Only CONSUMER.INFO was missing from a machine's grants; the rest was already there
This commit is contained in:
@@ -244,16 +244,15 @@ func PermissionsFor(p Principal) (Permissions, error) {
|
|||||||
case KindNode:
|
case KindNode:
|
||||||
// A host publishes its own node's control traffic and subscribes its own declaration —
|
// A host publishes its own node's control traffic and subscribes its own declaration —
|
||||||
// and nothing of any other node's.
|
// and nothing of any other node's.
|
||||||
// And what the host does with its consumer, nothing more: binding to it asks the server
|
// And binding to its consumer, which asks the server about it (CONSUMER.INFO) — the one
|
||||||
// about it (CONSUMER.INFO) and hears the answer on its own inbox; hearing a declaration
|
// thing the host does that nothing granted. Found the first time a machine dialled a
|
||||||
// acknowledges it. Found the first time a machine dialled a permissioned server: refused
|
// permissioned server: "this node cannot read its declarations" (2026-09-28). The ack and
|
||||||
// for both, and "this node cannot read its declarations" (2026-09-28).
|
// the inbox are granted below with every principal's.
|
||||||
pub = []string{
|
pub = []string{
|
||||||
"mesh.control." + p.Node + ".>",
|
"mesh.control." + p.Node + ".>",
|
||||||
"$JS.API.CONSUMER.INFO.NODES." + p.Node,
|
"$JS.API.CONSUMER.INFO.NODES." + p.Node,
|
||||||
"$JS.ACK.NODES." + p.Node + ".>",
|
|
||||||
}
|
}
|
||||||
sub = []string{"mesh.node." + p.Node + ".declare", p.inbox()}
|
sub = []string{"mesh.node." + p.Node + ".declare"}
|
||||||
|
|
||||||
case KindModule:
|
case KindModule:
|
||||||
// 1. Its own namespace: it publishes its events there and serves its tools there. Nothing
|
// 1. Its own namespace: it publishes its events there and serves its tools there. Nothing
|
||||||
|
|||||||
+2
-2
@@ -32,8 +32,8 @@ accounts {
|
|||||||
subscribe: { allow: ["_INBOX.enrol.one.>"] }
|
subscribe: { allow: ["_INBOX.enrol.one.>"] }
|
||||||
} }
|
} }
|
||||||
{ user: "node.one", password: "$2a$11$nnnnnnnnnnnnnnnnnnnnnn", permissions: {
|
{ user: "node.one", password: "$2a$11$nnnnnnnnnnnnnnnnnnnnnn", permissions: {
|
||||||
publish: { allow: ["$JS.ACK.NODES.one.>", "$JS.ACK.NODES.one.>", "$JS.API.CONSUMER.INFO.NODES.one", "mesh.control.one.>"] }
|
publish: { allow: ["$JS.ACK.NODES.one.>", "$JS.API.CONSUMER.INFO.NODES.one", "mesh.control.one.>"] }
|
||||||
subscribe: { allow: ["_INBOX.node.one.>", "_INBOX.node.one.>", "mesh.node.one.declare"] }
|
subscribe: { allow: ["_INBOX.node.one.>", "mesh.node.one.declare"] }
|
||||||
} }
|
} }
|
||||||
{ user: "one.telegram", password: "$2a$11$tttttttttttttttttttttt", permissions: {
|
{ user: "one.telegram", password: "$2a$11$tttttttttttttttttttttt", permissions: {
|
||||||
publish: { allow: ["$JS.ACK.EVENTS.one_telegram.>", "mesh.seat.telegram-sender.event.delivered", "mesh.seat.telegram-sender.event.failed"] }
|
publish: { allow: ["$JS.ACK.EVENTS.one_telegram.>", "mesh.seat.telegram-sender.event.delivered", "mesh.seat.telegram-sender.event.failed"] }
|
||||||
|
|||||||
Reference in New Issue
Block a user