managarten/docs/future
Till JS 6882ffb626 feat(shared-ai): Mission Key-Grant contract + plan for encrypted server-side runs
Foundation for Phase 2+ of the Mission Key-Grant flow: lets mana-ai
execute missions that depend on encrypted inputs (notes/tasks/events/
journal/kontext) without needing an open browser tab. Opt-in per
mission, Zero-Knowledge users excluded.

- Canonical HKDF-SHA256 derivation (scope-bound via tables + recordIds
  in the HKDF info string → scope changes invalidate the grant
  cryptographically, not just via a runtime check)
- Mission.grant field on the shared Mission type
- Golden snapshot + drift-guard test so webapp wrap path and mana-auth
  wrap endpoint can't silently diverge
- Ideas backlog at docs/future/AI_AGENTS_IDEAS.md
- Full rollout plan at docs/plans/ai-mission-key-grant.md
- COMPANION_BRAIN_ARCHITECTURE.md §21 captures the flow + privacy
  guarantees + non-goals

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-15 13:41:35 +02:00
..
AI_AGENTS_IDEAS.md feat(shared-ai): Mission Key-Grant contract + plan for encrypted server-side runs 2026-04-15 13:41:35 +02:00
FIRSTS_MODULE.md docs: add firsts module design document 2026-04-10 22:23:21 +02:00
MAIL_SERVER_DEDICATED.md chore: complete ManaCore → Mana rename (docs, go modules, plists, images) 2026-04-07 12:26:10 +02:00
MODULE_IDEAS.md refactor: rename zitare -> quotes (Zitate) 2026-04-14 20:59:16 +02:00
ROTATE_LEAKED_API_KEYS.md docs: add TODO for rotating leaked API keys from git history 2026-03-23 12:10:53 +01:00