Watch
0
0
Fork
You've already forked hyperhive
0

swarm UI: delete linked accounts

Each row of an agent's linked accounts, except its own `main` matrix
account, gets a delete action. swarm-controller serves DELETE beside each
PUT (matrix-accounts/{account}, forge-accounts/{label}, github-account),
answers 404 for an account the store does not hold, refuses `main`, and
removes every version through `delete_all_versions`.

The matrix confirmation has a revoke checkbox, off by default: the
controller logs the stored token out at its homeserver first, and keeps
the account when that fails or no homeserver is stored.

The controller's policy gains `delete` on each agent's
`metadata/.../matrix/+`, `forge/+` and `github-token`, pinned in
bao-grants.nix.

Refs #4855
This commit is contained in:
atlas 2026-10-02 23:31:39 +02:00
commit bbf931207f
7 changed files with 705 additions and 35 deletions

View file

@ -60,6 +60,33 @@ a link dialog closes.
none. What the token needs and how the agent uses it:
[GitHub accounts](../integrations/github.md).
#### Deleting a linked account
Every row except the matrix `main` row has a **delete** action. Its
confirmation names the account and its host, and confirming sends one
request:
| kind | route |
| ------- | ------------------------------------------------------------------- |
| matrix | `DELETE /api/hives/{hive}/agents/{agent}/matrix-accounts/{account}` |
| forgejo | `DELETE /api/hives/{hive}/agents/{agent}/forge-accounts/{label}` |
| github | `DELETE /api/hives/{hive}/agents/{agent}/github-account` |
swarm-controller removes every version of the entry from the swarm secret
store, and answers 404 when the store holds nothing there. It refuses `main`: the
swarm mints that account and would re-mint it. The panel requests the list
again after a delete.
The matrix confirmation has a checkbox, off by default, that logs the token
out at its homeserver first (`?revoke=true`). If the homeserver doesn't
confirm the logout, or the account has no homeserver stored, the account stays
in the store and the dialog shows why. Deleting a forge account or GitHub token
leaves the token valid at its provider; revoke it there.
The agent isn't told about a delete. Its matrix daemon drops the account when
it next lists the store, within two minutes. Its forge and GitHub units never
delete a file, so a token already fetched into `<state>` stays there.
Where each credential lives and who reads it:
[`credentials.md`](credentials.md).