MCPcopy Create free account
hub / github.com/atomicdotdev/atomic / from_environment

Function from_environment

atomic-cli/src/commands/delegation.rs:190–243  ·  view source on GitHub ↗

A grant supplied through [`DELEGATION_ENV`], verified and checked to belong to this agent. Returns `Err` rather than `Ok(None)` when the variable is set but unusable. Falling back to the store there would be worse than failing: the operator asked for a specific grant, and silently using a different one is how you get an agent acting under a scope nobody intended.

(identity: &Identity)

Source from the content-addressed store, hash-verified

188/// asked for a specific grant, and silently using a different one is how you
189/// get an agent acting under a scope nobody intended.
190fn from_environment(identity: &Identity) -> CliResult<Option<ResolvedDelegation>> {
191 let Ok(encoded) = std::env::var(DELEGATION_ENV) else {
192 return Ok(None);
193 };
194 let encoded = encoded.trim();
195 if encoded.is_empty() {
196 return Ok(None);
197 }
198
199 let document = cert::decode_from_transport(encoded).map_err(|e| CliError::DelegationError {
200 message: format!("{DELEGATION_ENV} is not a usable grant: {e}"),
201 })?;
202
203 let delegation =
204 cert::verify_self_contained(&document).map_err(|e| CliError::DelegationError {
205 message: format!("The grant in {DELEGATION_ENV} does not verify: {e}"),
206 })?;
207
208 if delegation.delegate != identity.id.to_did() {
209 // Compare DIDs, and say so. Display names are not unique — two agents
210 // called `alice+claude` on different machines are different keys, and
211 // an error reading "issued to 'alice+claude', not 'alice+claude'" tells
212 // the reader nothing.
213 return Err(CliError::DelegationError {
214 message: format!(
215 "The grant in {DELEGATION_ENV} was issued to a different key.\n \
216 Grant is for {} ({})\n \
217 Running as {} ({})",
218 delegation.delegate_name,
219 delegation.delegate,
220 identity.name,
221 identity.id.to_did()
222 ),
223 });
224 }
225
226 if delegation.is_expired() {
227 return Err(CliError::DelegationError {
228 message: format!(
229 "The grant in {DELEGATION_ENV} expired {}. Ask for a fresh one.",
230 delegation
231 .expires
232 .map(|e| e.format("on %Y-%m-%d %H:%M UTC").to_string())
233 .unwrap_or_else(|| "some time ago".to_string())
234 ),
235 });
236 }
237
238 Ok(Some(ResolvedDelegation {
239 delegation,
240 document,
241 status: DelegationStatus::Active,
242 }))
243}
244
245/// Pre-flight a specific operation before paying for a network round trip.
246///

Callers 1

active_forFunction · 0.85

Calls 5

decode_from_transportFunction · 0.85
verify_self_containedFunction · 0.85
to_didMethod · 0.80
is_emptyMethod · 0.45
is_expiredMethod · 0.45

Tested by

no test coverage detected