aboutsummaryrefslogtreecommitdiffstats
path: root/docs/MESHBAY_DESIGN.md
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-10-09 12:16:51 +0200
committerChristophe Besson <cbesson@gmail.com>2026-10-09 12:17:38 +0200
commit4ae61dc4e1dcca6ae24131fcd9acc55124e3c0af (patch)
tree44fd15f6175ade9b0b884f846dfd9d66e2b3bc80 /docs/MESHBAY_DESIGN.md
parent6832df6177ad973ad0e1b4f0a49d7a6da06c6e04 (diff)
downloadmeshbay-4ae61dc4e1dcca6ae24131fcd9acc55124e3c0af.tar.gz
feat: let the operator purge a group's chat (MNP 6.1)
Signed chat_purge from the Chat settings deletes every stored message; epoch keys and attachments stay. The ack is broadcast so open chat panels empty. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'docs/MESHBAY_DESIGN.md')
-rw-r--r--docs/MESHBAY_DESIGN.md7
1 files changed, 5 insertions, 2 deletions
diff --git a/docs/MESHBAY_DESIGN.md b/docs/MESHBAY_DESIGN.md
index b874632..c0ccbbc 100644
--- a/docs/MESHBAY_DESIGN.md
+++ b/docs/MESHBAY_DESIGN.md
@@ -16,7 +16,7 @@
> them โ€” it names the invariant that holds today, not the incident that produced
> it. ยง13 is the register of those labels.
>
-> Wire versions at the time of writing: **MNP 6.0** (oldest peer accepted 4.0),
+> Wire versions at the time of writing: **MNP 6.1** (oldest peer accepted 4.0),
> **MHP 0.1**, packages **0.19.0**. The normative source for the wire format is
> `MESHBAY_NODE_PROTOCOL.md`; this document states the design the protocol
> serves, not its byte layout.
@@ -1838,7 +1838,10 @@ chat opens at the newest page. A forwards pager is not what a chat opens with.
`meshbay-node chat prune <days>` deletes **messages only, never an epoch key**. An
epoch with no messages is harmless; an epoch key deleted while messages still need
-it is an unreadable archive.
+it is an unreadable archive. The operator's purge (the signed `chat_purge`, from
+the Chat settings) is the same rule with no age: every message goes, the epoch
+keys and the attachments stay. The replay index goes with the rows, which costs
+nothing, since a sealed message is taken only from the device that signed it.
**A message is bounded in size and in rate, like every other member-supplied
write.** Sending one costs the operator a row that nothing expires, every other