Encryption: group/space multi-recipient #18
Labels
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference: Cordy/Cairn#18
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Extends at-rest encryption to shared spaces once per-group spaces exist. Objects in
/spaces/<group>encrypt to all current members' age identities + the recovery recipient, so any member can decrypt.Deferred from the v0.3 encryption probe.
Decision — approved (Manuel's review, relayed by Nikola 2026-07-31):
Recorded as approval of the multi-recipient design for group/space encryption: files in a shared space encrypted to all member recipients (plus recovery), so any member can be served decrypted content. Un-gated — implementable once greenlit.
Note for implementation planning: #28 (post-quantum) is explicitly blocked on how multi-recipient shakes out, so this issue leads the remaining encryption work. Interpretation caveat flagged to Nikola: "good as it is" was read as "the proposed design is good — proceed"; if it instead meant "current single-recipient behaviour is fine, no work needed," say so and this closes instead.