fix: align workspace diagnostic contracts

This commit is contained in:
2026-08-04 00:37:57 +02:00
parent f6494fd8ef
commit 565e93a456
12 changed files with 346 additions and 42 deletions
@@ -163,6 +163,7 @@ diagnostics:
method: POST
path: /vector/diagnostic-probe
auth: bearer
response: { operation: operation }
embedding:
method: GET
path: /models
@@ -219,7 +220,8 @@ the model/dimensions response fields. Only `GET` and `POST`, `none`/`bearer`/`x-
authentication, origin-relative paths without a query or fragment, and identifier-shaped response
field names are accepted.
`vector_rest.reversible_probe`, when present, is POST-only. It is called with a generated
`vector_rest.reversible_probe`, when present, is an authenticated POST with a declared response
field that must echo each requested `create`/`remove` operation. It is called with a generated
diagnostic record create request and a matching remove request, with cleanup retried in `finally`.
An upsert-only service cannot be declared as this probe. All ordinary diagnostics remain read-only.
The complete request, response, timeout, reader-only fallback, SSH, and private-CA limitations are
@@ -310,7 +312,10 @@ Transport behavior is encapsulated behind connector adapters.
### 8.1 Direct
Direct adapters connect to the configured host and port with the native protocol. PostgreSQL direct access supports TLS modes and CA files. Vector direct access uses the native vector-store protocol or database driver.
Direct adapters connect to the configured host and port with the native protocol. PostgreSQL
direct access uses a supplied CA file when present and otherwise requires runtime system trust;
certificate verification is never disabled. Vector direct access uses the native vector-store
protocol or database driver.
### 8.2 REST API
@@ -323,7 +328,9 @@ trusted TLS-termination boundary.
### 8.3 SSH tunnel
SSH adapters verify the remote host against an explicit known-hosts file, open a temporary local tunnel, and pass the resulting endpoint to the corresponding direct adapter. Host-key checking cannot be disabled by the form.
SSH adapters verify the remote host against an explicit known-hosts file, open a temporary local
tunnel, and pass the resulting endpoint to the corresponding direct adapter, including its
verified private-CA-or-system-trust policy. Host-key checking cannot be disabled by the form.
Transport selection is installation-specific because a production server may connect directly while a laptop reaches the same logical resource through REST or SSH.
@@ -592,6 +599,8 @@ Legacy sessions without workspace revision use the existing compatibility resolu
- Git SSH uses explicit known-hosts verification.
- REST and direct TLS validation cannot be disabled silently.
- Diagnostics sanitize provider errors before returning them to the browser.
- `auth: none` diagnostics neither require nor read an API-key file; authenticated REST
diagnostics still require the declared local secret file.
- Production CORS remains same-origin; absence of embedded authentication does not imply cross-origin write access.
- The first release allows every user who can access the ThothII application to publish workspace changes. This limitation is documented until an authorization layer is introduced.