One name per thing, per the HQ glossary: the module/container/image/binary/repo becomes mesh-controller, the seat the-controller, and the store+broker pair the foundation (embedded base bundles, default template and example lock renamed with their go:embed directives). No behaviour change — a pure vocabulary rename. Claude-Session: https://claude.ai/code/session_01D6qtiYU3P9jk3pnAXyAFyx
33 lines
1.6 KiB
TypeScript
33 lines
1.6 KiB
TypeScript
// Reading the manager node's PUBLIC sealing key out of the bound facts the mesh delivers, and
|
|
// writing a sealed refresh token in the wire shape mesh-controller reads.
|
|
//
|
|
// **The public key is delivered, not derived.** The manager module holds no node key of its own
|
|
// (novox/hq ADR 0050) — it is deliberately never given one. To seal a refresh token to this node it
|
|
// needs the node's PUBLIC sealing key, and mesh-controller puts that in the manager holder's bound facts
|
|
// (`serves.manager_public_key`), safe to disclose because it is public. Both adoption and every
|
|
// rotation read it from there.
|
|
|
|
import { readFileSync, writeFileSync, renameSync, mkdirSync } from "node:fs";
|
|
import { dirname } from "node:path";
|
|
|
|
/** The manager node's public sealing key, from the bound facts file the mesh delivers. */
|
|
export function managerPublicKey(boundFile: string): string {
|
|
const raw = JSON.parse(readFileSync(boundFile, "utf8")) as { serves?: Record<string, unknown> };
|
|
const key = raw.serves?.["manager_public_key"];
|
|
if (typeof key !== "string" || key === "") {
|
|
throw new Error(
|
|
"the bound facts carry no manager_public_key — this node is not the licence's manager, or " +
|
|
"the manager holder has not been delivered yet",
|
|
);
|
|
}
|
|
return key;
|
|
}
|
|
|
|
/** Write a sealed refresh token in the {sealed, manager_key} wire shape mesh-controller reads. */
|
|
export function writeSealedGrant(path: string, sealed: string, managerKey: string): void {
|
|
mkdirSync(dirname(path), { recursive: true });
|
|
const tmp = `${path}.tmp`;
|
|
writeFileSync(tmp, JSON.stringify({ sealed, manager_key: managerKey }), { mode: 0o600 });
|
|
renameSync(tmp, path);
|
|
}
|