Let's begin by riffing off the title of the previous post, "The passage of time." Almost a year of time has passed since that past post. During that time, my personal pico has been busily collecting temperature readings at the rate of 30 per hour (so, we're talking a quarter million events).
Meanwhile, Phil Windley, the inventor of picos, and a world-class expert in identity and authorization, has been busy improving those aspects of the pico engine. So, there are many updates to consider.
The first big change is authentication, identifying yourself to a pico engine.
How to use picos
But first we need to talk about different ways that a person can use a pico, and feel that they own and control it. Up until now, there was no need to authenticate to use a pico; you just had to know where it is on the Internet.
Provide your own pico engine
Someone with sufficient technical knowledge and skill has to install and operate each pico engine. This person may allow others to use picos on the same pico engine. There are suggestions for doing this in How to make money hosting picos. The changes discussed here make this somewhat easier to do.
The preference at Pico Labs would be for each person to install their own instance of the pico engine. In that case, they are the administrator and have full control of the engine and the developer user interface, and all of the picos hosted by that engine. However, anyone else who has access to the developer UI also has access to all of the picos, so such sharing has to be limited to a trusted community.
Providing picos to others
Another approach is offered by the PLAN (Pico Labs Affiliates Network), first mentioned here in Tutorial for a new application, as a way to avoid having to install/control your own pico engine, yet still write a web application. In PLAN, pico owners are identified by an email address that they control. Others are prevented from using their pico even if they guess the URL, because of checks in each app page, based on cookies held by the browser. Only the admin has access to the developer UI of the pico engine; developers use a collection of "apps" to do their programming. So, PLAN really provides a different developer UI.
Version 1.5
Upgrading a pico engine to version 1.5 (released July 13, 2026) makes a big change. When you upgrade, you will not have access to your picos in the developer UI until you claim them and are given a passkey. Once you accept the fact that you have to login to your developer UI, everything proceeds as before.
The novelty is that, if your pico engine is available on the Internet, no one else will be able to use it at all (because they will not possess your passkey). This is a huge improvement over version 1.4 and earlier pico engines.
Providing picos to others
This version provides a mechanism that you can use to invite another person to use picos on your pico engine. The novelty here is that they will have their very own root pico and will not be able to see yours! And vice versa, you will not be able to see their root pico.
The passkeys mean that each pico user has his or her own set of picos. A new vocabulary term "mesh" is what we call a root pico and all of its child picos (and their children, etc.). Each person using a pico engine going forward will have their own mesh of picos for which they can use the standard pico engine developer user interface.
A downside is that, as the administrator of the shared pico engine, you can no longer see anything in the other users' picos. Of course, that is by design. But it also means that you cannot assist them as readily with unforeseen problems. You can have them share their screen and walk them through actions in their developer UI. On the whole, this is for the best.
Impact on PLAN
Since pico users in the PLAN do not currently use the developer UI, everything can continue as before. There would now, however, be an opportunity to invite such a user to graduate into using the standard developer UI by inviting them to form their own mesh within PLAN the pico engine.
Migration
To support graduation into use of the standard developer UI (instead of the app approach of PLAN), we would have to give the user control of their PLAN pico (the one named for their email address).
We would need a way for one of the affiliate picos (in the example, the one identified by the account bruce_conrad@byu.edu) to become a child of the owner pico in the Bruce's mesh when he accepts the invitation from the PLAN administrator to create a passkey in the PLAN pico engine.
Once such a migration was completed, Bruce would be able to use the pico engine developer UI to manage his picos, in addition to the UI provided by PLAN.
Notes
"busily collecting" may be true, but is hardly noticeable to the pico engine, which is capable of handling events at thousands of times that rate. Computers are valuable in part because they are so much faster than us.
"know where it was" meaning the URL of the developer UI of the pico engine.
"Version 1.5" Phil Windley introduces this new version in his blog post Identity for the Pico Engine.
"the account bruce_conrad@byu.edu" as a string of cahracters is a perfectly valid pico name, and even though it looks very much like an email address—which it is not—web scrapers, do not make the mistake of thinking you can send email messages there—they will bounce!
"migration was completed" is aspirational at this point; the mechanisms to perfom such a migration do not yet exist.

No comments:
Post a Comment