Files
hermes-agent/website/docs/user-guide
Teknium 1cf3639813 test(bot-mode): pin grant-refresh reauthorization on execution-policy drift
Follow-ups on the salvaged #97797 transport:

- Blocker 2 from the #97681 exact-head review claimed near-expiry refresh
  silently mints against the target's CURRENT policy. On this head the
  handler DOES refuse drift (_require_unchanged_execution_policy -> 403
  room_reauthorization_required), but nothing pinned the handler-level
  behavior: removing the drift check still passed the entire grants suite
  (the check was only unit-tested in isolation). New HTTP-level regression
  test drives /v1/room-members/grants/refresh with a drifted-policy grant
  and requires the 403; sabotage-verified (check removed -> test fails).
- cancel() conflict resolution: keeps our race-retry routing loop from
  #99099 with this layer's peer-stop acknowledgement body inside it
  (peer receipt -> settle completion -> local interrupt escalation).
- docs: NAT one-way-reachability note in bot-mode.md — Desktop is a viewer,
  not a relay; put room authority on the host everyone can reach (field
  finding from /bin/bash on #97681).
2026-08-31 01:04:11 -07:00
..