The view reads directly and makes no consumer: a consumer's deliver subject publishes anywhere
Review of the view (research 036): granted CONSUMER.CREATE on the bucket's stream, the view made a push consumer delivering to mesh.mod.mesh-issues.event.opened, and a module subscribed there received the bucket's entry as the tracker's event — measured on 2.11.17. The server does not hold a deliver subject to its creator's permissions, so a consumer grant is a publish to any subject. The view now binds and reads directly, nothing else: STREAM.INFO, DIRECT.GET by key, and the batch DIRECT.GET (multi_last) that lists every key's newest value into its inbox. No watch: the page re-reads the key a tracker event names (every event carries the number). The live test lists with the batch, follows a moved event to the re-read, and is refused the consumer and the watch with nothing reaching the event subject; the mutation (CONSUMER.CREATE back) fails three tests. The credential says how to read, and that the step making it work is the next `bus upgrade` while a new bus build waits, not a push.
This commit is contained in:
+1
-1
@@ -57,7 +57,7 @@ accounts {
|
||||
allow_responses: { max: 1, ttl: "1m" }
|
||||
} }
|
||||
{ user: "view", password: "$2a$11$vvvvvvvvvvvvvvvvvvvvvv", permissions: {
|
||||
publish: { allow: ["$JS.API.CONSUMER.CREATE.KV_mesh-issues_issues.>", "$JS.API.CONSUMER.DELETE.KV_mesh-issues_issues.>", "$JS.API.CONSUMER.INFO.KV_mesh-issues_issues.>", "$JS.API.DIRECT.GET.KV_mesh-issues_issues.>", "$JS.API.STREAM.INFO.KV_mesh-issues_issues", "$JS.FC.KV_mesh-issues_issues.>"] }
|
||||
publish: { allow: ["$JS.API.DIRECT.GET.KV_mesh-issues_issues", "$JS.API.DIRECT.GET.KV_mesh-issues_issues.>", "$JS.API.STREAM.INFO.KV_mesh-issues_issues"] }
|
||||
subscribe: { allow: ["_INBOX.view.>", "mesh.mod.mesh-delivery.event.group", "mesh.mod.mesh-delivery.event.transition", "mesh.mod.mesh-issues.event.linked", "mesh.mod.mesh-issues.event.moved", "mesh.mod.mesh-issues.event.noted", "mesh.mod.mesh-issues.event.opened", "mesh.seat.mesh-controller.event.condition-changed", "mesh.seat.mesh-controller.event.condition-cleared", "mesh.seat.mesh-controller.event.condition-raised", "mesh.seat.mesh-controller.event.plan-moved"] }
|
||||
} }
|
||||
]
|
||||
|
||||
Reference in New Issue
Block a user