swarm-controller: refuse linking over an existing account
The matrix, forge and github link routes wrote their credential unconditionally, so linking a name that was already linked replaced the working account. For matrix that lost the device the agent's crypto store belongs to (#4838). Each route now reads the account's store path first and answers 409, naming the existing account, when something is stored there. Nothing is written. Replacing an account takes the delete from #4899, then a link. The matrix route checks before password mode's login, so a refused link mints no new device at the homeserver. The check is a read then a write, not an atomic step; two concurrent links to one name can still both pass it. Closes #4856
This commit is contained in:
parent
4a50d29a64
commit
8ad2af735e
10 changed files with 303 additions and 63 deletions
|
|
@ -1,11 +1,11 @@
|
|||
// <LinkForgeAccountForm> — writes an external forge account (base URL +
|
||||
// token) for one agent into the swarm secret store.
|
||||
// PUTs `/api/hives/{hive}/agents/{agent}/forge-accounts/{label}` — 200
|
||||
// (`{ url }`) on success, 400/500 as `problem+json`, shown via
|
||||
// (`{ url }`) on success, 400/409/500 as `problem+json`, shown via
|
||||
// `ApiErrorPanel` like `LinkMatrixAccountForm`.
|
||||
//
|
||||
// The label is what the agent passes to `hive-forge -f <label>`. A blind
|
||||
// set/update: no route hands a token back. Linked labels and URLs show on
|
||||
// set: no route hands a token back. Linked labels and URLs show on
|
||||
// the agent panel (`LinkedAccounts`).
|
||||
import { useState } from "preact/hooks";
|
||||
import { ApiErrorPanel } from "@hive/shared/api-error-panel.js";
|
||||
|
|
|
|||
|
|
@ -1,10 +1,10 @@
|
|||
// <LinkGithubAccountForm> — writes a GitHub personal access token for one
|
||||
// agent into the swarm secret store.
|
||||
// PUTs `/api/hives/{hive}/agents/{agent}/github-account` — 204 on success,
|
||||
// 400/500 as `problem+json`, shown via `ApiErrorPanel` like
|
||||
// 400/409/500 as `problem+json`, shown via `ApiErrorPanel` like
|
||||
// `LinkForgeAccountForm`.
|
||||
//
|
||||
// One token per agent. A blind set/update: no route hands a token back.
|
||||
// One token per agent. A blind set: no route hands a token back.
|
||||
// Whether one is stored shows on the agent panel (`LinkedAccounts`).
|
||||
import { useState } from "preact/hooks";
|
||||
import { ApiErrorPanel } from "@hive/shared/api-error-panel.js";
|
||||
|
|
|
|||
|
|
@ -8,12 +8,12 @@
|
|||
// PUT, straight to swarm-controller — never held here past
|
||||
// the request, never stored.
|
||||
// PUTs `/api/hives/{hive}/agents/{agent}/matrix-accounts/{account}` —
|
||||
// 200 (`{ user_id? }`) on success, 400/500 on the documented failure
|
||||
// 200 (`{ user_id? }`) on success, 400/409/500 on the documented failure
|
||||
// arms — all handled generically via `readApiError`/`ApiErrorPanel`,
|
||||
// same as every other form here, since the response is `problem+json`
|
||||
// regardless of which arm fired.
|
||||
//
|
||||
// A blind set/update action: no route hands a token back, so there is
|
||||
// A blind set action: no route hands a token back, so there is
|
||||
// nothing to edit. What is already linked shows on the agent panel
|
||||
// (`LinkedAccounts`), names and hosts only. That matches "make it 1:1 for now, we will split later" and
|
||||
// "adding them and assigning them should be separate things" — both
|
||||
|
|
|
|||
Loading…
Reference in a new issue