ADR 0158: the controller's half is built (mesh-controller PR 184); the provider definitions remain

This commit is contained in:
2026-10-01 12:27:39 +02:00
parent c58f4d6790
commit bef510fda2
2 changed files with 4 additions and 2 deletions
+2 -2
View File
@@ -130,7 +130,7 @@ recovery addresses both alike.
### A provider with one credential
*Decided 2026-10-01 ([ADR 0158](../../02-DECISIONS/0158-a-provider-with-one-credential-shares-it-with-every-consumer.md)); to be built.*
*Decided 2026-10-01 ([ADR 0158](../../02-DECISIONS/0158-a-provider-with-one-credential-shares-it-with-every-consumer.md)); the controller's half built the same day (mesh-controller PR 184): the offer's word, the need carrying the shared secret's name, the vault's one value under one generation stamp, remade for every holder on a later binding or a rotation, the rotate command sending every holder. What remains is each provider's definition saying `credential` and `taken`, with a start that applies the file — the media catalogue's work.*
Software that holds one credential — a download client's web password, an indexer's one API key —
cannot give each consumer a login, so ADR 0048's form does not fit it and its values were accepted
@@ -142,7 +142,7 @@ plaintext it remakes the value for every holder at once when a consumer binds or
rotation is asked, and the mesh sends every holding machine together. The provider takes it as it
says it takes its own secret (`taken`, issue 180); consumers read it at start. An accepted value is
sealed to the consumers of the moment and not remade; a consumer that binds later waits for the next
acceptance. *How it is checked:* the rows of ADR 0158's table, once built.
acceptance. *How it is checked:* the rows of ADR 0158's table; the controller's rows pass, the live row waits for the first provider.
## Beyond generate and hold