Watch
0
0
Fork
You've already forked hyperhive
0

swarm: narrow the revoke grant to the queue leaf, not the whole agent prefix

revoke_queue_credential only ever deletes swarm/agents/<agent>/queue
(agent_queue_path + a literal "queue" suffix), never anything else
under an agent's prefix. secret/metadata/swarm/agents/+/queue matches
that exactly — `+` is bao's single-segment glob, the same form
swarm-nats-auth's read grant already uses for the data-side path.

Also rewords the module-eval test's stale note about a read/list grant
handing a "write-only principal" the version history: the controller
has held read on secret/data/swarm/agents/* since the mint-and-verify
read-before-write change, so it was never write-only on that path.
This commit is contained in:
atlas 2026-09-27 21:55:35 +02:00 • committed by mara
commit 642be57678
2 changed files with 10 additions and 6 deletions

View file

@ -400,7 +400,7 @@ let
capabilities = ["create", "read", "update"]
}
path "${credentialMountPath}/metadata/swarm/agents/*" {
path "${credentialMountPath}/metadata/swarm/agents/+/queue" {
capabilities = ["delete"]
}