swarm UI: delete linked accounts
Each row of an agent's linked accounts, except its own `main` matrix
account, gets a delete action. swarm-controller serves DELETE beside each
PUT (matrix-accounts/{account}, forge-accounts/{label}, github-account),
answers 404 for an account the store does not hold, refuses `main`, and
removes every version through `delete_all_versions`.
The matrix confirmation has a revoke checkbox, off by default: the
controller logs the stored token out at its homeserver first, and keeps
the account when that fails or no homeserver is stored.
The controller's policy gains `delete` on each agent's
`metadata/.../matrix/+`, `forge/+` and `github-token`, pinned in
bao-grants.nix.
Refs #4855
This commit is contained in:
parent
ed9c0f53ed
commit
bbf931207f
7 changed files with 705 additions and 35 deletions
|
|
@ -60,6 +60,33 @@ a link dialog closes.
|
|||
none. What the token needs and how the agent uses it:
|
||||
[GitHub accounts](../integrations/github.md).
|
||||
|
||||
#### Deleting a linked account
|
||||
|
||||
Every row except the matrix `main` row has a **delete** action. Its
|
||||
confirmation names the account and its host, and confirming sends one
|
||||
request:
|
||||
|
||||
| kind | route |
|
||||
| ------- | ------------------------------------------------------------------- |
|
||||
| matrix | `DELETE /api/hives/{hive}/agents/{agent}/matrix-accounts/{account}` |
|
||||
| forgejo | `DELETE /api/hives/{hive}/agents/{agent}/forge-accounts/{label}` |
|
||||
| github | `DELETE /api/hives/{hive}/agents/{agent}/github-account` |
|
||||
|
||||
swarm-controller removes every version of the entry from the swarm secret
|
||||
store, and answers 404 when the store holds nothing there. It refuses `main`: the
|
||||
swarm mints that account and would re-mint it. The panel requests the list
|
||||
again after a delete.
|
||||
|
||||
The matrix confirmation has a checkbox, off by default, that logs the token
|
||||
out at its homeserver first (`?revoke=true`). If the homeserver doesn't
|
||||
confirm the logout, or the account has no homeserver stored, the account stays
|
||||
in the store and the dialog shows why. Deleting a forge account or GitHub token
|
||||
leaves the token valid at its provider; revoke it there.
|
||||
|
||||
The agent isn't told about a delete. Its matrix daemon drops the account when
|
||||
it next lists the store, within two minutes. Its forge and GitHub units never
|
||||
delete a file, so a token already fetched into `<state>` stays there.
|
||||
|
||||
Where each credential lives and who reads it:
|
||||
[`credentials.md`](credentials.md).
|
||||
|
||||
|
|
|
|||
Loading…
Reference in a new issue