Skip to content

Consent-based entitlement model #16

@bradgessler

Description

@bradgessler

Replace v1's hardcoded authority→policy resolution with a mobile-app-style consent flow.

  • Server declares the entitlements it wants (paths/modes, URL schemes, env vars).
  • Client shows a one-time consent prompt; grant cached per-authority; client enforces.
  • Security behavior must be identical across client impls → covered by shared security conformance vectors (a permissive bug in one client = a vulnerability).

Metadata

Metadata

Assignees

No one assigned

    Labels

    P1Priority 1v2Terminalwire v2 clean-sheet rewrite

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions