aboutsummaryrefslogtreecommitdiffstats
path: root/docs/USERGUIDE.md
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-08-15 02:34:19 +0200
committerChristophe Besson <cbesson@gmail.com>2026-08-15 02:34:19 +0200
commit84b032c65e17267d41e04605e79eea82a6f5a59f (patch)
treeeb7708a72944bb15540e103b4319242199af6fbb /docs/USERGUIDE.md
parent5338894f7fec9e1a60affb0e2ff3b9797bcbc968 (diff)
downloadmeshbay-84b032c65e17267d41e04605e79eea82a6f5a59f.tar.gz
feat(groups): editable description, and one source of operator authority
A description could only be set the moment a group was created, so every group made before anyone thought of one stayed blank for good. The owner can now edit it from the group's page, and PATCH /v1/groups/{id} takes it. That endpoint takes the description and nothing else, deliberately. The name, the visibility and the join policy are the terms members joined on; a private group that can quietly become public is not the group they agreed to be in. Changing those needs a decision about who gets told, not a field on a form — there is a test saying so. Separately, the legacy operator key is gone. `admin_pk_ed25519` in node.toml named the operator before the roster existed and was kept so that an existing deployment would keep working; nothing uses it, and a second source of node authority is not something to carry around out of politeness. Authority is the roster, read fresh on every check. It is removed rather than ignored: a config that still names the key gets a warning at startup pointing at the file. Dropping it in silence would refuse invites and file deletion with a signature error that looks like a bug somewhere else — which is exactly how finding M3 presented. Two tests were verifying admin operations by naming a key in the context, which was the legacy path. They now pair an operator into a roster, the way an operator does. The authority test anchored on the deleted function and passed vacuously once it disappeared; it states the invariant against the verifier and the daemon instead. Also defined .btn-secondary, used in four places and styled in none. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Diffstat (limited to 'docs/USERGUIDE.md')
-rw-r--r--docs/USERGUIDE.md20
1 files changed, 20 insertions, 0 deletions
diff --git a/docs/USERGUIDE.md b/docs/USERGUIDE.md
index 214b6e9..8a1e405 100644
--- a/docs/USERGUIDE.md
+++ b/docs/USERGUIDE.md
@@ -221,6 +221,25 @@ Response:
Save `group_id` — you will need it in your `node.toml` and when adding members.
+### The description
+
+Set it at creation with `"description"`, or later from the group's page — the owner
+sees an **Edit description** link under the name. Members see it on their home page
+and, for public groups, in Explore.
+
+```
+PATCH /v1/groups/{group_id}
+Authorization: Bearer <access_token> (the group's owner)
+{"description": "host grenoble"}
+→ 200 {"group_id": "...", "description": "host grenoble"}
+```
+
+An empty string clears it; anything past 512 characters is trimmed rather than
+refused. The description is all this endpoint changes: the name, the visibility and
+the join policy are the terms members joined on, and a private group that could
+quietly become public is not the group they agreed to be in. Changing those needs a
+decision about who gets told, so it is not a field on a form.
+
### Public vs. private groups
| | Public | Private |
@@ -815,6 +834,7 @@ they speak MNP (§6), and their only HTTP surface is the operator's admin UI on
| POST | `/v1/groups` | Access token | Create group. Body: `name`. Returns `group_id`. |
| GET | `/v1/groups` | None / Access token | List/search groups. Private groups require membership. |
| GET | `/v1/groups/{group_id}` | None / Access token | Group metadata. |
+| PATCH | `/v1/groups/{group_id}` | Access token (owner) | Edit the description. Body: `description`. Nothing else is editable — see §3. |
| DELETE | `/v1/groups/{group_id}` | Access token (admin) | Revoke and delete group. |
**GEK distribution — removed.** The hub used to carry wrapped group keys between members.