identity: a consumer's identity fits the tightest backend, via a slug (ADR 0054)
A module may declare a short `slug`; the mesh derives mesh_<node>_<slug|name> and refuses at assignment (naming the slug as the remedy) when it would still overflow — identityLimit is now 20, an S3 access key's, the tightest of the backends a login reaches (04-ISSUES/010). The slug rides the grant so the provider derives the same login the consumer does, even across nodes. CheckIdentity is now wired, in grantsFor. Also, the minted secret shrinks to 40 chars (30 bytes) from 43: an S3 secret key is 8-40, the same fit-the-tightest-backend rule on the credential's other half. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
@@ -54,7 +54,10 @@ func Make(consumerKey, providerKey string) (Sealed, error) {
|
||||
return Sealed{}, fmt.Errorf("both ends need a sealing key before a secret can be made")
|
||||
}
|
||||
|
||||
value := make([]byte, 32)
|
||||
// 30 bytes, not 32: base64url of 30 is exactly 40 characters, and 40 is the longest secret an
|
||||
// S3 access key accepts (8–40), the tightest of the backends a minted password reaches — the same
|
||||
// "fit the tightest backend" rule ADR 0054 sets for the login, on the secret. 240 bits is ample.
|
||||
value := make([]byte, 30)
|
||||
if _, err := rand.Read(value); err != nil {
|
||||
return Sealed{}, err
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user