The runtime hears on its own inbox

Every user's inbox is private to it and the grant names it; a reply space the client invented was
refused, and with it every pull for the next message and every answer to a tool call.
This commit is contained in:
2026-09-28 04:30:22 +02:00
parent 46b56d53a6
commit d703cebff4
+4
View File
@@ -85,6 +85,10 @@ export async function connectNats(
pass: cred.password, pass: cred.password,
name: `${cred.node ?? "?"}.${self}`, name: `${cred.node ?? "?"}.${self}`,
tls: cred.fingerprint ? await pinnedTls(cred.url, cred.fingerprint) : undefined, tls: cred.fingerprint ? await pinnedTls(cred.url, cred.fingerprint) : undefined,
// Its own inbox, not a random one: every user's inbox is private to it (design 25 §4), and the
// grant names `_INBOX.<user>.>` — a reply space the client invented would be refused, and with
// it every pull for the next message and every answer to a tool call.
inboxPrefix: cred.user ? `_INBOX.${cred.user}` : undefined,
// Reconnect forever: the bus being restarted is an upgrade, not a reason for every module on // Reconnect forever: the bus being restarted is an upgrade, not a reason for every module on
// the mesh to exit. `close()` stays the only thing that ends the connection. // the mesh to exit. `close()` stays the only thing that ends the connection.
maxReconnectAttempts: -1, maxReconnectAttempts: -1,