A claim may name the verbs it serves for its seat (hq ADR 0160)

The store's databases is not postgres's postgres_list_databases, and a holder may serve both. A
claim's serves names the seat's verbs the module implements for the role; absent, the module's own
tools must list every verb the seat promises, which is how a module named like its seat says they
are one and the same. Registration refuses a claim naming a verb the seat never promised, and the
credential's claims carry the claim's own verbs to the runtime.
This commit is contained in:
2026-10-01 15:18:34 +02:00
parent a2b1f9e936
commit 18958154f0
7 changed files with 86 additions and 8 deletions
+16 -1
View File
@@ -133,7 +133,22 @@ func schema(properties map[string]string, required []string) map[string]any {
return out
}
// unservedVerbs is what a seat promises and a claimant's `tools` does not answer.
// unpromised is what a claim says it serves and the seat's protocol never promised.
func unpromised(serves []string, promised []Verb) []string {
has := map[string]bool{}
for _, v := range promised {
has[v.Name] = true
}
var extra []string
for _, s := range serves {
if !has[s] {
extra = append(extra, s)
}
}
return extra
}
// unservedVerbs is what a seat promises and a claimant's offer for it does not answer.
func unservedVerbs(tools []string, promised []Verb) []string {
has := map[string]bool{}
for _, t := range tools {