Providers create the credential the mesh minted, sealing nothing (ADR 0053)
redis, postgres and minio adapters drop generatePassword + the returned credential: each creates the resource under the login the mesh derived (`as`) with the password the mesh minted (`p.password`). minio's client gains a secret-key argument so it sets the mesh's secret rather than generating one. umami (analytics) is re-pointed at the new contract too; its siteId return is a data-provision concern ADR 0053 scopes out. Proven: mesh-lab provider-uses-mesh-credential green — redis creates the consumer's login with the mesh's password, the consumer authenticates (PONG), no seal key set. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
@@ -10,7 +10,7 @@
|
||||
// creation the MinIO admin REST API guards behind an encrypted payload `fetch` cannot form.
|
||||
// This mirrors hal's MinIOClient/MinIOAdmin split, folded into one client the module builds from env.
|
||||
|
||||
import { createHash, createHmac, randomBytes } from "node:crypto";
|
||||
import { createHash, createHmac } from "node:crypto";
|
||||
import { execFile } from "node:child_process";
|
||||
import { readFileSync, writeFileSync, unlinkSync } from "node:fs";
|
||||
import { tmpdir } from "node:os";
|
||||
@@ -205,14 +205,15 @@ export class MinioClient {
|
||||
// --- admin plane (mc CLI) ------------------------------------------------
|
||||
|
||||
/**
|
||||
* Create a service account scoped to one bucket and return its credential. The MinIO admin REST
|
||||
* API encrypts this request with a key derived (Argon2) from the root secret, which node built-ins
|
||||
* cannot reproduce — so, as hal did, the module drives the `mc` CLI, which the provisioner image
|
||||
* bundles.
|
||||
* Create a service account scoped to one bucket, under a given access key and secret key, and
|
||||
* return the pair. The secret key is the mesh's — the mesh mints one password per consumer and
|
||||
* hands a copy to both ends (novox/hq ADR 0053), so minio sets that as the secret rather than
|
||||
* generating one the consumer could never learn. The MinIO admin REST API encrypts this request
|
||||
* with a key derived (Argon2) from the root secret, which node built-ins cannot reproduce — so, as
|
||||
* hal did, the module drives the `mc` CLI, which the runtime image bundles.
|
||||
*/
|
||||
async createAccessKey(bucket: string, accessKey: string): Promise<AccessKey> {
|
||||
async createAccessKey(bucket: string, accessKey: string, secretKey: string): Promise<AccessKey> {
|
||||
await this.ensureAlias();
|
||||
const secretKey = randomBytes(20).toString("hex");
|
||||
const policyPath = join(this.mcConfigDir, `policy-${accessKey}.json`);
|
||||
writeFileSync(policyPath, bucketPolicy(bucket), { mode: 0o600 });
|
||||
try {
|
||||
|
||||
Reference in New Issue
Block a user