diff --git a/crates/didbot-operator/src/bin/didbot-operator.rs b/crates/didbot-operator/src/bin/didbot-operator.rs index 4f2f2f73..8178cfbc 100644 --- a/crates/didbot-operator/src/bin/didbot-operator.rs +++ b/crates/didbot-operator/src/bin/didbot-operator.rs @@ -88,7 +88,8 @@ enum Verb { #[arg(long, conflicts_with = "revoke")] check: bool, /// Delete your bot.did.operator record for , which pauses it and everything - /// beneath it at the deployment's next poll + /// beneath it after the deployment's grace window (six hours by default). `didbot + /// account lock ` stops an account now, and `didbot estop --pause` a server #[arg(long)] revoke: bool, /// A server's hostname, or an account's @@ -471,8 +472,10 @@ async fn revoke_record(name: &str, operator: &str, json: Json) -> Result<(), Ref |_| { format!( "deleted {}, which named {}\n\ - the deployment reads this at its next operator poll and pauses that account \ - and everything beneath it; this command does not wait for that to happen.", + it and everything beneath it pause after the deployment's grace window (six \ + hours by default); this command does not wait for that to happen.\n\ + `didbot account lock {name} --server ` stops an account now, and \ + `didbot estop --pause --server ` a server.", revoked.record_uri, revoked.subject ) }, diff --git a/crates/didbot-operator/src/operate/account.rs b/crates/didbot-operator/src/operate/account.rs index ec95b331..45540886 100644 --- a/crates/didbot-operator/src/operate/account.rs +++ b/crates/didbot-operator/src/operate/account.rs @@ -552,8 +552,8 @@ pub struct Revoked { /// /// The read is what makes this safe to run against a typo: a key that holds /// some other account's claim is left alone and named in the refusal. The -/// deployment reads the deletion at its next operator poll, which is what -/// pauses the account and everything beneath it. +/// deployment's operator poll pauses the account and everything beneath it +/// once it has gone the grace window without reading the record. pub async fn revoke( own_pds: &W, operator_did: &str, diff --git a/crates/didbot-operator/src/operate/walk.rs b/crates/didbot-operator/src/operate/walk.rs index 41f3aa18..029a87a8 100644 --- a/crates/didbot-operator/src/operate/walk.rs +++ b/crates/didbot-operator/src/operate/walk.rs @@ -71,8 +71,10 @@ pub enum WalkError { /// both. #[error( "{operator} holds no bot.did.operator/{name}: the edge from {account} up to it is \ - paused, whether the record was taken back or never written, and a deployment \ - hosting {account} stops it and everything beneath it at its next poll" + paused, whether the record was taken back or never written. A deployment hosting \ + {account} stops it and everything beneath it after the deployment's grace window \ + (six hours by default); `didbot account lock` stops an account now, and `didbot \ + estop --pause` a server" )] Paused { /// The account below the edge. diff --git a/docs/cli.md b/docs/cli.md index 2a01dae7..c74a7381 100644 --- a/docs/cli.md +++ b/docs/cli.md @@ -325,8 +325,9 @@ didbot app end-logins --client https://app.example/client.json \ the operator's own repository rather than the deployment: it deletes `bot.did.operator/` there, through the delete action of the same scope the claim was written with, after reading the record back and confirming it -names that account. The deployment finds that at its next poll and pauses -the account and everything beneath it. +names that account. The deployment pauses the account and everything beneath +it after its grace window, six hours by default. `didbot account lock ` +stops an account at once, and `didbot estop --pause` stops a server. ## The agent host's commands diff --git a/plan/ownership.md b/plan/ownership.md index f33889f4..5e5dce28 100644 --- a/plan/ownership.md +++ b/plan/ownership.md @@ -154,9 +154,9 @@ new account is the authorization. --revoke ` reads `bot.did.operator/` out of the human's own repository, confirms it names that account, and deletes it through the delete action of the scope the claim was written under. - The deployment's poll pauses the account and everything beneath it; - `didbot operate --check` names the edge as paused from then on - (`operate::walk::WalkError::Paused`). + The deployment's poll pauses the account and everything beneath it + after the grace window; `didbot operate --check` names the edge as + paused from then on (`operate::walk::WalkError::Paused`). - [x] **The operator acts on one hosted account.** `POST /dashboard/api/accounts/{did}/lock`, `unlock`, `lift-quarantine`,