access: persist the access audit to state.db #90

Open
opened 2026-09-20 13:16:48 +00:00 by padreug · 0 comments
Owner

ADR-003 decision 7 says every grant/deny is audited to state.db (hashed credential, timestamp, role, outcome), with optional later publication as a Nostr event. What shipped in #86 is recordAccessAudit() in stores/atm.ts, which only console.info()s a truncated hash.

Needed:

  • a state:record-access-event IPC handler in electron/main.ts next to state:record-transaction, plus preload exposure
  • an access_events table in state.db (credential_id_hash, role, result, reason, at); never a raw external_id or lnurlw
  • recordAccessAudit() writes through it; dev unlocks recorded with role operator and credential dev-unlock
  • Nostr mirroring stays out of scope

See the 2026-09-20 amendment in docs/adr/003-nfc-access-control-layer.md.

ADR-003 decision 7 says every grant/deny is audited to state.db (hashed credential, timestamp, role, outcome), with optional later publication as a Nostr event. What shipped in #86 is `recordAccessAudit()` in stores/atm.ts, which only console.info()s a truncated hash. Needed: - a `state:record-access-event` IPC handler in electron/main.ts next to `state:record-transaction`, plus preload exposure - an `access_events` table in state.db (credential_id_hash, role, result, reason, at); never a raw external_id or lnurlw - `recordAccessAudit()` writes through it; dev unlocks recorded with role operator and credential `dev-unlock` - Nostr mirroring stays out of scope See the 2026-09-20 amendment in docs/adr/003-nfc-access-control-layer.md.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
aiolabs/bitspire#90
No description provided.