summaryrefslogtreecommitdiffstats
path: root/docs/MESHBAY_DESIGN.md
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-10-05 11:27:20 +0200
committerChristophe Besson <cbesson@gmail.com>2026-10-05 11:27:20 +0200
commit28752696f376eb11feb686580a435b166750a723 (patch)
treea879254f126d6d83096c7a7c3a181a151e3be7f2 /docs/MESHBAY_DESIGN.md
parent6cdc6016d72dcfb7530ac38a8fa92232418ac305 (diff)
downloadmeshbay-28752696f376eb11feb686580a435b166750a723.tar.gz
fix: list as members only the accounts the node has admitted
The Members list showed the hub's membership, which an account gains when it accepts the invitation or redeems a link, before it has presented its code to the node. The node's roster is the authority (MESHBAY_DESIGN.md §3.4), so the list now crosses the hub's members with the sealed group roster the node already sends every connected member. An account the node has not admitted yet is shown to the owner alone, as waiting for its code, with the Remove button; other members do not see it. When the roster cannot be read, the hub's list is shown as before. groupRoster() takes { fresh: true } so the page sees who joined since the connection opened. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'docs/MESHBAY_DESIGN.md')
-rw-r--r--docs/MESHBAY_DESIGN.md6
1 files changed, 5 insertions, 1 deletions
diff --git a/docs/MESHBAY_DESIGN.md b/docs/MESHBAY_DESIGN.md
index 9c87372..78a9cb5 100644
--- a/docs/MESHBAY_DESIGN.md
+++ b/docs/MESHBAY_DESIGN.md
@@ -393,7 +393,11 @@ Four properties, each load-bearing:
attempt is an audit event.
3. **The node's roster is the authority**, not hub membership. A hub that invents
an account, adds it to a group and mints it a token gets
- `not_authorized_for_group`.
+ `not_authorized_for_group`. The Members list says the same: it shows the
+ accounts the node has admitted (the sealed group roster, §11.7 of the protocol).
+ One the hub counts as a member but that has not presented its code yet is
+ shown to the owner alone, as waiting for its code; when the roster cannot be
+ read, the hub's list is shown.
4. **Wrapping happens on every connection.** Nothing is stored per member, so key
rotation propagates by itself and revocation actually takes effect. (Rotating
the key after a revocation is still required — the ex-member holds the current