Registration receipt 描述权限上限,而不是发放万能凭据

Registration receipt 描述权限上限,而不是发放万能凭据 由 Archify 生成的架构图。 Compiled plan · enabled capabilities · 唯一 authority derivation Compiled plan enabled capabilities Accepted Provider Claims · limits + failure semantics · 唯一 authority derivation Accepted Provider Claims limits + failure semantics Unique Runtime owner · real component ownership · 唯一 authority derivation Unique Runtime owner real component ownership Sealed binding set · exact capability fingerprints · 唯一 authority derivation Sealed binding set exact capability fingerprints Registration Authority · registration:read / write · 唯一 authority derivation · server re-read Registration Authority registration:read / write server re-read ProductRegistrationReceiptV2 · actor scope requirements · 唯一 authority derivation · no secret ProductRegistrationReceiptV2 actor scope requirements no secret Agent handle · read / propose only · Principal-scoped handles Agent handle read / propose only Reviewer handle · target review scope · Principal-scoped handles Reviewer handle target review scope Executor handle · only when enabled · Principal-scoped handles Executor handle only when enabled Revalidator handle · dependency convergence · Principal-scoped handles Revalidator handle dependency convergence memory:admin · Memory domain only · 不再作为 V2 authority source · not Registration admin memory:admin Memory domain only not Registration admin Legacy Memory handoff · historical V1 carrier · 不再作为 V2 authority source · ignored for new V2 Legacy Memory handoff historical V1 carrier ignored for new V2 HTTP 403 not consulted for new V2 唯一 authority derivation Principal-scoped handles 不再作为 V2 authority source 图例 前端 后端 数据库 安全 外部系统

Receipt 不是 credential

  • • 只描述 actor role、namespace 与 maximum scopes
  • • 调用者仍需独立认证 credential
  • • open 时再取 role、binding 与实际 scope 的交集

按域管理

  • • memory:admin 只提升 Memory
  • • Evidence、Graph Proposal、Registration 等使用各自 scopes
  • • 不存在隐式 Foundation 超级管理员

能力不存在就不发角色

  • • proposal_only 不产生 reviewer 或 executor
  • • Graph-only 不获得 Memory 或 Relation scope
  • • 共享 ReviewDecision 不自行授予目标审核权