feat(device-core): expose safe project control views
This commit is contained in:
@@ -50,6 +50,10 @@ The standalone Hub application `Device Core` / `Device Manager` is the human
|
||||
control-plane shell. Its server-owned BFF calls the disabled-by-default
|
||||
management and query API in `device-control-core`; browsers never receive the
|
||||
Core bearer token and never author actor, role, group or owner-scope headers.
|
||||
The authorized project workspace exposes only bounded metadata for catalog,
|
||||
routes/sessions, bindings, configuration state, command state, audit and access;
|
||||
raw audit/configuration payloads, command parameters/transport refs, external
|
||||
approval proofs, credential refs and restricted identifier digests remain in Core.
|
||||
Foundry remains a downstream consumer for project-approved device data and is
|
||||
not the device registry or administration boundary.
|
||||
|
||||
|
||||
Reference in New Issue
Block a user