diff --git a/internal/broker/nats.go b/internal/broker/nats.go index 3c18343..c2ee807 100644 --- a/internal/broker/nats.go +++ b/internal/broker/nats.go @@ -244,8 +244,16 @@ func PermissionsFor(p Principal) (Permissions, error) { case KindNode: // A host publishes its own node's control traffic and subscribes its own declaration — // and nothing of any other node's. - pub = []string{"mesh.control." + p.Node + ".>"} - sub = []string{"mesh.node." + p.Node + ".declare"} + // And what the host does with its consumer, nothing more: binding to it asks the server + // about it (CONSUMER.INFO) and hears the answer on its own inbox; hearing a declaration + // acknowledges it. Found the first time a machine dialled a permissioned server: refused + // for both, and "this node cannot read its declarations" (2026-09-28). + pub = []string{ + "mesh.control." + p.Node + ".>", + "$JS.API.CONSUMER.INFO.NODES." + p.Node, + "$JS.ACK.NODES." + p.Node + ".>", + } + sub = []string{"mesh.node." + p.Node + ".declare", p.inbox()} case KindModule: // 1. Its own namespace: it publishes its events there and serves its tools there. Nothing