Skip to content

feat(protected-content): from Creator to a readable object - #204

Open
irzhywau wants to merge 1 commit into
feat/protected-content-runtime-authorityfrom
feat/protected-content-creator-reader
Open

irzhywau wants to merge 1 commit into
feat/protected-content-runtime-authorityfrom
feat/protected-content-creator-reader

Conversation

@irzhywau

@irzhywau irzhywau commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

What this does

A creator protects any file and lists it in one flow from the new Creator app. The source type decides the path:

  • video and audio take the rendition path;
  • everything else becomes an object on the chunked-payload path.

The kind then decides the viewer. The new Elacity Reader renders protected pictures, documents, text, 3D models, books and comics.

  • Audio is a first-class rendition rather than video with the picture missing.
  • CENC protection header: protected media carries a pssh box declaring the Elacity post-quantum hybrid-threshold scheme. One module writes, parses and admits it.
  • Crypto review package: docs/PROTECTED_CONTENT_CRYPTO_REVIEW.md documents every primitive, what each construction binds, and a threat model with the test that pins each claim.

Reviewing

About 62k of the lines are three.js and pdf.js, vendored under capsules/elacity-reader/browser/vendor/ for the Reader. Check their versions and licenses there rather than reading them. Tests are about 7k lines.

Stack

Second of four, based on #203:

  1. feat(protected-content): one authority, the Runtime, and no 10% disk floor (ELACITY-2299) #203 One authority
  2. feat(protected-content): from Creator to a readable object #204 this PR: from Creator to a readable object
  3. feat(protected-content): a mint that completes and an open that works #205 A mint that completes and an open that works
  4. feat(protected-content): buy from any live offer #206 Buy from any live offer

Supersedes the first half of #62. Closes #49. Part of #42 (custody/operator UX is not complete). Part of #48; external review stays open.

Verification

The whole stack (top of PR 4) passes locally:

  • cargo fmt --check and workspace clippy with -D warnings
  • just test-elastos and just test-capsules (21 capsules)
  • every source-gate script and the capsule browser tests
  • just product-ui-source

The same checks are running on this branch alone; I'll post the result as a comment. GitHub CI is the arbiter.

… readable object

Squashes the first half of the 0.7.1 follow-up (#42, #48, #49) into one slice.

A creator uploads a file through the Library transport and protects and lists
it in one flow, through the Creator app. The source mime decides the kind:
video and audio take the rendition path, everything else is an object and takes
the chunked-payload path, and the kind then decides the viewer, so the creator
never picks one. Non-media objects work end to end, and Elacity Reader renders
pictures, documents, text, 3D models, books and comics.

Audio becomes a first-class rendition rather than a video with the picture
missing: media-provider probes the source, keeps exactly one track, and skips
cover art rather than taking it for a video track. Protected media carries a
CENC Protection System Specific Header declaring the Elacity post-quantum
hybrid-threshold scheme, written, parsed and admitted by one module so the
producer, the read path and the layout validator cannot drift apart.

The crypto-review package documents every primitive with its crate version and
parameters, what each construction binds, and a threat model naming the test
that pins each claim.

Original commits: 9404e8d, afabc11, d10b199, 0617957, ca7fa26, 2596100,
9709934.
@irzhywau

irzhywau commented Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

The local run on this branch alone was stopped to save disk space, so GitHub CI is the check for this branch on its own. The full stack (top of #206) passes every check locally.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants