A tool's grant covers the machine-addressed subject, and a credential names the seats its module claims (hq ADR 0159)
`invokes: [<module>.<tool>]` now grants `mesh.mod.<module>.tool.<tool>` and the same with the machine as its last token, which is how a call reaches one machine's instance. The broker credential the mesh writes carries `claims`: each seat the module claims, its scope, and the verbs the seat promises, so the runtime serves them on the seat's subjects; the holder's grant, composed from the holding, is what admits the subscription.
This commit is contained in:
@@ -91,3 +91,16 @@ func TestADeclaredInvokeReachesTheComposedUser(t *testing.T) {
|
||||
}
|
||||
has(t, perms.Publish, "mesh.mod.*.tool.>")
|
||||
}
|
||||
|
||||
// A module's tool is addressed two ways (novox/hq ADR 0159): to whichever instance answers, and to
|
||||
// the instance on one machine. A grant for the tool covers both and nothing wider.
|
||||
func TestInvokingAToolMayAddressTheMachineToo(t *testing.T) {
|
||||
got, err := invokedSubjects([]string{"postgres.postgres_query"})
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
want := []string{"mesh.mod.postgres.tool.postgres_query", "mesh.mod.postgres.tool.postgres_query.*"}
|
||||
if len(got) != 2 || got[0] != want[0] || got[1] != want[1] {
|
||||
t.Fatalf("the grant is %v, want %v", got, want)
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user