Update planning package after Phase 0B

This commit is contained in:
JesseMarkowitz
2026-09-01 20:41:23 -04:00
parent ba737de9b4
commit 717670afe0
34 changed files with 2061 additions and 1204 deletions
+78 -32
View File
@@ -1,6 +1,6 @@
# Adventure Storyteller — Security Threat Model
**Status:** Draft v0.1
**Status:** v1.0 — local-only hardening requirements informed by Phase 0B
**Purpose:** Define the security and privacy boundaries for a local-only interactive storytelling application.
## 1. Security Objective
@@ -79,7 +79,9 @@ Trusted to receive:
- retrieved local knowledge,
- user input.
For v1, Ollama should be accessed through loopback unless the user explicitly configures otherwise in a future release.
For v1, Ollama may run either on the storyteller machine or on an explicitly configured machine on the user's trusted LAN. Same-host loopback remains the default. When Ollama is on another LAN host, story prompt/context data necessarily crosses the local network to that approved inference machine.
The inference host should restrict access to Ollama using host firewall/network controls appropriate to the local environment. LAN inference does not authorize LAN exposure of the storyteller UI/API.
### 4.3 Local browser
@@ -124,10 +126,11 @@ Preferred allowed v1 network paths:
```text
Browser -> local storyteller application
Storyteller -> 127.0.0.1 Ollama
OR -> explicitly approved trusted-LAN Ollama host
Storyteller -> optional explicitly configured local media service
```
Everything else should be denied or absent.
Everything else should be denied or absent. An approved LAN Ollama host is inside the v1 local trust boundary; arbitrary Internet/cloud inference is not.
## 7. Default Bind Addresses
@@ -139,10 +142,13 @@ Preferred defaults:
```
### Ollama
Same-host default:
```text
127.0.0.1
```
A separate inference machine may listen on an explicitly chosen LAN interface/address as required for the storyteller to reach it. That host should use firewall/network policy to limit access to trusted clients.
### Media services
```text
127.0.0.1
@@ -156,7 +162,7 @@ Do not bind to:
by default.
LAN exposure may be considered later as a separate explicit feature.
LAN exposure of the **storyteller UI/API** may be considered later as a separate explicit feature. This does not prohibit the v1 storyteller backend from connecting outbound to an approved LAN Ollama host.
## 8. Forbidden v1 Network Behavior
@@ -209,17 +215,21 @@ creates a data-exfiltration path.
For v1:
- prefer a fixed local Ollama endpoint,
- or allow only loopback endpoints.
- default to same-host loopback Ollama,
- allow an explicitly configured trusted-LAN Ollama endpoint,
- surface the effective destination clearly in configuration/diagnostics,
- reject or keep arbitrary public Internet endpoints outside normal v1 configuration.
Possible allowed forms:
Examples of allowed forms include:
```text
http://127.0.0.1:11434
http://localhost:11434
http://192.168.1.50:11434
http://inferencebox.local:11434
```
Anything else should be rejected unless a future advanced configuration explicitly enables it.
The LAN hostname/address must be an intentional user configuration. Do not infer that every non-loopback endpoint is trusted merely because it resolves.
## 11. Imported Files Must Be Data Only
@@ -716,15 +726,9 @@ No automatic runtime update check is required.
## 48. Dependency Risk
Phase 0B should inventory:
- Python dependencies,
- npm dependencies,
- native modules,
- optional cloud SDKs,
- abandoned packages,
- packages with install/postinstall scripts.
Phase 0B inventoried the major inherited surfaces in the selected base and identified concrete removals and runtime leaks. Production milestones must continue dependency review as code is stripped and upgraded, including Python/npm/native modules, optional cloud SDKs, install/postinstall behavior, and security advisories.
Prefer removing dependencies that only support unwanted cloud features.
Prefer removing dependencies that only support unwanted cloud/hosted features.
## 49. Supply Chain
@@ -766,22 +770,22 @@ The application should only have permissions needed to:
It should not need broad system access.
## 53. LAN Mode — Future Only
## 53. Storyteller LAN Access — Future Only
If LAN access is added later, it must be a distinct security mode.
LAN **inference** is supported in v1: the loopback-bound storyteller may connect outbound to an explicitly configured trusted-LAN Ollama machine.
It should require:
LAN access to the **storyteller browser UI/API** is different and remains a future security mode. If added later, it should require:
- explicit enablement,
- authentication,
- TLS or trusted local network assumptions,
- host/firewall documentation,
- session protection.
