From 041abeb4d7185e9842d4c168c122f7bf222b008d Mon Sep 17 00:00:00 2001 From: 4gray Date: Mon, 3 Aug 2026 09:57:36 +0200 Subject: [PATCH] docs(stalker): tighten the token-revalidation trade-off wording MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Greptile review feedback: the watchdog mitigation was the most important part of that paragraph and sat behind the caveat. It now follows the MAC-sharing vector directly, and the paragraph ends by naming what is actually left uncovered — a same-host static stream played while no watchdog is up — so a future reader can size the residual without re-deriving it. Co-Authored-By: Claude Opus 5 --- docs/architecture/stalker-portal.md | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/docs/architecture/stalker-portal.md b/docs/architecture/stalker-portal.md index a51d048b7..02fa6e477 100644 --- a/docs/architecture/stalker-portal.md +++ b/docs/architecture/stalker-portal.md @@ -401,9 +401,10 @@ an authorization failure. This is narrower than it sounds: per the 4.9.35 reference, handshake tokens have **no TTL**, and failing to send the watchdog does **not** invalidate auth (it only clears the admin panel's "online" status). The one real vector left is another device performing `get_profile` -on the same MAC — common enough on shared subscriptions. Where a watchdog is -running it still self-heals within a ping cycle, because the ping goes through -`makeAuthenticatedRequest`. +on the same MAC — common enough on shared subscriptions, but wherever a +watchdog is running it still self-heals within a ping cycle, because the ping +goes through `makeAuthenticatedRequest` too. What is left uncovered is a +same-host static stream played while no watchdog is up. Revalidating on every static playback would cost exactly the round trip this section exists to remove, so it is deliberately not done here. The right home