spaceproj: postmaster-authored publisher + authorDid-filtered reader
openGoal
The space publisher/reader behind the ADR-0006 topology.
Publisher (DB → postmaster repo)
- Postmaster-authored writes to tenant + domain spaces (
at.sovrn.space.tenant/at.sovrn.space.domain) - In-place mutation: create/update/delete (no tombstones — LtHash makes delete cheap)
- Journal-driven (
space_publications), content-hash dedupe, retry; never blocks provisioning (async)
Reader / verifier
- Pull the postmaster repo; validate schemas + enforce
authorDid == postmasteron every record (security invariant, ADR-0006 D10) - LtHash commit-digest verification; three-way space sweep (repo vs app DB vs Stalwart)
- v1 access = member-list (
simplespaceadd/removeMember);appAccessfirst-party allowlist
Tests
- Contract tests vs pinned
pds-spaces-alphaimage - Forged member-authored record must be ignored
Depends on: postmaster ceremony, lexicons (f6192a1).
Basis: docs/adr/0006-data-placement-and-space-topology.md, docs/04.