Skip to content

Federation: peering-token mint takes peerHubId + boundOrgId, handshake drops boundOrgId, bad token is 401 #20

Description

@boisedude

agledger-api 2a38f4e1 (unreleased, on main; ships in the next tag) changes three federation wire shapes the SDK types and calls.

1. Peering tokens are bound at mint (agledger-api#1994).

  • POST /federation/v1/admin/peering-tokens now requires { "peerHubId": "<the calling Server's instanceId>", "boundOrgId": "<local org uuid>", "label"?: string }. The 201 adds peerHubId and boundOrgId. An unknown org answers 404; a hub id already registered answers 409.
  • POST /federation/v1/peer no longer takes boundOrgId (the body is additionalProperties: false, so sending it is a 400). The body is { peerHubId, peerUrl, signingPublicKey, peeringToken }, and peerHubId must be the id the token was minted for (else 422, token unconsumed).
  • An unknown, consumed or expired token now answers 401 (was 422), before any other check.

2. Settlement Signal reason (agledger-api#1985). Free text no longer crosses the federation wire. POST /federation/v1/signals still accepts reason (so 1.8.0 peers validate) and ignores it. A record's settlementSignal.reason is always null when source is inbound.

3. Co-sign (agledger-api#1986). A signal without counterSignature for a record whose type the receiver registered with coSignRequired: true is refused with 422, retryable: false, reason: co_sign_required.

What to change:

  • The peering-token create method takes and sends peerHubId and boundOrgId (required).
  • The handshake params type drops boundOrgId.
  • The docs for the handshake's token errors say 401, not 422.
  • The signal relay params' reason doc says the receiver ignores it (or drop the field). The SettlementSignalSummary.reason doc notes it is null for inbound signals.

No state is left in this repo's tree for you.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions