Skip to content

[Copilot Planning] Meshspaces privacy-boundary and cross-context leakage audit #49

Description

@kwalus

Context: We are planning Meshspaces for Canopy: one machine managing multiple fully isolated mesh runtimes via a thin shell. This issue is for planning/review support against the repo as it exists today. We are not implementing Meshspaces in this issue.

Goal: Identify privacy-boundary failures, hidden cross-context leakage risks, and UI/shell conveniences that would quietly undermine isolation.

Focus areas:

  • browser state collisions (cookies, localStorage, session, CSRF, notifications)
  • shell-level previews and shared-screen leakage risk
  • wrong-mesh actions caused by stale state or ambiguous context
  • machine-local vs shell-local vs mesh-local data confusion
  • invite import and mesh label/GUID collision risks
  • child-runtime vs shell trust boundary

Expected deliverable:

  • Open a PR from a Copilot branch with a concise findings report in docs/meshspaces-review/privacy-boundary-audit.md
  • If helpful, make small doc/spec clarifications only. Do not start Meshspaces implementation.

Ground rules:

  • Do not implement multi-mesh runtime behavior.
  • Prefer findings, checklists, and doc clarifications over code changes.
  • If you identify missing tests or APIs, document them rather than building the feature.
  • Prioritise privacy and scope-boundary failures over convenience.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions