Resync hq ADR references 0044-0054 -> 0039-0049 after the hq record reconciliation

This commit is contained in:
2026-09-05 12:49:16 +02:00
parent afc1ae1ecf
commit 6e8c18afff
140 changed files with 179 additions and 179 deletions
+3 -3
View File
@@ -1,4 +1,4 @@
// mssql's admin client — mssql's own code, living in the module (novox/hq ADR 0044). Both this
// mssql's admin client — mssql's own code, living in the module (novox/hq ADR 0039). Both this
// module's tools and its provisioner import it, and nothing outside mssql does.
//
// SQL is executed through `sqlcmd`, not a wire-protocol driver: the module may take NO npm
@@ -86,7 +86,7 @@ export class MssqlClient {
// `-h -1` drops the column-header rule; `-y 0`/`-Y 0` lift the display-width cap so a long
// JSON document is not truncated; `-W` trims trailing whitespace so the JSON chunks rejoin
// cleanly. sqlcmd from the mssql-tools ships in the runtime container, the way `psql` ships
// with postgres's — the module owns its own code (ADR 0044) and shells out to it.
// with postgres's — the module owns its own code (ADR 0039) and shells out to it.
const { stdout } = await run(
"sqlcmd",
[
@@ -109,7 +109,7 @@ export class MssqlClient {
/**
* Create a login and a database it owns (mapped as a db_owner user), idempotently. The login,
* the database and the user all carry the consumer's minted name, so the consumer owns exactly
* its own database — a name it cannot learn is a database it cannot reach (ADR 0053).
* its own database — a name it cannot learn is a database it cannot reach (ADR 0048).
*/
async createDatabaseAndLogin(database: string, login: string, password: string): Promise<void> {
const logins = await this.query(
+1 -1
View File
@@ -1,6 +1,6 @@
// mssql's events entrypoint, loaded by the per-node tool host (the provisioner container runs
// ./provisioner separately). The database lifecycle events are EMITTED from the provisioner, where
// the lifecycle actually happens (novox/hq ADR 0046/0047):
// the lifecycle actually happens (novox/hq ADR 0041/0042):
// module.mssql.database.provisioned — a consumer's database + login/user was created
// module.mssql.database.deprovisioned — that database was removed
// Here in the tool host we react to them, keeping a lightweight audit trail of who was granted a
+1 -1
View File
@@ -1,7 +1,7 @@
{
"name": "@novox/module-mssql",
"version": "0.1.0",
"description": "mssql — provides the mesh mssql-database interface. Its client, provisioner, tools and events live here (novox/hq ADR 0044).",
"description": "mssql — provides the mesh mssql-database interface. Its client, provisioner, tools and events live here (novox/hq ADR 0039).",
"type": "module",
"private": true,
"dependencies": {
+2 -2
View File
@@ -1,12 +1,12 @@
// mssql's provisioner — the adapter that makes mssql a provider of the mesh `mssql-database`
// interface. The reconcile loop, the contributions file, and reading the mesh's minted password
// are the sdk harness's; this writes only the per-service half: how mssql creates and removes a
// consumer's database + login/user with the mesh-minted credential (novox/hq ADR 0044/0045/0053).
// consumer's database + login/user with the mesh-minted credential (novox/hq ADR 0039/0040/0048).
//
// The `mssql-database` interface: a consumer connects to a database it alone owns, as `as` with
// the password the mesh minted.
//
// **The login name and password are the mesh's, not the provisioner's (ADR 0053).** The mesh
// **The login name and password are the mesh's, not the provisioner's (ADR 0048).** The mesh
// derives the login and hands it to both ends, and mints the password. mssql creates a login, a
// same-named database, and a db_owner user under exactly that login — a name the consumer cannot
// learn is a database it cannot reach.
+1 -1
View File
@@ -1,4 +1,4 @@
// mssql's tools — mssql's own code (novox/hq ADR 0044), importing mssql's own client. They return
// mssql's tools — mssql's own code (novox/hq ADR 0039), importing mssql's own client. They return
// structured data; the mesh serves them through the sdk's tool harness. Both call through
// MssqlClient, the module's one pending execution boundary (see client.ts): the tool shapes are
// fixed and correct, and surface the work honestly through that boundary.