AdapterPoolHubAccessToken
Namespace: Meshmakers.Octo.Sdk.Common.Adapters
The access token a pool member presents on its own management connection to the
controller's /adapterPoolHub — the lending pool's identity, never a borrower's (AB#5865).
public sealed class AdapterPoolHubAccessToken : IServiceClientAccessToken
Inheritance Object → AdapterPoolHubAccessToken
Implements IServiceClientAccessToken
Remarks:
🔴 Deliberately not the process-wide . During a
lease the borrower-identity participant writes the BORROWER's token into that holder, because
every service client and pipeline node of the leased execution must act as the borrower. The
pool hub client used to read the same holder through its AccessTokenProvider, which is
called on every (re)connect: a connection rebuilt while a lease was running (controller
restart, network blip) was authenticated as the borrower, and the deferred re-registration
after the lease went out on that connection. The controller logged "presents a token of tenant
'leasetest' but claims to belong to a pool of tenant 'meshdev'" and would refuse it under
AdapterPoolHubAuthorization:Mode=Enforce (test-2-dev, 2026-10-07).
Separate holders also stop the two writers from clobbering each other the other way round: the member's own credential refresh (AdapterAccessTokenService) no longer overwrites a borrower token mid-lease, and leaving a lease no longer wipes the member's own token.
Written by AdapterAccessTokenService on a pool member (the member's own client credential, tenant = lending pool's tenant); read only by the pool hub client. Empty when the member has no own client credential — exactly what the connection presented before outside a lease.
Properties
AccessToken
public string AccessToken { get; set; }
Property Value
Constructors
AdapterPoolHubAccessToken()
public AdapterPoolHubAccessToken()
Events
AccessTokenUpdated
public event EventHandler AccessTokenUpdated;