and full snapshots. This is unsafe if those credentials are also used as participant-view credentials; the deployment boundary is currently unclear.
Acceptance criteria
References: Diagnosis, Control-plane authorization, Ecosystem responsibilities.
Requirements