aboutsummaryrefslogtreecommitdiffstats
path: root/docs
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-09-28 22:39:05 +0200
committerChristophe Besson <cbesson@gmail.com>2026-09-28 22:39:05 +0200
commit215864bf655f7dcb793e80c836598655d6d945a9 (patch)
tree2213bb56f97137c97c1b50eb6ce19e9394862b6c /docs
parentaaa372f862ffb7fd093da699e483c9118381e2cc (diff)
downloadmeshbay-215864bf655f7dcb793e80c836598655d6d945a9.tar.gz
docs: keypair_bundle_delete is reserved for device_policy (O3)
The node honours it and no interface sends it; offered alone it would strand the next browser that signs in. Stated in both documents. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'docs')
-rw-r--r--docs/MESHBAY_DESIGN.md3
-rw-r--r--docs/MESHBAY_NODE_PROTOCOL.md4
2 files changed, 6 insertions, 1 deletions
diff --git a/docs/MESHBAY_DESIGN.md b/docs/MESHBAY_DESIGN.md
index f152883..c37e43b 100644
--- a/docs/MESHBAY_DESIGN.md
+++ b/docs/MESHBAY_DESIGN.md
@@ -618,7 +618,8 @@ control. It closes for a native device unconditionally, because that device's ke
is in no bundle anywhere. It closes for an *account* only when no browser needs a
bundle on that node — which needs `device_policy {allow_bundle: false}`, **signed
by a pinned key** so the decision is the user's and never the hub's (open item
-O3).
+O3). Withdrawing a bundle already exists on the wire (`keypair_bundle_delete`) and
+is not offered in the interface: it belongs with that decision, not before it.
---
diff --git a/docs/MESHBAY_NODE_PROTOCOL.md b/docs/MESHBAY_NODE_PROTOCOL.md
index 2e314f2..c3254da 100644
--- a/docs/MESHBAY_NODE_PROTOCOL.md
+++ b/docs/MESHBAY_NODE_PROTOCOL.md
@@ -663,6 +663,10 @@ nodes.
* Identity keys are **per node**. There is nothing to carry between nodes, and an
operator who cracks the copy on their own disk gets a key that opens nothing
anywhere else.
+* `keypair_bundle_delete` is **reserved for `device_policy`** (`MESHBAY_DESIGN.md`
+ §3.7, open item O3): the node honours it, and no interface sends it yet. Withdrawing
+ the bundle is only safe once the account has chosen not to need it from a browser —
+ a lone button would strand the next browser that signs in.
### 7.1a Per-account blobs (MNP 3.1)