diff options
| author | Christophe Besson <cbesson@gmail.com> | 2026-10-09 12:08:31 +0200 |
|---|---|---|
| committer | Christophe Besson <cbesson@gmail.com> | 2026-10-09 12:08:31 +0200 |
| commit | 6832df6177ad973ad0e1b4f0a49d7a6da06c6e04 (patch) | |
| tree | d9040ce0da5d82400d1b973344615ca1c6b67b3c /packages/meshbay-hub/src/meshbay_hub/api/users.py | |
| parent | 2860f1de75af1d44d35292ecbf79c68f02409d19 (diff) | |
| download | meshbay-6832df6177ad973ad0e1b4f0a49d7a6da06c6e04.tar.gz | |
feat: notifications on Android while closed, with nothing to install
The phone fetches what is new every fifteen minutes with a poll secret
(POST /v1/push/poll) that reads notification lines and nothing else. When a
UnifiedPush distributor is already installed, the hub also pushes at once,
encrypted to the phone (RFC 8291); losing the distributor falls back to
fetching.
The hub now honours "disable all notifications" itself: create_notification
creates nothing for that account, as it already did for a muted group, so
neither switch lets anything reach a phone. The interface used to be the only
reader of the account-wide switch.
Push endpoints are member-supplied URLs: a send refuses non-public
addresses, connects to the address it checked, and follows no redirect.
Android build untested here (no SDK on this machine).
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub/api/users.py')
| -rw-r--r-- | packages/meshbay-hub/src/meshbay_hub/api/users.py | 3 |
1 files changed, 3 insertions, 0 deletions
diff --git a/packages/meshbay-hub/src/meshbay_hub/api/users.py b/packages/meshbay-hub/src/meshbay_hub/api/users.py index 795a902..130240e 100644 --- a/packages/meshbay-hub/src/meshbay_hub/api/users.py +++ b/packages/meshbay-hub/src/meshbay_hub/api/users.py @@ -46,6 +46,7 @@ from meshbay_hub.db.models import ( KnownBrowser, Node, Notification, + PushSubscription, RefreshToken, User, UserDevice, @@ -1361,6 +1362,7 @@ async def password_reset( .values(revoked=True)) await db.execute(delete(UserDevice).where(UserDevice.user_id == user.id)) await db.execute(delete(KnownBrowser).where(KnownBrowser.user_id == user.id)) + await db.execute(delete(PushSubscription).where(PushSubscription.user_id == user.id)) # A code sent to the address on file is a stronger proof than a passphrase, # and it is the way out of a lockout somebody else caused. await login_throttle.clear(db, user.username) @@ -1579,6 +1581,7 @@ async def erase_account(db: AsyncSession, user: User, owned_groups: str = "refus await db.execute(delete(Node).where(Node.user_id == user.id)) await db.execute(delete(UserDevice).where(UserDevice.user_id == user.id)) await db.execute(delete(KnownBrowser).where(KnownBrowser.user_id == user.id)) + await db.execute(delete(PushSubscription).where(PushSubscription.user_id == user.id)) await db.execute(delete(EmailVerification).where(EmailVerification.user_id == user.id)) # Links this account issued for a group it no longer owns; the ones for its # own groups went with them above. A used link keeps pointing at the |