aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-hub/src/meshbay_hub/static/group-page.js
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-09-30 17:13:40 +0200
committerChristophe Besson <cbesson@gmail.com>2026-09-30 17:13:40 +0200
commitb1ebcdeb9082457972c41a47e77494902335d262 (patch)
treeb19384b868197ecda88ce79765a0f60812dbc815 /packages/meshbay-hub/src/meshbay_hub/static/group-page.js
parent6d167392f6f8ede37e2794a68a3738f8ba03131d (diff)
downloadmeshbay-b1ebcdeb9082457972c41a47e77494902335d262.tar.gz
feat: browser access, decided in the desktop application
Off for an account made there: its identities stay on the device and nothing is left on nodes. Turned on from the Profile page behind a native confirmation; each node is settled when its group next opens. The hub keeps a mirror a browser reads to say why a group will not open; it grants nothing. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub/static/group-page.js')
-rw-r--r--packages/meshbay-hub/src/meshbay_hub/static/group-page.js14
1 files changed, 14 insertions, 0 deletions
diff --git a/packages/meshbay-hub/src/meshbay_hub/static/group-page.js b/packages/meshbay-hub/src/meshbay_hub/static/group-page.js
index d2259b9..4510848 100644
--- a/packages/meshbay-hub/src/meshbay_hub/static/group-page.js
+++ b/packages/meshbay-hub/src/meshbay_hub/static/group-page.js
@@ -9,6 +9,7 @@ import {
HUB, session, hubFetch, ensureFreshToken,
_loadBundleKey, _loadRecoveryKey, _storeBundleKey,
} from './hub-client.js';
+import * as platform from './platform.js';
import { APPS, visibleApps } from './apps.js';
import { GroupName } from './group-name.js';
import { useStickyBand } from './sticky.js';
@@ -202,6 +203,17 @@ function GroupPage({ groupId, group, token, username, userId, userPrefs,
// This browser holds a key the node does not know, for an account it does.
// Not the operator's problem: a device already paired here can admit it.
const [needsDevice, setNeedsDevice] = useState(false);
+ // In a browser, for an account whose identities the desktop application
+ // keeps to itself: said when this group cannot be opened here, so the way
+ // in is named — the application — instead of a code nobody can use. Starts
+ // as "native" so the application never flashes a notice about itself.
+ const [nativeKeys, setNativeKeys] = useState(true);
+ useEffect(() => {
+ let gone = false;
+ platform.nativeKeys().then((n) => { if (!gone) setNativeKeys(n); }, () => {});
+ return () => { gone = true; };
+ }, []);
+ const browserAccessOff = !nativeKeys && userPrefs && userPrefs.browser_access === 'off';
const [deviceCode, setDeviceCode] = useState('');
const [codeInput, setCodeInput] = useState('');
// This browser has never derived the passphrase-bundle key (fresh browser,
@@ -905,6 +917,8 @@ function GroupPage({ groupId, group, token, username, userId, userPrefs,
</button>
`}
</div>
+ ${browserAccessOff && (error || needsDevice || needsCode || needsPass) && html`
+ <p class="settings-hint" style="margin-bottom:12px">${t('group.browser_access_off')}</p>`}
${error && html`<div class="error-msg" style="margin-bottom:12px">${error}${' '}
<button class="admin-btn" style="margin-left:8px;font-size:0.9em"
onClick=${() => setRetryKey(k => k + 1)}>${t('group.retry')}</button>