Watch
0
0
Fork
You've already forked hyperhive
0
hyperhive/swarm-controller/src/agent_icon.rs
atlas 9513058a71 swarm: serve an agent's icon at swarm scope
An agent is not fixed to a hive, so its icon cannot be resolved as
hive -> agent. This adds the swarm-level half: an `agent-icons` KV
bucket keyed by the agent name alone — no hive token, so an agent that
moves hives keeps its icon and one that is stopped still has one — and
`GET /api/agents/<name>/icon` on swarm-controller serving it
same-origin, like every other `/api/*` route swarm-ui calls.

404 is the "this agent has no icon" answer, the same contract the
per-agent harness's own `GET /icon` has for an unconfigured agent.
Until the agent-side publisher lands, that is every agent's answer:
the publisher runs inside the container and an agent's NATS grants are
hive-scoped, which cannot authorise a write to a single-token agent
key. The read side needs no grant change — the controller already
holds `$KV.*.>` and `$JS.API.DIRECT.GET.*.>`.

The response carries `Content-Security-Policy: sandbox` and `nosniff`:
the body is an operator-authored SVG served from this daemon's own
origin, and an SVG can carry script.

Hive-side icon serving is untouched.

Refs #4502
2026-09-28 13:47:37 +02:00

57 lines
2.2 KiB
Rust

//! Reads an agent's icon out of the swarm's agent-icon KV bucket.
//!
//! Sibling of [`crate::agent_status`] and built the same way — the bucket
//! is resolved on first use and cached, a resolution failure is not — but
//! a much smaller read: one key, no roster to be complete against and no
//! freshness to derive. An icon is not a report about the agent, it is a
//! property of it, so there is nothing for a timestamp to mean here.
//!
//! **No hive is named on this path**, because the key does not carry one —
//! see `swarm_queue_client::agent_icon` for why, and for the grant work
//! the publish side is still waiting on.
use anyhow::{Context, Result};
/// Reads the agent-icon bucket. Holds a NATS client rather than a bucket
/// handle, so a controller that starts before the bucket exists picks it
/// up without a restart.
pub struct AgentIconReader {
client: async_nats::Client,
store: tokio::sync::OnceCell<async_nats::jetstream::kv::Store>,
}
impl AgentIconReader {
#[must_use]
pub fn new(client: async_nats::Client) -> Self {
Self {
client,
store: tokio::sync::OnceCell::new(),
}
}
async fn store(
&self,
) -> std::result::Result<&async_nats::jetstream::kv::Store, swarm_queue_client::Error> {
self.store
.get_or_try_init(|| swarm_queue_client::agent_icon::open_or_create(&self.client))
.await
}
/// `agent`'s icon, or `None` when it has published none.
///
/// The bytes are returned unopened: this daemon does not parse, rewrite
/// or validate the SVG, and a consumer that renders it must treat it as
/// the untrusted document it is — see `get_agent_icon`'s response
/// headers.
pub async fn get(&self, agent: &str) -> Result<Option<Vec<u8>>> {
// An unconnected client does not fail a JetStream request, it hangs
// on it — see `swarm_queue_client::ensure_connected`.
swarm_queue_client::ensure_connected(&self.client)?;
let store = self.store().await?;
let icon = store
.get(agent)
.await
.with_context(|| format!("reading the agent-icon entry for {agent}"))?;
Ok(icon.map(Into::into))
}
}