A tool's grant covers the machine-addressed subject, and a credential names the seats its module claims (hq ADR 0159)
`invokes: [<module>.<tool>]` now grants `mesh.mod.<module>.tool.<tool>` and the same with the machine as its last token, which is how a call reaches one machine's instance. The broker credential the mesh writes carries `claims`: each seat the module claims, its scope, and the verbs the seat promises, so the runtime serves them on the seat's subjects; the holder's grant, composed from the holding, is what admits the subscription.
This commit is contained in:
@@ -660,7 +660,10 @@ func invokedSubjects(invokes []string) ([]string, error) {
|
||||
return nil, fmt.Errorf(
|
||||
"%q does not name a tool: one invokes <module>.<tool>, seat:<seat>.<verb>, or * for every one", t)
|
||||
}
|
||||
out = append(out, "mesh.mod."+module+".tool."+tool)
|
||||
// Both ways a module's tool is addressed (novox/hq ADR 0159): to whichever instance
|
||||
// answers, and to the instance on one machine, which is the same subject with the machine
|
||||
// as its last token.
|
||||
out = append(out, "mesh.mod."+module+".tool."+tool, "mesh.mod."+module+".tool."+tool+".*")
|
||||
}
|
||||
return out, nil
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user