A claim may name the verbs it serves for its seat (hq ADR 0160)
The store's databases is not postgres's postgres_list_databases, and a holder may serve both. A claim's serves names the seat's verbs the module implements for the role; absent, the module's own tools must list every verb the seat promises, which is how a module named like its seat says they are one and the same. Registration refuses a claim naming a verb the seat never promised, and the credential's claims carry the claim's own verbs to the runtime.
This commit is contained in:
@@ -716,7 +716,9 @@ func claimsFor(ctx context.Context, inv *inventory.Inventory, m catalogue.Manife
|
||||
claimed := seatClaimed{Seat: c.Name, Scope: c.At()}
|
||||
if s, known := byName[c.Name]; known {
|
||||
claimed.Scope = s.Scope
|
||||
claimed.Serves = catalogue.VerbNames(s.Serves)
|
||||
// The verbs the runtime serves for the seat: the claim's own when it names them
|
||||
// (ADR 0160), else every verb the seat promises, which its tools then answer.
|
||||
claimed.Serves = c.ServesFor(catalogue.Manifest{Tools: catalogue.VerbNames(s.Serves)})
|
||||
}
|
||||
out = append(out, claimed)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user