diff options
| author | Christophe Besson <cbesson@gmail.com> | 2026-09-30 16:58:31 +0200 |
|---|---|---|
| committer | Christophe Besson <cbesson@gmail.com> | 2026-09-30 16:58:31 +0200 |
| commit | 6d167392f6f8ede37e2794a68a3738f8ba03131d (patch) | |
| tree | 9caacef15dd034c6425f4bb623e0cd50a28ec52a /packages/meshbay-client/src/preload.js | |
| parent | 8926f163dad9d32dc06c3a142658a4e11d9c12c1 (diff) | |
| download | meshbay-6d167392f6f8ede37e2794a68a3738f8ba03131d.tar.gz | |
feat(client): the desktop application keeps M and every node identity in its main process
keyring.js derives, opens, mints, seals, signs and agrees there; the page gets
public keys and a handle. Argon2 comes from the page's own WebAssembly build
(Electron's crypto has none). Without OS key storage the page keeps its keys as
a browser does. A node's bundle is settled after connecting, re-sealed when the
key changed.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'packages/meshbay-client/src/preload.js')
| -rw-r--r-- | packages/meshbay-client/src/preload.js | 26 |
1 files changed, 26 insertions, 0 deletions
diff --git a/packages/meshbay-client/src/preload.js b/packages/meshbay-client/src/preload.js index 632718b..469bc48 100644 --- a/packages/meshbay-client/src/preload.js +++ b/packages/meshbay-client/src/preload.js @@ -80,6 +80,32 @@ contextBridge.exposeInMainWorld('meshbay', { forget: () => ipcRenderer.invoke('device:forget'), }, + // The account's bundle key and its identity on every node (keyring.js). + // Held in the main process: the interface is told public keys and handed + // signatures and agreements, never a private key or the key that opens + // bundles. Bytes cross as base64. + keys: { + available: () => ipcRenderer.invoke('keys:available'), + deriveSession: (o) => ipcRenderer.invoke('keys:derive-session', o), + commitPending: (u) => ipcRenderer.invoke('keys:commit-pending', u), + dropPending: (u) => ipcRenderer.invoke('keys:drop-pending', u), + hasSession: (u) => ipcRenderer.invoke('keys:has-session', u), + forgetSession: (u) => ipcRenderer.invoke('keys:forget-session', u), + identity: (u, n) => ipcRenderer.invoke('keys:identity', u, n), + openBundle: (u, n, o) => ipcRenderer.invoke('keys:open-bundle', u, n, o), + mint: (u, n) => ipcRenderer.invoke('keys:mint', u, n), + sealBundle: (u, n, o) => ipcRenderer.invoke('keys:seal-bundle', u, n, o), + sealRecovery: (u, n, m, name) => ipcRenderer.invoke('keys:seal-recovery', u, n, m, name), + markSealed: (u, n, fp) => ipcRenderer.invoke('keys:mark-sealed', u, n, fp), + fingerprint: (u) => ipcRenderer.invoke('keys:fingerprint', u), + sign: (u, n, bytes) => ipcRenderer.invoke('keys:sign', u, n, bytes), + shared: (u, n, peer) => ipcRenderer.invoke('keys:shared', u, n, peer), + playlistKey: (u) => ipcRenderer.invoke('keys:playlist-key', u), + browserAccess: (u) => ipcRenderer.invoke('keys:browser-access', u), + setBrowserAccess: (u, on) => ipcRenderer.invoke('keys:set-browser-access', u, on), + createdHere: (u) => ipcRenderer.invoke('keys:created-here', u), + }, + // Whether the OS protects what the main process stores. The store itself is // not reachable from here: it holds the device key above. secrets: { |