← Back to list
01Issue
FeatureOpenSwamp CLIPublic
AssigneesNone
Relationships
#3134 Docs: serve restricted-model-types matches any @ spelling; restriction warnings in serve and check-config
Opened by skunk-ape · 10/7/2026
What changed (swamp-club#3129)
--restricted-model-types/auth.restricted-model-typesnow matches a type in any spelling: a leading@is ignored on the list entry, on the requested type and on the stored type. Listing@acme/deployoracme/deployrestricts the same type, for model create, method run, direct type execution and adding a workflow step. Before this, an@-prefixed extension type had to be listed in both spellings; that workaround is no longer needed.- A
restricted-model-typesentry that names no type (@,::) now stopsswamp servefrom starting. swamp servewarns at startup about a barerestricted-model-typesentry that names no registered type, and about arestricted-commandsentry that is not a server command. Command names match exactly.swamp serve check-configreportsrestricted-commandsentries that are not server commands as warnings, and an entry that names no type as a failed check. It does not check whether a model type is registered.
Pages to update
content/manual/reference/swamp-serve/authorization.md, the "restricted model types" section (around the--restricted-model-types 'command/shell'example): add that a leading@is ignored when matching, give an extension-type example (@acme/deploy), and mention the startup warning.content/manual/reference/swamp-serve/serve-flags.md: the--restricted-model-typesrow says types are "normalized on parse —Command::Shell,COMMAND.SHELL, andcommand/shellall match". Add that a leading@is ignored too. Add "names match exactly" to the--restricted-commandsrow.- The
swamp serve check-configreference, if one exists: the new restriction warnings and the failed check.
02Bog Flow
Open
No activity in this phase yet.
03Sludge Pulse
Sign in to post a ripple.