Skip to content

fix(myra,web): the definition declares the hub credential binding and use requirement (CL-8603) - #951

Merged
TheGreatAxios merged 1 commit into
mainfrom
cl-8603-definition-hub-credential
Sep 18, 2026
Merged

TheGreatAxios merged 1 commit into
mainfrom
cl-8603-definition-hub-credential

Conversation

@TheGreatAxios

Copy link
Copy Markdown
Contributor

Summary

  • The artifact tools on a fresh workbench failed with Runtime capability "credentials" was requested but not provided by the host: the frozen definition carried no credential bindings, because the binding lived only in the web's hand-built JSON while the deployed definition is what the bundle's buildMyraWorkflow returns.
  • The client's post-deploy POST /grants could never succeed either: the run principal is created by the run's first trigger, not by the deploy request.
  • buildMyraWorkflow now takes the hub credential id in its input and declares both the credentialBindings entry (artifact tools hub handle) and a creator-sourced credential:{id} / use requirement conditioned on the artifact tools package. Stock run-grant materialization resolves that against the deployer's authority at first trigger and stamps the grant the sidecar's credential gate checks.
  • The hand-built definition JSON for Myra and for created agents mirrors both fields; the binding and requirement helpers live in @corbits/myra/workflow-ids so the bundle and the web share one source.
  • All client-side grant code (grantArtifactToolsCredentialUse, authorizeMyraHubCredential, deployment and principal lookups) is deleted. One deploy step now provisions the token, the credential, the binding and the grant.

Testing

  • bun run check green.
  • Live verification on a fresh workbench follows the merge (the dev stack runs from main).

… use requirement, so the client grant step goes away (CL-8603)
@linear-code

linear-code Bot commented Sep 18, 2026

Copy link
Copy Markdown

CL-8603

@TheGreatAxios
TheGreatAxios merged commit 25179bc into main Sep 18, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant