The command API, which refuses everything until it knows who is asking

novox/hq ADR 0035: one implementation, several surfaces, and a surface
holds no decisions. The act of assigning — including that an assignment
which does not resolve is kept and still refused — moved into acts.go,
and the command line now calls it too. Two surfaces, one refusal, in the
same words.

It will not run without --issuer, and refuses at start rather than per
request so it is found by whoever ran it rather than by whoever finds
it. There is no flag that removes the check.

The authenticator is honest about what it is: no token can be verified
until an identity provider exists, because that is a module and none is
running, so every request is refused and told that the command line
still works. A surface that functioned without authentication would be
one somebody left running — and the board this stands behind is
published on a public name.

Four refusals, four tests. The last one first asserted "not 200", which
passed because a request with no database fails at the store anyway — it
proved nothing about whether the input was checked. It now asserts the
specific refusal, and bites when the check is removed.
This commit is contained in:
2026-09-01 01:55:56 +02:00
parent 8cf1ecf6a5
commit d0511ee3fe
10 changed files with 572 additions and 15 deletions
+8 -15
View File
@@ -208,28 +208,21 @@ func assignCommand(ctx context.Context, verb string, args []string) error {
return err
}
defer open.Close()
inv := open.inventory
// The act itself is in acts.go, so the command API refuses exactly what this refuses
// (novox/hq ADR 0035). What differs between the surfaces is how the answer is printed.
act := assign
if verb == "unassign" {
if err := inv.Unassign(ctx, args[0], args[1]); err != nil {
return err
}
fmt.Printf("%s no longer runs %s — run `push %s` to make it so\n", args[0], args[1], args[0])
return nil
act = unassign
}
if err := inv.Assign(ctx, args[0], args[1]); err != nil {
return err
said, err := act(ctx, open, args[0], args[1])
if said != "" {
fmt.Println(said)
}
fmt.Printf("%s is assigned %s\n", args[0], args[1])
// Resolved immediately, because an assignment that cannot be applied should be said now
// rather than at the next push. The assignment is kept either way: it is what a person meant,
// and the refusal is about the set rather than about this one.
if _, _, err := planFor(ctx, open, args[0]); err != nil {
if err != nil {
fmt.Println()
return err
}
fmt.Printf(" run `push %s` to send it\n", args[0])
return nil
}