Resync hq ADR references 0044-0054 -> 0039-0049 after the hq record reconciliation
This commit is contained in:
@@ -1,4 +1,4 @@
|
||||
// mssql's admin client — mssql's own code, living in the module (novox/hq ADR 0044). Both this
|
||||
// mssql's admin client — mssql's own code, living in the module (novox/hq ADR 0039). Both this
|
||||
// module's tools and its provisioner import it, and nothing outside mssql does.
|
||||
//
|
||||
// SQL is executed through `sqlcmd`, not a wire-protocol driver: the module may take NO npm
|
||||
@@ -86,7 +86,7 @@ export class MssqlClient {
|
||||
// `-h -1` drops the column-header rule; `-y 0`/`-Y 0` lift the display-width cap so a long
|
||||
// JSON document is not truncated; `-W` trims trailing whitespace so the JSON chunks rejoin
|
||||
// cleanly. sqlcmd from the mssql-tools ships in the runtime container, the way `psql` ships
|
||||
// with postgres's — the module owns its own code (ADR 0044) and shells out to it.
|
||||
// with postgres's — the module owns its own code (ADR 0039) and shells out to it.
|
||||
const { stdout } = await run(
|
||||
"sqlcmd",
|
||||
[
|
||||
@@ -109,7 +109,7 @@ export class MssqlClient {
|
||||
/**
|
||||
* Create a login and a database it owns (mapped as a db_owner user), idempotently. The login,
|
||||
* the database and the user all carry the consumer's minted name, so the consumer owns exactly
|
||||
* its own database — a name it cannot learn is a database it cannot reach (ADR 0053).
|
||||
* its own database — a name it cannot learn is a database it cannot reach (ADR 0048).
|
||||
*/
|
||||
async createDatabaseAndLogin(database: string, login: string, password: string): Promise<void> {
|
||||
const logins = await this.query(
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
// mssql's events entrypoint, loaded by the per-node tool host (the provisioner container runs
|
||||
// ./provisioner separately). The database lifecycle events are EMITTED from the provisioner, where
|
||||
// the lifecycle actually happens (novox/hq ADR 0046/0047):
|
||||
// the lifecycle actually happens (novox/hq ADR 0041/0042):
|
||||
// module.mssql.database.provisioned — a consumer's database + login/user was created
|
||||
// module.mssql.database.deprovisioned — that database was removed
|
||||
// Here in the tool host we react to them, keeping a lightweight audit trail of who was granted a
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"name": "@novox/module-mssql",
|
||||
"version": "0.1.0",
|
||||
"description": "mssql — provides the mesh mssql-database interface. Its client, provisioner, tools and events live here (novox/hq ADR 0044).",
|
||||
"description": "mssql — provides the mesh mssql-database interface. Its client, provisioner, tools and events live here (novox/hq ADR 0039).",
|
||||
"type": "module",
|
||||
"private": true,
|
||||
"dependencies": {
|
||||
|
||||
@@ -1,12 +1,12 @@
|
||||
// mssql's provisioner — the adapter that makes mssql a provider of the mesh `mssql-database`
|
||||
// interface. The reconcile loop, the contributions file, and reading the mesh's minted password
|
||||
// are the sdk harness's; this writes only the per-service half: how mssql creates and removes a
|
||||
// consumer's database + login/user with the mesh-minted credential (novox/hq ADR 0044/0045/0053).
|
||||
// consumer's database + login/user with the mesh-minted credential (novox/hq ADR 0039/0040/0048).
|
||||
//
|
||||
// The `mssql-database` interface: a consumer connects to a database it alone owns, as `as` with
|
||||
// the password the mesh minted.
|
||||
//
|
||||
// **The login name and password are the mesh's, not the provisioner's (ADR 0053).** The mesh
|
||||
// **The login name and password are the mesh's, not the provisioner's (ADR 0048).** The mesh
|
||||
// derives the login and hands it to both ends, and mints the password. mssql creates a login, a
|
||||
// same-named database, and a db_owner user under exactly that login — a name the consumer cannot
|
||||
// learn is a database it cannot reach.
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
// mssql's tools — mssql's own code (novox/hq ADR 0044), importing mssql's own client. They return
|
||||
// mssql's tools — mssql's own code (novox/hq ADR 0039), importing mssql's own client. They return
|
||||
// structured data; the mesh serves them through the sdk's tool harness. Both call through
|
||||
// MssqlClient, the module's one pending execution boundary (see client.ts): the tool shapes are
|
||||
// fixed and correct, and surface the work honestly through that boundary.
|
||||
|
||||
Reference in New Issue
Block a user