aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-hub/src/meshbay_hub/static/group-page.js
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-09-30 16:58:31 +0200
committerChristophe Besson <cbesson@gmail.com>2026-09-30 16:58:31 +0200
commit6d167392f6f8ede37e2794a68a3738f8ba03131d (patch)
tree9caacef15dd034c6425f4bb623e0cd50a28ec52a /packages/meshbay-hub/src/meshbay_hub/static/group-page.js
parent8926f163dad9d32dc06c3a142658a4e11d9c12c1 (diff)
downloadmeshbay-6d167392f6f8ede37e2794a68a3738f8ba03131d.tar.gz
feat(client): the desktop application keeps M and every node identity in its main process
keyring.js derives, opens, mints, seals, signs and agrees there; the page gets public keys and a handle. Argon2 comes from the page's own WebAssembly build (Electron's crypto has none). Without OS key storage the page keeps its keys as a browser does. A node's bundle is settled after connecting, re-sealed when the key changed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub/static/group-page.js')
-rw-r--r--packages/meshbay-hub/src/meshbay_hub/static/group-page.js23
1 files changed, 10 insertions, 13 deletions
diff --git a/packages/meshbay-hub/src/meshbay_hub/static/group-page.js b/packages/meshbay-hub/src/meshbay_hub/static/group-page.js
index fcb905b..d2259b9 100644
--- a/packages/meshbay-hub/src/meshbay_hub/static/group-page.js
+++ b/packages/meshbay-hub/src/meshbay_hub/static/group-page.js
@@ -249,7 +249,7 @@ function GroupPage({ groupId, group, token, username, userId, userPrefs,
// it is asked for with that token. Persisted so this browser is set up
// from now on.
const { pepper, version } = await window.MeshBayKeys.fetchBundlePepper(token);
- session.bundleKey = await window.MeshBayKeys.deriveBundleSessionKey(
+ session.bundleKey = await window.MeshBayKeys.sessionBundleKey(
pass, username, userId, pepper, version);
await _storeBundleKey(session.bundleKey);
setPassInput('');
@@ -509,18 +509,15 @@ function GroupPage({ groupId, group, token, username, userId, userPrefs,
};
setOperatorPaired(transport.memberRole === 'operator');
- // A first join to this node generated an identity for it; leave it with
- // the node so any other browser can become the same person here with the
- // passphrase. It is this node's key and no other's.
- if (transport.connected && transport.newNodeBundle) {
- try {
- await transport.storeKeypairBundle(
- transport.newNodeBundle, transport.newNodeBundleRecovery);
- transport.newNodeBundle = null;
- transport.newNodeBundleRecovery = null;
- } catch (e) {
- console.warn('[MeshBay] could not leave our key with the node:', e.message);
- }
+ // What this node should hold of our identity: the bundle of one just
+ // created, so another browser can become the same person here — or, in
+ // the desktop application, whatever the account's browser access says.
+ // Not awaited: nothing on this page depends on it, and the group opens
+ // without waiting for a round trip to the node about a backup.
+ if (transport.connected) {
+ transport.settleNodeBundle().catch((e) => {
+ console.warn('[MeshBay] could not settle our key with the node:', e.message);
+ });
}
// Import GEK from transport (fetched from node during handshake)