runtime: take node and module identity from the sealed credential
The mesh scoped the account to a node and module; the credential now carries both, so the runtime names its queue and stamps its events as the mesh authorised without a manifest interpolating a node the vocabulary has no token for. Verified: with only MESH_BROKER_FILE, the audit logger consumed as anchor/audit-logger. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
+5
-2
@@ -24,11 +24,14 @@ interface Reply {
|
||||
error?: string;
|
||||
}
|
||||
|
||||
/** A broker credential as the mesh delivers it (novox/hq ADR 0048): an amqps URL and the
|
||||
* fingerprint of the certificate the broker must present. A plain string is a bootstrap URL. */
|
||||
/** A broker credential as the mesh delivers it (novox/hq ADR 0048): an amqps URL, the fingerprint
|
||||
* of the certificate the broker must present, and the node and module the account is scoped to (so
|
||||
* the runtime names its queue as the mesh did). A plain string is a bootstrap URL. */
|
||||
export interface Credential {
|
||||
url: string;
|
||||
fingerprint?: string;
|
||||
node?: string;
|
||||
module?: string;
|
||||
}
|
||||
|
||||
/**
|
||||
|
||||
Reference in New Issue
Block a user