fix(#3344): type the roster entry's name as Ident, per review
A bare String in a crate whose whole suite types validated names as hive_types::Ident, so a consumer had to re-derive at the boundary what every sibling field gets checked for free. Ident is strictly narrower than the store's charset — [a-z0-9-] against the [A-Za-z0-9._-] the users database allows, because that file holds humans too. Every agent name is a legal Ident by construction (creation parses one before the job is queued), so the narrowing costs real agents nothing. What it does mean is that a human hand-added to the agent group cannot be described as an agent: the reader omits that row and logs it, rather than failing the whole roster or quietly shrinking the answer. The REQUEST keeps its String. That side carries what a caller asked for, and validating it server-side is what lets a bad name be refused with a message instead of failing to deserialise.
This commit is contained in:
parent
e71c9cc431
commit
d58be6834b
6 changed files with 51 additions and 7 deletions
|
|
@ -77,9 +77,10 @@ impl AuthBridge {
|
|||
/// facts, and only one of them is a valid render.
|
||||
pub async fn list_agent_identities(&self) -> Result<Vec<String>> {
|
||||
match self.request(&BridgeRequest::ListAgentIdentities).await? {
|
||||
BridgeResponse::Agents { agents } => {
|
||||
Ok(agents.into_iter().map(|entry| entry.name).collect())
|
||||
}
|
||||
BridgeResponse::Agents { agents } => Ok(agents
|
||||
.into_iter()
|
||||
.map(|entry| entry.name.into_string())
|
||||
.collect()),
|
||||
other => {
|
||||
anyhow::bail!("swarm-authelia-bridge answered a roster request with {other:?}")
|
||||
}
|
||||
|
|
|
|||
Loading…
Reference in a new issue