aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-hub/src/meshbay_hub
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-10-01 09:46:39 +0200
committerChristophe Besson <cbesson@gmail.com>2026-10-01 09:46:39 +0200
commit0d0898c656afb8c1faa9fa91ba525e8a3e6a34ee (patch)
treea74f7d7e651b981f84421f38f53d88084a544138 /packages/meshbay-hub/src/meshbay_hub
parent5b0cd92012bb162f6290fbfb97938f41cad81b7a (diff)
downloadmeshbay-0d0898c656afb8c1faa9fa91ba525e8a3e6a34ee.tar.gz
fix(node): how a hosted group admits people is the operator's, not the hub's
attach_group no longer copies join_policy and visibility from the hub's answer: they come with the operator's request (the desktop creation form, `group add --open`) and default to invite/private; the CLI says when the hub lists the group otherwise. Every string written into node.toml is escaped (toml_string) and read back through tomllib, so a group or folder name cannot write lines of its own (F-17). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub')
-rw-r--r--packages/meshbay-hub/src/meshbay_hub/static/create-group-page.js3
1 files changed, 3 insertions, 0 deletions
diff --git a/packages/meshbay-hub/src/meshbay_hub/static/create-group-page.js b/packages/meshbay-hub/src/meshbay_hub/static/create-group-page.js
index d4c2ab8..bdb3dbc 100644
--- a/packages/meshbay-hub/src/meshbay_hub/static/create-group-page.js
+++ b/packages/meshbay-hub/src/meshbay_hub/static/create-group-page.js
@@ -255,6 +255,9 @@ function CreateGroupWizard({ token, username, onCreated, onNodeLinked, allowPubl
name: name.trim(),
path: mainRoot.path,
writable: mainRoot.writable !== false,
+ // How people join is set on the node, from this form — the node does
+ // not take it from the hub.
+ joinPolicy,
};
await platform.node.op('attachGroup', attachBody);
await platform.node.op('reload');