diff --git a/docs/SESSIONS.md b/docs/SESSIONS.md index 99d51741..8f6d497d 100644 --- a/docs/SESSIONS.md +++ b/docs/SESSIONS.md @@ -488,3 +488,4 @@ are never rewritten or removed; corrections are new entries. 2026-10-05T02:58:34Z | Sage (T3 Claude Code, thread 1ef1e4f8) | slice 1 SR runbook, S5 rulings | docs/guides/slice-1-identities.md drafted for Darkwing's review (row 35); lead decision 56 accepts Dewey's Q1-Q5; Rocko started row 37 2026-10-05T03:03:02Z | Sage (T3 Claude Code, thread 1ef1e4f8) | schema v3a | Darkwing's v3a (29daa482) rerun matched on Node 26; lead decision 57; row 37 note 2026-10-05T03:10:32Z | Sage (T3 Claude Code, thread 1ef1e4f8) | row 35 SR round 2 | guide revised per Darkwing's round 1 (comment 26709): mint error path, jq strings, read -rs Gitea tokens, business-prefixed bot names; PRD 0.4 REQ-CRED-1 naming; lead decision 58 +2026-10-05T03:14:10Z | Sage (T3 Claude Code, thread 1ef1e4f8) | row 35 SR round 3 | Darkwing's round 2 (comment 26712): revoke before rm in rotation; optional items taken (.new then mv, one-role loop, api silent-failure note, botId placeholder) diff --git a/docs/guides/slice-1-identities.md b/docs/guides/slice-1-identities.md index 07e60163..f583d3dd 100644 --- a/docs/guides/slice-1-identities.md +++ b/docs/guides/slice-1-identities.md @@ -92,8 +92,9 @@ password, so this part uses the web UI. done ``` - `read` and `printf` are shell builtins, so the value never reaches - `ps` or the history. Don't use an editor, which can leave a swap or + For one role, as in a rotation, name only that role: `for r in coder; + do ...`. `read` and `printf` are shell builtins, so the value never + reaches `ps` or the history. Don't use an editor, which can leave a swap or backup copy behind. 5. Log out of each bot account. Record today's date as each Gitea token's `rotateBy` base. Section 5 has the rotation schedule. @@ -194,7 +195,9 @@ for r in pm cto coder reviewer sync; do done ``` -Note the five ids. Bot usernames must start with `bot-`, and this guide +Note the five ids. Each call prints one line. A missing line means the +call failed, because `api` uses `curl -sf`, which prints nothing on an +HTTP error. Bot usernames must start with `bot-`, and this guide uses `bot--` so two businesses on one instance don't collide. @@ -242,9 +245,10 @@ mint() { # mint ROLE BOT_ID SCOPES_FILE curl -s --fail-with-body -H @"$S/vikunja-owner.hdr" -H 'Content-Type: application/json' \ -X POST "$VK/api/v2/tokens" --data-binary @- -o "$resp" || { jq -c '{code, message}' "$resp"; rm -f "$resp"; return 1; } - jq -je '.token | strings' "$resp" > "$S/$r-vikunja.token" && + jq -je '.token | strings' "$resp" > "$S/$r-vikunja.token.new" && + mv "$S/$r-vikunja.token.new" "$S/$r-vikunja.token" && jq -c '{id, owner_id, expires_at, starts_tk: (.token | startswith("tk_"))}' "$resp" - rm -f "$resp" + rm -f "$resp" "$S/$r-vikunja.token.new" } mint pm "$S/scopes-pm.json" mint cto "$S/scopes-worker.json" @@ -257,8 +261,9 @@ Check that each line shows `starts_tk: true` and the `expires_at` you set. Vikunja accepts a past expiry without complaint, so read it. On an error, `mint` prints the response's `code` and `message`, which carry no token. Code 14002 means a scope name is wrong. Fix the scope file and -mint again. If the response has no `token` field, `mint` writes nothing -usable and stops; delete the empty file before you retry. +mint again. If the response has no `token` field, `mint` stops and +leaves any existing token file as it was, so a bad mint during rotation +doesn't empty the live file. ## 4. Check and clean up @@ -276,7 +281,8 @@ passing for all nine, closes row SR's gate. The business file (`~/.config/mosaic-dev/businesses/mosaic-stack.json`, row S1) references each file by absolute path, and never holds a value. One role's entry looks like this. Row S1's validator has the final -shape. +shape. `botId` 0 is a placeholder for the id you noted in section 3, and +S1 refuses 0. ```json "coder": { "definition": "coder", @@ -294,9 +300,10 @@ role. The stack never writes this file. - **Vikunja**, before `expires`: in a new shell, rerun section 0, the owner login in section 2, and the `api` and `mint` definitions in section 3. Mint a new token for the same bot, update `expires` in the - business file, restart the broker, and finish with section 4's - `rm -f`. Then revoke the old token: - `api -X DELETE "$VK/api/v2/tokens/"`. The broker refuses to + business file, and restart the broker. Revoke the old token while the + owner header still exists: + `api -X DELETE "$VK/api/v2/tokens/"`. Then finish with section + 4's `rm -f`, which deletes the header. The broker refuses to start with a token past its `expires`, and it treats any 401 as a refusal, never a retry. - **Gitea**, every 90 days or at once if a token may have leaked: log in