MCPcopy Create free account
hub / github.com/atomicdotdev/atomic / execute

Method execute

atomic-cli/src/commands/identity/register.rs:113–350  ·  view source on GitHub ↗
(&self)

Source from the content-addressed store, hash-verified

111
112impl Register {
113 async fn execute(&self) -> CliResult<()> {
114 // 1. Open the identity store.
115 let store = IdentityStore::open_default().map_err(|e| {
116 CliError::Internal(anyhow::anyhow!("Failed to open identity store: {e}"))
117 })?;
118
119 // 2. Load the identity.
120 let identity = if let Some(name) = &self.identity {
121 store
122 .load_by_name(name)
123 .map_err(|_| CliError::IdentityNotFound(name.clone()))?
124 } else {
125 store
126 .get_default()
127 .map_err(|e| {
128 CliError::Internal(anyhow::anyhow!("Failed to load default identity: {e}"))
129 })?
130 .ok_or_else(|| {
131 CliError::Internal(anyhow::anyhow!(
132 "No default identity set. Create one first:\n \
133 atomic identity new <name> --email <email> --set-default"
134 ))
135 })?
136 };
137
138 // 2b. An agent must never mint a tenant. Registration creates one
139 // whose slug is the identity name, so letting an agent through
140 // here would give a delegated key its own top-level namespace —
141 // the opposite of "an agent can never exceed its human".
142 if identity.identity_type.is_delegated() || identity.identity_type.is_agent() {
143 return Err(CliError::InvalidArgument {
144 message: format!(
145 "'{}' is an agent identity, and registering creates a tenant.\n \
146 Enroll it under a human instead:\n \
147 atomic identity agent create <name>\n \
148 or, for a key generated elsewhere:\n \
149 atomic identity delegation push",
150 identity.name
151 ),
152 });
153 }
154
155 // 3. Load the keypair (needs the secret key for signing).
156 let keypair = store.load_keypair(&identity.id, None).map_err(|e| {
157 CliError::Internal(anyhow::anyhow!(
158 "Failed to load keypair for '{}': {e}",
159 identity.name
160 ))
161 })?;
162
163 // 4. Build the registration payload.
164 let username = &identity.name;
165 let public_key_b32 = identity.public_key_base32();
166 let timestamp = Utc::now();
167 let timestamp_str = timestamp.to_rfc3339_opts(chrono::SecondsFormat::Secs, true);
168
169 // 5. Build and sign the canonical payload.
170 let payload = format!("{SIGNING_DOMAIN}\n{username}\n{public_key_b32}\n{timestamp_str}");

Callers 1

runMethod · 0.45

Calls 15

parse_tenancy_modeFunction · 0.85
derive_profile_nameFunction · 0.85
apply_registrationFunction · 0.85
print_successFunction · 0.85
print_next_stepsFunction · 0.85
print_errorFunction · 0.85
load_by_nameMethod · 0.80
is_delegatedMethod · 0.80
is_agentMethod · 0.80
load_keypairMethod · 0.80
public_key_base32Method · 0.80
postMethod · 0.80

Tested by

no test coverage detected