feat(mosaic): complete credential lifecycle and fail closed
This commit is contained in:
@@ -534,12 +534,21 @@ get_gitea_token() {
|
||||
# would post PRs/issues/reviews under the WRONG agent (e.g. rev2's review attributed
|
||||
# to coder3), corrupting Gate-16 author≠reviewer separation. Hard-stop instead so the
|
||||
# caller aborts loudly rather than acting as the wrong identity.
|
||||
echo "Error: git identity '$_ident' requested (via $_ident_src) for host '$host', but no per-slot token at $_idtok." >&2
|
||||
echo " Refusing to borrow another slot's token. Provision the per-slot token, or unset the identity to use shared credentials." >&2
|
||||
printf 'MOSAIC_CREDENTIAL_REFUSAL outcome=refused reason=no-token-for-identity identity=%s host=%s shared_path_entered=false source=%s path=%s\n' \
|
||||
"$_ident" "$host" "$_ident_src" "$_idtok" >&2
|
||||
return 1
|
||||
fi
|
||||
fi
|
||||
|
||||
# Fleet automation never borrows a shared human/default credential. An
|
||||
# explicit interactive caller may still reach the shared paths below, but
|
||||
# a fleet process must name an identity and resolve that identity exactly.
|
||||
if [[ -n "${MOSAIC_AGENT_NAME:-}" ]]; then
|
||||
printf 'MOSAIC_CREDENTIAL_REFUSAL outcome=refused reason=identity-required identity=<unset> host=%s shared_path_entered=false source=MOSAIC_AGENT_NAME\n' \
|
||||
"$host" >&2
|
||||
return 1
|
||||
fi
|
||||
|
||||
# 1. Mosaic credential loader (host → service mapping, run in subshell to avoid polluting env)
|
||||
if [[ -f "$cred_loader" ]]; then
|
||||
local token
|
||||
|
||||
Reference in New Issue
Block a user