aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-hub/src/meshbay_hub/static/transport-rewrap.js
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-09-30 16:58:31 +0200
committerChristophe Besson <cbesson@gmail.com>2026-09-30 16:58:31 +0200
commit6d167392f6f8ede37e2794a68a3738f8ba03131d (patch)
tree9caacef15dd034c6425f4bb623e0cd50a28ec52a /packages/meshbay-hub/src/meshbay_hub/static/transport-rewrap.js
parent8926f163dad9d32dc06c3a142658a4e11d9c12c1 (diff)
downloadmeshbay-6d167392f6f8ede37e2794a68a3738f8ba03131d.tar.gz
feat(client): the desktop application keeps M and every node identity in its main process
keyring.js derives, opens, mints, seals, signs and agrees there; the page gets public keys and a handle. Argon2 comes from the page's own WebAssembly build (Electron's crypto has none). Without OS key storage the page keeps its keys as a browser does. A node's bundle is settled after connecting, re-sealed when the key changed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub/static/transport-rewrap.js')
-rw-r--r--packages/meshbay-hub/src/meshbay_hub/static/transport-rewrap.js16
1 files changed, 16 insertions, 0 deletions
diff --git a/packages/meshbay-hub/src/meshbay_hub/static/transport-rewrap.js b/packages/meshbay-hub/src/meshbay_hub/static/transport-rewrap.js
index e0ae0fe..8bf884c 100644
--- a/packages/meshbay-hub/src/meshbay_hub/static/transport-rewrap.js
+++ b/packages/meshbay-hub/src/meshbay_hub/static/transport-rewrap.js
@@ -101,6 +101,22 @@ async function rewrapAllNodes(o) {
tp.connect(n.node_id, o.token, g.id, null, null, oldKey,
o.username, o.userId, null, recoveryKey, undefined, n.pk_node),
30000, 'connect');
+ if (tp.identity && tp.identity.native) {
+ // The desktop application holds this identity: it seals, and only
+ // for an account with browser access — without it, nothing of the
+ // identity is on the node to re-seal.
+ const P = window.MeshBayPlatform.keys;
+ if (await P.browserAccess(o.userId)) {
+ const sealed = await P.sealBundle(o.userId, tp.nodePk,
+ { pending: Boolean(o.newBundleKey && o.newBundleKey.pending) });
+ const rec = o.recoveryKey
+ ? await P.sealRecovery(o.userId, tp.nodePk, o.recoveryKey, o.username) : null;
+ await tp.storeKeypairBundle(sealed.bundle, rec);
+ await P.markSealed(o.userId, tp.nodePk, sealed.fingerprint);
+ }
+ anyOk = true;
+ continue;
+ }
if (tp.newNodeBundle) {
// No identity existed on this node — connect just minted one under
// the old key. Don't persist it: the next time this group is opened