From bf5339cec2cd1ccd2048e61b56e902c94844ceff Mon Sep 17 00:00:00 2001 From: jochen Date: Fri, 4 Sep 2026 01:53:23 +0200 Subject: [PATCH] runtime: take node and module identity from the sealed credential The mesh scoped the account to a node and module; the credential now carries both, so the runtime names its queue and stamps its events as the mesh authorised without a manifest interpolating a node the vocabulary has no token for. Verified: with only MESH_BROKER_FILE, the audit logger consumed as anchor/audit-logger. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF --- src/broker-amqp.ts | 7 +++++-- src/main.ts | 5 +++++ 2 files changed, 10 insertions(+), 2 deletions(-) diff --git a/src/broker-amqp.ts b/src/broker-amqp.ts index ef3c183..78c57dd 100644 --- a/src/broker-amqp.ts +++ b/src/broker-amqp.ts @@ -24,11 +24,14 @@ interface Reply { error?: string; } -/** A broker credential as the mesh delivers it (novox/hq ADR 0048): an amqps URL and the - * fingerprint of the certificate the broker must present. A plain string is a bootstrap URL. */ +/** A broker credential as the mesh delivers it (novox/hq ADR 0048): an amqps URL, the fingerprint + * of the certificate the broker must present, and the node and module the account is scoped to (so + * the runtime names its queue as the mesh did). A plain string is a bootstrap URL. */ export interface Credential { url: string; fingerprint?: string; + node?: string; + module?: string; } /** diff --git a/src/main.ts b/src/main.ts index 1e98b6d..bea038a 100644 --- a/src/main.ts +++ b/src/main.ts @@ -40,6 +40,11 @@ async function connectBroker(): Promise { console.error(`mesh-tools: ${file} carries no url — it is not a broker credential`); process.exit(1); } + // The mesh scoped this account to a node and module; take the runtime's identity from the + // credential so its queue and the events it emits match what the mesh authorised, no matter + // what the environment says. + if (credential.node) process.env.MESH_NODE = credential.node; + if (credential.module) process.env.MESH_MODULE = credential.module; return connectAmqp(credential, { assumeExchanges: true }); } const url = process.env.MESH_BROKER_URL;