novox/hq ADR 0159, issue 182. invokes: [<module>.<tool>] grants the plain subject and the same with the machine as its last token. The broker credential the mesh writes gains claims: each seat the module claims, its scope, and the verbs the seat promises, so the runtime (mesh-tools, same branch name) serves them on the seat's subjects; the holder's grant, composed from the holding, admits the subscription. Test: the grant covers both subjects. make check was green before the gofmt-only follow-up commit; no behaviour changed by it.
Merge first, before mesh-tools: the grant must exist before any runtime serves the second subject.
novox/hq ADR 0159, issue 182. `invokes: [<module>.<tool>]` grants the plain subject and the same with the machine as its last token. The broker credential the mesh writes gains `claims`: each seat the module claims, its scope, and the verbs the seat promises, so the runtime (mesh-tools, same branch name) serves them on the seat's subjects; the holder's grant, composed from the holding, admits the subscription. Test: the grant covers both subjects. `make check` was green before the gofmt-only follow-up commit; no behaviour changed by it.
**Merge first**, before mesh-tools: the grant must exist before any runtime serves the second subject.
`invokes: [<module>.<tool>]` now grants `mesh.mod.<module>.tool.<tool>` and the same with the
machine as its last token, which is how a call reaches one machine's instance. The broker
credential the mesh writes carries `claims`: each seat the module claims, its scope, and the verbs
the seat promises, so the runtime serves them on the seat's subjects; the holder's grant, composed
from the holding, is what admits the subscription.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
novox/hq ADR 0159, issue 182.
invokes: [<module>.<tool>]grants the plain subject and the same with the machine as its last token. The broker credential the mesh writes gainsclaims: each seat the module claims, its scope, and the verbs the seat promises, so the runtime (mesh-tools, same branch name) serves them on the seat's subjects; the holder's grant, composed from the holding, admits the subscription. Test: the grant covers both subjects.make checkwas green before the gofmt-only follow-up commit; no behaviour changed by it.Merge first, before mesh-tools: the grant must exist before any runtime serves the second subject.