Watch
0
0
Fork
You've already forked hyperhive
0

swarm-controller: refuse linking over an existing account

The matrix, forge and github link routes wrote their credential
unconditionally, so linking a name that was already linked replaced the
working account. For matrix that lost the device the agent's crypto store
belongs to (#4838).

Each route now reads the account's store path first and answers 409,
naming the existing account, when something is stored there. Nothing is
written. Replacing an account takes the delete from #4899, then a link.

The matrix route checks before password mode's login, so a refused link
mints no new device at the homeserver.

The check is a read then a write, not an atomic step; two concurrent
links to one name can still both pass it.

Closes #4856
This commit is contained in:
atlas 2026-10-03 13:29:26 +02:00
commit 8ad2af735e
10 changed files with 303 additions and 63 deletions

View file

@ -50,7 +50,8 @@ store identity, or no queue address, publishes no subagent terminals.
Each agent on `/agents` opens three dialogs that write a credential for it
into the swarm secret store through swarm-controller. All three are blind
set/update actions: no route hands a token back.
set actions: no route hands a token back. swarm-controller refuses to link a
name that already holds an account; delete that account first to replace it.
The agent's detail panel lists its linked accounts under **accounts**, one row
per account: kind, name and host. Opening an agent makes one request,
@ -75,12 +76,14 @@ a link dialog closes.
`swarm/agents/<agent>/forge/<label>`. The agent's
`hive-agent-forge-accounts` unit fetches it into
`<state>/forge-<label>-token` and `<state>/forge-<label>.json`, the files
`hive-forge -f <label>` reads. The unit never deletes a pair: linking
the same label again overwrites both files, and a pair whose label the
store doesn't list stays untouched.
`hive-forge -f <label>` reads. The unit rewrites a pair whenever the
store's account for its label differs, and never deletes one: a pair whose
label the store doesn't list stays untouched. swarm-controller answers 409
to a link for a label that already holds an account, so replacing one
takes a delete, then a new link.
- **link a github account** — `PUT /api/hives/{hive}/agents/{agent}/github-account`
with a personal access token, stored at `swarm/agents/<agent>/github-token`.
One token per agent: linking again replaces it. The agent's
One token per agent. The agent's
`hive-agent-github-token` unit fetches it into `<state>/github-token`,
the file its `gh` wrapper, git credential helper and GitHub notification
poller read. A `github-token` already in place stays when the store holds