Files
alknet/docs/architecture/questions/023-handler-identity-registration-path-and-composition-authority.md
T
glm-5.2 1baa619ce9 docs(arch): decompose open-questions.md into per-OQ files under questions/
The monolithic open-questions.md (1310 lines, 47 OQs) was large enough to be
unmanageable, with high size variance (OQ-42 at 220 lines next to OQ-06 at 8).
Decomposed into one file per OQ under docs/architecture/questions/ (NNN-slug.md,
mirroring the ADR convention), with open-questions.md retained as the index:
theme-grouped tables plus a cross-theme Deferred/Blocked section that surfaces
the 6 deferred OQs with their Blocked-on conditions inline (the safe-exit
visibility surface). Per-OQ content moved verbatim; all 62 inbound links stay
valid (none used anchors). README's curated OQ summary dropped (now redundant
with the index tables).

Also seeds tasks/architecture/ with this task plus two follow-ups found during
the decompose: OQ-09/10 missing structured Blocked-on fields, and the
tasks/architecture/ blocker-task half of the Safe Exit protocol being
unenforced.
2026-07-06 16:07:59 +00:00

1.7 KiB
Raw Blame History

OQ-23: Handler Identity Registration Path and Composition Authority

  • Origin: operation-registry.md, call-protocol.md, ADR-015
  • Status: resolved
  • Door type: One-way (security model), two-way (bundle shape)
  • Priority: high
  • Resolution: ADR-015 said handler identity was "set at registration by the assembly layer" but the registration API (register(spec, handler)) had no place for it — meaning every internal call would check ACL against None, reproducing the escalation gap ADR-015 was written to close. ADR-022 resolves this with a registration bundle (HandlerRegistration) carrying provenance, composition_authority (replacing handler_identity: Identity — it's a declared authority bundle, not a peer identity), scoped_env, and capabilities. The dispatch path (build_root_context and OperationEnv::invoke()) reads from the bundle. Provenance determines which ops can compose: only Local and Session get composition authority; leaves (FromOpenAPI, FromMCP, FromCall) get None — they don't compose, so they don't need it. Capabilities are per-request on OperationContext, populated from the bundle (resolving the closure-capture vs context ambiguity). The kernel/user analogy: user's authority checked once at the External gate; handler's composition authority used for all composition inside; scoped env bounds reachability. No intersection — the user's authority does not limit internal calls. See ADR-022.
  • Cross-references: ADR-014, ADR-015, ADR-022, docs/reviews/001-pre-implementation-architecture-sanity-check.md (C1–C4), operation-registry.md, call-protocol.md