matrix: the agent's daemon pulls its linked accounts from bao itself
hive-matrix-daemon now learns which external matrix accounts it has from the swarm secret store, under the agent's own certificate, and the hive push chain for matrix is gone. The daemon lists swarm/agents/<agent>/matrix/ (the `list` its policy grants on its own metadata subtree), reads each account's homeserver from its credential, and brings the accounts up with their tokens from the store. Every two minutes it lists again and exits with 75 when the set of linked accounts changed; the unit restarts on 75 without counting a failure. A listed name whose credential reads as absent is skipped and logged once. At start it removes the matrix-token-<a> / matrix-account-<a>.json pairs a hive delivered (a sidecar marks a pair as delivered; a declared tokenFile keeps its token). Removed: CredentialNotice and the $SWARM.credential.* subject and NATS grant, the controller's publish and its queue precondition on the PUT route, hive-c0re's credential subscription arm and workers/credential.rs, priv_client::write_agent_matrix_token, hive-priv's WriteAgentMatrixToken and its helpers, and the daemon's state-dir account discovery. Kept: WriteAgentGithubToken and the external-forge path (WriteAgentExtraForgeAccount, extra_forges.rs) are untouched, and a declared matrixAccounts tokenFile is still read when the store has no token for that account. Refs #4348
This commit is contained in:
parent
e04616eb70
commit
97fb76ce99
22 changed files with 553 additions and 813 deletions
|
|
@ -221,42 +221,6 @@ pub const DEPLOY_SUBJECT_WILDCARD: &str = "$SWARM.deploy.*";
|
|||
/// cannot drift into naming different families.
|
||||
const DEPLOY_SUBJECT_PREFIX: &str = "$SWARM.deploy";
|
||||
|
||||
/// The subject the controller publishes on to tell `hive` that a credential
|
||||
/// for one of its agents is waiting in the secret store. Same per-hive family
|
||||
/// as [`deploy_subject`], here for the same three-crate reason.
|
||||
///
|
||||
/// 🔑 **The message NAMES a credential and never carries one**, and the note
|
||||
/// on [`deploy_subject`] is why: the family split buys quiet, not
|
||||
/// confidentiality — the auth-callout responder scopes `pub` and leaves `sub`
|
||||
/// unrestricted, so any hive that wanted another's messages could subscribe to
|
||||
/// them. A secret in this payload would be readable swarm-wide. The hive reads
|
||||
/// the value from the store under its own identity instead, where the store's
|
||||
/// policy is the thing that actually scopes it.
|
||||
#[must_use]
|
||||
pub fn credential_subject(hive: &str) -> String {
|
||||
format!("{CREDENTIAL_SUBJECT_PREFIX}.{hive}")
|
||||
}
|
||||
|
||||
/// The publish grant covering every [`credential_subject`] — a wildcard for
|
||||
/// the same no-roster reason as [`DEPLOY_SUBJECT_WILDCARD`].
|
||||
pub const CREDENTIAL_SUBJECT_WILDCARD: &str = "$SWARM.credential.*";
|
||||
|
||||
/// Shared by [`credential_subject`] and [`CREDENTIAL_SUBJECT_WILDCARD`] so the
|
||||
/// two cannot drift into naming different families.
|
||||
const CREDENTIAL_SUBJECT_PREFIX: &str = "$SWARM.credential";
|
||||
|
||||
/// What a [`credential_subject`] message says: which agent's credential
|
||||
/// changed, and which account it belongs to. Deliberately the whole payload —
|
||||
/// anything more would be either derivable by the reader or a secret that
|
||||
/// must not be on the wire.
|
||||
#[derive(Debug, Clone, PartialEq, Eq, serde::Serialize, serde::Deserialize)]
|
||||
pub struct CredentialNotice {
|
||||
/// The agent whose state dir receives the credential.
|
||||
pub agent: String,
|
||||
/// The external account the credential authenticates as.
|
||||
pub account: String,
|
||||
}
|
||||
|
||||
/// What a [`deploy_subject`] message carries.
|
||||
///
|
||||
/// Only the agent: the subject already names the hive, and repeating it here
|
||||
|
|
|
|||
Loading…
Reference in a new issue