mirror of
https://github.com/euzu/tuliprox.git
synced 2026-10-04 15:02:16 +02:00
A single write permission could not express the policy the DVR needs: a user who may request a recording is not necessarily one who may cancel someone else's, and neither implies the right to delete a file. Replace it with recording.create, recording.manage and recording.delete, and map each action onto the one it actually needs: - create private/shared -> recording.create - edit, cancel, manage rules -> recording.manage - delete, system retention sweep -> recording.delete The split renumbers every permission bit above recording.read, so CURRENT_PERMISSION_SCHEMA_VERSION is bumped to 4 and tokens issued earlier fail closed at the validator instead of having their bits reinterpreted. The removed recording.write name now decodes to nothing, so a groups file that still lists it loses the permission rather than silently gaining one of the three replacements. Permission bit values are frozen in a test: they are the wire format, and reordering the enum would reinterpret every issued token.