fix: align workspace diagnostic contracts
This commit is contained in:
@@ -163,6 +163,7 @@ diagnostics:
|
||||
method: POST
|
||||
path: /vector/diagnostic-probe
|
||||
auth: bearer
|
||||
response: { operation: operation }
|
||||
embedding:
|
||||
method: GET
|
||||
path: /models
|
||||
@@ -219,7 +220,8 @@ the model/dimensions response fields. Only `GET` and `POST`, `none`/`bearer`/`x-
|
||||
authentication, origin-relative paths without a query or fragment, and identifier-shaped response
|
||||
field names are accepted.
|
||||
|
||||
`vector_rest.reversible_probe`, when present, is POST-only. It is called with a generated
|
||||
`vector_rest.reversible_probe`, when present, is an authenticated POST with a declared response
|
||||
field that must echo each requested `create`/`remove` operation. It is called with a generated
|
||||
diagnostic record create request and a matching remove request, with cleanup retried in `finally`.
|
||||
An upsert-only service cannot be declared as this probe. All ordinary diagnostics remain read-only.
|
||||
The complete request, response, timeout, reader-only fallback, SSH, and private-CA limitations are
|
||||
@@ -310,7 +312,10 @@ Transport behavior is encapsulated behind connector adapters.
|
||||
|
||||
### 8.1 Direct
|
||||
|
||||
Direct adapters connect to the configured host and port with the native protocol. PostgreSQL direct access supports TLS modes and CA files. Vector direct access uses the native vector-store protocol or database driver.
|
||||
Direct adapters connect to the configured host and port with the native protocol. PostgreSQL
|
||||
direct access uses a supplied CA file when present and otherwise requires runtime system trust;
|
||||
certificate verification is never disabled. Vector direct access uses the native vector-store
|
||||
protocol or database driver.
|
||||
|
||||
### 8.2 REST API
|
||||
|
||||
@@ -323,7 +328,9 @@ trusted TLS-termination boundary.
|
||||
|
||||
### 8.3 SSH tunnel
|
||||
|
||||
SSH adapters verify the remote host against an explicit known-hosts file, open a temporary local tunnel, and pass the resulting endpoint to the corresponding direct adapter. Host-key checking cannot be disabled by the form.
|
||||
SSH adapters verify the remote host against an explicit known-hosts file, open a temporary local
|
||||
tunnel, and pass the resulting endpoint to the corresponding direct adapter, including its
|
||||
verified private-CA-or-system-trust policy. Host-key checking cannot be disabled by the form.
|
||||
|
||||
Transport selection is installation-specific because a production server may connect directly while a laptop reaches the same logical resource through REST or SSH.
|
||||
|
||||
@@ -592,6 +599,8 @@ Legacy sessions without workspace revision use the existing compatibility resolu
|
||||
- Git SSH uses explicit known-hosts verification.
|
||||
- REST and direct TLS validation cannot be disabled silently.
|
||||
- Diagnostics sanitize provider errors before returning them to the browser.
|
||||
- `auth: none` diagnostics neither require nor read an API-key file; authenticated REST
|
||||
diagnostics still require the declared local secret file.
|
||||
- Production CORS remains same-origin; absence of embedded authentication does not imply cross-origin write access.
|
||||
- The first release allows every user who can access the ThothII application to publish workspace changes. This limitation is documented until an authorization layer is introduced.
|
||||
|
||||
|
||||
Reference in New Issue
Block a user