A person may be issued, listed and revoked

Design 25 §7's first item, which existed as a permission model and as nothing a person
could actually be given. There is a record now, and three commands.

Their authority is a list of tools and nothing else. Not a module: they hold no seat,
nothing is addressed to them, nothing is delivered to them, and they have no consumer to
acknowledge. What they have is permission to ask — which is why there is no scope and no
node in the record.

Stating what somebody may call replaces what was there rather than adding to it: a list
that could only grow is a permission nobody can take back. Forgetting somebody takes
their credential with them, because a person's row gone with their bus user left behind
is a credential that still works and that nothing derives — the worst of both, since it
keeps working and nobody can explain why.

The credential is printed once and the mesh keeps only a hash, the same contract a token
has. And it starts working at the next composition rather than immediately, because the
bus's users are a file — said out loud in both the issue and the revoke messages, since
"revoked" that still works for another minute is worth knowing about.

Four properties held by test, each a way of being wrong that would not announce itself:
a person may publish exactly the tool subjects they were given and nothing on control,
nodes or events; they cannot answer a request; changing the list removes what is no longer
named; and forgetting them revokes them.
This commit is contained in:
2026-09-27 17:07:19 +02:00
parent 8e2824201a
commit 53e8f5bdd8
5 changed files with 355 additions and 3 deletions
+7 -2
View File
@@ -80,8 +80,13 @@ func (i *Inventory) BusRecords(ctx context.Context) (broker.Records, error) {
}
out.Enrolling = enrolling
// People are not recorded yet: the account model is built (design 25 §7's first item) and
// `operator issue` is not, so there is nobody to derive. Left empty rather than guessed at.
people, err := i.People(ctx)
if err != nil {
return broker.Records{}, err
}
for _, p := range people {
out.People[p.Name] = p.Invokes
}
return out, nil
}
+67
View File
@@ -163,3 +163,70 @@ func (i *Inventory) SeedBusUser(ctx context.Context, u BusUser, password string)
u.Username, u.Kind, u.Node, u.Module, string(hash))
return err
}
// A person who may call the mesh's tools (novox/hq design 25 §7).
//
// **Their authority is a list of tools and nothing else.** Not a module: they hold no seat, nothing is
// addressed to them, nothing is delivered to them, and they have no consumer to acknowledge. What
// they have is permission to ask.
// Person is somebody who may reach the mesh's tools.
type Person struct {
Name string
// Invokes are the tools they may call, each `<module>.<tool>`, or the single entry `*` for an
// administrator.
Invokes []string
}
// RecordPerson adds somebody, or changes what they may call.
//
// Replacing rather than merging: what a person may call is stated in full, so a change that meant to
// remove a tool does remove it. A list that could only grow is a permission nobody can take back.
func (i *Inventory) RecordPerson(ctx context.Context, p Person) error {
if p.Name == "" {
return errors.New("a person needs a name: it becomes their user on the bus")
}
if len(p.Invokes) == 0 {
return fmt.Errorf(
"%s may call nothing, so there is no reason for them to reach the mesh. Name the tools, "+
"or `*` for an administrator", p.Name)
}
_, err := i.store.Pool().Exec(ctx,
`insert into person (name, invokes) values ($1, $2)
on conflict (name) do update set invokes = excluded.invokes`,
p.Name, p.Invokes)
return err
}
// People is everybody who may reach the mesh's tools.
func (i *Inventory) People(ctx context.Context) ([]Person, error) {
rows, err := i.store.Pool().Query(ctx, `select name, invokes from person order by name`)
if err != nil {
return nil, err
}
defer rows.Close()
var out []Person
for rows.Next() {
var p Person
if err := rows.Scan(&p.Name, &p.Invokes); err != nil {
return nil, err
}
out = append(out, p)
}
return out, rows.Err()
}
// ForgetPerson removes somebody and the credential they were given.
//
// **Both, or neither is a revocation.** A person's row gone and their bus user left behind is a
// credential that still works and that nothing derives, which is the worst of both: it keeps working
// and nobody can explain why.
func (i *Inventory) ForgetPerson(ctx context.Context, name string) error {
if name == "" {
return errors.New("forgetting nobody would forget everybody")
}
if _, err := i.store.Pool().Exec(ctx, `delete from person where name = $1`, name); err != nil {
return err
}
return i.ForgetBusUser(ctx, "person."+name)
}
@@ -0,0 +1,19 @@
-- A person who may call the mesh's tools from a workstation.
--
