Skip to content

Reach hosted channels from a browser without a host gateway #182

Description

@iamnbutler

Allow a browser to reach a hosted channel without a reachable Ace host gateway. This is optional later work under #13; the first deployed pilot #176 can use the existing native/host route.

The original #13 requested browser reachability and per-person sign-in. Preserve that need while keeping the tailnet the sole authority for team membership and collaboration access. Ace must not introduce its own accounts, invitations, team membership or parallel authorization system, and a shared host/service secret must never become a browser participant credential.

Acceptance

  • Design a browser-to-cell route and a per-person identity/authorization proof tied to the existing tailnet authority. Document how team membership is checked, revoked and refreshed, and how browser origin/session handling works.
  • Keep server/workspace shared secrets out of browser clients and user-visible URLs. Enforce owner operations, ordinary chat and collaborator-agent invocation using the same policy as existing clients.
  • Open history, post attributed chat, watch live updates and invoke permitted agents directly against the cell, while displaying workspace availability honestly. Repository files and tools remain on the workspace.
  • Verify a real browser with no reachable host gateway, two people where available, membership removal/revocation, reconnect and an offline workspace. Refused/expired identity must not queue unauthorized work.
  • Document the team's deployment/configuration requirements and unsupported cases. Ace remains team-operated software rather than a hosting service.

Reuse hosted lifecycle/discovery work in #13. This issue does not require a new cloud execution environment or include real-phone UI qualification (#18), directory push (#14), cross-gateway terminals (#11), or execution-host handoff (#49).

Optional later milestone under #13, following the supported host route and its deployed qualification.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions