give: never take a trusted party's secret at a desk, and announce it before it is kept (hq ADR 0259 §10, the confirmation review's N1-give)
A desk's prompt is answered over the desk machine's bus, on a subject that machine's runtime answers; on a desk machine agents run as the operator, who holds that credential, so an agent could answer first with a bot token of its own sealed to the call's key. The secret of a module running as an account of its own (the Telegram bot's token) is now refused at the desk, before anybody is asked, naming the line to type at the controller's terminal; there it is announced on every channel, the old one among them, before it is kept, and not kept when that announcement fails. What is typed at the terminal is not echoed. Tests: the refusal with nobody asked, and only the desk machine's launcher may answer its prompt (MaySubscribe).
This commit is contained in:
@@ -564,6 +564,17 @@ func (i *Inventory) DeclaresOwnSecret(ctx context.Context, module, name string)
|
||||
return GivableAtDesk(m, name)
|
||||
}
|
||||
|
||||
// RunsAsItsOwnAccount says a module runs as an account of its own (novox/hq ADR 0259 §8): a trusted party — the
|
||||
// router, a channel that proves its sender or shows a link's code — whose own secret is what the operator's
|
||||
// answers are believed by. Its value is given at the controller's terminal alone.
|
||||
func (i *Inventory) RunsAsItsOwnAccount(ctx context.Context, module string) (bool, error) {
|
||||
m, err := i.declared(ctx, module)
|
||||
if err != nil {
|
||||
return false, err
|
||||
}
|
||||
return m.RunsAs != "", nil
|
||||
}
|
||||
|
||||
// BrokerSecret is the own secret that is a module's bus account, which `issue` mints.
|
||||
const BrokerSecret = "broker"
|
||||
|
||||
|
||||
Reference in New Issue
Block a user