feat(coordinator): worker trust tiers (C1) — enroll volunteers, quarantine untrusted
- migration 0012: workers.owner_id + trust_level (trusted/untrusted) - verifier/authctx read the JWT verified claim; IsTrusted() = admin||verified - /workers/register resolves trust from auth: service token or verified/admin JWT -> trusted; plain user JWT -> untrusted, tagged with owner_id - claim quarantines untrusted workers (no tasks) until quorum (C2) lands - unit tests for trust resolution, quarantine, and the verified claim Additive and backward compatible: shared-token workers stay trusted, so the existing worker flow and team tests are unchanged. Quorum verification (C2) is deferred.
This commit is contained in:
@@ -4,6 +4,8 @@ import (
|
||||
"io"
|
||||
|
||||
"github.com/google/uuid"
|
||||
|
||||
"github.com/emil28092005/SciMesh/coordinator/internal/domain"
|
||||
)
|
||||
|
||||
// Use-case boundary types. Adapters map their wire formats onto these, so the
|
||||
@@ -28,6 +30,11 @@ type ChunkInput struct {
|
||||
type RegisterWorkerInput struct {
|
||||
Name string
|
||||
Capabilities []string
|
||||
// OwnerID is the userservice user registering this worker; nil for a
|
||||
// shared-token registration. TrustLevel is resolved by the transport layer
|
||||
// from how the caller authenticated.
|
||||
OwnerID *uuid.UUID
|
||||
TrustLevel domain.WorkerTrust
|
||||
}
|
||||
|
||||
type ClaimTaskInput struct {
|
||||
|
||||
Reference in New Issue
Block a user