NEC-100: ADR 0007 and SAFE-D2 still credit Relay with role-based access control #162
No reviewers
Labels
No labels
area:docs
area:identity
area:ops
area:plugin
area:server
channel:community
channel:direct
channel:owned
channel:press
channel:social
e2ee-constrained
gate:at-ga
gate:pre-ga
marketing
parity
relay:absent
relay:planned
relay:requested
relay:supported
risk:additive
risk:contract
risk:none
usability
No milestone
No project
No assignees
2 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
Nectenda/nectenda!162
Loading…
Reference in a new issue
No description provided.
Delete branch "worktree-nec-100-adr-0007-and-safe-d2-still-credit-relay"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Task: NEC-100 — https://projectron.nerchure.com/tasks/100
SAFE-D2 (docs/v1/invariants.md) and ADR 0007 still said competitors whose servers read plaintext offer role-based access control. NEC-50 corrected the same claim elsewhere: no Relay release ships read-only, and their Reader role is merged but not released. Both now say a server that reads plaintext could make read-only a simple check, that Relay had not released one as of 24 September 2026, and point at competition-relay.md's Permissions section for sources. ADR 0007's Consequences now describe positioning.md's weakness-to-own as parity today, and drop 'parity is not the goal'. The E2EE argument (a server that cannot read plaintext cannot judge a write) is unchanged. The covering test, security-model-claims.test.ts, gains a comment saying it defends only the disclaimer, not the market fact. spec-delta was mutation-checked: it refuses the SAFE-D2 rewording without the test touch, and accepts it with. conformance.md is regenerated for the one-line shift. Acceptance greps: grep -n role-based docs/v1/invariants.md and grep -n 'role-based|parity is not the goal' docs/v1/adr/0007-no-read-only-membership.md both return nothing.
Spec:
docs/changes/NEC-100-adr-0007-safe-d2-relay-rbac/spec.mdChangelog
NONE
494f7a9ecac2cbf0a0fd