hive-c0re: stop minting agent forge tokens
Delete ensure_user_for and mint_and_persist_agent_token, the user step of sync_agent (the per-rebuild re-mint, #4644) and of forge_after_first_spawn, and the hive-priv WriteAgentForgeToken request that wrote the token into the agent's state dir. hivectl forge create-user now refuses an agent and points at swarmctl agent mint-forge-token. mint_token, ensure_user_exists and TOKEN_SCOPES stay: provision_user_token and the core bootstrap still call them. Refs #3782
This commit is contained in:
parent
dd32a395f7
commit
b5d07d4df2
10 changed files with 59 additions and 126 deletions
|
|
@ -316,10 +316,10 @@ pub enum HostRequest {
|
|||
room: Option<String>,
|
||||
},
|
||||
/// Create or refresh a forge account + API token for `name`. Daemon-side
|
||||
/// equivalent of `hivectl forge create-user`: for an existing agent it
|
||||
/// provisions the account and persists the token to `<notes>/forge-token`;
|
||||
/// for a non-agent (operator/human) it mints a user and returns the token
|
||||
/// in [`HostResponse::messages`]. `password` is resolved client-side
|
||||
/// equivalent of `hivectl forge create-user`: for a non-agent
|
||||
/// (operator/human) it mints a user and returns the token in
|
||||
/// [`HostResponse::messages`]. An existing agent is refused: its token is
|
||||
/// swarm-controller's to mint. `password` is resolved client-side
|
||||
/// (inline flag or stdin) and only meaningful for non-agent accounts.
|
||||
ForgeCreateUser {
|
||||
name: Ident,
|
||||
|
|
|
|||
Loading…
Reference in a new issue