Reads MESH_BROKER_FILE — the sealed {url,fingerprint,node,module} the mesh delivered — and connects over amqps pinned to exactly that certificate, two-phase (fetch cert, verify fingerprint, then trust only it) because Node's checkServerIdentity doesn't run under rejectUnauthorized:false, so a naive connect-then-check would leak the password to an impostor.
A scoped module (assumeExchanges) never declares the exchanges nor its dead-lettered queue (its account may not) — the mesh pre-declared them, so it passively checkQueues, binds, consumes.
The RPC reply queue is lazy, and a module registering no tools serves none — a pure-events consumer touches only what its account allows.
Identity (node/module) comes from the credential, so no manifest need interpolate a node.
Verified end-to-end against a real broker as the scoped account, and in the lab (assigned audit-logger, 1/1).
Stacked on events/adr-0047-alignment (the ADR 0047 wire alignment, PR #1).
Implements ADR 0048's runtime half.
- Reads `MESH_BROKER_FILE` — the sealed `{url,fingerprint,node,module}` the mesh delivered — and connects over **amqps pinned to exactly that certificate**, two-phase (fetch cert, verify fingerprint, then trust only it) because Node's `checkServerIdentity` doesn't run under `rejectUnauthorized:false`, so a naive connect-then-check would leak the password to an impostor.
- A scoped module (`assumeExchanges`) never declares the exchanges nor its dead-lettered queue (its account may not) — the mesh pre-declared them, so it passively `checkQueue`s, binds, consumes.
- The RPC reply queue is lazy, and a module registering no tools serves none — a pure-events consumer touches only what its account allows.
- Identity (node/module) comes from the credential, so no manifest need interpolate a node.
Verified end-to-end against a real broker as the scoped account, and in the lab (assigned audit-logger, 1/1).
Stacked on `events/adr-0047-alignment` (the ADR 0047 wire alignment, PR #1).
https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
A module reads its broker credential from MESH_BROKER_FILE — the sealed
{url,fingerprint} the mesh delivered — and connects over amqps pinned to
exactly that certificate. The pin is two-phase (fetch cert, verify, then
trust only it), because Node's checkServerIdentity does not run under
rejectUnauthorized:false, so a naive connect-then-check would already have
sent the password to whoever answered.
A scoped module (assumeExchanges) never declares the exchanges (its account
may not) nor its own queue with a dead-letter (the broker refuses that to a
non-administrator) — the mesh pre-declared the queue, so it passively checks
it, binds and consumes. The RPC reply queue is lazy, and a module that
registered no tools serves none: a pure-events consumer touches only what its
account allows.
Verified end-to-end against a real broker as the scoped account: the audit
logger consumes # and records events, over an account that is not the
broker's own.
Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
The mesh scoped the account to a node and module; the credential now carries
both, so the runtime names its queue and stamps its events as the mesh
authorised without a manifest interpolating a node the vocabulary has no token
for. Verified: with only MESH_BROKER_FILE, the audit logger consumed as
anchor/audit-logger.
Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Implements ADR 0048's runtime half.
MESH_BROKER_FILE— the sealed{url,fingerprint,node,module}the mesh delivered — and connects over amqps pinned to exactly that certificate, two-phase (fetch cert, verify fingerprint, then trust only it) because Node'scheckServerIdentitydoesn't run underrejectUnauthorized:false, so a naive connect-then-check would leak the password to an impostor.assumeExchanges) never declares the exchanges nor its dead-lettered queue (its account may not) — the mesh pre-declared them, so it passivelycheckQueues, binds, consumes.Verified end-to-end against a real broker as the scoped account, and in the lab (assigned audit-logger, 1/1).
Stacked on
events/adr-0047-alignment(the ADR 0047 wire alignment, PR #1).https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
A module reads its broker credential from MESH_BROKER_FILE — the sealed {url,fingerprint} the mesh delivered — and connects over amqps pinned to exactly that certificate. The pin is two-phase (fetch cert, verify, then trust only it), because Node's checkServerIdentity does not run under rejectUnauthorized:false, so a naive connect-then-check would already have sent the password to whoever answered. A scoped module (assumeExchanges) never declares the exchanges (its account may not) nor its own queue with a dead-letter (the broker refuses that to a non-administrator) — the mesh pre-declared the queue, so it passively checks it, binds and consumes. The RPC reply queue is lazy, and a module that registered no tools serves none: a pure-events consumer touches only what its account allows. Verified end-to-end against a real broker as the scoped account: the audit logger consumes # and records events, over an account that is not the broker's own. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzFPull request closed