anthropic-bed: prove the host unseals the refresh token, no node-key stub
The bed follows the reworked flow: the manager module seals the refresh token to the node's
PUBLIC key, the HOST unseals it and mounts the cleartext at the manager's bound path, and the
refresh reads that cleartext -- no fake node key pair is mounted any more, the host uses its
own real sealing key.
- the manager is a model-access holder deployed first, so its bound facts (carrying the node
public key) are delivered; the consumer is added only once an access token exists to seal.
- adopt reads the node public key from the bound facts; the test asserts the host mounts the
cleartext refresh token for the manager, and that it reaches nowhere on the consuming node.
- the refresh_grant assertion reads { sealed, manager_key }.
Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
@@ -1,13 +1,15 @@
|
||||
# One machine that becomes a mesh, then plays out the whole model-access refreshable-grant flow for
|
||||
# Anthropic (novox/hq ADR 0050, Phase C) with the vendor's OAuth endpoint STUBBED — no real Anthropic
|
||||
# is reached. The bed proves the one property the carve-out rests on: the refresh token is opened only
|
||||
# on the manager node, the control plane seals and delivers only the ACCESS token, and a consuming
|
||||
# node writes an access-token-only credential and is never given a refresh token.
|
||||
# Anthropic (novox/hq ADR 0050) with the vendor's OAuth endpoint STUBBED — no real Anthropic is
|
||||
# reached. The bed proves the one property the carve-out rests on: the refresh token is delivered ONLY
|
||||
# to the manager node — as an ordinary sealed credential the HOST unseals — the control plane seals and
|
||||
# delivers only the ACCESS token, and a consuming node writes an access-token-only credential and is
|
||||
# never given a refresh token.
|
||||
#
|
||||
# The flow the test drives (OAuth stubbed, so it is the FLOW that is proven, not the vendor):
|
||||
# manager opens the at-rest envelope on the manager node -> calls the stub token endpoint ->
|
||||
# submits back only { access token, re-sealed refresh envelope } -> mesh-control seals the access
|
||||
# token per holder -> the consumer runtime writes ~/.claude/.credentials.json, access-token-only.
|
||||
# the manager module seals the refresh token to the node's PUBLIC key -> the host unseals it and
|
||||
# mounts the cleartext at the manager's bound path -> the manager calls the stub token endpoint ->
|
||||
# submits back only { access token, re-sealed box } -> mesh-control seals the access token per
|
||||
# consumer holder -> the consumer runtime writes ~/.claude/.credentials.json, access-token-only.
|
||||
#
|
||||
# MESH_LAB_HOST_BINARY=.../mesh-host MESH_LAB_BUNDLE=.../examples/substrate-first-node.lock
|
||||
# Build BOTH runtime images into the local daemon first (the scenario stocks and serves them by
|
||||
|
||||
Reference in New Issue
Block a user