P00 endpoint, principal, and resource matrix¶
Status: source-derived at tentative SHA 1b75af4e76ad4b4afc9ce23769877566f6ec10e2. The original checkout has unrelated ingestion edits, so this is not the frozen integration SHA. Root baseline restore/build passed; the root coordinator owns the full-test result and final baseline record.
The exact method/route/source ledger is endpoint-registration-ledger.md, generated from production and development registration sources. This document classifies those routes. Existing RequireAdmin*, RequireAnyRole, RequireAuthorization, and RequireClientScope entries describe current metadata only; none proves target resource authorization.
Engine registration matrix¶
| Registration family (exact bases) | Current principal/policy | Protected resource or operation | Target permission/policy | Owner |
|---|---|---|---|---|
AccountEndpoints /accounts; AuthenticationEndpoints /auth; ProfileEndpoints /profiles |
Authenticated group with per-route Administrator/role policies; several public login/recovery flows | Self account/security/session, account list/grants/invitations, profile settings/admin, elevation | Human self-service vs identity.users.read/write; new effective-admin + optional grant unlock; no service-app /me |
P02 |
SetupEndpoints /setup/v1 |
setup-session policy, public bootstrap boundary | first administrator, libraries/providers, restore, completion | narrowly scoped setup principal; fail closed after completion; backup.restore does not make setup public |
P02 |
ClientAuthorizationEndpoints nested /api/v1/oauth, /api/v1/pairing, /api/v1/devices |
device/token issuance public; review/decision authenticated; device operations scope/auth policies | pairing, access/refresh tokens, device binding/capabilities | Application + Account + Profile binding and registry consent intersection | P02, then P03 resource checks |
AdminEndpoints /admin |
Admin | legacy inbound keys; outbound provider config | replace /admin/api-keys with Application credentials (identity.applications.write); provider routes use provider permissions |
P02/P03 |
SystemEndpoints /system, /maintenance; Engine /health* |
status/live exceptions; admin health/readiness/backups/maintenance | status/readiness, backup files, orphan sweep | system.status.read, backup.*, storage.*; preserve only minimal liveness/status public facts |
P03 |
DisplayEndpoints /api/v1/display; DetailEndpoints /api/v1/details; LibraryEndpoints /library; WorkEndpoints /works; PersonEndpoints /persons; CharacterEndpoints /library/*; TimelineEndpoints /timeline; UniverseGraphEndpoints root /universe*; CanonEndpoints root /metadata/*; SearchEndpoints /search |
native scope or broad profile roles; mixed admin mutations | browse/search/details/counts/people/works/universe/timeline | library.read filtered before query/count/cache; metadata mutations split to metadata.* |
P03 |
CollectionEndpoints /collections plus CollectionPersonalMediaEndpoints on same group |
broad roles/admin | catalogue, structural/curated membership, artwork, placements, View-backed collection sources | collections.read/write plus library grants; View-linked expansion also requires exact P04 resource proof |
P03/P04 |
StreamEndpoints /stream; HlsStreamEndpoints /stream/hls/...; PlaybackEndpoints /api/v1/playback; PlayerEndpoints /api/v1/player; ProgressEndpoints /api/v1/progress; PlaybackSegmentEndpoints /playback; ReadEndpoints /read; ReaderEndpoints /reader |
client scopes or broad roles; signed HLS route anonymous | byte/range streams, artwork, HLS package, encode/offline, player/queue/progress, reader state/content | matching registry scope + feature/library/profile restriction on every lookup; signed grants bounded/revocable | P03 |
LibraryItemEndpoints and ItemCanonicalEndpoints /library/items; MetadataEndpoints /metadata plus navigator partial; DeferredEnrichmentEndpoints /metadata/pass2; EnrichmentRefreshEndpoints /ingestion/refresh-schedule; ReviewEndpoints /review; ReportEndpoints /reports |
broad roles/admin | canonical edits, matching, artwork, enrichment, review and reports | metadata.read/write/match/enrichment.*, review.*; personal status remains profile-scoped |
P03 |
IngestionEndpoints /ingestion; ActivityEndpoints /activity; OperationsEndpoints /operations; MaintenanceEndpoints /maintenance/* |
Standard-or-admin with admin mutations | active status, history, scan/upload/retry/cancel, retention/maintenance | ingestion.status/history/run/retry/cancel, system.activity.read, storage.config.write |
P03 |
SettingsEndpoints /settings; UISettingsEndpoints /settings/ui; NetworkEndpoints /settings/network and /network; ServerFolderEndpoints /settings/server-folders; LibraryMutationEndpoints /libraries/*; LibraryReorganizationEndpoints /settings/libraries/{libraryId}/reorganization; ProviderCatalogueEndpoints /providers; CapabilityEndpoints root capability routes; AiEndpoints /ai; PluginEndpoints /plugins |
broad roles/admin | configuration, secrets, folders, network, storage, AI and plugins | exact providers.*, network.*, storage.*, ai.*, plugins.*; self profile preferences remain human/profile only |
P03 |
ViewEndpoints /view; ViewDiscoveryEndpoints /view; collection personal-media handlers |
broad roles plus admin subroutes; signed Dashboard profile assertion | scopes/preferences, folders/assets/content/thumbnails/uploads, Gallery/shares, Shared contributions, per-profile admin sources | account View feature + exact Mine/Shared/admin-selected profile; view.*; missing-equivalent denial before enumeration/files |
P04 |
Development DebugEndpoints /debug, DevSeedEndpoints and IntegrationTestEndpoints /dev |
development environment; mixed explicit/fallback policy | destructive fixtures, seed/wipe, debug enrichment | remain development-only and effective-admin; never application services | P03 guardrail |
Dashboard and realtime edges¶
| Edge | Current behavior | Target decision | Owner |
|---|---|---|---|
/.well-known/tuvima on Engine and Web |
anonymous discovery | public, fixed non-sensitive server/client capability facts | P02/P03 |
Web /api/v1/{**clientPath} |
anonymous catch-all proxy forwards native Authorization and rewrites stream/person paths | proxy is transport only; upstream must authenticate and enforce every registry/resource decision | P03/P05 |
Web /pair GET/POST |
browser page; relies on Dashboard user challenge and antiforgery; calls Engine pairing endpoints | authenticated human approval bound to active Account/Profile; preserve HTML flow and native wire | P02/P05 |
Web /auth/login|reset|invite|passkeys/*, /auth/external/{providerId} |
intentionally anonymous entry/callback routes, with antiforgery where state changes use forms | remain narrow auth entry points; verified callbacks only; never accept caller identity claims as proof | P02/P05 |
Web /auth/logout, /account/elevate, /account/security, passkey registration/elevation |
authenticated browser session | self-service human only; admin unlock is grant/session/version bound | P02/P05 |
Web /engine-stream/{assetId} and /engine-image/{**enginePath} |
stream currently lacks endpoint auth metadata and uses Dashboard forwarding; image requires auth | require active browser session and upstream library/artwork decision; no seed Owner fallback | P03/P05 |
Web /engine-hls/{grant}/{packageId}/{**resourcePath} |
anonymous signed-grant proxy | keep URL consumable by media stack, but validate short-lived revocable resource grant upstream and at proxy | P03/P05 |
Web /view-media/{grant} |
signed profile-bound grant; no endpoint auth metadata; mutates active-profile accessor before proxy | grant must bind account/session/profile/resource/version, return 404-equivalent, and never switch ambient authority as authorization | P04/P05 |
Web /_tuvima/remote-probe, /health/live, /health/ready, /culture/set, static assets/Razor |
remote probe/live/culture/static anonymous; readiness output is public on Web | public output must stay non-sensitive; culture redirect remains local-only safe; component routes use browser auth/fallback | P05 |
Engine /intercom hub |
route is AllowAnonymous; middleware and hub filter require a short-lived session bearer token; publishers use Clients.All |
internal Dashboard audience remains session authenticated and resource filtered; external apps require events.subscribe + underlying read permission through P11 service |
P02/P05/P11 |
Known direct global publishers include SignalREventPublisher and ProviderHealthMonitorService; endpoint-triggered review events flow through the publisher. P11 must inventory all IHubContext<Intercom> and Clients.All calls again after the cutover.
Public exception allowlist¶
Only these route purposes may remain unauthenticated after the cutover: liveness and minimal discovery/status; setup bootstrap while setup is incomplete and protected by setup-session state; login, recovery, invitation acceptance, verified external-auth challenges/callbacks, and device OAuth issuance; signed HLS/View resource URLs whose grants carry server-validated authority; static framework assets. AllowAnonymous on the Intercom route and Web native proxy is a transport requirement and does not authorize the upstream resource.
Development /dev and /debug routes are not public exceptions. Swagger is development-only and inherits environment/network constraints; it does not waive endpoint policy.
Guardrail acceptance¶
P01 supplies typed endpoint permission metadata. P03/P04 must add a runtime route-data-source test that enumerates all production endpoint registrations and rejects application-facing handlers without one of: public-exception metadata, authenticated-human/self-service metadata, setup metadata, typed permission metadata, or internal Dashboard transport metadata. The generated ledger is a review aid; the runtime test is the acceptance authority because nested groups and conventions can change effective metadata.