identity: a consumer's identity fits the tightest backend, via a slug (ADR 0054)
A module may declare a short `slug`; the mesh derives mesh_<node>_<slug|name> and refuses at assignment (naming the slug as the remedy) when it would still overflow — identityLimit is now 20, an S3 access key's, the tightest of the backends a login reaches (04-ISSUES/010). The slug rides the grant so the provider derives the same login the consumer does, even across nodes. CheckIdentity is now wired, in grantsFor. Also, the minted secret shrinks to 40 chars (30 bytes) from 43: an S3 secret key is 8-40, the same fit-the-tightest-backend rule on the credential's other half. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
@@ -59,6 +59,10 @@ type Grant struct {
|
||||
// Values are what that module contributed — the name it wants, and anything else the
|
||||
// provision's own vocabulary defines.
|
||||
Values map[string]any
|
||||
// Slug is the consumer module's identity slug, if it declared one — carried on the grant so the
|
||||
// provider side derives the same login the consumer does, even across nodes where the consumer's
|
||||
// manifest is not in view (novox/hq ADR 0054). Empty means "use the module name".
|
||||
Slug string
|
||||
// At is where the consuming machine is on the private network, empty if it is not on one.
|
||||
//
|
||||
// Passed in with the grant because it is a fact about another machine, and resolution answers
|
||||
@@ -293,7 +297,7 @@ func (r Resolution) Declaration(with Rendering) ([]map[string]any, error) {
|
||||
}
|
||||
found = here
|
||||
}
|
||||
file, err := boundFile(*found, m.Binds[to], ConsumerIdentity(r.Node, m.Module))
|
||||
file, err := boundFile(*found, m.Binds[to], ConsumerIdentity(r.Node, IdentitySource(m.Slug, m.Module)))
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
@@ -490,7 +494,7 @@ func (r Resolution) contributions(settings SettingsBy, grants []Grant,
|
||||
}
|
||||
out[g.Provision] = append(out[g.Provision], Contribution{
|
||||
From: g.From, Node: g.Consumer, At: g.At, Values: g.Values,
|
||||
As: ConsumerIdentity(g.Consumer, g.From),
|
||||
As: ConsumerIdentity(g.Consumer, IdentitySource(g.Slug, g.From)),
|
||||
Secret: grantPath(directories[g.Provision], g.Consumer, g.From),
|
||||
})
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user