A claim may name the verbs it serves for its seat (hq ADR 0160)
The store's databases is not postgres's postgres_list_databases, and a holder may serve both. A claim's serves names the seat's verbs the module implements for the role; absent, the module's own tools must list every verb the seat promises, which is how a module named like its seat says they are one and the same. Registration refuses a claim naming a verb the seat never promised, and the credential's claims carry the claim's own verbs to the runtime.
This commit is contained in:
@@ -52,6 +52,22 @@ type Claim struct {
|
||||
Name string `json:"name"`
|
||||
// Scope defaults to the node, which is where nearly everything singular is singular.
|
||||
Scope string `json:"scope,omitempty"`
|
||||
// Serves names the seat's verbs this module implements for the role, when its own tools are
|
||||
// not the seat's (novox/hq ADR 0159, 0160): the store's `databases` is not postgres's
|
||||
// `postgres_list_databases`, and a holder may well serve both. The runtime serves an
|
||||
// implementation registered under the seat's name on the seat's subjects. Absent, the
|
||||
// module's own `tools` must list every verb the seat promises, which is how a module named
|
||||
// like its seat — the catalogue, the records — says they are one and the same.
|
||||
Serves []string `json:"serves,omitempty"`
|
||||
}
|
||||
|
||||
// ServesFor is what this claim offers a seat's protocol: the verbs it names, else the module's
|
||||
// own tools.
|
||||
func (c Claim) ServesFor(m Manifest) []string {
|
||||
if len(c.Serves) > 0 {
|
||||
return c.Serves
|
||||
}
|
||||
return m.Tools
|
||||
}
|
||||
|
||||
// At is this claim's scope, with the default applied.
|
||||
|
||||
Reference in New Issue
Block a user