bao: drop matrix-ctl's per-hive sender-token grant
swarm-controller is the only minter of swarm/hives/<hive>/matrix/sender-token since #4820, so the swarm-matrix-ctl policy's first stanza granted a write no code performs. The policy keeps its one used stanza, the swarm appservice token that `swarm-matrix-ctl appservice publish` writes. deploy.bao.matrixCtlHiveName only named the hive in the dropped stanza and goes with it. hive-matrix.nix no longer calls the per-hive appservice's as_token hive-c0re's authority: tuwunel loads the registration and creates the sender account, and no client presents that token.
This commit is contained in:
parent
b8ec0f4f85
commit
b58a0d8ba9
3 changed files with 19 additions and 64 deletions
|
|
@ -422,32 +422,19 @@ let
|
|||
# the `services/` prefix the publisher holds would be a real loss even
|
||||
# though it would read as tidier.
|
||||
#
|
||||
# ⚠️ `hives` is PLURAL, because the path segment comes from
|
||||
# `Kind::Hive`'s strum serialisation and not from `Kind::label`, which
|
||||
# renders the singular for error text. The singular spelling evaluates,
|
||||
# deploys, and 403s every read with "permission denied" and nothing else.
|
||||
#
|
||||
# 🩸 The hive NAME in the middle is the per-hive half of this credential:
|
||||
# the token used to be one swarm-wide value under `services/matrix/`,
|
||||
# which every hive's own policy granted read on. The negative arms below
|
||||
# are what keep it from drifting back — neither the `services/*` tree nor
|
||||
# a `hives/*` wildcard may appear, since either one hands matrix-ctl (or
|
||||
# a hive) reach beyond the single leaf it owns.
|
||||
#
|
||||
# The one other leaf is the swarm appservice token, which matrix-ctl
|
||||
# mints and publishes for the controller. Counted, so a third stanza
|
||||
# fails rather than riding along beside two correct ones.
|
||||
name = "matrix-ctl's grant is one hive's sender token and the swarm appservice token, nothing else";
|
||||
# The leaf is the swarm appservice token, which matrix-ctl mints and
|
||||
# publishes for the controller. Counted, so a second stanza fails rather
|
||||
# than riding along beside a correct one.
|
||||
name = "matrix-ctl's grant is the swarm appservice token, nothing else";
|
||||
ok =
|
||||
let
|
||||
s = baoGrantHere.systemd.services.swarm-bao-matrix-ctl-policy.script;
|
||||
in
|
||||
lib.hasInfix "path \"secret/data/swarm/hives/h1/matrix/sender-token\" {" s
|
||||
&& lib.hasInfix "path \"secret/data/swarm/controller/swarm-controller/matrix/appservice-token\" {\n capabilities = [\"create\", \"update\", \"read\"]\n}" s
|
||||
&& lib.length (lib.splitString "path \"" s) == 3
|
||||
lib.hasInfix "path \"secret/data/swarm/controller/swarm-controller/matrix/appservice-token\" {\n capabilities = [\"create\", \"update\", \"read\"]\n}" s
|
||||
&& lib.length (lib.splitString "path \"" s) == 2
|
||||
&& !(lib.hasInfix "secret/data/swarm/services" s)
|
||||
&& !(lib.hasInfix "secret/data/swarm/agents" s)
|
||||
&& !(lib.hasInfix "secret/data/swarm/hives/*" s)
|
||||
&& !(lib.hasInfix "secret/data/swarm/hives" s)
|
||||
&& !(lib.hasInfix "sys/policies/acl" s);
|
||||
}
|
||||
{
|
||||
|
|
|
|||
Loading…
Reference in a new issue