diff options
| author | Christophe Besson <cbesson@gmail.com> | 2026-09-12 09:47:46 +0200 |
|---|---|---|
| committer | Christophe Besson <cbesson@gmail.com> | 2026-09-12 16:36:54 +0200 |
| commit | 7c3a1d6fd765ef0421d0f3d85e512e10ea2f6f87 (patch) | |
| tree | 00d05d94cbe1216085ffa94173b6643cd50c8b1e /packages/meshbay-hub/src | |
| parent | bf7ff9ec311660318c8562abe03ef4db62475c98 (diff) | |
| download | meshbay-7c3a1d6fd765ef0421d0f3d85e512e10ea2f6f87.tar.gz | |
docs: availability between members is a finding category
The first three reviews asked who can read what, who can impersonate whom,
and what a hostile node can forge. None asked what a legitimate but
misconfigured or careless member costs everyone else — which is the question
a group platform lives on, because every member was invited by someone who
trusted them and none of them is an attacker.
C2 had asked "can a node claim a group its owner is not in?" and the answer
was correctly no. Nobody had asked what happens when a node claims one its
owner *is* in but does not host, which is how a group went dark for all of
its members with its real host online throughout.
§13.5b is the register, AV1 to AV8. The lens, for anything reviewed from
here: a participant supplies input; if anyone other than the sender bears the
cost, there is a ceiling to write, and it goes on every path that writes the
state.
CLAUDE.md gets the working rule and the incident as a lesson, and the stale
path to sync-ui.js corrected — it lives under scripts/, not build/.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01T4YmK41VsEURWFdop4EEeT
Diffstat (limited to 'packages/meshbay-hub/src')
0 files changed, 0 insertions, 0 deletions