Encryption: group/space multi-recipient #18

Open
opened 2026-07-25 16:25:39 +00:00 by Cordy · 0 comments
Owner

Extends at-rest encryption to shared spaces once per-group spaces exist. Objects in /spaces/<group> encrypt to all current members' age identities + the recovery recipient, so any member can decrypt.

  • Re-encrypt/rewrap on membership change (design: lazy vs eager).
  • Couples with the §5.4 authz work and group resolution.

Deferred from the v0.3 encryption probe.

Extends at-rest encryption to shared spaces once per-group spaces exist. Objects in `/spaces/<group>` encrypt to **all current members' age identities + the recovery recipient**, so any member can decrypt. - Re-encrypt/rewrap on membership change (design: lazy vs eager). - Couples with the §5.4 authz work and group resolution. Deferred from the v0.3 encryption probe.
Sign in to join this conversation.
No labels
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: Cordy/Cairn#18
No description provided.