// Reading the manager node's PUBLIC sealing key out of the bound facts the mesh delivers, and // writing a sealed refresh token in the wire shape mesh-controller reads. // // **The public key is delivered, not derived.** The manager module holds no node key of its own // (novox/hq ADR 0050) — it is deliberately never given one. To seal a refresh token to this node it // needs the node's PUBLIC sealing key, and mesh-controller puts that in the manager holder's bound facts // (`serves.manager_public_key`), safe to disclose because it is public. Both adoption and every // rotation read it from there. import { readFileSync, writeFileSync, renameSync, mkdirSync } from "node:fs"; import { dirname } from "node:path"; /** The manager node's public sealing key, from the bound facts file the mesh delivers. */ export function managerPublicKey(boundFile: string): string { const raw = JSON.parse(readFileSync(boundFile, "utf8")) as { serves?: Record }; const key = raw.serves?.["manager_public_key"]; if (typeof key !== "string" || key === "") { throw new Error( "the bound facts carry no manager_public_key — this node is not the licence's manager, or " + "the manager holder has not been delivered yet", ); } return key; } /** Write a sealed refresh token in the {sealed, manager_key} wire shape mesh-controller reads. */ export function writeSealedGrant(path: string, sealed: string, managerKey: string): void { mkdirSync(dirname(path), { recursive: true }); const tmp = `${path}.tmp`; writeFileSync(tmp, JSON.stringify({ sealed, manager_key: managerKey }), { mode: 0o600 }); renameSync(tmp, path); }