4.4 done: a person's account and their client
The account existed as a permission model and as nothing a person could be given; there is a record and three commands now. The client is two surfaces over one thing, a command line and an MCP server, both using the client a module's runtime uses — so what a person may do is answered by the same permission list that answers it for a module. Design 25 §7 says nothing of this is built before its bed passes, and this was built before. Noted in the task rather than quietly ignored.
This commit is contained in:
@@ -557,16 +557,40 @@ it, and the beds that need a mesh living on NATS can finally run.
|
||||
that forgot it. The check earned itself at once: the composer was granting a role's whole event
|
||||
branch *and* the one event it follows, and the wider grant wins — so only the submitting half of
|
||||
a role is granted now, and what comes back is named exactly.
|
||||
- [~] 4.4 a person's client — **the account is done**: a person is not a module and holds no
|
||||
seat, so their authority is a list of tools (or `*` for an administrator) and nothing else.
|
||||
Held to four properties, each a way of being wrong that would not announce itself: nothing
|
||||
but tools, so a person cannot claim a module said something; no ack subject, because
|
||||
authority over a consumer that does not exist is authority nobody audits; no ability to
|
||||
answer, because a person who can answer a request is impersonating a module on a bus where
|
||||
anyone may serve a tool; and two people do not share an inbox.
|
||||
- [x] 4.4 a person's client — **the account and the program are both in.**
|
||||
|
||||
**The account**: a person is not a module and holds no seat, so their authority is a list of
|
||||
tools (or `*` for an administrator) and nothing else. Held to four properties, each a way of
|
||||
being wrong that would not announce itself: nothing but tools, so a person cannot claim a
|
||||
module said something; no ack subject, because authority over a consumer that does not exist
|
||||
is authority nobody audits; no ability to answer, because a person who can answer a request is
|
||||
impersonating a module on a bus where anyone may serve a tool; and two people do not share an
|
||||
inbox. Issued, listed and revoked by command; stating what somebody may call replaces what was
|
||||
there, because a list that could only grow is a permission nobody can take back; and forgetting
|
||||
somebody takes their credential with them, or it is not a revocation.
|
||||
|
||||
**The program**: two surfaces over one thing — a command line and an MCP server — both adapters
|
||||
over the same three calls, because a second way of reaching a tool is a second thing to keep
|
||||
correct. It uses the client a module's runtime uses, so what a person may do is answered by the
|
||||
same permission list that answers it for a module and an audit has nothing separate to read.
|
||||
|
||||
Three decisions in it worth keeping. It lists what the **catalogue** has rather than what this
|
||||
credential may call: somebody seeing only their own tools cannot tell "not installed" from "not
|
||||
yours", and those need different people to fix them. A failed call says which of three things
|
||||
happened — nobody serves it, this credential may not, or the tool was slow — because the
|
||||
remedies are in three different places and without that they are one timeout and a stack trace.
|
||||
And the MCP surface decides nothing: the names are the ones a person types, the schemas are the
|
||||
modules' own, an answer is passed through unshaped, and a tool that fails comes back as a tool
|
||||
error rather than a protocol error, because the request was well-formed and the mesh answered it.
|
||||
|
||||
Both surfaces are driven against a running bus, including a host's notification being answered
|
||||
with nothing and an unknown method refused.
|
||||
|
||||
> **Design 25 §7 says "nothing is built of this before §10's bed passes", and this was built
|
||||
> before.** Recorded rather than quietly ignored: the operator asked for it, it is on the
|
||||
> critical path for nothing and blocked by nothing, and the bed it waits for is 4.1's. If the
|
||||
> bed changes what a person's client should be, this is what gets changed.
|
||||
|
||||
Still to build: the client program itself — the command line and the MCP surface over it.
|
||||
It needs nothing from the consume side, so it is not blocked by step 3.
|
||||
- [~] 4.5 reports and catch-up: a node that was unreachable catches up rather than losing them —
|
||||
**the reports half is in and proved against a server** (3.4): held through the store's absence
|
||||
by the server rather than by the controller, superseded ones settled by the digest they carry.
|
||||
|
||||
Reference in New Issue
Block a user