diff options
| author | Christophe Besson <cbesson@gmail.com> | 2026-10-09 12:16:51 +0200 |
|---|---|---|
| committer | Christophe Besson <cbesson@gmail.com> | 2026-10-09 12:17:38 +0200 |
| commit | 4ae61dc4e1dcca6ae24131fcd9acc55124e3c0af (patch) | |
| tree | 44fd15f6175ade9b0b884f846dfd9d66e2b3bc80 /docs | |
| parent | 6832df6177ad973ad0e1b4f0a49d7a6da06c6e04 (diff) | |
| download | meshbay-4ae61dc4e1dcca6ae24131fcd9acc55124e3c0af.tar.gz | |
feat: let the operator purge a group's chat (MNP 6.1)
Signed chat_purge from the Chat settings deletes every stored message;
epoch keys and attachments stay. The ack is broadcast so open chat
panels empty.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'docs')
| -rw-r--r-- | docs/MESHBAY_DESIGN.md | 7 | ||||
| -rw-r--r-- | docs/MESHBAY_NODE_PROTOCOL.md | 7 | ||||
| -rw-r--r-- | docs/USERGUIDE.md | 3 |
3 files changed, 14 insertions, 3 deletions
diff --git a/docs/MESHBAY_DESIGN.md b/docs/MESHBAY_DESIGN.md index b874632..c0ccbbc 100644 --- a/docs/MESHBAY_DESIGN.md +++ b/docs/MESHBAY_DESIGN.md @@ -16,7 +16,7 @@ > them — it names the invariant that holds today, not the incident that produced > it. §13 is the register of those labels. > -> Wire versions at the time of writing: **MNP 6.0** (oldest peer accepted 4.0), +> Wire versions at the time of writing: **MNP 6.1** (oldest peer accepted 4.0), > **MHP 0.1**, packages **0.19.0**. The normative source for the wire format is > `MESHBAY_NODE_PROTOCOL.md`; this document states the design the protocol > serves, not its byte layout. @@ -1838,7 +1838,10 @@ chat opens at the newest page. A forwards pager is not what a chat opens with. `meshbay-node chat prune <days>` deletes **messages only, never an epoch key**. An epoch with no messages is harmless; an epoch key deleted while messages still need -it is an unreadable archive. +it is an unreadable archive. The operator's purge (the signed `chat_purge`, from +the Chat settings) is the same rule with no age: every message goes, the epoch +keys and the attachments stay. The replay index goes with the rows, which costs +nothing, since a sealed message is taken only from the device that signed it. **A message is bounded in size and in rate, like every other member-supplied write.** Sending one costs the operator a row that nothing expires, every other diff --git a/docs/MESHBAY_NODE_PROTOCOL.md b/docs/MESHBAY_NODE_PROTOCOL.md index 0045f78..1355aaa 100644 --- a/docs/MESHBAY_NODE_PROTOCOL.md +++ b/docs/MESHBAY_NODE_PROTOCOL.md @@ -1173,6 +1173,7 @@ broadcast, every connected peer in the group learns the change without reconnect | `chat_link_preview` | `on\|off` | operator | `chat_link_preview_ack{enabled}` | yes | | `search_listed` | `on\|off` | operator | `search_listed_ack{listed}` | yes | | `chat_epoch` | `group_id` | operator | `chat_epoch_ack{epoch}` | yes | +| `chat_purge` | `group_id`, always the connection's group | operator | `chat_purge_ack{removed}` | yes: every open chat panel empties | **Upload policy is not in this table**, and that is the design: whether a member may write is a property of each root (its `writable` flag), not a switch over the group. A single @@ -2126,6 +2127,7 @@ it back (§3.5). | `client_diag` | C→N | auth | the video player's own view of a stream, written to the node's log beside its own (a stream event at INFO, the periodic state at DEBUG); the node acts on none of it and sends no reply | | `member_revoke` / `_ack` | C→N / N→C | signed | stop serving the key to someone | | `chat_epoch` / `_ack` | C→N / N⇒C | signed | open a new chat epoch by hand | +| `chat_purge` / `_ack` | C→N / N⇒C | signed | delete the group's stored chat; epoch keys and attachments stay (6.1) | | `app_directories` / `_ack` | C→N / N⇒C | signed | one application's folders, keyed by app name | | `chat_directory` / `_ack` | C→N / N⇒C | signed | where chat attachments are written | | `chat_link_preview` / `_ack` | C→N / N⇒C | signed | whether the node unfurls posted links | @@ -2175,7 +2177,7 @@ message: ## 13. Versioning and compatibility -MNP versions independently of the package version. Current: **`6.0`**; oldest peer +MNP versions independently of the package version. Current: **`6.1`**; oldest peer accepted: **`4.0`**. 4.0 is the floor: a member presents a short-lived node-audience token bound to one node @@ -2198,6 +2200,9 @@ ten operator messages no client ever sent (§10.4, "The node's own controls"). T also refuses to sign them, so a node older than 6.0 cannot be driven into them by a script in its page either. +6.1 adds the signed `chat_purge` (§10.4), additively: a 6.0 node gives no +answer, as for any unknown type, and nothing else changes. + The two numbers are separate on purpose. `MNP_VERSION` says what this build speaks; `MNP_MIN_SUPPORTED` says what it will talk to, and moving the second is a decision about whether an older peer can still do anything useful: diff --git a/docs/USERGUIDE.md b/docs/USERGUIDE.md index eb659e1..9db9748 100644 --- a/docs/USERGUIDE.md +++ b/docs/USERGUIDE.md @@ -323,6 +323,9 @@ previews. off. - **History is kept on the node**, and stays readable to members. A member removed from the group cannot read anything written after their removal. +- The operator can **purge the chat** from the group's Settings, Chat + section: every message goes, for everyone, and cannot be brought back. + Attachments stay in their folder. - Sometimes a message reads *"Written before this device could read this conversation"* — that is a device added later, not an error. A message marked *"the signature does not match the sender"* is different and worth asking |