diff options
| author | Christophe Besson <cbesson@gmail.com> | 2026-09-30 17:13:40 +0200 |
|---|---|---|
| committer | Christophe Besson <cbesson@gmail.com> | 2026-09-30 17:13:40 +0200 |
| commit | b1ebcdeb9082457972c41a47e77494902335d262 (patch) | |
| tree | b19384b868197ecda88ce79765a0f60812dbc815 /packages/meshbay-hub/src/meshbay_hub/static/group-page.js | |
| parent | 6d167392f6f8ede37e2794a68a3738f8ba03131d (diff) | |
| download | meshbay-b1ebcdeb9082457972c41a47e77494902335d262.tar.gz | |
feat: browser access, decided in the desktop application
Off for an account made there: its identities stay on the device and nothing is
left on nodes. Turned on from the Profile page behind a native confirmation;
each node is settled when its group next opens. The hub keeps a mirror a
browser reads to say why a group will not open; it grants nothing.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub/static/group-page.js')
| -rw-r--r-- | packages/meshbay-hub/src/meshbay_hub/static/group-page.js | 14 |
1 files changed, 14 insertions, 0 deletions
diff --git a/packages/meshbay-hub/src/meshbay_hub/static/group-page.js b/packages/meshbay-hub/src/meshbay_hub/static/group-page.js index d2259b9..4510848 100644 --- a/packages/meshbay-hub/src/meshbay_hub/static/group-page.js +++ b/packages/meshbay-hub/src/meshbay_hub/static/group-page.js @@ -9,6 +9,7 @@ import { HUB, session, hubFetch, ensureFreshToken, _loadBundleKey, _loadRecoveryKey, _storeBundleKey, } from './hub-client.js'; +import * as platform from './platform.js'; import { APPS, visibleApps } from './apps.js'; import { GroupName } from './group-name.js'; import { useStickyBand } from './sticky.js'; @@ -202,6 +203,17 @@ function GroupPage({ groupId, group, token, username, userId, userPrefs, // This browser holds a key the node does not know, for an account it does. // Not the operator's problem: a device already paired here can admit it. const [needsDevice, setNeedsDevice] = useState(false); + // In a browser, for an account whose identities the desktop application + // keeps to itself: said when this group cannot be opened here, so the way + // in is named — the application — instead of a code nobody can use. Starts + // as "native" so the application never flashes a notice about itself. + const [nativeKeys, setNativeKeys] = useState(true); + useEffect(() => { + let gone = false; + platform.nativeKeys().then((n) => { if (!gone) setNativeKeys(n); }, () => {}); + return () => { gone = true; }; + }, []); + const browserAccessOff = !nativeKeys && userPrefs && userPrefs.browser_access === 'off'; const [deviceCode, setDeviceCode] = useState(''); const [codeInput, setCodeInput] = useState(''); // This browser has never derived the passphrase-bundle key (fresh browser, @@ -905,6 +917,8 @@ function GroupPage({ groupId, group, token, username, userId, userPrefs, </button> `} </div> + ${browserAccessOff && (error || needsDevice || needsCode || needsPass) && html` + <p class="settings-hint" style="margin-bottom:12px">${t('group.browser_access_off')}</p>`} ${error && html`<div class="error-msg" style="margin-bottom:12px">${error}${' '} <button class="admin-btn" style="margin-left:8px;font-size:0.9em" onClick=${() => setRetryKey(k => k + 1)}>${t('group.retry')}</button> |