aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-hub/src/meshbay_hub/static/transport-chat.js
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-09-30 21:04:39 +0200
committerChristophe Besson <cbesson@gmail.com>2026-09-30 21:04:39 +0200
commit0378e8e0912a1a7e6cea4424e69d524e7afecbf8 (patch)
tree4ae94e32d6638b4c2cc1ae4f74cbe5d00c940636 /packages/meshbay-hub/src/meshbay_hub/static/transport-chat.js
parent0ed56d3a1b4f71cf622d3e27edc87a15ef33c185 (diff)
downloadmeshbay-0378e8e0912a1a7e6cea4424e69d524e7afecbf8.tar.gz
fix: an identity signs a named kind, and a device approval answers a request
The desktop main process builds every transcript itself from fields (transcripts.js) and signs no raw bytes; the page's identity has the same contract (crypto.js transcriptFor). The keyring seals no bundle while browser access is off. On the node, device_add must redeem a pending request filed by the same keys, and device_revoke is signed under its own prefix (meshbay:device_revoke:v1), so a retirement signature admits nothing. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub/static/transport-chat.js')
-rw-r--r--packages/meshbay-hub/src/meshbay_hub/static/transport-chat.js7
1 files changed, 5 insertions, 2 deletions
diff --git a/packages/meshbay-hub/src/meshbay_hub/static/transport-chat.js b/packages/meshbay-hub/src/meshbay_hub/static/transport-chat.js
index f0604ce..e49eb4c 100644
--- a/packages/meshbay-hub/src/meshbay_hub/static/transport-chat.js
+++ b/packages/meshbay-hub/src/meshbay_hub/static/transport-chat.js
@@ -172,8 +172,11 @@ extendTransport(class {
const { nonce, ct } = await C.sealChat(
epochKey, gid, epoch, this.devicePk, plaintext);
const device = C.b64decode(this.devicePk);
- const sig = C.b64decode(await this._identity.sign(
- C.chatSigningTranscript(gid, epoch, device, nonce, ct)));
+ // The transcript names the signing device as this identity's own key,
+ // which is what `devicePk` is once the node has been told (device_hello).
+ const sig = C.b64decode(await this._identity.signAs('chat', {
+ groupId: gid, epoch, nonce: C.b64encode(nonce), ct: C.b64encode(ct),
+ }));
const msg = await this._sendAndWait({
type: 'chat_msg',