swarm-controller: refuse linking over an existing account
The matrix, forge and github link routes wrote their credential unconditionally, so linking a name that was already linked replaced the working account. For matrix that lost the device the agent's crypto store belongs to (#4838). Each route now reads the account's store path first and answers 409, naming the existing account, when something is stored there. Nothing is written. Replacing an account takes the delete from #4899, then a link. The matrix route checks before password mode's login, so a refused link mints no new device at the homeserver. The check is a read then a write, not an atomic step; two concurrent links to one name can still both pass it. Closes #4856
This commit is contained in:
parent
4a50d29a64
commit
8ad2af735e
10 changed files with 303 additions and 63 deletions
|
|
@ -50,7 +50,8 @@ store identity, or no queue address, publishes no subagent terminals.
|
|||
|
||||
Each agent on `/agents` opens three dialogs that write a credential for it
|
||||
into the swarm secret store through swarm-controller. All three are blind
|
||||
set/update actions: no route hands a token back.
|
||||
set actions: no route hands a token back. swarm-controller refuses to link a
|
||||
name that already holds an account; delete that account first to replace it.
|
||||
|
||||
The agent's detail panel lists its linked accounts under **accounts**, one row
|
||||
per account: kind, name and host. Opening an agent makes one request,
|
||||
|
|
@ -75,12 +76,14 @@ a link dialog closes.
|
|||
`swarm/agents/<agent>/forge/<label>`. The agent's
|
||||
`hive-agent-forge-accounts` unit fetches it into
|
||||
`<state>/forge-<label>-token` and `<state>/forge-<label>.json`, the files
|
||||
`hive-forge -f <label>` reads. The unit never deletes a pair: linking
|
||||
the same label again overwrites both files, and a pair whose label the
|
||||
store doesn't list stays untouched.
|
||||
`hive-forge -f <label>` reads. The unit rewrites a pair whenever the
|
||||
store's account for its label differs, and never deletes one: a pair whose
|
||||
label the store doesn't list stays untouched. swarm-controller answers 409
|
||||
to a link for a label that already holds an account, so replacing one
|
||||
takes a delete, then a new link.
|
||||
- **link a github account** — `PUT /api/hives/{hive}/agents/{agent}/github-account`
|
||||
with a personal access token, stored at `swarm/agents/<agent>/github-token`.
|
||||
One token per agent: linking again replaces it. The agent's
|
||||
One token per agent. The agent's
|
||||
`hive-agent-github-token` unit fetches it into `<state>/github-token`,
|
||||
the file its `gh` wrapper, git credential helper and GitHub notification
|
||||
poller read. A `github-token` already in place stays when the store holds
|
||||
|
|
|
|||
Loading…
Reference in a new issue