identity: a consumer's identity fits the tightest backend, via a slug (ADR 0054)

A module may declare a short `slug`; the mesh derives mesh_<node>_<slug|name> and
refuses at assignment (naming the slug as the remedy) when it would still overflow —
identityLimit is now 20, an S3 access key's, the tightest of the backends a login
reaches (04-ISSUES/010). The slug rides the grant so the provider derives the same
login the consumer does, even across nodes. CheckIdentity is now wired, in grantsFor.

Also, the minted secret shrinks to 40 chars (30 bytes) from 43: an S3 secret key is
8-40, the same fit-the-tightest-backend rule on the credential's other half.

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
2026-09-05 02:51:39 +02:00
parent b1bf1659d9
commit 9b7ba2e20c
7 changed files with 120 additions and 17 deletions
+4 -1
View File
@@ -54,7 +54,10 @@ func Make(consumerKey, providerKey string) (Sealed, error) {
return Sealed{}, fmt.Errorf("both ends need a sealing key before a secret can be made")
}
value := make([]byte, 32)
// 30 bytes, not 32: base64url of 30 is exactly 40 characters, and 40 is the longest secret an
// S3 access key accepts (8–40), the tightest of the backends a minted password reaches — the same
// "fit the tightest backend" rule ADR 0054 sets for the login, on the secret. 240 bits is ample.
value := make([]byte, 30)
if _, err := rand.Read(value); err != nil {
return Sealed{}, err
}