Do not accidentally inherit LAN exposure because a candidate project binds to all interfaces.
Do not accidentally inherit storyteller LAN exposure because a candidate project binds to all interfaces.
## 54. Tailscale / VPN Access
Same as LAN mode.
Treat remote access to the storyteller UI/API like storyteller LAN access.
Useful later, but not a v1 requirement.
@@ -1064,6 +1068,35 @@ Classify each hit:
- development-only,
- false positive.
## 71A. Phase 0B Confirmed Risks in the Selected AI-DnD Base
Phase 0B runtime validation found specific inherited behaviors that production must remove or package differently:
1. **First-use tokenizer download**
- `tiktoken` attempted to fetch `cl100k_base` from a Microsoft-hosted endpoint on the first isolated turn.
- Production must bundle/cache the required encoding or replace that path so ordinary story use never depends on Internet access.
2. **Runtime Google Fonts**
- the SPA requested Google-hosted font assets and the existing CSP permits those hosts.
- Production must self-host required fonts or use local/system fonts and remove the remote CSP allowances.
3. **Unneeded cloud/hosted surface**
- hosted auth/multi-user/demo/analytics/Render/Neon/Postgres/cloud-provider paths are outside the v1 trust model.
- Remove these paths rather than simply hiding them when practical.
4. **QuickJS/campaign scripting**
- executable campaign scripting is outside the v1 trust boundary.
- Remove/disable the engine and replace any test-only instrumentation that depended on it.
5. **Endpoint policy mismatch**
- inherited network guarding is aimed at hosted deployment behavior, not at preventing accidental story-data exfiltration.
- Production should default to loopback Ollama, explicitly support a configured trusted-LAN Ollama host, and reject/avoid arbitrary public Internet inference endpoints.
6. **Postgres is removable**
- Phase 0B found no architectural blocker to dropping Postgres support; SQLite remains the v1 store.
These are production hardening requirements, not optional polish.
## 72. Phase 0B Runtime Network Test
After all dependencies/models are preinstalled:
@@ -1083,13 +1116,13 @@ After all dependencies/models are preinstalled:
13. generate local image in Open Dungeon if evaluated,
14. monitor sockets/DNS.
Record every non-loopback attempt.
Record every non-loopback attempt and classify it as approved trusted-LAN inference/media traffic or unexpected traffic.
## 73. Runtime Pass Condition
For ordinary v1 story operation:
> No story content or imported content leaves loopback or explicitly approved local endpoints.
> No story content or imported content leaves explicitly approved local infrastructure. Same-host loopback and explicitly configured trusted-LAN Ollama/media endpoints are permitted; Internet/cloud destinations are not.
Unexpected DNS/HTTP attempts must be explained and removed or disabled.
@@ -1098,7 +1131,7 @@ Unexpected DNS/HTTP attempts must be explained and removed or disabled.
Minimum v1 acceptance:
- app works with outbound Internet blocked,
- Ollama connection remains local,
- Ollama connection remains within explicitly approved local infrastructure,
- no cloud API key required,
- no external telemetry,
- imported Markdown does not execute script,
@@ -1139,30 +1172,43 @@ Potential later improvements:
These are not required for initial v1 unless Phase 0B reveals a specific need.
## 77. Current Security Recommendation
## 77. Selected Security Posture
The production architecture should intentionally be narrow:
The production architecture is intentionally narrow:
```text
NO:
cloud providers
hosted auth/accounts
web tools
general plugins
MCP
shell execution
QuickJS/campaign scripting
remote document fetch
runtime CDN/fonts/assets
telemetry
analytics
remote embeddings/vector stores
YES:
local browser
local app
local FastAPI app
local SQLite/files
local Ollama
local retrieval
optional local media services
local-infrastructure Ollama (same-host or approved trusted-LAN)
local lexical/semantic retrieval
optional explicitly configured local media services in the future
```
The safest implementation is not the one with the most configurable providers.
Required production defaults:
It is the one with the fewest ways story data can leave the machine accidentally.
- storyteller binds loopback by default,
- Ollama endpoint is same-host loopback by default,
- explicitly configured trusted-LAN Ollama endpoints are supported,
- arbitrary public/Internet inference endpoints are rejected or absent from normal v1 configuration,
- tokenizer assets required for runtime are packaged locally,
- browser assets/fonts are local,
- no cloud API-key UI exists in v1,
- outbound-network-blocked acceptance testing is part of release gating.
The safest implementation is the one with the fewest accidental paths for story data to leave the machine.