Volter World

0010: Dashboard session custody

Status: accepted for implementation. Date: 2026-09-30. Work: t_ad153e0a, c31; first need: Cloudflare's fresh dashboard sign-in under c4 t_759d88a5.

The shared world-ui session kit derived a bearer cookie from email, time and the number of session rows. A dashboard credential must instead draw from the World's credential custody. The kit records a new bookkeeping issuance subject, derives its secret with ctx.secret, then records the signed-in session and sets its existing HttpOnly, Secure, SameSite cookie. Packs continue using the same session kit. No pack hand-rolls session issuance, and this changes neither vendor session-expiry policy nor the sign-in password check.

Construction includes no automated checks; final slate verification owns distinct-session and branch checks.

View Markdown source