-- novox/hq design 25 §7. Everything else that reaches the bus is a machine or a module running on
-- one; this is the exception the mesh has always had informally — somebody at a terminal — and never
-- recorded. Until now "the operator" meant whoever held the keys, which is a role and not a record,
-- so nothing could say who may call what.
--
-- **The authority is a list of tools and nothing else.** A person is not a module: they hold no seat,
-- nothing is addressed to them, nothing is delivered to them, and they have no consumer to
-- acknowledge. What they have is permission to ask. That is why there is no scope column and no node
-- column — a person is not on a machine.
create table person (
name text primary key,
-- The tools this person may invoke, each `<module>.<tool>`, or the single entry `*` for an
-- administrator. Stored as given: the permission is derived from it at every composition, so a
-- normalised form here would be a second opinion about authority (novox/hq ADR 0043).
invokes text[] not null default '{}',
created timestamptz not null default now()
);
+120
View File
@@ -0,0 +1,120 @@
package inventory
import (
"context"
"strings"
"testing"
"github.com/novox/mesh-controller/internal/broker"
)
// Somebody who may call the mesh's tools, and what the bus makes of them.
// A person's authority is a list of tools, and it becomes exactly that on the bus — nothing on
// control, nothing on nodes, nothing they could publish as a module.
func TestAPersonMayCallToolsAndNothingElse(t *testing.T) {
inv := ForTest(t)
ctx := context.Background()
if err := inv.RecordPerson(ctx, Person{Name: "ada",
Invokes: []string{"mesh-catalog.catalog_tools"}}); err != nil {
t.Fatal(err)
}
records, err := inv.BusRecords(ctx)
if err != nil {
t.Fatal(err)
}
if got := records.People["ada"]; len(got) != 1 || got[0] != "mesh-catalog.catalog_tools" {
t.Fatalf("ada may call %v", got)
}
users, err := broker.Users(records)
if err != nil {
t.Fatal(err)
}
var found bool
for _, u := range users {
if u.Username() != "person.ada" {
continue
}
found = true
perms, err := broker.PermissionsFor(u)
if err != nil {
t.Fatal(err)
}
if len(perms.Publish) != 1 || perms.Publish[0] != "mesh.mod.mesh-catalog.tool.catalog_tools" {
t.Errorf("ada may publish %v, which should be the one tool and nothing else", perms.Publish)
}
for _, s := range perms.Publish {
if strings.HasPrefix(s, "mesh.control") || strings.HasPrefix(s, "mesh.node") ||
strings.Contains(s, ".event.") {
t.Errorf("a person may publish %s — an event would let them claim a module said "+
"something, and control is not theirs", s)
}
}
if perms.AllowResponses {
t.Error("a person may answer a request, which is impersonating a module on a bus where " +
"anyone may serve a tool")
}
}
if !found {
t.Fatal("no bus user was derived for a recorded person")
}
}
// Stating what somebody may call replaces what was there. A list that could only grow is a permission
// nobody can take back.
func TestChangingWhatAPersonMayCallRemovesWhatIsNotNamed(t *testing.T) {
inv := ForTest(t)
ctx := context.Background()
if err := inv.RecordPerson(ctx, Person{Name: "ada", Invokes: []string{"a.one", "b.two"}}); err != nil {
t.Fatal(err)
}
if err := inv.RecordPerson(ctx, Person{Name: "ada", Invokes: []string{"a.one"}}); err != nil {
t.Fatal(err)
}
people, err := inv.People(ctx)
if err != nil {
t.Fatal(err)
}
if len(people) != 1 || len(people[0].Invokes) != 1 || people[0].Invokes[0] != "a.one" {
t.Fatalf("ada may call %v; the removed tool is still there", people)
}
}
// Somebody who may call nothing is refused: there is no reason for them to reach the mesh, and an
// empty list is more likely a mistake than an intention.
func TestSomebodyWhoMayCallNothingIsRefused(t *testing.T) {
inv := ForTest(t)
if err := inv.RecordPerson(context.Background(), Person{Name: "ada"}); err == nil {
t.Fatal("somebody who may call nothing was recorded")
}
}
// Forgetting somebody takes their credential with them. **Both, or it is not a revocation**: a
// person's row gone and their bus user left behind is a credential that still works and that nothing
// derives.
func TestForgettingAPersonTakesTheirCredential(t *testing.T) {
inv := ForTest(t)
ctx := context.Background()
if err := inv.RecordPerson(ctx, Person{Name: "ada", Invokes: []string{"a.one"}}); err != nil {
t.Fatal(err)
}
if _, err := inv.MintBusPassword(ctx, BusUser{Username: "person.ada", Kind: BusPerson}); err != nil {
t.Fatal(err)
}
if err := inv.ForgetPerson(ctx, "ada"); err != nil {
t.Fatal(err)
}
if _, known, err := inv.BusUserHash(ctx, "person.ada"); err != nil || known {
t.Fatalf("a forgotten person's credential still works: %v %v", known, err)
}
records, err := inv.BusRecords(ctx)
if err != nil {
t.Fatal(err)
}
if _, still := records.People["ada"]; still {
t.Fatal("a forgotten person is still composed into the bus")
}
}