runtime: take node and module identity from the sealed credential
The mesh scoped the account to a node and module; the credential now carries both, so the runtime names its queue and stamps its events as the mesh authorised without a manifest interpolating a node the vocabulary has no token for. Verified: with only MESH_BROKER_FILE, the audit logger consumed as anchor/audit-logger. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
@@ -40,6 +40,11 @@ async function connectBroker(): Promise<Broker> {
|
||||
console.error(`mesh-tools: ${file} carries no url — it is not a broker credential`);
|
||||
process.exit(1);
|
||||
}
|
||||
// The mesh scoped this account to a node and module; take the runtime's identity from the
|
||||
// credential so its queue and the events it emits match what the mesh authorised, no matter
|
||||
// what the environment says.
|
||||
if (credential.node) process.env.MESH_NODE = credential.node;
|
||||
if (credential.module) process.env.MESH_MODULE = credential.module;
|
||||
return connectAmqp(credential, { assumeExchanges: true });
|
||||
}
|
||||
const url = process.env.MESH_BROKER_URL;
|
||||
|
||||
Reference in New Issue
Block a user