diff --git a/internal/broker/nats.go b/internal/broker/nats.go index 3c18343..00830c7 100644 --- a/internal/broker/nats.go +++ b/internal/broker/nats.go @@ -244,7 +244,14 @@ func PermissionsFor(p Principal) (Permissions, error) { case KindNode: // A host publishes its own node's control traffic and subscribes its own declaration — // and nothing of any other node's. - pub = []string{"mesh.control." + p.Node + ".>"} + // And binding to its consumer, which asks the server about it (CONSUMER.INFO) — the one + // thing the host does that nothing granted. Found the first time a machine dialled a + // permissioned server: "this node cannot read its declarations" (2026-09-28). The ack and + // the inbox are granted below with every principal's. + pub = []string{ + "mesh.control." + p.Node + ".>", + "$JS.API.CONSUMER.INFO.NODES." + p.Node, + } sub = []string{"mesh.node." + p.Node + ".declare"} case KindModule: diff --git a/internal/broker/testdata/composed.conf b/internal/broker/testdata/composed.conf index f64b2e8..d764044 100644 --- a/internal/broker/testdata/composed.conf +++ b/internal/broker/testdata/composed.conf @@ -32,7 +32,7 @@ accounts { subscribe: { allow: ["_INBOX.enrol.one.>"] } } } { user: "node.one", password: "$2a$11$nnnnnnnnnnnnnnnnnnnnnn", permissions: { - publish: { allow: ["$JS.ACK.NODES.one.>", "mesh.control.one.>"] } + publish: { allow: ["$JS.ACK.NODES.one.>", "$JS.API.CONSUMER.INFO.NODES.one", "mesh.control.one.>"] } subscribe: { allow: ["_INBOX.node.one.>", "mesh.node.one.declare"] } } } { user: "one.telegram", password: "$2a$11$tttttttttttttttttttttt", permissions: {