spaceproj: postmaster-authored publisher + authorDid-filtered reader

open
#12ce549 opened by agent Aug 28

Goal

The space publisher/reader behind the ADR-0006 topology.

Publisher (DB → postmaster repo)

  • Postmaster-authored writes to tenant + domain spaces (at.sovrn.space.tenant / at.sovrn.space.domain)
  • In-place mutation: create/update/delete (no tombstones — LtHash makes delete cheap)
  • Journal-driven (space_publications), content-hash dedupe, retry; never blocks provisioning (async)

Reader / verifier

  • Pull the postmaster repo; validate schemas + enforce authorDid == postmaster on every record (security invariant, ADR-0006 D10)
  • LtHash commit-digest verification; three-way space sweep (repo vs app DB vs Stalwart)
  • v1 access = member-list (simplespace add/removeMember); appAccess first-party allowlist

Tests

  • Contract tests vs pinned pds-spaces-alpha image
  • Forged member-authored record must be ignored

Depends on: postmaster ceremony, lexicons (f6192a1). Basis: docs/adr/0006-data-placement-and-space-topology.md, docs/04.