diff options
| author | Christophe Besson <cbesson@gmail.com> | 2026-10-07 22:12:54 +0200 |
|---|---|---|
| committer | Christophe Besson <cbesson@gmail.com> | 2026-10-07 22:20:45 +0200 |
| commit | 462d76898a306981fbeac859cd54da1468e80639 (patch) | |
| tree | 9a49723da751b4a7225e3dd37181ecceed192f3a /docs/MESHBAY_DESIGN.md | |
| parent | 92e6b9823119b5461efc304a81e79e186a928e6d (diff) | |
| download | meshbay-462d76898a306981fbeac859cd54da1468e80639.tar.gz | |
fix(node): name members admitted without an invitation name
A member who joined by link, by a new device or into an open group was
pinned in the roster with no name, so the audit log showed only the
first characters of their id. The hub's MNP token now carries the
account's username, and after the handshake the node writes it into the
roster for an account whose name is empty. An invitation's name is never
overwritten; the name is a label, authority stays on `sub`.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'docs/MESHBAY_DESIGN.md')
| -rw-r--r-- | docs/MESHBAY_DESIGN.md | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/docs/MESHBAY_DESIGN.md b/docs/MESHBAY_DESIGN.md index baf8e1e..0284dbe 100644 --- a/docs/MESHBAY_DESIGN.md +++ b/docs/MESHBAY_DESIGN.md @@ -1131,7 +1131,7 @@ token (E10).** A member hands whatever it presents here to the node operator, who is in the threat model, so the credential must open nothing at the hub. The hub signs two audiences with its one key: a session token (`aud` = the hub API) for `hubFetch` and signaling, and a short-lived **MNP token** (`aud = MNP_AUD`, -from `POST /v1/nodes/mnp-token`) that carries the member's `sub`, `jti` and **the +from `POST /v1/nodes/mnp-token`) that carries the member's `sub`, `username`, `jti` and **the one group the connection is for** — never the member's other groups, which the operator it is handed to has no business learning — and is the only thing presented in the handshake. The node binds `MNP_AUD` |