Skip to content

Add protected staged asset delivery - #336

Draft
MajorIncident wants to merge 1 commit into
chore/closeout-330-activate-316from
feature/protected-staged-assets
Draft

MajorIncident wants to merge 1 commit into
chore/closeout-330-activate-316from
feature/protected-staged-assets

Conversation

@MajorIncident

Copy link
Copy Markdown
Owner

Issue

Implements #316.

Stack

316A started

This draft establishes the canonical protected staged asset contract before runtime work.

Key decisions:

  • server-only registry keyed by stable assetId;
  • Student asset authority comes only from the stable Student class-session capability and currently cumulative released staged content;
  • workspace edit capabilities do not authorize assets;
  • Instructor access remains class/exercise-scoped;
  • no permanent/public protected asset URLs;
  • route through the existing single Classroom dispatcher to preserve the Vercel function budget;
  • synthetic fixtures only until Classroom follow-on: Author and validate the first production staged KT Case Study #317 provides reviewed official source material.

Canonical contract: docs/classroom-protected-assets.md.

Planned slices

  • 316A contract + server registry/authorization boundary
  • 316B rich Student payload + semantic table rendering
  • 316C protected image/document-page retrieval + rendering
  • 316D deployment/security/mobile/a11y/final audit

Cold restart

Read #316 and docs/classroom-protected-assets.md, then continue 316A. Preserve the #313 progressive-disclosure and #328–#330 access/persistence invariants.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant