The give verb opened the desk's hidden prompt for a module's own secret, with the desk named. Now the secret-ask verb (secret ask <node> <module> <name> [--at <desk>]) opens the same prompt from anywhere on the mesh, with the desk the module's machine unless named, and give composes the same line. Every ask is recorded in the store before the prompt opens (migration 0091): one open ask per secret, three an hour, so an agent cannot keep a prompt in front of the operator. The prompt names who asked, from the bus's word on the caller cut to a name's characters, never an argument of the call. The value stays typed at the desk, sealed to the one call and then to the module's machine, never in an argument, a log or an event; a secret the mesh makes itself and a trusted party's secret are refused as before.
19 lines
922 B
SQL
19 lines
922 B
SQL
-- A module's own secret asked for at a desk (novox/hq ADR 0277).
|
|
--
|
|
-- Every ask for a module's own secret at a desk: who asked, for which secret of which module on which
|
|
-- machine, at which desk, and how it ended. Read before a prompt opens, so that one open ask per secret and
|
|
-- few per hour hold: an agent that keeps a prompt in front of the operator until they type is refused.
|
|
create table secret_ask (
|
|
id bigserial primary key,
|
|
node uuid not null references node(id) on delete cascade,
|
|
module text not null,
|
|
name text not null,
|
|
asked_by text not null,
|
|
desk text not null,
|
|
opened_at timestamptz not null default now(),
|
|
ended_at timestamptz,
|
|
-- given · dismissed · timed-out · empty · refused · failed
|
|
outcome text
|
|
);
|
|
create index secret_ask_by_secret on secret_ask (node, module, name, opened_at desc);
|