diff options
| author | Christophe Besson <cbesson@gmail.com> | 2026-09-30 11:22:24 +0200 |
|---|---|---|
| committer | Christophe Besson <cbesson@gmail.com> | 2026-09-30 11:22:24 +0200 |
| commit | 69554fac7eba6eef7eb8a1c0111c5b92e7f21256 (patch) | |
| tree | 87ae908d008159c4237b31dade3f385a629c3c7b /docs/MESHBAY_DESIGN.md | |
| parent | e2a487c3cd24589b9d9bd298b79d8efaa9914480 (diff) | |
| download | meshbay-69554fac7eba6eef7eb8a1c0111c5b92e7f21256.tar.gz | |
fix: a member can no longer lock a node, crash it with a link, or stop hub cleanup
- node: only a wrong code counts towards the join lock, now per account
(5) as well as node-wide (20), and it is consulted only when a code is
tried. Every member reconnecting gets the group key through join_request,
so a lock checked before recognition let one member refuse it to everyone.
- node: link previews read the body as a stream and stop at the cap,
counted on decoded bytes; a declared oversized image is not read; 15 s
total deadline; image decoding off the loop. `client.get` had buffered
the whole (decompressed) response before the caps looked at it.
- hub: the daily purge of never-verified accounts detaches their IP-log
rows (keeping the name) and clears every other reference first, and each
cleanup step runs on its own. On PostgreSQL the bare DELETE violated the
ip_logs foreign key and stopped every purge behind it for good.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'docs/MESHBAY_DESIGN.md')
| -rw-r--r-- | docs/MESHBAY_DESIGN.md | 4 |
1 files changed, 3 insertions, 1 deletions
diff --git a/docs/MESHBAY_DESIGN.md b/docs/MESHBAY_DESIGN.md index 2efedca..6e90402 100644 --- a/docs/MESHBAY_DESIGN.md +++ b/docs/MESHBAY_DESIGN.md @@ -378,7 +378,9 @@ Four properties, each load-bearing: account in one group — except an invitation link's, which names its account when it is redeemed (below) — stored only as `sha256(code)`. A password KDF over 40 uniformly random bits would buy nothing. Guessing is bounded by 5 attempts per - connection and a node-wide lockout, and every attempt is an audit event. + connection and by wrong-code limits per account and node-wide — consulted only + when a code is tried, never for a device the node already pinned — and every + attempt is an audit event. 3. **The node's roster is the authority**, not hub membership. A hub that invents an account, adds it to a group and mints it a token gets `not_authorized_for_group`. |