Let a signed-in user turn their own machine into a worker without the shared token. The coordinator already binds a JWT-authenticated registration to owner_id as untrusted; this adds the missing pieces. userservice: long-lived worker keys (scimesh_wk_live_*, hash-at-rest) with create/list/revoke and a public /worker-tokens/exchange that trades a key for a short-lived JWT carrying the owner current role/verified. python worker: SCIMESH_WORKER_KEY + SCIMESH_USERSERVICE_URL; a token provider exchanges the key and refreshes the JWT proactively and on 401, so a long-running worker survives token expiry. Static bearer token path is unchanged. coordinator UI: an "add your machine" page that mints a key and shows a ready-to-run command, proxying key management to the userservice; the dashboard gains an owner-scoped "my machines" section. docs: how to run a worker from your account, plus the untrusted/quorum/ verified trust model.
14 lines
456 B
Go
14 lines
456 B
Go
package domain
|
|
|
|
import "errors"
|
|
|
|
// Domain validation errors. They describe an entity that cannot be constructed,
|
|
// independent of storage or transport, and the HTTP layer maps them to 400.
|
|
var (
|
|
ErrEmptyEmail = errors.New("email is required")
|
|
ErrInvalidEmail = errors.New("email is not a valid address")
|
|
ErrEmptyPasswordHash = errors.New("password hash is required")
|
|
|
|
ErrWorkerKeyNameTooLong = errors.New("worker key name is too long")
|
|
)
|