A machine may bind its consumer #102

Merged
jschoubben merged 3 commits from fix/a-node-may-bind-its-consumer into main 2026-09-27 23:18:20 +00:00
2 changed files with 9 additions and 2 deletions
+8 -1
View File
@@ -244,7 +244,14 @@ func PermissionsFor(p Principal) (Permissions, error) {
case KindNode: case KindNode:
// A host publishes its own node's control traffic and subscribes its own declaration — // A host publishes its own node's control traffic and subscribes its own declaration —
// and nothing of any other node's. // and nothing of any other node's.
pub = []string{"mesh.control." + p.Node + ".>"} // And binding to its consumer, which asks the server about it (CONSUMER.INFO) — the one
// thing the host does that nothing granted. Found the first time a machine dialled a
// permissioned server: "this node cannot read its declarations" (2026-09-28). The ack and
// the inbox are granted below with every principal's.
pub = []string{
"mesh.control." + p.Node + ".>",
"$JS.API.CONSUMER.INFO.NODES." + p.Node,
}
sub = []string{"mesh.node." + p.Node + ".declare"} sub = []string{"mesh.node." + p.Node + ".declare"}
case KindModule: case KindModule:
+1 -1
View File
@@ -32,7 +32,7 @@ accounts {
subscribe: { allow: ["_INBOX.enrol.one.>"] } subscribe: { allow: ["_INBOX.enrol.one.>"] }
} } } }
{ user: "node.one", password: "$2a$11$nnnnnnnnnnnnnnnnnnnnnn", permissions: { { user: "node.one", password: "$2a$11$nnnnnnnnnnnnnnnnnnnnnn", permissions: {
publish: { allow: ["$JS.ACK.NODES.one.>", "mesh.control.one.>"] } publish: { allow: ["$JS.ACK.NODES.one.>", "$JS.API.CONSUMER.INFO.NODES.one", "mesh.control.one.>"] }
subscribe: { allow: ["_INBOX.node.one.>", "mesh.node.one.declare"] } subscribe: { allow: ["_INBOX.node.one.>", "mesh.node.one.declare"] }
} } } }
{ user: "one.telegram", password: "$2a$11$tttttttttttttttttttttt", permissions: { { user: "one.telegram", password: "$2a$11$tttttttttttttttttttttt", permissions: {