Watch
0
0
Fork
You've already forked hyperhive
0

swarm-controller: refuse linking over an existing account

The matrix, forge and github link routes wrote their credential
unconditionally, so linking a name that was already linked replaced the
working account. For matrix that lost the device the agent's crypto store
belongs to (#4838).

Each route now reads the account's store path first and answers 409,
naming the existing account, when something is stored there. Nothing is
written. Replacing an account takes the delete from #4899, then a link.

The matrix route checks before password mode's login, so a refused link
mints no new device at the homeserver.

The check is a read then a write, not an atomic step; two concurrent
links to one name can still both pass it.

Closes #4856
This commit is contained in:
atlas 2026-10-03 13:29:26 +02:00
commit 8ad2af735e
10 changed files with 303 additions and 63 deletions

View file

@ -1,11 +1,11 @@
// <LinkForgeAccountForm> — writes an external forge account (base URL +
// token) for one agent into the swarm secret store.
// PUTs `/api/hives/{hive}/agents/{agent}/forge-accounts/{label}` — 200
// (`{ url }`) on success, 400/500 as `problem+json`, shown via
// (`{ url }`) on success, 400/409/500 as `problem+json`, shown via
// `ApiErrorPanel` like `LinkMatrixAccountForm`.
//
// The label is what the agent passes to `hive-forge -f <label>`. A blind
// set/update: no route hands a token back. Linked labels and URLs show on
// set: no route hands a token back. Linked labels and URLs show on
// the agent panel (`LinkedAccounts`).
import { useState } from "preact/hooks";
import { ApiErrorPanel } from "@hive/shared/api-error-panel.js";

View file

@ -1,10 +1,10 @@
// <LinkGithubAccountForm> — writes a GitHub personal access token for one
// agent into the swarm secret store.
// PUTs `/api/hives/{hive}/agents/{agent}/github-account` — 204 on success,
// 400/500 as `problem+json`, shown via `ApiErrorPanel` like
// 400/409/500 as `problem+json`, shown via `ApiErrorPanel` like
// `LinkForgeAccountForm`.
//
// One token per agent. A blind set/update: no route hands a token back.
// One token per agent. A blind set: no route hands a token back.
// Whether one is stored shows on the agent panel (`LinkedAccounts`).
import { useState } from "preact/hooks";
import { ApiErrorPanel } from "@hive/shared/api-error-panel.js";

View file

@ -8,12 +8,12 @@
// PUT, straight to swarm-controller — never held here past
// the request, never stored.
// PUTs `/api/hives/{hive}/agents/{agent}/matrix-accounts/{account}` —
// 200 (`{ user_id? }`) on success, 400/500 on the documented failure
// 200 (`{ user_id? }`) on success, 400/409/500 on the documented failure
// arms — all handled generically via `readApiError`/`ApiErrorPanel`,
// same as every other form here, since the response is `problem+json`
// regardless of which arm fired.
//
// A blind set/update action: no route hands a token back, so there is
// A blind set action: no route hands a token back, so there is
// nothing to edit. What is already linked shows on the agent panel
// (`LinkedAccounts`), names and hosts only. That matches "make it 1:1 for now, we will split later" and
// "adding them and assigning them should be separate things" — both