//! The local component that issues per-context credentials on an agent host. //! //! `plan/node.md` argues for a process rather than a per-hook program on two //! grounds: a short-lived program has to read the node credential off disk //! every time it runs, and a machine running several sessions fires many //! hooks at once with nowhere to coalesce what they ask for. This crate is //! that process. //! //! [`socket`] is the privilege boundary everything else sits behind, and the //! part worth building first because it is the part that is dangerous to get //! wrong: what is on the other side of it is credential issuance, and this //! project has already paid once for a local socket left wider than it //! meant to be. //! //! [`protocol`] is what crosses it. The harness adapter that speaks it lives //! in another repository and is not written in Rust, so the wire format is //! the contract rather than these types. //! //! [`cli`] is the other end of that wire: what `didbot-oauth`, the one //! agent-facing command, uses to make an exchange over it. [`direct`] is what //! that command does when there is no daemon to exchange with -- one account, //! one token from the environment, the same routes. //! //! [`decisions`] is the other direction: the sign-in requests an agent is //! asked about. Those come from the server, so this daemon holds the account //! credential ([`secret`]) it needs to fetch them, polls for them //! ([`poll`]), keeps them ([`pending`]) and relays the agent's answer. It //! decides none of it. //! //! [`node`] is what the daemon holds that a hook must not: the host's own //! key, minted on first start and never handed out. [`jwt`] is how that key //! speaks for the host at the server, and [`registrar`] is the server's //! account routes it speaks to. `didbot-register`, the command that gives a //! host its identity, shares the key and the routes. #![forbid(unsafe_code)] #[cfg(test)] mod double; pub mod cli; pub mod context; pub mod decisions; pub mod direct; pub mod jwt; pub mod loopback; pub mod node; pub mod pending; pub mod placement; pub mod poll; pub mod protocol; pub mod register; pub mod registrar; pub mod rotate; #[cfg(test)] pub(crate) mod scratch; pub mod secret; pub mod serve; mod shut; pub mod socket;