fix: read-only invitees auto-join passive
tmux refuses new-session from read-only clients ('client is
read-only'), so an active join for an -r invitee died under set -eu
with a raw tmux error. Detect the R flag on the caller's ACL line in
the existing preflight and fall back to the mirrored view.
This commit is contained in:
parent
f3209e39d1
commit
587a462e3c
2 changed files with 42 additions and 3 deletions
23
party
23
party
|
|
@ -949,12 +949,29 @@ EOF
|
||||||
|
|
||||||
# Auth gate. The joiner must already be on the access list (added
|
# Auth gate. The joiner must already be on the access list (added
|
||||||
# by the host via `party invite`). Pre-flight here so the user gets
|
# by the host via `party invite`). Pre-flight here so the user gets
|
||||||
# a helpful message instead of an opaque tmux refusal.
|
# a helpful message instead of an opaque tmux refusal. For an
|
||||||
if ! "$PARTY_TMUX" -S "$RR_SOCKET" server-access -l 2>/dev/null \
|
# unauthorized caller server-access -l prints its refusal on stderr
|
||||||
| awk '{print $1}' | grep -qx "$USER"; then
|
# with EMPTY stdout (and exit 0 — see party_conn_state), so the awk
|
||||||
|
# match comes up empty and we land in the exit-13 branch.
|
||||||
|
acl_line=$("$PARTY_TMUX" -S "$RR_SOCKET" server-access -l 2>/dev/null \
|
||||||
|
| awk -v u="$USER" '$1 == u { print; exit }')
|
||||||
|
if [ -z "$acl_line" ]; then
|
||||||
echo "party: '$RR_PARTY_NAME', ask $RR_HOST_USER to invite you." >&2
|
echo "party: '$RR_PARTY_NAME', ask $RR_HOST_USER to invite you." >&2
|
||||||
exit 13
|
exit 13
|
||||||
fi
|
fi
|
||||||
|
# Read-only invitees cannot create the guest session: tmux refuses
|
||||||
|
# with "client is read-only" (verified 3.3a/3.5a), which would kill
|
||||||
|
# an active join mid-new-session under set -eu. Detect the R flag
|
||||||
|
# on our own ACL line and take the mirrored view instead. Flag
|
||||||
|
# format is "user (R)" on 3.3–3.5 and "user (U,R)" on newer tmux;
|
||||||
|
# both end the flag list in "R)".
|
||||||
|
case "$acl_line" in
|
||||||
|
*"R)"*)
|
||||||
|
if [ "$passive" != 1 ]; then
|
||||||
|
echo "party: you are read-only on '$RR_PARTY_NAME'; joining passive (mirrored view)." >&2
|
||||||
|
passive=1
|
||||||
|
fi ;;
|
||||||
|
esac
|
||||||
|
|
||||||
if [ "$passive" = 1 ]; then
|
if [ "$passive" = 1 ]; then
|
||||||
# Mirror the host's pane focus, read-only at the tmux client
|
# Mirror the host's pane focus, read-only at the tmux client
|
||||||
|
|
|
||||||
|
|
@ -85,3 +85,25 @@ STUB
|
||||||
[ "$status" -eq 0 ]
|
[ "$status" -eq 0 ]
|
||||||
[[ "$output" == *"no parties found"* ]]
|
[[ "$output" == *"no parties found"* ]]
|
||||||
}
|
}
|
||||||
|
|
||||||
|
@test "read-only invitee joining active falls back to passive with a notice" {
|
||||||
|
# tmux refuses new-session from a read-only client ("client is
|
||||||
|
# read-only", exit 1 — verified 3.3a/3.5a), so an active join for an
|
||||||
|
# -r invitee died mid-command under set -eu. cmd_join must detect the
|
||||||
|
# R flag on its own ACL line and attach passive instead. The unquoted
|
||||||
|
# STUB delimiter is deliberate: $USER expands at write time, \$* at
|
||||||
|
# run time.
|
||||||
|
cat > "$PARTY_TMP/tmux-ro" <<STUB
|
||||||
|
#!/bin/sh
|
||||||
|
case "\$*" in
|
||||||
|
*"server-access -l"*) printf '%s (R)\nsomehost (W)\n' "$USER"; exit 0 ;;
|
||||||
|
esac
|
||||||
|
exit 0
|
||||||
|
STUB
|
||||||
|
chmod +x "$PARTY_TMP/tmux-ro"
|
||||||
|
export PARTY_TMUX="$PARTY_TMP/tmux-ro"
|
||||||
|
PARTY_DRY_RUN=1 run "$PARTY_BIN" join fiesta
|
||||||
|
[ "$status" -eq 0 ]
|
||||||
|
[[ "$output" == *"read-only"* ]]
|
||||||
|
[[ "$output" == *"attach-session -r -t fiesta"* ]]
|
||||||
|
}
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue