aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-hub/src/meshbay_hub/db/models.py
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-10-09 12:08:31 +0200
committerChristophe Besson <cbesson@gmail.com>2026-10-09 12:08:31 +0200
commit6832df6177ad973ad0e1b4f0a49d7a6da06c6e04 (patch)
treed9040ce0da5d82400d1b973344615ca1c6b67b3c /packages/meshbay-hub/src/meshbay_hub/db/models.py
parent2860f1de75af1d44d35292ecbf79c68f02409d19 (diff)
downloadmeshbay-6832df6177ad973ad0e1b4f0a49d7a6da06c6e04.tar.gz
feat: notifications on Android while closed, with nothing to install
The phone fetches what is new every fifteen minutes with a poll secret (POST /v1/push/poll) that reads notification lines and nothing else. When a UnifiedPush distributor is already installed, the hub also pushes at once, encrypted to the phone (RFC 8291); losing the distributor falls back to fetching. The hub now honours "disable all notifications" itself: create_notification creates nothing for that account, as it already did for a muted group, so neither switch lets anything reach a phone. The interface used to be the only reader of the account-wide switch. Push endpoints are member-supplied URLs: a send refuses non-public addresses, connects to the address it checked, and follows no redirect. Android build untested here (no SDK on this machine). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub/db/models.py')
-rw-r--r--packages/meshbay-hub/src/meshbay_hub/db/models.py28
1 files changed, 28 insertions, 0 deletions
diff --git a/packages/meshbay-hub/src/meshbay_hub/db/models.py b/packages/meshbay-hub/src/meshbay_hub/db/models.py
index dbc0f10..7291485 100644
--- a/packages/meshbay-hub/src/meshbay_hub/db/models.py
+++ b/packages/meshbay-hub/src/meshbay_hub/db/models.py
@@ -398,6 +398,34 @@ class ContentReview(Base):
decided_by: Mapped[str | None] = mapped_column(String(64))
+class PushSubscription(Base):
+ """A phone told about this account's notifications (§11.3): pushed to its
+ Web Push endpoint when it has one, fetched with its poll secret when not.
+
+ The endpoint is a capability — whoever holds the URL can wake the phone —
+ and the keys are what the hub encrypts to, so the push server relays bytes
+ it cannot read. One account holds a handful at most
+ (`api/push.MAX_SUBSCRIPTIONS`): the rows are shared, and every notification
+ costs one outbound request per row.
+ """
+
+ __tablename__ = "push_subscriptions"
+
+ id: Mapped[str] = mapped_column(String(36), primary_key=True, default=_uuid)
+ user_id: Mapped[str] = mapped_column(ForeignKey("users.id"), nullable=False)
+ # All three empty for a phone with no push distributor, which fetches instead.
+ endpoint: Mapped[str | None] = mapped_column(String(1024), nullable=True)
+ p256dh: Mapped[str | None] = mapped_column(String(128), nullable=True)
+ auth: Mapped[str | None] = mapped_column(String(32), nullable=True)
+ # sha256 of the secret `POST /v1/push/poll` is answered for; never the secret.
+ poll_hash: Mapped[str | None] = mapped_column(String(64), nullable=True)
+ created_at: Mapped[datetime] = mapped_column(DateTime(timezone=True), default=_now)
+
+ __table_args__ = (
+ Index("ix_push_subscriptions_user_endpoint", "user_id", "endpoint", unique=True),
+ )
+
+
class UserPreference(Base):
__tablename__ = "user_preferences"