Files
buzz/migrations/0034_relay_admin_outbox_claim_token.sql
DuncanandWill Pfleger 5505e608b9 feat(relay): OPERATOR/MODERATOR role model for relay admin API with NIP-98 auth
Gate the relay admin moderation API (/api/admin/v1) behind explicit
authentication configuration selected by BUZZ_ADMIN_AUTH: token (default),
disabled, or nip98. In nip98 mode every request carries a signed kind-27235
NIP-98 event; the authenticated pubkey resolves to an OPERATOR or MODERATOR
principal from RELAY_OPERATOR_PUBKEYS, the RELAY_OWNER_PUBKEY fallback, or the
relay_operators table. Replaces the BUZZ_ADMIN_INSECURE_NO_AUTH bypass with a
role model that is revocable without rotating a shared secret and fails closed
at every boundary.

Co-authored-by: Will Pfleger <pfleger.will@gmail.com>
Signed-off-by: Will Pfleger <pfleger.will@gmail.com>
2026-08-12 23:20:29 -04:00

10 lines
464 B
SQL

-- Fenced outbox delivery: add a per-claim opaque token to relay_admin_outbox.
--
-- Without this, mark_outbox_delivered and fail_outbox_row only fence on row ID,
-- which allows a stale worker (whose lease already expired) to overwrite a newer
-- worker's terminal update. The claim token is a real ownership fence: completion
-- and failure updates require the token written at claim time.
ALTER TABLE relay_admin_outbox
ADD COLUMN outbox_claim_token UUID;