aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-client/src/transcripts.js
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-10-02 11:54:56 +0200
committerChristophe Besson <cbesson@gmail.com>2026-10-02 11:54:56 +0200
commitd7b7f1049d95e45e6316ac419cb434088c15bd5e (patch)
tree77da46e2fe3cb70af5fb2eebcbb1d69dad410b88 /packages/meshbay-client/src/transcripts.js
parent56a8cf9167e8c7b0f2df15afed88031608adf782 (diff)
parent754387590fa1754436b4648f969915888c6f6c9e (diff)
downloadmeshbay-d7b7f1049d95e45e6316ac419cb434088c15bd5e.tar.gz
Merge branch 'main' of meshbay.org:meshbayHEADmain
Diffstat (limited to 'packages/meshbay-client/src/transcripts.js')
-rw-r--r--packages/meshbay-client/src/transcripts.js16
1 files changed, 15 insertions, 1 deletions
diff --git a/packages/meshbay-client/src/transcripts.js b/packages/meshbay-client/src/transcripts.js
index 0b6d0c0..8b0f6ef 100644
--- a/packages/meshbay-client/src/transcripts.js
+++ b/packages/meshbay-client/src/transcripts.js
@@ -30,6 +30,20 @@ function lenPrefixed(prefix, parts) {
return Buffer.concat(chunks);
}
+// The signed operations this application asks a node to perform
+// (meshbay_common/adminop.py). A list, not a pattern: what widens a node's
+// sharing — `root_add`, `root_update`, `group_attach`, gone from MNP 6.0 — is
+// never signed here, so a node older than that cannot be driven into it by a
+// script in the page either.
+const ADMIN_OPS = new Set([
+ 'file_delete', 'dir_delete', 'invite_create', 'invite_link_create',
+ 'invite_cancel', 'member_revoke', 'apps_enabled', 'set_scan_settings',
+ 'tmdb_config', 'tmdb_enabled', 'tmdb_override', 'tmdb_rematch',
+ 'musicbrainz_enabled', 'root_remove', 'root_eject', 'root_plug',
+ 'app_directories', 'chat_directory', 'chat_link_preview', 'search_listed',
+ 'chat_epoch',
+]);
+
// ── Field checks ──────────────────────────────────────────────────────────
//
// Shapes, not trust: what is checked here is that a field is what its name
@@ -143,7 +157,7 @@ function transcriptFor(kind, f, ctx) {
}
case 'admin': {
const op = String(fields.op ?? '');
- if (!/^[a-z_]{1,32}$/.test(op)) refuse('not an operation');
+ if (!ADMIN_OPS.has(op)) refuse('not an operation');
return lenPrefixed(PREFIX.admin, [
enc(op), enc(sameNode()), enc(groupId(fields.groupId)),
enc(text(fields.subject, 'the subject', 16384)),