docs: freeze attachment gates contract (Scooling 2F-b-a, Thinking)
Freeze docs/ATTACHMENT-STORE-CONTRACT-2F-b.md — the Knowtation side of the Scooling Phase 2F entry criteria (attachment listing, scoped metadata reads, data-lifecycle/consent/deletion, prompt-injection labeling).
Attachments are DERIVED (read-time) from three existing sources: media/** files, frontmatter Mist blob IDs (SPEC §2.4), and embedded body URLs (media-url-extract). Durable state is a small consent/retention overlay (hub_attachment_store.json), mirroring the calendar store. Read-only listAttachments/getAttachment over three identical surfaces (CLI/MCP/Hub REST); scope INHERITED from the owning note (deny-by-default); *ForClient content-minimization (no bytes/paths/credentialed URLs/OCR); untrusted injection-labeling; automatic deletion propagation. Seven-tier test matrix + hosted smoke checklist + OpenAPI shapes + Scooling mediaLibraryAdapter/v0 mapping (§6). Mirrors TASK-STORE-CONTRACT-2G.md structure.
Contract only: no lib/attachments code, no Hub routes, no posture flips. Build is 2F-b-b (Auto) on feat/phase-2f-b-attachment-store. Consent-toggle/OCR/connector writes are separate Tier 3 gates.
Semantic Changes
69 symbols
0 comments
muse hub commit comment sha256:82c82af23c41421d6b82adf4f0e28c036a500928d2e7a7741aa22d8527dcdf5a --body "your comment"
No comments yet. Be the first to start the discussion.