aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-hub/src/meshbay_hub/static/transport-admin.js
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-09-30 15:48:51 +0200
committerChristophe Besson <cbesson@gmail.com>2026-09-30 15:48:51 +0200
commit8926f163dad9d32dc06c3a142658a4e11d9c12c1 (patch)
tree4d36d1c18154cb46e6e80c59ef6c607972caa81e /packages/meshbay-hub/src/meshbay_hub/static/transport-admin.js
parent8d96cf2314b45e0737f932998b5422c27a2ae72e (diff)
downloadmeshbay-8926f163dad9d32dc06c3a142658a4e11d9c12c1.tar.gz
refactor(hub): the transport holds an identity, never a private key
Two public keys, sign() and shared(); the apps take transport.signFn. What holds the keys (this page, or the desktop main process) is the identity's business alone. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub/static/transport-admin.js')
-rw-r--r--packages/meshbay-hub/src/meshbay_hub/static/transport-admin.js7
1 files changed, 3 insertions, 4 deletions
diff --git a/packages/meshbay-hub/src/meshbay_hub/static/transport-admin.js b/packages/meshbay-hub/src/meshbay_hub/static/transport-admin.js
index c7c3f47..d5226fc 100644
--- a/packages/meshbay-hub/src/meshbay_hub/static/transport-admin.js
+++ b/packages/meshbay-hub/src/meshbay_hub/static/transport-admin.js
@@ -17,7 +17,7 @@ extendTransport(class {
async pairOperator(userId, code) {
if (!this._connected) throw new Error('Not connected to the node');
if (!userId) throw new Error('Missing user id');
- if (!this._sessionKeys || !this._sessionKeys.skEdB64 || !this._sessionKeys.skXB64) {
+ if (!this._identity) {
throw new Error('Identity keys unavailable in this browser — sign in again');
}
if (!this._nonceNode || !this.nodePk) {
@@ -28,14 +28,13 @@ extendTransport(class {
// Both public keys are derived from OUR OWN secret keys, never read back from
// the hub: signing a public key the directory handed us would reintroduce the
// substitution this whole mechanism exists to close.
- const pkEdB64 = await _pkEdFromSk(this._sessionKeys.skEdB64);
- const pkXB64 = await _pkFromSk(this._sessionKeys.skXB64);
+ const { pkEdB64, pkXB64 } = this._identity;
const ts = Math.floor(Date.now() / 1000);
// group_id is empty: operator authority is node-wide, not per group.
const transcript = C.joinTranscript(
this.nodePk, '', userId, pkEdB64, pkXB64, this._nonceNode, ts);
- const sig = await window.MeshBayKeys.signBytes(this._sessionKeys.skEdB64, transcript);
+ const sig = await this._identity.sign(transcript);
const resp = await this._sendAndWait({
type: 'join_request',