Issue 339 made every trusted setting the controller's terminal's alone, so an agent could only hand the operator a line to type at the control node. Now anyone the bus admits may PROPOSE a layer: settings propose keeps the proposal in the controller's own asks (the asked bucket, which the controller alone writes), judged as settings set judges, and asks the operator on the operator channel at the level approve with every key, its exact new value (in its shape where a path or an address may not leave the mesh), the was of a changed key, the removed keys and the layer's fingerprint. The serving controller sets the layer on the warrant alone: once, for the ask it holds, only when the record's values still digest to what the option bound and the layer is still the one shown, with the terminal's judgement and history, and keeps who approved it beside the layer, which settings says back (migration 0090). Decline, expiry, a cancel, a replacement or the router's refusal discard it; nothing is asked when no router, no grant or no channel can carry it. settings proposals lists them. The push afterwards is a separate act.
9 lines
557 B
SQL
9 lines
557 B
SQL
-- A trusted setting set on the operator's warrant (novox/hq ADR 0277): a layer says who set it.
|
|
--
|
|
-- Until now a layer carried only when it was set: a layer the operator approved on their phone and one typed
|
|
-- at the controller's terminal looked the same, and `settings` could not say "approved by the operator via
|
|
-- telegram". Kept with the layer, and with the history copy of it, so the provenance of a replaced layer is
|
|
-- read back beside its values.
|
|
alter table settings add column set_by text;
|
|
alter table settings_history add column set_by text;
|