A grant supplied through [`DELEGATION_ENV`], verified and checked to belong to this agent. Returns `Err` rather than `Ok(None)` when the variable is set but unusable. Falling back to the store there would be worse than failing: the operator asked for a specific grant, and silently using a different one is how you get an agent acting under a scope nobody intended.
(identity: &Identity)
| 188 | /// asked for a specific grant, and silently using a different one is how you |
| 189 | /// get an agent acting under a scope nobody intended. |
| 190 | fn from_environment(identity: &Identity) -> CliResult<Option<ResolvedDelegation>> { |
| 191 | let Ok(encoded) = std::env::var(DELEGATION_ENV) else { |
| 192 | return Ok(None); |
| 193 | }; |
| 194 | let encoded = encoded.trim(); |
| 195 | if encoded.is_empty() { |
| 196 | return Ok(None); |
| 197 | } |
| 198 | |
| 199 | let document = cert::decode_from_transport(encoded).map_err(|e| CliError::DelegationError { |
| 200 | message: format!("{DELEGATION_ENV} is not a usable grant: {e}"), |
| 201 | })?; |
| 202 | |
| 203 | let delegation = |
| 204 | cert::verify_self_contained(&document).map_err(|e| CliError::DelegationError { |
| 205 | message: format!("The grant in {DELEGATION_ENV} does not verify: {e}"), |
| 206 | })?; |
| 207 | |
| 208 | if delegation.delegate != identity.id.to_did() { |
| 209 | // Compare DIDs, and say so. Display names are not unique — two agents |
| 210 | // called `alice+claude` on different machines are different keys, and |
| 211 | // an error reading "issued to 'alice+claude', not 'alice+claude'" tells |
| 212 | // the reader nothing. |
| 213 | return Err(CliError::DelegationError { |
| 214 | message: format!( |
| 215 | "The grant in {DELEGATION_ENV} was issued to a different key.\n \ |
| 216 | Grant is for {} ({})\n \ |
| 217 | Running as {} ({})", |
| 218 | delegation.delegate_name, |
| 219 | delegation.delegate, |
| 220 | identity.name, |
| 221 | identity.id.to_did() |
| 222 | ), |
| 223 | }); |
| 224 | } |
| 225 | |
| 226 | if delegation.is_expired() { |
| 227 | return Err(CliError::DelegationError { |
| 228 | message: format!( |
| 229 | "The grant in {DELEGATION_ENV} expired {}. Ask for a fresh one.", |
| 230 | delegation |
| 231 | .expires |
| 232 | .map(|e| e.format("on %Y-%m-%d %H:%M UTC").to_string()) |
| 233 | .unwrap_or_else(|| "some time ago".to_string()) |
| 234 | ), |
| 235 | }); |
| 236 | } |
| 237 | |
| 238 | Ok(Some(ResolvedDelegation { |
| 239 | delegation, |
| 240 | document, |
| 241 | status: DelegationStatus::Active, |
| 242 | })) |
| 243 | } |
| 244 | |
| 245 | /// Pre-flight a specific operation before paying for a network round trip. |
| 246 | /// |
no test coverage detected