honcho/docs
Rajat Ahuja 326a757cdb
Fix scoped JWTs (#679)
* Peer- and session-scoped JWTs were effectively workspace-scoped: auth() walked the route's declared scope and fell through to a workspace match, so a {w: ws-a, p: alice} token could act on any peer in ws-a.

* feat: peer keys can read sessions they belong to; require workspace on scoped keys

* fix: authorize JWTs by narrowest scope and gate member reads

Follow-up hardening on the narrowest-claim auth fix:

- Scope get_peer_config member-read to the caller's own peer; a session
  member could previously read a co-member's per-session config.
- Enforce session membership on POST /peers/{id}/chat: the session_id
  arrives in the body (invisible to require_auth), so a peer key could
  read any session's injected message history. Check is_peer_in_session
  in the handler before the dialectic runs.
- Consolidate the workspace-match check in auth() to a single hoisted
  guard so no branch can silently re-open cross-workspace access.
- Normalize empty-string scope claims to None in verify_jwt so a blank
  workspace can't satisfy the peer/session token-shape invariant.
- Extract scope_requires_workspace(), shared by verify_jwt and the keys
  API so the creation-time guard and verification invariant can't drift.
  route requires auth) and CLAUDE.md auth-scoping guidance.
- docs: describe narrow-scope key semantics in the platform reference.

---------

Co-authored-by: Vineeth Voruganti <13438633+VVoruganti@users.noreply.github.com>
2026-06-22 17:30:00 -04:00
..
changelog chore(docs): Release Candidate for v3.0.10 (#813) 2026-06-15 17:19:51 -04:00
images Fix typos (#440) 2026-03-22 15:52:55 -04:00
logo color theme and broken link fix (#213) 2025-09-24 16:06:54 -04:00
snippets cli docs (#589) 2026-04-20 23:25:12 -04:00
v1 feat: retry on more httpx exceptions (#467) 2026-04-03 12:20:53 -04:00
v2 Connection Exponential Backoff (#758) 2026-06-01 12:57:07 -04:00
v3 Fix scoped JWTs (#679) 2026-06-22 17:30:00 -04:00
README.md Add Pre-commit Hooks (#165) 2025-07-22 15:17:53 -04:00
bun.lock v3.0.6 Release Candidate (#550) 2026-04-10 13:16:42 -04:00
docs.json chore(docs): Release Candidate for v3.0.10 (#813) 2026-06-15 17:19:51 -04:00
favicon.svg [0.0.7] — 2024-04-01 (#50) 2024-04-01 10:58:42 -07:00
package.json v3.0.6 Release Candidate (#550) 2026-04-10 13:16:42 -04:00

README.md

Honcho Docs

These docs are built using Next.js via mintlify.

Setting Up Honcho's Docs Locally

  1. Clone the repository:
git clone git@github.com:plastic-labs/honcho.git
  1. Navigate into the docs folder:
cd honcho/docs/

The docs folder contains the markdown files that make up the documentation. The majority of the files are in the pages directory. Some notable files in this folder include:

  1. Verify that you have Node.js and npm installed in your system. You can check by running:
node --version
npm --version
  1. If not installed, download Node.js and npm from the respective official websites.

  2. Once you have Node.js and npm running, proceed to install pnpm - another package manager that helps to manage project dependencies:

npm install -g pnpm
  1. Install the project dependencies using pnpm:
pnpm i
  1. After the successful installation of the project dependencies, start the local server:
pnpm dev

Now, you should be able to view the docs on your local environment by visiting http://localhost:3000. You can explore the different markdown files and make changes as you see fit.