Design 25 §6 says an enrolling node subscribes the inbox its own token derives. It had none: `sub` was empty, so a node would publish its request and wait out its timeout against a mesh that had answered — the handshake could not have completed. And there was one shared `enrolment` user, which cannot carry that inbox at all: a permission belongs to a user, so an inbox per token means a user per token. Named after the node, which **is** the token's id — a token is issued for a node record, the mesh holds one live claim per record, and the node's name is the one identifier both sides have before anything else is agreed. It is also exactly what the other transport does, where the account is named after the node and the secret is its password. A nameless enrolment user is now refused rather than composed into `_INBOX.enrol..>`: an empty subject token, and worse, one every nameless enrolment user would share — which is one machine able to read the credentials sealed to another. Still to wire: something that composes one of these per live token. Nothing composes enrolment users yet, on either bus — on the old one the account is made imperatively through the broker's management API when a token is issued, and here there is no management API, so issuing a token has to recompose the server's configuration. That is the remaining half of enrolment on the new bus.
51 lines
2.3 KiB
Plaintext
51 lines
2.3 KiB
Plaintext
# Composed by the mesh controller. Do not edit: the next composition overwrites it.
|
|
# Accounts and permissions are derived from what each module declares and nothing
|
|
# else (novox/hq ADR 0043, design 29 §2).
|
|
|
|
port: 4222
|
|
http: 127.0.0.1:8222
|
|
|
|
tls {
|
|
cert_file: "/tls/tls.crt"
|
|
key_file: "/tls/tls.key"
|
|
ca_file: "/tls/ca.crt"
|
|
verify: true
|
|
}
|
|
|
|
jetstream {
|
|
store_dir: "/data"
|
|
}
|
|
|
|
accounts {
|
|
MESH {
|
|
users = [
|
|
{ user: "controller", password: "$2a$11$cccccccccccccccccccccc", permissions: {
|
|
publish: { allow: ["$JS.ACK.CONTROL.controller.>", "$JS.ACK.EVENTS.controller.>", "$JS.API.>", "mesh.build.>", "mesh.control.>", "mesh.node.>"] }
|
|
subscribe: { allow: ["$JS.API.>", "_INBOX.controller.>", "mesh.build.>", "mesh.control.>", "mesh.mod.mesh-catalog.event.module.mesh-catalog.catching-up", "mesh.mod.mesh-catalog.event.module.mesh-catalog.upgraded"] }
|
|
allow_responses: { max: 1, ttl: "1m" }
|
|
} }
|
|
{ user: "enrol.one", password: "$2a$11$eeeeeeeeeeeeeeeeeeeeee", permissions: {
|
|
publish: { allow: ["mesh.control.enrol"] }
|
|
subscribe: { allow: ["_INBOX.enrol.one.>"] }
|
|
} }
|
|
{ user: "node.one", password: "$2a$11$nnnnnnnnnnnnnnnnnnnnnn", permissions: {
|
|
publish: { allow: ["$JS.ACK.NODES.one.>", "mesh.control.one.>"] }
|
|
subscribe: { allow: ["_INBOX.node.one.>", "mesh.node.one.declare"] }
|
|
} }
|
|
{ user: "one.telegram", password: "$2a$11$tttttttttttttttttttttt", permissions: {
|
|
publish: { allow: ["$JS.ACK.EVENTS.one_telegram.>", "mesh.seat.telegram-sender.event.delivered", "mesh.seat.telegram-sender.event.failed"] }
|
|
subscribe: { allow: ["_INBOX.one.telegram.>", "mesh.mod.telegram.tool.status", "mesh.seat.telegram-sender.accept.send"] }
|
|
allow_responses: { max: 1, ttl: "1m" }
|
|
} }
|
|
{ user: "two.audit", password: "$2a$11$aaaaaaaaaaaaaaaaaaaaaa", permissions: {
|
|
publish: { allow: ["$JS.ACK.EVENTS.two_audit.>"] }
|
|
subscribe: { allow: ["_INBOX.two.audit.>", "mesh.mod.shop.event.order.placed"] }
|
|
} }
|
|
{ user: "two.shop", password: "$2a$11$ssssssssssssssssssssss", permissions: {
|
|
publish: { allow: ["$JS.ACK.EVENTS.two_shop.>", "mesh.mod.shop.event.order.placed", "mesh.seat.telegram-sender.accept.send"] }
|
|
subscribe: { allow: ["_INBOX.two.shop.>"] }
|
|
} }
|
|
]
|
|
}
|
|
}
|