aboutsummaryrefslogtreecommitdiffstats
path: root/docs/invite-pairing-v1.md
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-09-01 14:08:32 +0200
committerChristophe Besson <cbesson@gmail.com>2026-09-01 14:08:32 +0200
commitcfc91e0a424163869c64d30e55d55a53f18a3dbf (patch)
tree04ed3bbec11690f62f1e2a738bf89f4b763332e5 /docs/invite-pairing-v1.md
parentba45a3c94806f612fa62812e0b36d08b581a2e47 (diff)
downloadmeshbay-cfc91e0a424163869c64d30e55d55a53f18a3dbf.tar.gz
refactor(node): JSON-only control API, Node page absorbs the admin dashboard
Remove the node daemon's server-rendered admin UI (GET / and /audit, the _render_* helpers and inline templates) and the `meshbay-node ui` CLI verb. The loopback control API stays; it is now JSON only, ruff-clean, and 453 lines (was 1074). Also drop three never-wired endpoints (/api/config, /api/chat/history, /ws/chat, plus broadcast_chat) and the pointless 18000/tcp firewall profiles. The desktop client's Node page (static/node-page.js) takes over what the dashboard showed, reorganised into six tabs (Overview, Groups, Roster, Peers, Audit, Settings): - Overview: version, node id, QUIC port, hub, index-cache maintenance - Roster: node-wide view with unpin - Peers and Audit: auto-load on open, no Load button - Audit: real usernames and group names (resolved from the roster and node.toml), Previous/Next pagination newest-first, Export CSV of every matching row - Settings: node settings, STUN, ICE, denylist, then Unlink from hub Backend: audit.get_entries gains `offset`; /api/audit and /api/peers resolve ids to names via a new _display_names helper; CSP tightened to default-src 'none' now that no HTML is served. draft-v6 sections 2.11 and 2.12 corrected -- the Node page uses the loopback API, not MNP. One capability is intentionally dropped: browser-based admin on a headless server. The CLI covers every operation there. See docs/refactor-node-ui.md. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MQCaZnde4Bjjdu84dhSuF5
Diffstat (limited to 'docs/invite-pairing-v1.md')
-rw-r--r--docs/invite-pairing-v1.md4
1 files changed, 2 insertions, 2 deletions
diff --git a/docs/invite-pairing-v1.md b/docs/invite-pairing-v1.md
index ad36a1a..ee4d257 100644
--- a/docs/invite-pairing-v1.md
+++ b/docs/invite-pairing-v1.md
@@ -456,7 +456,7 @@ key material at all, and that the retired message reaches no handler.
|---|---|
| `member list` / `invite` / `revoke` / `unpin`, all over SSH, no browser | `daemon.main` |
| Roster endpoints behind the per-run session token (11.5.3) | `ui/app.py` |
-| Roster section in the local admin UI, every value escaped (H2) | `ui/app.py._render_roster` |
+| Roster view in the desktop client's Node page (Preact escapes by default; H2) | `static/node-page.js` |
| `_daemon_api` / `_resolve_group` — one loopback call path for every command | `daemon.py` |
| Codes written to `data_dir/invite-code` and `data_dir/pair-code` | `roster.write_code_file` |
@@ -494,7 +494,7 @@ longer window costs little — single use, one account, never seen by the hub, a
must cover `join_request`)
- `daemon.py` — `_resolve_admin_pk` → roster lookup with the legacy config fallback;
new CLI commands; `status` output
-- `ui/app.py` — roster and invites in the local admin UI, escaped as per 11.5.16
+- `ui/app.py` — roster and invites over the token-gated loopback API (JSON)
### Common
- `protocol.py` — four message constants