Skip to content

[Spike] Define the production oracle contract, privacy model, and freshness policy #113

Description

@knytcomics-ui

Category

Spike

Question

What oracle transport and response contract provide trustworthy, privacy-preserving, freshness-aware scores?

Context

The extension uses a deterministic local stub. The production oracle interface, authentication, provenance, and privacy behavior are unresolved here.

Why This Matters

This decision controls adapter APIs, cache policy, failure behavior, documentation, and production readiness.

Areas to Investigate

  • Authenticated HTTPS and response signing.
  • Freshness and expiration.
  • Network-specific scoring.
  • Data minimization and retention.
  • Availability and abuse protection.
  • Response versioning and compatibility.
  • Cacheability.

Evaluation Criteria

Reliability, privacy, security, latency, cost, freshness, compatibility, and complexity.

Expected Deliverables

Comparison matrix, proposed interface, threat analysis, privacy recommendation, freshness policy, failure-state proposal, and implementation plan.

Acceptance Criteria

  • At least two approaches are compared.
  • Request and response fields are specified.
  • Freshness and stale behavior are defined.
  • Privacy and retention implications are documented.
  • Recommendation and rejected alternatives are recorded.

Follow-Up Opportunities

Production adapter, cache implementation, score provenance UI, and oracle monitoring.

Cross-Repository Impact

Extension ↔ grydlock-oracle-adapter; sibling repository unavailable locally.

Complexity

Spike

Impact

Critical — blocks the primary product capability.

Suggested Labels

spike, architecture, security, privacy

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions