Session protocol core
Creates and expires invitations, approves exact device keys, owns MLS group state, rejects replay, and manages local encrypted state.
Architecture
Clients own the session keys and decide membership. Identity providers supply evidence, mailboxes hold bounded ciphertext, and transports carry opaque envelopes. Opaque framing is content-agnostic; it does not itself prove encryption. Replacing one service should not change the authority of another.
Each boundary exposes only the authority needed for one job, even when a provider or transport changes.
Creates and expires invitations, approves exact device keys, owns MLS group state, rejects replay, and manages local encrypted state.
Checks whether one exact device key may be considered. The prototype supports private capability invitations; other evidence types come later.
may approve one KeyPackageTemporarily stores bounded ciphertext in mailboxes addressed by separate secret capabilities.
may retain ciphertextMoves opaque envelopes. The memory adapter supports deterministic adverse tests, while the Iroh adapter provides experimental connected FastV1 delivery. Offline, durable, Private, and production profiles come later.
may move opaque bytesEach step owns the exact value it checked. A later caller cannot swap the device key or treat successful delivery as proof of membership.
Oversized, malformed, non-canonical, unknown-version, expired, or context-mismatched objects stop here.
session-protocolThe verifier owns the exact parsed KeyPackage and checks its invitation, challenge, replay context, credential identity, leaf key, version, and ciphersuite.
admission-capabilityThe approval view cannot add a member. The provider keeps the proof, replay reservation, and exact one-shot MLS input.
session-admissionThe MLS adapter consumes the approved value, creates Add and Welcome, advances the group, and later protects messages, updates, and removal.
session-crypto-mlsThe SQLCipher laboratory commits the MLS snapshot, replay state, consumed invitation, decision, and encrypted Welcome outbox as one transaction, then reloads that authorization state after restart. Production key custody and stale-snapshot rollback resistance remain open.
implemented laboratoryDeposit, receive, acknowledge, and rotate use separate capabilities. Knowing a delivery identifier never grants permission to delete it.
Each crate implements a narrow protocol or storage boundary. The names below describe tested laboratory components, not a finished security product.
session-protocol · session-coresession-admission · admission-capability · session-crypto-hpkesession-crypto · session-crypto-mlssession-transport · transport-memory · transport-irohsession-inviter-transaction · session-storage · storage-sqlciphersessionctlThis page provides the mental model. The repository document defines the detailed invariants, object contracts, and current evidence boundary.
Open architecture ↗