swarm: narrow the revoke grant to the queue leaf, not the whole agent prefix
revoke_queue_credential only ever deletes swarm/agents/<agent>/queue (agent_queue_path + a literal "queue" suffix), never anything else under an agent's prefix. secret/metadata/swarm/agents/+/queue matches that exactly — `+` is bao's single-segment glob, the same form swarm-nats-auth's read grant already uses for the data-side path. Also rewords the module-eval test's stale note about a read/list grant handing a "write-only principal" the version history: the controller has held read on secret/data/swarm/agents/* since the mint-and-verify read-before-write change, so it was never write-only on that path.
This commit is contained in:
parent
215a8aedc4
commit
642be57678
2 changed files with 10 additions and 6 deletions
|
|
@ -400,7 +400,7 @@ let
|
|||
capabilities = ["create", "read", "update"]
|
||||
}
|
||||
|
||||
path "${credentialMountPath}/metadata/swarm/agents/*" {
|
||||
path "${credentialMountPath}/metadata/swarm/agents/+/queue" {
|
||||
capabilities = ["delete"]
|
||||
}
|
||||
|
||||
|
|
|
|||
Loading…
Reference in a new issue