Tell the server: bump the epoch, then deny-list each known grant. The epoch first, because it is the part that actually stops the agent and covers grants nobody has a copy of. Deny-listing the ones we do know is the audit trail on top.
(
&self,
agent: &atomic_identity::Identity,
revoked: &[(String, atomic_identity::Identity, serde_json::Value)],
)
| 168 | /// and covers grants nobody has a copy of. Deny-listing the ones we do know |
| 169 | /// is the audit trail on top. |
| 170 | async fn notify_server( |
| 171 | &self, |
| 172 | agent: &atomic_identity::Identity, |
| 173 | revoked: &[(String, atomic_identity::Identity, serde_json::Value)], |
| 174 | ) { |
| 175 | let Some((_, delegator, _)) = revoked.first() else { |
| 176 | return; |
| 177 | }; |
| 178 | |
| 179 | let Ok((client, url)) = |
| 180 | crate::commands::client::build_apex_client_as(delegator, self.server.as_deref()).await |
| 181 | else { |
| 182 | print_warning( |
| 183 | "Revoked locally, but no server could be reached. Outstanding grants stay \ |
| 184 | valid until the server is told.\n \ |
| 185 | Retry with: atomic identity agent revoke <name>", |
| 186 | ); |
| 187 | return; |
| 188 | }; |
| 189 | |
| 190 | match self.bump_epoch(&client, agent).await { |
| 191 | Ok(()) => println!(" Epoch bumped {url} — every outstanding grant is now dead"), |
| 192 | Err(e) => print_warning(&format!( |
| 193 | "Could not bump the epoch at {url}: {e}\n \ |
| 194 | Grants this machine has never seen REMAIN VALID until it succeeds.\n \ |
| 195 | Retry with: atomic identity agent revoke {}", |
| 196 | agent.name |
| 197 | )), |
| 198 | } |
| 199 | |
| 200 | for (urn, _, revocation) in revoked { |
| 201 | let request = RevokeDelegationRequest { |
| 202 | revocation: revocation.clone(), |
| 203 | }; |
| 204 | match client.revoke_delegation(urn, &request).await { |
| 205 | Ok(_) => println!(" Deny-listed {urn}"), |
| 206 | Err(e) => print_warning(&format!("Could not deny-list {urn}: {e}")), |
| 207 | } |
| 208 | } |
| 209 | } |
| 210 | |
| 211 | /// Find the agent's server-side id and bump its epoch. |
| 212 | /// |
no test coverage detected