runtime: take node and module identity from the sealed credential

The mesh scoped the account to a node and module; the credential now carries
both, so the runtime names its queue and stamps its events as the mesh
authorised without a manifest interpolating a node the vocabulary has no token
for. Verified: with only MESH_BROKER_FILE, the audit logger consumed as
anchor/audit-logger.

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
2026-09-04 01:53:23 +02:00
parent 04a689e008
commit bf5339cec2
2 changed files with 10 additions and 2 deletions
+5 -2
View File
@@ -24,11 +24,14 @@ interface Reply {
error?: string; error?: string;
} }
/** A broker credential as the mesh delivers it (novox/hq ADR 0048): an amqps URL and the /** A broker credential as the mesh delivers it (novox/hq ADR 0048): an amqps URL, the fingerprint
* fingerprint of the certificate the broker must present. A plain string is a bootstrap URL. */ * of the certificate the broker must present, and the node and module the account is scoped to (so
* the runtime names its queue as the mesh did). A plain string is a bootstrap URL. */
export interface Credential { export interface Credential {
url: string; url: string;
fingerprint?: string; fingerprint?: string;
node?: string;
module?: string;
} }
/** /**
+5
View File
@@ -40,6 +40,11 @@ async function connectBroker(): Promise<Broker> {
console.error(`mesh-tools: ${file} carries no url — it is not a broker credential`); console.error(`mesh-tools: ${file} carries no url — it is not a broker credential`);
process.exit(1); process.exit(1);
} }
// The mesh scoped this account to a node and module; take the runtime's identity from the
// credential so its queue and the events it emits match what the mesh authorised, no matter
// what the environment says.
if (credential.node) process.env.MESH_NODE = credential.node;
if (credential.module) process.env.MESH_MODULE = credential.module;
return connectAmqp(credential, { assumeExchanges: true }); return connectAmqp(credential, { assumeExchanges: true });
} }
const url = process.env.MESH_BROKER_URL; const url = process.env.MESH_BROKER_URL;