aboutsummaryrefslogtreecommitdiffstats
path: root/docs/MESHBAY_DESIGN.md
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-09-30 11:22:24 +0200
committerChristophe Besson <cbesson@gmail.com>2026-09-30 11:22:24 +0200
commit69554fac7eba6eef7eb8a1c0111c5b92e7f21256 (patch)
tree87ae908d008159c4237b31dade3f385a629c3c7b /docs/MESHBAY_DESIGN.md
parente2a487c3cd24589b9d9bd298b79d8efaa9914480 (diff)
downloadmeshbay-69554fac7eba6eef7eb8a1c0111c5b92e7f21256.tar.gz
fix: a member can no longer lock a node, crash it with a link, or stop hub cleanup
- node: only a wrong code counts towards the join lock, now per account (5) as well as node-wide (20), and it is consulted only when a code is tried. Every member reconnecting gets the group key through join_request, so a lock checked before recognition let one member refuse it to everyone. - node: link previews read the body as a stream and stop at the cap, counted on decoded bytes; a declared oversized image is not read; 15 s total deadline; image decoding off the loop. `client.get` had buffered the whole (decompressed) response before the caps looked at it. - hub: the daily purge of never-verified accounts detaches their IP-log rows (keeping the name) and clears every other reference first, and each cleanup step runs on its own. On PostgreSQL the bare DELETE violated the ip_logs foreign key and stopped every purge behind it for good. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'docs/MESHBAY_DESIGN.md')
-rw-r--r--docs/MESHBAY_DESIGN.md4
1 files changed, 3 insertions, 1 deletions
diff --git a/docs/MESHBAY_DESIGN.md b/docs/MESHBAY_DESIGN.md
index 2efedca..6e90402 100644
--- a/docs/MESHBAY_DESIGN.md
+++ b/docs/MESHBAY_DESIGN.md
@@ -378,7 +378,9 @@ Four properties, each load-bearing:
account in one group — except an invitation link's, which names its account
when it is redeemed (below) — stored only as `sha256(code)`. A password KDF over 40
uniformly random bits would buy nothing. Guessing is bounded by 5 attempts per
- connection and a node-wide lockout, and every attempt is an audit event.
+ connection and by wrong-code limits per account and node-wide — consulted only
+ when a code is tried, never for a device the node already pinned — and every
+ attempt is an audit event.
3. **The node's roster is the authority**, not hub membership. A hub that invents
an account, adds it to a group and mints it a token gets
`not_authorized_for_group`.