Commit graph

2 commits

Author SHA1 Message Date
f9e02fc3e4 fixed del key bug 2026-08-14 01:12:20 -05:00
cbb26b19b9 Track multi-user as a direction, not a project
Separate people with their own drawings, alerts and notifications, behind OIDC
against a self-hosted Authentik that can federate Google. Written as phases that
each pay for themselves while the app is still single-user, so none of it is
scaffolding waiting on a decision.

The ordering conclusion worth stating plainly: do not build local accounts.
Going to OIDC means the app never stores or hashes a password, so building that
first means deleting it later. Shared password to OIDC subject, with nothing in
between.

One thing to fix regardless: the JWT signing key is sha256 of the password.
Today that is merely weak, since anyone holding a cookie can brute-force the
password offline. With several users it cannot work at all — either everyone
shares a signing key, or the key varies per user and a token cannot be verified
without already knowing who sent it. Added to the risk register.

The fork that decides the architecture is not an engineering one: whose market
data. One shared feed is redistribution, which Schwab's agreement and CME's
beneath it generally prohibit; each user bringing their own brokerage account
avoids the question entirely but means a stream, a token and a weekly re-auth
each, and the shared bar store stops being shared. That answer is only needed
before the last phase, which is why it is not a blocker on starting.

AGENTS.md points at both planning documents, because the cheapest moment to know
whether new state is shared or per-user is while it is being written.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-11 16:21:25 -05:00