Review of 083: finishing an enrolment whose token was spent takes proof of the key's private half, a live lease and a first delivery — a public key alone cannot replay a spent token; shutdown leaves held messages for the broker; identical builds supersede; what is held leaves room in the prefetch
This commit is contained in:
@@ -216,17 +216,20 @@ var ErrTokenInUse = errors.New("the token is being used by another enrolment")
|
||||
// of a lease, and says which node it enrols. The same presenter may claim it again, as may anyone
|
||||
// once the lease has lapsed; nothing is spent until Spend (novox/hq 04-ISSUES/083).
|
||||
//
|
||||
// A token this same presenter already spent is claimed again too: its spend reached the store and
|
||||
// the answer did not reach the node, which asked again. Refusing it then would lock out a machine
|
||||
// the mesh holds as enrolled — with the key it is still presenting.
|
||||
func (i *Inventory) Claim(ctx context.Context, secret, by string) (Node, error) {
|
||||
// A token this same presenter already spent may be claimed again when `again` says so — the
|
||||
// caller has proof the presenter holds the key's private half — and only while its claim's lease
|
||||
// is live: its spend reached the store and the answer did not reach the node, which asked again.
|
||||
// Refusing it then would lock out a machine the mesh holds as enrolled. Without the proof a spent
|
||||
// token stays spent to everyone, as ADR 0004 says.
|
||||
func (i *Inventory) Claim(ctx context.Context, secret, by string, again bool) (Node, error) {
|
||||
var id string
|
||||
err := i.store.Pool().QueryRow(ctx,
|
||||
`update enrolment_token set claimed_by = $2, claimed_until = now() + $3::interval
|
||||
`update enrolment_token set claimed_by = $2,
|
||||
claimed_until = case when redeemed is null then now() + $3::interval else claimed_until end
|
||||
where secret = $1 and expires > now()
|
||||
and ((redeemed is null and (claimed_by is null or claimed_by = $2 or claimed_until < now()))
|
||||
or (redeemed is not null and claimed_by = $2))
|
||||
returning node`, hashSecret(secret), by, ClaimLease.String()).Scan(&id)
|
||||
or (redeemed is not null and $4 and claimed_by = $2 and claimed_until > now()))
|
||||
returning node`, hashSecret(secret), by, ClaimLease.String(), again).Scan(&id)
|
||||
if errors.Is(err, pgx.ErrNoRows) {
|
||||
// Unusable, or held by someone else — told apart, because the second passes.
|
||||
var held bool
|
||||
|
||||
Reference in New Issue
Block a user