aboutsummaryrefslogtreecommitdiffstats
path: root/docs
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-09-30 12:57:58 +0200
committerChristophe Besson <cbesson@gmail.com>2026-09-30 12:57:58 +0200
commit2c6921aa2c35ffd41b6c453e6700574ef631ba2c (patch)
tree01c766e13607e4f957900bfd36b4f722e8c8b3c5 /docs
parent8a4651e9d223de856ff085b329801998f95db138 (diff)
downloadmeshbay-2c6921aa2c35ffd41b6c453e6700574ef631ba2c.tar.gz
fix(client): the page names node operations, and the app confirms what widens the node
node:call is replaced by named operations with checked arguments; hosting a group, sharing an unpicked folder, key rotation, denylist clearing and a change of node account are confirmed by a native dialog. Every channel checks its sender, secrets:get/set/clear are gone, node:start writes the app's own hub. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'docs')
-rw-r--r--docs/MESHBAY_DESIGN.md21
-rw-r--r--docs/USERGUIDE.md7
2 files changed, 26 insertions, 2 deletions
diff --git a/docs/MESHBAY_DESIGN.md b/docs/MESHBAY_DESIGN.md
index cd97aa2..d63f722 100644
--- a/docs/MESHBAY_DESIGN.md
+++ b/docs/MESHBAY_DESIGN.md
@@ -2261,7 +2261,24 @@ What running it establishes, and what each fact costs:
- **The device's hub key lives in the main process, never in the renderer.**
Generated, stored and used there; the interface asks for a signature and is never
handed a key. Same rule as the save dialog, and for the same reason: the renderer
- parses decrypted content from nodes, which is attacker-controlled input.
+ parses decrypted content from nodes, which is attacker-controlled input. The
+ secret store that holds it is not reachable from the page either: a generic
+ read and write by name was a way to take the key and to replace it, and nothing
+ in the interface used it.
+- **The page administers the local node by operation, never by route.** It names
+ one of the operations the interface performs (`NODE_OPS` in `main.js`); the main
+ process checks the arguments — ids are ids, names are encoded — builds the
+ request and adds the node's token. `node:start` writes the hub this application
+ is signed in to and a username the hub would register, never a value the page
+ supplies verbatim. **What widens what the node shares or admits, or replaces its
+ group key, is confirmed by a dialog the main process draws**: hosting a group,
+ sharing a folder not chosen in the native folder picker (one chosen there is its
+ own confirmation, so the ordinary path asks nothing twice), rotating the key,
+ clearing the denylist, and pointing the node at another account. The words come
+ from the interface's catalogues, read by the main process; the page sets the
+ language and nothing else. An in-page confirmation is one a script in the page
+ can answer for itself. **Every channel answers only the packaged page's top-level
+ document.**
- **OS-backed secret storage is real on a desktop and honest without one.** With a
keyring it is keyring-backed; headless, the same code reports unavailable and
**refuses to store rather than downgrading silently**.
@@ -3435,7 +3452,7 @@ had already been asked.
| **O1** | Initial key setup in the pre-proof window — deferred; that window is where C4 and C5b came from |
| **O2** | A LAN enrolment door — one endpoint, bounded window, one-time code, closing permanently on success |
| **O3** | `device_policy {allow_bundle: false}`, signed by a pinned key — **the mechanism that actually closes C4** (§3.7) |
-| **O4** | Isolating the node-admin panel from the process holding user keys |
+| **O4** | Isolating the node-admin panel from the process holding user keys. **Narrowed**: the panel reaches the node through named operations, and what widens the node is confirmed natively (§8.2); it still runs in the renderer that parses node content |
| **O5** | An unlock key in the environment, for the **node** |
| **O6** | The engine version floor, verified rather than assumed |
| **O8** | A minimum client version in the hub version endpoint — **done** (§5.6) |
diff --git a/docs/USERGUIDE.md b/docs/USERGUIDE.md
index a802ae1..e190a92 100644
--- a/docs/USERGUIDE.md
+++ b/docs/USERGUIDE.md
@@ -203,6 +203,13 @@ any. So the application is the one to prefer for anything you care about. The
browser stays, and is a perfectly reasonable way to use MeshBay — being able to
open a group on someone else's laptop with nothing installed is worth having.
+The application asks in a small window of its own, not in the page, before it
+hosts a group on this computer, shares a folder you did not pick in its folder
+dialog, replaces a group's key, clears the denylist, or points the node at
+another account. A folder you pick in the folder dialog is not asked about
+twice. That window belongs to the application, so nothing displayed in the page
+— which shows content from other people's nodes — can answer it for you.
+
---
## 4. Joining a group