FlowDrop Workflow Specification 1.0-draft

Driving a session is a write, and an absent identity owns nothing

A turn spends the owner's memory, so the right to watch a conversation is not the right to continue it. And the caller with no identity is not a caller whose identity happens to be zero.

The rule

Normative: this is the rule
  1. Authorization to read a session does not authorize driving it.
  2. A principal that may only view a session must not be able to send it a turn, stop it or reset it, because the turn runs under the session owner's identity and reads and writes the owner's memory (MEM-8).
  3. Every ownership test requires a real identity on both sides.
  4. A principal carrying no identity never owns anything, and a session carrying no owner is owned by nobody rather than by everybody, so an unidentified caller never acquires ownership of a session, a transcript or a run snapshot by matching one absent identity against another.
Rule identifiers are permanent and are never renumbered. Each implementation publishes its own standing against these rules; this specification does not.spec 1.0-draft · MEM-9 · changed in spec 1.0