aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-common/src/meshbay_common/adminop.py
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-10-02 11:54:56 +0200
committerChristophe Besson <cbesson@gmail.com>2026-10-02 11:54:56 +0200
commitd7b7f1049d95e45e6316ac419cb434088c15bd5e (patch)
tree77da46e2fe3cb70af5fb2eebcbb1d69dad410b88 /packages/meshbay-common/src/meshbay_common/adminop.py
parent56a8cf9167e8c7b0f2df15afed88031608adf782 (diff)
parent754387590fa1754436b4648f969915888c6f6c9e (diff)
downloadmeshbay-d7b7f1049d95e45e6316ac419cb434088c15bd5e.tar.gz
Merge branch 'main' of meshbay.org:meshbayHEADmain
Diffstat (limited to 'packages/meshbay-common/src/meshbay_common/adminop.py')
-rw-r--r--packages/meshbay-common/src/meshbay_common/adminop.py45
1 files changed, 14 insertions, 31 deletions
diff --git a/packages/meshbay-common/src/meshbay_common/adminop.py b/packages/meshbay-common/src/meshbay_common/adminop.py
index 4379519..bd7a439 100644
--- a/packages/meshbay-common/src/meshbay_common/adminop.py
+++ b/packages/meshbay-common/src/meshbay_common/adminop.py
@@ -47,14 +47,6 @@ OP_INVITE_LINK_CREATE = "invite_link_create"
# Taking back an unredeemed link, by the handle it was issued with.
OP_INVITE_CANCEL = "invite_cancel"
OP_MEMBER_REVOKE = "member_revoke"
-# Rotating the group key is what actually takes it away from a revoked member:
-# revocation stops the node serving the *next* key, and they still hold the
-# current one. The node generates the new key itself with its own CSPRNG, so
-# nothing arriving over MNP contributes key material — the C5b rule is about
-# key material from outside, not about the instruction.
-OP_GEK_ROTATE = "gek_rotate"
-# Forgetting a pinned identity, so someone can pair again after losing a device.
-OP_MEMBER_UNPIN = "member_unpin"
# Which group "applications" (Chat, Files, and whatever registers later) are
# shown to members. Signed like the rest: it decides what a member sees, not
# anything about key material, but an unsigned toggle would let any member
@@ -67,11 +59,6 @@ OP_APPS_ENABLED = "apps_enabled"
# security property in itself, but the pattern (every operator setting is
# signed) is what keeps the authorization model simple to reason about.
OP_SET_SCAN_SETTINGS = "set_scan_settings"
-# How many transfers one member may run at once in this group. Signed like the
-# rest: an unsigned cap is one any member can raise for themselves, which makes
-# the control a suggestion. The subject is "d=2,u=2" so what the operator is
-# shown before signing names the outcome and not the operation.
-OP_TRANSFER_LIMITS = "transfer_limits"
# Whether the node uses the operator's own API token/language instead of the
# shipped default — node-wide (docs/MESHBAY_DESIGN.md §9.7), one credential
# shared by every group. Signed like the rest: it turns on outbound
@@ -101,7 +88,6 @@ OP_TMDB_REMATCH = "tmdb_rematch"
# the lesson was already learned once). Signed for the same reason as
# tmdb_enabled.
OP_MUSICBRAINZ_ENABLED = "musicbrainz_enabled"
-OP_ROOT_ADD = "root_add"
OP_ROOT_REMOVE = "root_remove"
# One op for every application's directories. The subject is
# "<app>:<comma-joined sorted paths>" so what the operator is shown before
@@ -115,18 +101,26 @@ OP_CHAT_LINK_PREVIEW = "chat_link_preview"
# operator's, signed like the other per-group switches.
OP_SEARCH_LISTED = "search_listed"
# Open a new chat epoch for a group, by hand. The removals that matter open one
-# by themselves (member revoke/unpin, device revoke, gek_rotate); this is the
-# operator saying "do it anyway", which is the same shape as `gek_rotate` and
-# signed for the same reason.
+# by themselves (member revoke/unpin, device revoke, group key rotation); this is the
+# operator saying "do it anyway", and is signed like the rest.
#
# There is no op for *enabling* chat encryption. It is not a setting — MNP 2.0
# has no plaintext chat to fall back to.
OP_CHAT_EPOCH = "chat_epoch"
-OP_ROOT_UPDATE = "root_update"
OP_ROOT_EJECT = "root_eject"
OP_ROOT_PLUG = "root_plug"
-OP_GROUP_ATTACH = "group_attach"
-OP_GROUP_DETACH = "group_detach"
+# Also gone with 6.0, because no client ever sent them: `gek_rotate`,
+# `member_unpin`, `transfer_limits` and `group_detach`. Rotating the group key,
+# forgetting an identity, the per-member transfer caps and no longer hosting a
+# group are done on the node's machine — the desktop application's Node page
+# or the CLI. A door nobody uses is an untested way in.
+# OP_ROOT_ADD, OP_ROOT_UPDATE and OP_GROUP_ATTACH are gone (MNP 6.0). Each one
+# chose what of the operator's disk is shared and who may write there, and a
+# signature proves only that the operator's key signed — in a browser, through
+# code the hub serves; on the desktop, through a renderer that parses content
+# from nodes. Sharing a folder, hosting a group and opening a folder to writes
+# are done on the node's own machine (loopback) or with
+# the CLI, and a message that does not exist cannot be mis-authorized.
# OP_GEK_BUNDLE_STORE is gone. Members no longer hand the node key material at
# all: the node holds the GEK and wraps it itself, for a key the recipient proved
# they hold (see `join.py` and docs/MESHBAY_DESIGN.md §3.4). The operation existed
@@ -159,17 +153,6 @@ def secret_digest(value: str | None) -> str | None:
return "sha256:" + hashlib.sha256(value.encode()).hexdigest()
-def root_add_subject(path: str, name: str, kind: str, writable: bool,
- removable: bool) -> str:
- return structured_subject({"path": path, "name": name, "kind": kind,
- "writable": writable, "removable": removable})
-
-
-def group_attach_subject(name: str, shared_dir: str, writable: bool) -> str:
- return structured_subject({"name": name, "shared_dir": shared_dir,
- "writable": writable})
-
-
def invite_create_subject(user_id: str, username: str) -> str:
return structured_subject({"user_id": user_id, "username": username})