aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-09-28 22:39:05 +0200
committerChristophe Besson <cbesson@gmail.com>2026-09-28 22:39:05 +0200
commit215864bf655f7dcb793e80c836598655d6d945a9 (patch)
tree2213bb56f97137c97c1b50eb6ce19e9394862b6c
parentaaa372f862ffb7fd093da699e483c9118381e2cc (diff)
downloadmeshbay-215864bf655f7dcb793e80c836598655d6d945a9.tar.gz
docs: keypair_bundle_delete is reserved for device_policy (O3)
The node honours it and no interface sends it; offered alone it would strand the next browser that signs in. Stated in both documents. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
-rw-r--r--docs/MESHBAY_DESIGN.md3
-rw-r--r--docs/MESHBAY_NODE_PROTOCOL.md4
-rw-r--r--packages/meshbay-hub/src/meshbay_hub/static/transport-devices.js4
3 files changed, 10 insertions, 1 deletions
diff --git a/docs/MESHBAY_DESIGN.md b/docs/MESHBAY_DESIGN.md
index f152883..c37e43b 100644
--- a/docs/MESHBAY_DESIGN.md
+++ b/docs/MESHBAY_DESIGN.md
@@ -618,7 +618,8 @@ control. It closes for a native device unconditionally, because that device's ke
is in no bundle anywhere. It closes for an *account* only when no browser needs a
bundle on that node — which needs `device_policy {allow_bundle: false}`, **signed
by a pinned key** so the decision is the user's and never the hub's (open item
-O3).
+O3). Withdrawing a bundle already exists on the wire (`keypair_bundle_delete`) and
+is not offered in the interface: it belongs with that decision, not before it.
---
diff --git a/docs/MESHBAY_NODE_PROTOCOL.md b/docs/MESHBAY_NODE_PROTOCOL.md
index 2e314f2..c3254da 100644
--- a/docs/MESHBAY_NODE_PROTOCOL.md
+++ b/docs/MESHBAY_NODE_PROTOCOL.md
@@ -663,6 +663,10 @@ nodes.
* Identity keys are **per node**. There is nothing to carry between nodes, and an
operator who cracks the copy on their own disk gets a key that opens nothing
anywhere else.
+* `keypair_bundle_delete` is **reserved for `device_policy`** (`MESHBAY_DESIGN.md`
+ §3.7, open item O3): the node honours it, and no interface sends it yet. Withdrawing
+ the bundle is only safe once the account has chosen not to need it from a browser —
+ a lone button would strand the next browser that signs in.
### 7.1a Per-account blobs (MNP 3.1)
diff --git a/packages/meshbay-hub/src/meshbay_hub/static/transport-devices.js b/packages/meshbay-hub/src/meshbay_hub/static/transport-devices.js
index 4291cf8..199b6a2 100644
--- a/packages/meshbay-hub/src/meshbay_hub/static/transport-devices.js
+++ b/packages/meshbay-hub/src/meshbay_hub/static/transport-devices.js
@@ -268,6 +268,10 @@ extendTransport(class {
* The counterpart of storeKeypairBundle: turning the setting off has to remove
* what is already stored, not merely stop adding to it — otherwise the blob
* stays on every node the account has ever joined (C4).
+ *
+ * Nothing calls this yet, on purpose: it is reserved for `device_policy`
+ * (docs/MESHBAY_DESIGN.md §3.7, O3). Offered alone, it would strand the next
+ * browser that signs in to this node.
*/
async deleteKeypairBundle() {
const msg = await this._sendAndWait({