HUE-016 — Add cross-Space isolation, retrieval and context regression suite
Canonical source:
docs/roadmap/issues.json·HUE-016Specification status:
TBI· Readiness:agent:blocked
Prove Project/Area/Resource boundaries and explicit cross-Space links prevent accidental retrieval leakage.
- Create two-project fixtures with conflicting/private facts
- Exercise context assembly, search and memory operations
- Test archive/move/delete boundaries
Acceptance criteria
Section titled “Acceptance criteria”- No cross-project leakage in manifests or search
- Global allowlisted preference appears as expected
- Path/context attacks fail
- Regression suite is deterministic
Dependencies
Section titled “Dependencies”HUE-013HUE-014HUE-005
Non-goals
Section titled “Non-goals”- None beyond the documented scope.
Product contract
Section titled “Product contract”docs/03-spaces-sessions-knowledge.mddocs/06-projects-context-memory.mddocs/10-security-privacy-trust.md
Implementation handoff requirements
Section titled “Implementation handoff requirements”- Preserve the documented security, project, memory and event boundaries.
- Add or update automated tests for every observable acceptance criterion.
- Provide real verification output; do not rely on a worker/agent self-report.
- Update only the exact documentation sections whose status changed.
- Include screenshots or a recording for user-interface changes.
- Include migration, rollback and recovery notes for data/state changes.
- Link the pull request to this issue with
Closes #<issue-number>.