docs: a first SSO login makes a human's forge account
setup.md said Swarm SSO creates the operator's forge account, which was not true until the previous commits. It now says how: sign in to the forge once through authelia, then `swarmctl forge make-admin <you>`. sso.md says what that first login does and why ACCOUNT_LINKING is `login`. README, hivectl.md and forge.md drop `hivectl forge create-user`, and the swarmctl README gains `forge make-admin`. Refs #3782
This commit is contained in:
parent
d56d8f2b36
commit
0cbb7db2c0
6 changed files with 62 additions and 33 deletions
|
|
@ -15,11 +15,10 @@ each agent on relevant activity.
|
|||
|
||||
## Token scopes
|
||||
|
||||
Two scope sets live in `hive-c0re::forge`:
|
||||
Two scope sets:
|
||||
|
||||
**`TOKEN_SCOPES`** (per-agent tokens, and `hivectl forge create-user`
|
||||
accounts). swarm-controller mints agent tokens with a byte-identical copy,
|
||||
`forge::agent_token::AGENT_TOKEN_SCOPES`, pinned by a test:
|
||||
**`AGENT_TOKEN_SCOPES`** (swarm-controller's `forge::agent_token`, pinned
|
||||
by a test). swarm-controller mints every agent token with it:
|
||||
|
||||
| Scope | Why |
|
||||
| -------------------- | ------------------------------------------------------------------------------------------------------- |
|
||||
|
|
@ -32,9 +31,9 @@ accounts). swarm-controller mints agent tokens with a byte-identical copy,
|
|||
| `read:notification` | Poll `GET /notifications` for unread events. |
|
||||
| `write:notification` | Mark notifications read via `PATCH /notifications/threads/{id}`. |
|
||||
|
||||
**`CORE_TOKEN_SCOPES`** (hive-c0re's own `core` user): everything in
|
||||
`TOKEN_SCOPES` plus `read:admin` and `write:admin`. Site-admin
|
||||
membership alone isn't sufficient — Forgejo's token scope gate runs
|
||||
**`CORE_TOKEN_SCOPES`** (`hive-c0re::forge`, for its own `core` user):
|
||||
everything in `AGENT_TOKEN_SCOPES` plus `read:admin` and `write:admin`.
|
||||
Site-admin membership alone isn't sufficient — Forgejo's token scope gate runs
|
||||
before the user-permission check, so `/api/v1/admin/*` returns
|
||||
`403 Forbidden` for any token without the admin scope bits, even when
|
||||
the bearer is a site admin.
|
||||
|
|
|
|||
Loading…
Reference in a new issue