123 lines
3.8 KiB
Markdown
123 lines
3.8 KiB
Markdown
# Static Privacy and Network Review
|
|
|
|
**Date:** 2026-09-01
|
|
**Scope:** Source/config/documentation review only. Runtime capture is still required in Phase 0B.
|
|
|
|
## Target rule
|
|
|
|
The final v1 should be able to operate with Internet access physically blocked, with ordinary story data traveling only:
|
|
|
|
```text
|
|
Browser -> local application -> local Ollama
|
|
```
|
|
|
|
Future media should similarly use explicitly configured local providers.
|
|
|
|
## AI-DnD
|
|
|
|
### Static positives
|
|
- documented local single-user mode,
|
|
- local SQLite,
|
|
- local Ollama support,
|
|
- no auth required in local mode,
|
|
- hosted analytics are first-party application functionality rather than a required third-party browser tracker.
|
|
|
|
### Unwanted surfaces to remove
|
|
- OpenRouter/OpenAI/Groq/vLLM provider support,
|
|
- hosted account/guest flows,
|
|
- demo API keys,
|
|
- Render deployment,
|
|
- Neon/Postgres cloud deployment path,
|
|
- visit analytics,
|
|
- QuickJS user scripting,
|
|
- Claude CLI shim if not wanted,
|
|
- any hosted-mode rate-limit/account code that adds no local value.
|
|
|
|
### Risk
|
|
The cloud/hosted code is explicit and documented, which is good, but Phase 0B must prove it can be removed cleanly.
|
|
|
|
## Open Dungeon
|
|
|
|
### Static positives
|
|
- Ollama loopback default,
|
|
- local SQLite,
|
|
- local image backend,
|
|
- no telemetry requirement apparent in inspected package/config.
|
|
|
|
### Unwanted or optional surfaces
|
|
- OpenRouter configuration,
|
|
- arbitrary remote OpenAI-compatible endpoint support,
|
|
- Tailscale/LAN exposure options,
|
|
- any runtime remote assets,
|
|
- any model/image automatic download behavior after setup.
|
|
|
|
### Risk
|
|
The app is smaller, so hardening may be easier, but no runtime capture has been performed.
|
|
|
|
## ai-adventure
|
|
|
|
### Static positives
|
|
This project most closely matches the target from the outset:
|
|
- no telemetry,
|
|
- no cloud account,
|
|
- no MCP,
|
|
- no executable plugins,
|
|
- no shell tools,
|
|
- loopback model endpoint default,
|
|
- non-loopback warning,
|
|
- imported content treated as bounded data,
|
|
- path traversal/symlink defenses documented.
|
|
|
|
### Unwanted surface
|
|
- configurable non-loopback model endpoint should be prohibited or strongly gated in the target v1.
|
|
- LM Studio provider should be replaced/extended with Ollama.
|
|
|
|
## Reference projects
|
|
|
|
### Gamentic
|
|
Local defaults are strong, but the project intentionally supports cloud text/image/audio dialects as alternatives. A target fork would need those disabled. Its Docker/media stack also has setup-time model acquisition concerns separate from story-time privacy.
|
|
|
|
### Chronicler
|
|
Supports local Ollama but also broader providers and a separate local YantrikDB/MCP memory service. More moving parts than needed.
|
|
|
|
### Sonder / Corvus
|
|
Both support local backends but also remote provider configurations; Sonder additionally has extension/optional external-service surfaces.
|
|
|
|
### aiMultiFool
|
|
Primarily local, but direct code reuse is constrained by GPL considerations and it is not a fork finalist.
|
|
|
|
## Required Phase 0B runtime tests
|
|
|
|
For each finalist:
|
|
|
|
1. block outbound Internet access,
|
|
2. start the app,
|
|
3. create/load a story,
|
|
4. generate multiple turns,
|
|
5. trigger summarization/memory,
|
|
6. trigger embeddings where applicable,
|
|
7. save/restore/branch,
|
|
8. for Open Dungeon, generate a local image,
|
|
9. capture socket/DNS/HTTP activity,
|
|
10. fail the test if story content leaves loopback or explicitly approved LAN endpoints.
|
|
|
|
Record:
|
|
- process,
|
|
- destination IP/hostname,
|
|
- port,
|
|
- trigger,
|
|
- payload classification,
|
|
- whether required or optional.
|
|
|
|
## Recommended production hardening
|
|
|
|
- bind app and Ollama to loopback by default,
|
|
- allowlist provider URLs rather than accept arbitrary URLs,
|
|
- no API-key UI in v1,
|
|
- no remote URL ingestion,
|
|
- no executable campaign scripts,
|
|
- no third-party analytics,
|
|
- bundle frontend assets locally,
|
|
- content-security policy that rejects remote scripts/styles/images by default,
|
|
- CI test or integration harness that runs with outbound networking disabled.
|