<feed xmlns='http://www.w3.org/2005/Atom'>
<title>meshbay.git/packages/meshbay-client, branch 0.17</title>
<subtitle>MeshBay — read-only public mirror</subtitle>
<id>https://git.meshbay.org/meshbay.git/atom?h=0.17</id>
<link rel='self' href='https://git.meshbay.org/meshbay.git/atom?h=0.17'/>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/'/>
<updated>2026-10-02T08:51:19Z</updated>
<entry>
<title>refactor(mnp): remove ten operator messages no client sent</title>
<updated>2026-10-02T08:51:19Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-10-02T08:51:19Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=754387590fa1754436b4648f969915888c6f6c9e'/>
<id>urn:sha1:754387590fa1754436b4648f969915888c6f6c9e</id>
<content type='text'>
node_status, node_settings_set, roster_read, denylist_read, denylist_clear,
node_reload and the signed gek_rotate, member_unpin, transfer_limits,
group_detach leave MNP 6.0; the Node page and the CLI do this work over
loopback. Their ops keep their tests, moved to the ops level.

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>fix(client): no confirmation dialog for adding a folder or its flags</title>
<updated>2026-10-02T08:32:18Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-10-02T08:32:18Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=c928547ca6e402bfe5e06bb59d55ac91e6822cd0'/>
<id>urn:sha1:c928547ca6e402bfe5e06bb59d55ac91e6822cd0</id>
<content type='text'>
Removes confirmFolder (addRoot, attachGroup) and the writable confirmation
added in e4f6177, with their two catalogue keys.

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>feat(mnp): sharing a folder is decided on the node's machine only (MNP 6.0)</title>
<updated>2026-10-02T08:20:09Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-10-02T08:20:09Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=e4f61771131be635b9e81a19203a00707b4b19df'/>
<id>urn:sha1:e4f61771131be635b9e81a19203a00707b4b19df</id>
<content type='text'>
root_add, root_update and group_attach leave MNP: adding a directory and
switching writable/removable go through the loopback API (native dialog in
the desktop app) or the CLI. The operator's Settings tab still lists the
roots from any browser, read-only. The desktop app refuses to sign those
ops; a loopback flag change now reaches open pages (publish_roots).

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>feat(client): list cast receivers as they answer</title>
<updated>2026-10-02T06:39:56Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-10-02T06:39:56Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=e941cc4c39c38a12220153ea572bd4c7bb92fde0'/>
<id>urn:sha1:e941cc4c39c38a12220153ea572bd4c7bb92fde0</id>
<content type='text'>
The scan still runs six seconds, but the picker polls what it has found
and shows each receiver immediately. A rescan no longer has its timer
cut short by the scan it replaced.

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>fix(client): rotating a group key asks nothing</title>
<updated>2026-10-01T13:52:08Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-10-01T13:52:08Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=fcac9dcb6ba0ad346a754c7b9e7c59d38b64a4e8'/>
<id>urn:sha1:fcac9dcb6ba0ad346a754c7b9e7c59d38b64a4e8</id>
<content type='text'>
Rotation narrows rather than widens: members still connected receive the
new key, and nothing already shared changes.

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>fix(client): hosting a group asks nothing when its folder came from the picker</title>
<updated>2026-10-01T13:49:42Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-10-01T13:49:42Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=a64fe23de95f1495a831a1595b398fdd6149097e'/>
<id>urn:sha1:a64fe23de95f1495a831a1595b398fdd6149097e</id>
<content type='text'>
The folder chosen in the native picker is the consent; the dialog that
followed on every group creation asked the same thing twice.

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>chore: remove a spike page served in production and an unused derivation</title>
<updated>2026-10-01T11:25:58Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-10-01T11:25:58Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=b1878ab982ab72571915e7fbe2c1b558ea31f838'/>
<id>urn:sha1:b1878ab982ab72571915e7fbe2c1b558ea31f838</id>
<content type='text'>
static/webrtc-test.html posted a raw password to /login from the hub's own
origin; meshbay_common/keyderive.py derived keys from a password and nothing
called it (F-32).

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>fix: an MBK2 bundle is opened once and stored again as MBK3</title>
<updated>2026-10-01T11:06:32Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-10-01T11:06:32Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=e0905bd447f6214dc34e360554826ace45bde676'/>
<id>urn:sha1:e0905bd447f6214dc34e360554826ace45bde676</id>
<content type='text'>
Transitional. The Argon2 run that makes M makes A, the key MBK2 bundles were
sealed under; a session keeps it as a decrypt-only key (IndexedDB in a browser,
the key storage in the desktop app). A client meeting an MBK2 bundle opens it —
or its recovery copy — and stores the same identity as MBK3 once connected; the
desktop app reseals or withdraws it as browser access says. A session without
A asks for the passphrase once. Older formats stay refused by name. Replaces
the unpin-and-reinvite step the 0.17 flag day required on every node.

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>fix: downloads are marked and keep their extension; Explorer files are refused</title>
<updated>2026-10-01T09:47:39Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-10-01T09:47:39Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=760ac421b1944cd69a80e3a92127a1a966f15938'/>
<id>urn:sha1:760ac421b1944cd69a80e3a92127a1a966f15938</id>
<content type='text'>
The desktop app writes the Mark-of-the-Web on each file it saves on Windows, as
a browser does. Bidirectional controls are reserved characters in a saved name
(portable-name.js and paths.sanitize_for_download, and again in the main
process), so a name cannot display one extension and carry another. The node
refuses uploads of files Windows Explorer acts on by itself: desktop.ini,
.lnk, .url, .scf, .library-ms, .searchConnector-ms (F-19).

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
<entry>
<title>fix(node): how a hosted group admits people is the operator's, not the hub's</title>
<updated>2026-10-01T07:46:39Z</updated>
<author>
<name>Christophe Besson</name>
<email>cbesson@gmail.com</email>
</author>
<published>2026-10-01T07:46:39Z</published>
<link rel='alternate' type='text/html' href='https://git.meshbay.org/meshbay.git/commit/?id=0d0898c656afb8c1faa9fa91ba525e8a3e6a34ee'/>
<id>urn:sha1:0d0898c656afb8c1faa9fa91ba525e8a3e6a34ee</id>
<content type='text'>
attach_group no longer copies join_policy and visibility from the hub's
answer: they come with the operator's request (the desktop creation form,
`group add --open`) and default to invite/private; the CLI says when the hub
lists the group otherwise. Every string written into node.toml is escaped
(toml_string) and read back through tomllib, so a group or folder name cannot
write lines of its own (F-17).

Co-Authored-By: Claude Opus 5.5 &lt;noreply@anthropic.com&gt;
</content>
</entry>
</feed>
