A provider keeps one grant file per holder, with the local name in its id and path

The lab's vault refused a declaration naming two files with one identity: the
two secrets of one consumer. The holder's suffix is in the resource id and the path now.
This commit is contained in:
2026-09-21 20:41:19 +02:00
parent 3e5c010c5e
commit 5049d201c6
3 changed files with 46 additions and 6 deletions
+4 -2
View File
@@ -347,9 +347,11 @@ func (r Resolution) Declaration(with Rendering) ([]map[string]any, error) {
continue
}
first = append(first, map[string]any{
"id": GrantID(to, g.Consumer+"."+g.From),
// One file per holder — the consumer's module with its local name after it
// where it keeps several (ADR 0094); the lab found two files with one id.
"id": GrantID(to, g.Consumer+"."+holderAs(g.From, g.Local)),
"type": "file",
"path": grantPath(m.Grants[to], g.Consumer, g.From),
"path": grantPath(m.Grants[to], g.Consumer, holderAs(g.From, g.Local)),
"sealed": g.Sealed,
})
}